feat(oci): run official container images as native LXC containers

Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
MacRimi
2026-09-22 18:24:59 +02:00
co-authored by Claude Opus 5
parent b36498f215
commit bcabcb618c
670 changed files with 221410 additions and 215 deletions
+78 -1
View File
@@ -421,6 +421,22 @@ class HealthPersistence:
)
''')
cursor.execute('CREATE INDEX IF NOT EXISTS idx_excluded_interface ON excluded_interfaces(interface_name)')
# Disks the user wants left alone: no periodic SMART or temperature
# reads, so a drive can reach its own spin-down and stop cycling its
# heads. Keyed by a stable identity rather than the kernel name, which
# a USB drive can change (sda -> sdb) on every reconnection.
cursor.execute('''
CREATE TABLE IF NOT EXISTS excluded_disks (
id INTEGER PRIMARY KEY AUTOINCREMENT,
disk_key TEXT UNIQUE NOT NULL,
disk_name TEXT,
model TEXT,
serial TEXT,
excluded_at TEXT NOT NULL,
reason TEXT
)
''')
conn.commit()
@@ -430,7 +446,7 @@ class HealthPersistence:
required_tables = {'errors', 'events', 'system_capabilities', 'user_settings',
'notification_history', 'notification_last_sent', 'notification_delivery_claims',
'disk_registry', 'disk_observations',
'excluded_storages', 'excluded_interfaces'}
'excluded_storages', 'excluded_interfaces', 'excluded_disks'}
missing = required_tables - tables
if missing:
print(f"[HealthPersistence] WARNING: Missing tables after init: {missing}")
@@ -3257,6 +3273,67 @@ class HealthPersistence:
print(f"[HealthPersistence] Error removing interface exclusion: {e}")
return False
# ------------------------------------------------------------------
# Disk exclusions
# ------------------------------------------------------------------
def get_excluded_disks(self) -> List[Dict[str, Any]]:
"""Every disk the user has excluded from periodic reads."""
try:
with self._db_connection(row_factory=True) as conn:
cursor = conn.cursor()
cursor.execute('''
SELECT disk_key, disk_name, model, serial, excluded_at, reason
FROM excluded_disks
''')
return [dict(row) for row in cursor.fetchall()]
except Exception as e:
print(f"[HealthPersistence] Error getting excluded disks: {e}")
return []
def exclude_disk(self, disk_key: str, disk_name: str = None, model: str = None,
serial: str = None, reason: str = None) -> bool:
"""Add a disk to the exclusion list, or refresh its display fields."""
try:
with self._db_connection() as conn:
cursor = conn.cursor()
cursor.execute('''
INSERT INTO excluded_disks
(disk_key, disk_name, model, serial, excluded_at, reason)
VALUES (?, ?, ?, ?, ?, ?)
ON CONFLICT(disk_key) DO UPDATE SET
disk_name = excluded.disk_name,
model = excluded.model,
serial = excluded.serial
''', (disk_key, disk_name, model, serial, datetime.now().isoformat(), reason))
conn.commit()
return True
except Exception as e:
print(f"[HealthPersistence] Error excluding disk: {e}")
return False
def remove_disk_exclusion(self, disk_key: str) -> bool:
"""Put a disk back under periodic reads."""
try:
with self._db_connection() as conn:
cursor = conn.cursor()
cursor.execute('DELETE FROM excluded_disks WHERE disk_key = ?', (disk_key,))
conn.commit()
return cursor.rowcount > 0
except Exception as e:
print(f"[HealthPersistence] Error removing disk exclusion: {e}")
return False
def get_excluded_disk_keys(self) -> set:
"""Stable keys of the excluded disks (see disk_identity.disk_key)."""
try:
with self._db_connection() as conn:
cursor = conn.cursor()
cursor.execute('SELECT disk_key FROM excluded_disks')
return {row[0] for row in cursor.fetchall()}
except Exception:
return set()
def get_excluded_interface_names(self, check_type: str = 'health') -> set:
"""
Get set of interface names excluded for a specific check type.