feat(oci): run official container images as native LXC containers

Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
MacRimi
2026-09-22 18:24:59 +02:00
co-authored by Claude Opus 5
parent b36498f215
commit bcabcb618c
670 changed files with 221410 additions and 215 deletions
+29 -17
View File
@@ -208,7 +208,7 @@
"notApplicable": "n / A",
"error": "Fehler",
"system": "System",
"standby": "Stehen zu",
"standby": "Standby",
"standbyTitle": "Das Laufwerk befindet sich im Standby-Modus – Smartctl wurde übersprungen, um es im Ruhezustand zu halten",
"filesystemCorruption": "Dateisystembeschädigung erkannt",
"ioErrorOne": "{count} E/A-Fehler in 5 Min",
@@ -2206,7 +2206,7 @@
"password": "Passwort",
"usernamePlaceholder": "Geben Sie Ihren Benutzernamen ein",
"passwordPlaceholder": "Geben Sie Ihr Passwort ein",
"rememberMe": "Erinnere dich an mich",
"rememberMe": "Anmeldedaten merken",
"missingCredentials": "Bitte geben Sie Benutzernamen und Passwort ein",
"missingTotp": "Bitte geben Sie Ihren 2FA-Code ein",
"invalidCredentials": "Falscher Benutzername oder Passwort",
@@ -3396,7 +3396,7 @@
},
"roles": {
"active": "aktiv",
"standby": "stehen zu",
"standby": "Standby",
"down": "runter"
},
"empty": {
@@ -5208,6 +5208,9 @@
"noFindings": "No findings match the current filter.",
"affectedCount": "{count} affected",
"acceptedNotice": "{count} accepted risk(s) recorded on this host.",
"reviewOn": "Überprüfen am: {when}",
"reviewDue": "Zur Überprüfung fällig — die Entscheidung gilt weiter",
"reviewDueNotice": "{count} akzeptierte Entscheidung(en) stehen zur Überprüfung an.",
"states": {
"fail": "Failed",
"warn": "Warning",
@@ -5228,6 +5231,8 @@
},
"detail": {
"why": "Context",
"whatItMeans": "Was das bedeutet",
"whatToDo": "Was zu tun ist",
"evidence": "Evidence",
"affected": "Affected",
"acceptedRisk": "Accepted risk",
@@ -5674,20 +5679,23 @@
},
"summaryFallback": "The check could not be evaluated",
"acceptRisk": {
"action": "Accept risk",
"revoke": "Return to active",
"title": "Accept this risk",
"reasonLabel": "Reason",
"reasonHelp": "Required. It is recorded together with the author and the date.",
"reasonPlaceholder": "e.g. Lab containers, not covered on purpose",
"expiryLabel": "Review after",
"expiryHelp": "When the period ends the finding becomes active again.",
"expiryNever": "Does not expire",
"expiry90": "90 days",
"expiry180": "180 days",
"expiry365": "1 year",
"cancel": "Cancel",
"confirm": "Accept risk"
"action": "Risiko akzeptieren",
"revoke": "Wieder aktivieren",
"title": "Dieses Risiko akzeptieren",
"reasonLabel": "Begründung",
"reasonHelp": "Erforderlich. Sie wird zusammen mit Urheber und Datum festgehalten.",
"reasonPlaceholder": "z. B. Labor-Container, absichtlich nicht abgedeckt",
"expiryLabel": "Gilt nicht mehr nach",
"expiryHelp": "Nach Ablauf des Zeitraums wird der Befund wieder aktiv.",
"expiryNever": "Läuft nicht ab",
"reviewLabel": "An Überprüfung erinnern",
"reviewHelp": "Die Entscheidung gilt weiter; sie wird nur wieder in Erinnerung gerufen.",
"reviewNever": "Keine Erinnerung",
"expiry90": "90 Tage",
"expiry180": "180 Tage",
"expiry365": "1 Jahr",
"cancel": "Abbrechen",
"confirm": "Risiko akzeptieren"
},
"incomplete": "Unvollständige Nachweise",
"progress": "{completed} von {total} geprüft",
@@ -6085,6 +6093,10 @@
"unchanged": "{count} Prüfungen ergaben dasselbe wie zuvor.",
"new": "Neu",
"newNote": "jetzt gemeldet, vorher nicht",
"worse": "Verschlechtert",
"worseNote": "weiterhin gemeldet, und schwerwiegender oder weiter reichend als zuvor",
"better": "Verbessert",
"betterNote": "weiterhin gemeldet, aber weniger schwerwiegend oder weniger weit reichend als zuvor",
"resolved": "Behoben",
"resolvedNote": "nicht mehr gemeldet, und niemand hat sie akzeptiert",
"accepted": "Akzeptiert",