mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-09-29 18:16:43 +00:00
feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,747 @@
|
||||
{
|
||||
"schema_version": "0.5.0",
|
||||
"kind": "proxmenux.oci-template",
|
||||
"id": "image-archivebox",
|
||||
"status": "generated-review-required",
|
||||
"catalog_ui": {
|
||||
"title": {
|
||||
"en_US": "ArchiveBox"
|
||||
},
|
||||
"tagline": {
|
||||
"en_US": "Self-hosted internet archiving solution"
|
||||
},
|
||||
"description": {
|
||||
"en_US": "ArchiveBox is a powerful, self-hosted internet archiving solution that allows you to create your own personal archive of web pages, PDFs, videos, and more. It functions as a personal internet archive, saving content in multiple formats for long-term preservation.\n\nThe system consists of multiple components:\n- **ArchiveBox**: The main application providing the web interface and archiving capabilities\n- **Sonic**: A fast search backend for full-text search across archived content\n- **ArchiveBox Scheduler**: A background service for scheduled archiving tasks\n- **NoVNC**: A web-based VNC client for browser-based archiving\n\n**Key Features:**\n- Save web pages in multiple formats (HTML, PDF, screenshots, etc.)\n- Full-text search across all archived content\n- Scheduled archiving of websites and RSS feeds\n- Browser-based archiving with NoVNC\n- User authentication and access control\n- Extract and save media files (videos, audio, PDFs, etc.)\n\n**Learn More:**\n- [ArchiveBox Official Website](https://archivebox.io)\n- [ArchiveBox GitHub Repository](https://github.com/ArchiveBox/ArchiveBox)\n- [ArchiveBox Documentation](https://github.com/ArchiveBox/ArchiveBox/wiki)\n"
|
||||
},
|
||||
"category": "documents",
|
||||
"category_label": "Documents & Notes",
|
||||
"author": "ArchiveBox",
|
||||
"developer": "ArchiveBox",
|
||||
"icon": null,
|
||||
"thumbnail": null,
|
||||
"screenshots": [],
|
||||
"architectures": [
|
||||
"amd64"
|
||||
],
|
||||
"launch": {
|
||||
"scheme": "http",
|
||||
"port": 8000,
|
||||
"path": "/"
|
||||
},
|
||||
"website": "https://archivebox.io",
|
||||
"documentation": null,
|
||||
"repository": "https://hub.docker.com/r/archivebox/archivebox",
|
||||
"tips": [],
|
||||
"mini_changelog": [],
|
||||
"display_version": null,
|
||||
"updated_at": null,
|
||||
"hidden": true,
|
||||
"hidden_reason": "Pending multi-container adaptation; retained for future work"
|
||||
},
|
||||
"source": {
|
||||
"provider": "official",
|
||||
"repository": "https://hub.docker.com/r/archivebox/archivebox",
|
||||
"revision": "e27286fc551a27ebc617239ccf45d9f2e741c213adeed4f9fc37df676c1cf27c",
|
||||
"image_repository_url": "https://hub.docker.com/r/archivebox/archivebox",
|
||||
"readme_pushed_at": "2026-09-11T10:43:22Z",
|
||||
"compose_sha256": "e27286fc551a27ebc617239ccf45d9f2e741c213adeed4f9fc37df676c1cf27c",
|
||||
"generated_at": "2026-09-13T15:48:20+00:00"
|
||||
},
|
||||
"container_contract": {
|
||||
"service_name": "archivebox",
|
||||
"container_name": "archivebox",
|
||||
"image": {
|
||||
"reference": "archivebox/archivebox:latest",
|
||||
"registry": "docker.io",
|
||||
"repository": "archivebox/archivebox",
|
||||
"tag": "latest",
|
||||
"digest": null,
|
||||
"pull_policy": "resolve-selected-tag-to-architecture-digest-at-install"
|
||||
},
|
||||
"environment": [
|
||||
{
|
||||
"name": "ADMIN_USERNAME",
|
||||
"example": "archivebox",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "ADMIN_PASSWORD",
|
||||
"example": "${GENERATED_ADMIN_PASSWORD}",
|
||||
"required": true,
|
||||
"sensitive": true,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "ALLOWED_HOSTS",
|
||||
"example": "*",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "CSRF_TRUSTED_ORIGINS",
|
||||
"example": "*",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "PUBLIC_INDEX",
|
||||
"example": "True",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "PUBLIC_SNAPSHOTS",
|
||||
"example": "True",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "PUBLIC_ADD_VIEW",
|
||||
"example": "False",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "SEARCH_BACKEND_ENGINE",
|
||||
"example": "sonic",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "SEARCH_BACKEND_HOST_NAME",
|
||||
"example": "archivebox_sonic",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "docker-compose"
|
||||
},
|
||||
{
|
||||
"name": "SEARCH_BACKEND_PASSWORD",
|
||||
"example": "${GENERATED_SEARCH_BACKEND_PASSWORD}",
|
||||
"required": true,
|
||||
"sensitive": true,
|
||||
"source": "docker-compose"
|
||||
}
|
||||
],
|
||||
"volumes": [
|
||||
{
|
||||
"id": "volume-0",
|
||||
"container_path": "/data",
|
||||
"compose_source_example": "/DATA/AppData/$AppID/data",
|
||||
"read_only": false,
|
||||
"required": true,
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
],
|
||||
"default": "managed-volume",
|
||||
"managed_volume": {
|
||||
"backup": true,
|
||||
"default_size_gb": 8
|
||||
}
|
||||
}
|
||||
],
|
||||
"ports": [
|
||||
{
|
||||
"container_port": 8000,
|
||||
"published_example": 18010,
|
||||
"protocol": "tcp",
|
||||
"required": true,
|
||||
"proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat"
|
||||
}
|
||||
],
|
||||
"related_services": [
|
||||
{
|
||||
"name": "archivebox_scheduler",
|
||||
"image": "archivebox/archivebox:latest"
|
||||
},
|
||||
{
|
||||
"name": "archivebox_sonic",
|
||||
"image": "archivebox/sonic:latest"
|
||||
},
|
||||
{
|
||||
"name": "archivebox_novnc",
|
||||
"image": "theasp/novnc:latest"
|
||||
}
|
||||
],
|
||||
"restart": "unless-stopped",
|
||||
"stop_grace_period": null,
|
||||
"original_compose": "name: archivebox\nservices:\n archivebox:\n image: archivebox/archivebox:latest\n container_name: archivebox\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - archivebox_network\n depends_on:\n - archivebox_sonic\n ports:\n - target: 8000\n published: '18010'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n environment:\n - ADMIN_USERNAME=archivebox\n - ADMIN_PASSWORD=${GENERATED_ADMIN_PASSWORD}\n - ALLOWED_HOSTS=*\n - CSRF_TRUSTED_ORIGINS=*\n - PUBLIC_INDEX=True\n - PUBLIC_SNAPSHOTS=True\n - PUBLIC_ADD_VIEW=False\n - SEARCH_BACKEND_ENGINE=sonic\n - SEARCH_BACKEND_HOST_NAME=archivebox_sonic\n - SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}\n healthcheck:\n test:\n - CMD\n - wget\n - --no-verbose\n - --tries=1\n - --spider\n - http://localhost:8000\n interval: 1m\n timeout: 3s\n archivebox_scheduler:\n image: archivebox/archivebox:latest\n container_name: archivebox_scheduler\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - archivebox_network\n depends_on:\n - archivebox_sonic\n command:\n - schedule\n - --foreground\n - --update\n - --every=day\n environment:\n - TIMEOUT=120\n - SEARCH_BACKEND_ENGINE=sonic\n - SEARCH_BACKEND_HOST_NAME=archivebox_sonic\n - SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /data\n archivebox_sonic:\n image: archivebox/sonic:latest\n container_name: archivebox_sonic\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - archivebox_network\n expose:\n - 1491\n environment:\n - SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data/sonic\n target: /var/lib/sonic/store\n archivebox_novnc:\n image: theasp/novnc:latest\n container_name: archivebox_novnc\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - archivebox_network\n ports:\n - target: 8080\n published: '18082'\n protocol: tcp\n environment:\n - DISPLAY_WIDTH=1920\n - DISPLAY_HEIGHT=1080\n - RUN_XTERM=no\nnetworks:\n archivebox_network:\n driver: bridge\n"
|
||||
},
|
||||
"compose_stack": {
|
||||
"project_name": "archivebox",
|
||||
"deployment_model": "one-native-oci-lxc-per-compose-service",
|
||||
"user_experience": "single-application-install",
|
||||
"main_service": "archivebox",
|
||||
"service_count": 4,
|
||||
"services": [
|
||||
{
|
||||
"name": "archivebox_novnc",
|
||||
"image": "theasp/novnc:latest",
|
||||
"is_main": false,
|
||||
"role": "dependency",
|
||||
"vmid_offset": 1,
|
||||
"depends_on": [],
|
||||
"frontend_network": true,
|
||||
"private_network": true,
|
||||
"compose": {
|
||||
"image": "theasp/novnc:latest",
|
||||
"container_name": "archivebox_novnc",
|
||||
"deploy": {
|
||||
"resources": {
|
||||
"reservations": {
|
||||
"memory": "128M"
|
||||
}
|
||||
}
|
||||
},
|
||||
"restart": "unless-stopped",
|
||||
"networks": [
|
||||
"archivebox_network"
|
||||
],
|
||||
"ports": [
|
||||
{
|
||||
"target": 8080,
|
||||
"published": "18082",
|
||||
"protocol": "tcp"
|
||||
}
|
||||
],
|
||||
"environment": [
|
||||
"DISPLAY_WIDTH=1920",
|
||||
"DISPLAY_HEIGHT=1080",
|
||||
"RUN_XTERM=no"
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "archivebox_sonic",
|
||||
"image": "archivebox/sonic:latest",
|
||||
"is_main": false,
|
||||
"role": "dependency",
|
||||
"vmid_offset": 2,
|
||||
"depends_on": [],
|
||||
"frontend_network": false,
|
||||
"private_network": true,
|
||||
"compose": {
|
||||
"image": "archivebox/sonic:latest",
|
||||
"container_name": "archivebox_sonic",
|
||||
"deploy": {
|
||||
"resources": {
|
||||
"reservations": {
|
||||
"memory": "128M"
|
||||
}
|
||||
}
|
||||
},
|
||||
"restart": "unless-stopped",
|
||||
"networks": [
|
||||
"archivebox_network"
|
||||
],
|
||||
"expose": [
|
||||
1491
|
||||
],
|
||||
"environment": [
|
||||
"SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}"
|
||||
],
|
||||
"volumes": [
|
||||
{
|
||||
"type": "bind",
|
||||
"source": "/DATA/AppData/$AppID/data/sonic",
|
||||
"target": "/var/lib/sonic/store"
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "archivebox_scheduler",
|
||||
"image": "archivebox/archivebox:latest",
|
||||
"is_main": false,
|
||||
"role": "dependency",
|
||||
"vmid_offset": 3,
|
||||
"depends_on": [
|
||||
"archivebox_sonic"
|
||||
],
|
||||
"frontend_network": false,
|
||||
"private_network": true,
|
||||
"compose": {
|
||||
"image": "archivebox/archivebox:latest",
|
||||
"container_name": "archivebox_scheduler",
|
||||
"deploy": {
|
||||
"resources": {
|
||||
"reservations": {
|
||||
"memory": "128M"
|
||||
}
|
||||
}
|
||||
},
|
||||
"restart": "unless-stopped",
|
||||
"networks": [
|
||||
"archivebox_network"
|
||||
],
|
||||
"depends_on": [
|
||||
"archivebox_sonic"
|
||||
],
|
||||
"command": [
|
||||
"schedule",
|
||||
"--foreground",
|
||||
"--update",
|
||||
"--every=day"
|
||||
],
|
||||
"environment": [
|
||||
"TIMEOUT=120",
|
||||
"SEARCH_BACKEND_ENGINE=sonic",
|
||||
"SEARCH_BACKEND_HOST_NAME=archivebox_sonic",
|
||||
"SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}"
|
||||
],
|
||||
"volumes": [
|
||||
{
|
||||
"type": "bind",
|
||||
"source": "/DATA/AppData/$AppID/data",
|
||||
"target": "/data"
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"name": "archivebox",
|
||||
"image": "archivebox/archivebox:latest",
|
||||
"is_main": true,
|
||||
"role": "frontend",
|
||||
"vmid_offset": 0,
|
||||
"depends_on": [
|
||||
"archivebox_sonic"
|
||||
],
|
||||
"frontend_network": true,
|
||||
"private_network": true,
|
||||
"compose": {
|
||||
"image": "archivebox/archivebox:latest",
|
||||
"container_name": "archivebox",
|
||||
"deploy": {
|
||||
"resources": {
|
||||
"reservations": {
|
||||
"memory": "128M"
|
||||
}
|
||||
}
|
||||
},
|
||||
"restart": "unless-stopped",
|
||||
"networks": [
|
||||
"archivebox_network"
|
||||
],
|
||||
"depends_on": [
|
||||
"archivebox_sonic"
|
||||
],
|
||||
"ports": [
|
||||
{
|
||||
"target": 8000,
|
||||
"published": "18010",
|
||||
"protocol": "tcp"
|
||||
}
|
||||
],
|
||||
"volumes": [
|
||||
{
|
||||
"type": "bind",
|
||||
"source": "/DATA/AppData/$AppID/data",
|
||||
"target": "/data"
|
||||
}
|
||||
],
|
||||
"environment": [
|
||||
"ADMIN_USERNAME=archivebox",
|
||||
"ADMIN_PASSWORD=${GENERATED_ADMIN_PASSWORD}",
|
||||
"ALLOWED_HOSTS=*",
|
||||
"CSRF_TRUSTED_ORIGINS=*",
|
||||
"PUBLIC_INDEX=True",
|
||||
"PUBLIC_SNAPSHOTS=True",
|
||||
"PUBLIC_ADD_VIEW=False",
|
||||
"SEARCH_BACKEND_ENGINE=sonic",
|
||||
"SEARCH_BACKEND_HOST_NAME=archivebox_sonic",
|
||||
"SEARCH_BACKEND_PASSWORD=${GENERATED_SEARCH_BACKEND_PASSWORD}"
|
||||
],
|
||||
"healthcheck": {
|
||||
"test": [
|
||||
"CMD",
|
||||
"wget",
|
||||
"--no-verbose",
|
||||
"--tries=1",
|
||||
"--spider",
|
||||
"http://localhost:8000"
|
||||
],
|
||||
"interval": "1m",
|
||||
"timeout": "3s"
|
||||
}
|
||||
}
|
||||
}
|
||||
],
|
||||
"top_level": {
|
||||
"name": "archivebox",
|
||||
"networks": {
|
||||
"archivebox_network": {
|
||||
"driver": "bridge"
|
||||
}
|
||||
}
|
||||
},
|
||||
"networking": {
|
||||
"frontend": "selected-proxmox-bridge",
|
||||
"private_required": true,
|
||||
"private_creation": "automatic-create-if-missing",
|
||||
"private_address_allocation": "automatic-static-address-per-service",
|
||||
"service_discovery": "private-addresses-with-compose-service-host-aliases",
|
||||
"dependency_external_access": "disabled-unless-service-publishes-ports",
|
||||
"prompt_user_for_private_network": false
|
||||
},
|
||||
"storage": [
|
||||
{
|
||||
"id": "archivebox-volume-0",
|
||||
"service": "archivebox",
|
||||
"container_path": "/data",
|
||||
"mode": "host-bind",
|
||||
"user_selectable": true,
|
||||
"backup": false,
|
||||
"shared_with_other_lxc": true,
|
||||
"source_path": null,
|
||||
"source_path_prompt": "Host directory for archivebox:/data"
|
||||
},
|
||||
{
|
||||
"id": "archivebox-scheduler-volume-0",
|
||||
"service": "archivebox_scheduler",
|
||||
"container_path": "/data",
|
||||
"mode": "host-bind",
|
||||
"user_selectable": true,
|
||||
"backup": false,
|
||||
"shared_with_other_lxc": true,
|
||||
"source_path": null,
|
||||
"source_path_prompt": "Host directory for archivebox_scheduler:/data"
|
||||
},
|
||||
{
|
||||
"id": "archivebox-sonic-volume-0",
|
||||
"service": "archivebox_sonic",
|
||||
"container_path": "/var/lib/sonic/store",
|
||||
"mode": "managed-volume",
|
||||
"user_selectable": false,
|
||||
"backup": true,
|
||||
"shared_with_other_lxc": false,
|
||||
"source_path": null,
|
||||
"source_path_prompt": null
|
||||
}
|
||||
],
|
||||
"orchestration": {
|
||||
"reserve_vmids_atomically": 4,
|
||||
"start_order": [
|
||||
"archivebox_novnc",
|
||||
"archivebox_sonic",
|
||||
"archivebox_scheduler",
|
||||
"archivebox"
|
||||
],
|
||||
"stop_order": [
|
||||
"archivebox",
|
||||
"archivebox_scheduler",
|
||||
"archivebox_sonic",
|
||||
"archivebox_novnc"
|
||||
],
|
||||
"dependency_readiness": "compose-healthcheck-then-port-or-process-fallback",
|
||||
"rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes"
|
||||
},
|
||||
"installer_inputs": {
|
||||
"prompted": [
|
||||
"stack_name",
|
||||
"base_vmid",
|
||||
"rootfs_storage",
|
||||
"persistent_data_destinations",
|
||||
"frontend_bridge",
|
||||
"frontend_ipv4_mode"
|
||||
],
|
||||
"automatic": [
|
||||
"dependent_vmids",
|
||||
"private_bridge",
|
||||
"private_subnet",
|
||||
"private_service_addresses",
|
||||
"compose_service_aliases",
|
||||
"generated_secrets",
|
||||
"dependency_start_and_stop_order"
|
||||
],
|
||||
"generated_secrets": [
|
||||
{
|
||||
"id": "admin-password",
|
||||
"strategy": "generate-cryptographically-random-at-install",
|
||||
"bindings": [
|
||||
{
|
||||
"service": "archivebox",
|
||||
"environment_variable": "ADMIN_PASSWORD"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "search-backend-password",
|
||||
"strategy": "generate-cryptographically-random-at-install",
|
||||
"bindings": [
|
||||
{
|
||||
"service": "archivebox",
|
||||
"environment_variable": "SEARCH_BACKEND_PASSWORD"
|
||||
},
|
||||
{
|
||||
"service": "archivebox_scheduler",
|
||||
"environment_variable": "SEARCH_BACKEND_PASSWORD"
|
||||
},
|
||||
{
|
||||
"service": "archivebox_sonic",
|
||||
"environment_variable": "SEARCH_BACKEND_PASSWORD"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"first_run": {
|
||||
"endpoints": [
|
||||
{
|
||||
"label": "Web UI",
|
||||
"scheme": "http",
|
||||
"port": 8000,
|
||||
"path": "/",
|
||||
"source": "compose-metadata"
|
||||
}
|
||||
],
|
||||
"credentials": []
|
||||
},
|
||||
"proxmox": {
|
||||
"runtime": "native-oci-lxc",
|
||||
"technology_status": "proxmox-technology-preview",
|
||||
"defaults": {
|
||||
"unprivileged": true,
|
||||
"ostype": "auto-from-image",
|
||||
"cores": 2,
|
||||
"memory_mb": 128,
|
||||
"swap_mb": 512,
|
||||
"rootfs_size_gb": 8,
|
||||
"rootfs_storage": "local-lvm",
|
||||
"volume_storage": "local-lvm",
|
||||
"template_storage": "local",
|
||||
"bridge": "vmbr0",
|
||||
"ipv4": "dhcp",
|
||||
"firewall": true,
|
||||
"host_managed_network": true,
|
||||
"onboot": false,
|
||||
"features": [
|
||||
"nesting=1"
|
||||
],
|
||||
"shutdown_timeout_seconds": 30
|
||||
},
|
||||
"image_metadata_policy": {
|
||||
"entrypoint": "import-from-oci-image",
|
||||
"cmd": "import-from-oci-image",
|
||||
"environment": "import-image-env-then-apply-compose-overrides",
|
||||
"user": "import-from-oci-image",
|
||||
"working_dir": "import-from-oci-image",
|
||||
"stop_signal": "import-from-oci-image"
|
||||
},
|
||||
"installer_profile": {
|
||||
"startup_healthcheck": {
|
||||
"type": "http",
|
||||
"scheme": "http",
|
||||
"port": 8000,
|
||||
"path": "/",
|
||||
"timeout_seconds": 180,
|
||||
"request_timeout_seconds": 3,
|
||||
"stability_seconds": 0,
|
||||
"verify_tls": true,
|
||||
"required": true,
|
||||
"source": "compose-healthcheck"
|
||||
}
|
||||
},
|
||||
"adaptations": [
|
||||
{
|
||||
"id": "imported-compose-source",
|
||||
"upstream_behavior": "The source definition deploys the complete Docker Compose application model.",
|
||||
"native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.",
|
||||
"reason": "Catalog import must not imply runtime compatibility.",
|
||||
"behavioral_impact": "No automatic installation before review.",
|
||||
"validation": "pending-per-application"
|
||||
},
|
||||
{
|
||||
"id": "rolling-latest-image",
|
||||
"upstream_behavior": "A discovered Compose may pin a release tag or digest.",
|
||||
"native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.",
|
||||
"reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.",
|
||||
"behavioral_impact": "The installed release can be newer than the discovered Compose revision.",
|
||||
"validation": "pending-per-application"
|
||||
},
|
||||
{
|
||||
"id": "dedicated-lxc-network",
|
||||
"upstream_behavior": "Docker publishes selected container ports on the Docker host.",
|
||||
"native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.",
|
||||
"reason": "A native LXC has its own address and does not require Docker port NAT.",
|
||||
"behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.",
|
||||
"validation": "pending-per-application"
|
||||
},
|
||||
{
|
||||
"id": "compose-shm-size",
|
||||
"upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.",
|
||||
"native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.",
|
||||
"reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.",
|
||||
"behavioral_impact": "None expected.",
|
||||
"validation": "not-requested-by-compose"
|
||||
},
|
||||
{
|
||||
"id": "compose-command",
|
||||
"upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.",
|
||||
"native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.",
|
||||
"reason": "Proxmox stores the effective OCI process as one entrypoint string.",
|
||||
"behavioral_impact": "None expected.",
|
||||
"validation": "not-requested-by-compose"
|
||||
},
|
||||
{
|
||||
"id": "compose-privileged-mode",
|
||||
"upstream_behavior": "Compose selects whether the container runs in privileged mode.",
|
||||
"native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.",
|
||||
"reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.",
|
||||
"behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.",
|
||||
"validation": "native-equivalent"
|
||||
},
|
||||
{
|
||||
"id": "compose-process-runtime",
|
||||
"upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.",
|
||||
"native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.",
|
||||
"reason": "The OCI process must start with the same identity, command and working directory without Docker.",
|
||||
"behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.",
|
||||
"validation": "not-requested-by-compose"
|
||||
},
|
||||
{
|
||||
"id": "compose-healthcheck",
|
||||
"upstream_behavior": "Docker periodically executes the declared container healthcheck.",
|
||||
"native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.",
|
||||
"reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.",
|
||||
"behavioral_impact": "The check runs during installation rather than continuously after installation.",
|
||||
"validation": "pending-per-application"
|
||||
},
|
||||
{
|
||||
"id": "compose-cpu-priority",
|
||||
"upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.",
|
||||
"native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.",
|
||||
"reason": "Both settings express relative CPU priority on different scales.",
|
||||
"behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.",
|
||||
"validation": "not-requested-by-compose"
|
||||
},
|
||||
{
|
||||
"id": "compose-network-identity",
|
||||
"upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.",
|
||||
"native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.",
|
||||
"reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.",
|
||||
"behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.",
|
||||
"validation": "pending-per-application"
|
||||
},
|
||||
{
|
||||
"id": "compose-network-mode",
|
||||
"upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.",
|
||||
"native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.",
|
||||
"reason": "The LXC is the application host and already has its own address and port namespace.",
|
||||
"behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.",
|
||||
"validation": "not-requested-by-compose"
|
||||
},
|
||||
{
|
||||
"id": "compose-capabilities-and-sysctls",
|
||||
"upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.",
|
||||
"native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.",
|
||||
"reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.",
|
||||
"behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.",
|
||||
"validation": "not-requested-by-compose"
|
||||
},
|
||||
{
|
||||
"id": "docker-engine-metadata",
|
||||
"upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.",
|
||||
"native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.",
|
||||
"reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.",
|
||||
"behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.",
|
||||
"validation": "not-requested-by-compose"
|
||||
},
|
||||
{
|
||||
"id": "compose-device-passthrough",
|
||||
"upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.",
|
||||
"native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.",
|
||||
"reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.",
|
||||
"behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.",
|
||||
"validation": "not-requested-by-compose"
|
||||
},
|
||||
{
|
||||
"id": "compose-host-ipc",
|
||||
"upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.",
|
||||
"native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.",
|
||||
"reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.",
|
||||
"behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.",
|
||||
"validation": "not-requested-by-compose"
|
||||
}
|
||||
],
|
||||
"generic_stack_review": [
|
||||
"archivebox_novnc: perfil de salud y persistencia pendiente",
|
||||
"archivebox_scheduler: perfil de salud y persistencia pendiente",
|
||||
"archivebox_sonic: perfil de salud y persistencia pendiente",
|
||||
"volumen compartido entre servicios pendiente"
|
||||
]
|
||||
},
|
||||
"compatibility": {
|
||||
"automatic_install_candidate": false,
|
||||
"validated": false,
|
||||
"supported_compose_keys": [
|
||||
"cap_add",
|
||||
"command",
|
||||
"container_name",
|
||||
"cpu_shares",
|
||||
"deploy",
|
||||
"devices",
|
||||
"entrypoint",
|
||||
"environment",
|
||||
"extra_hosts",
|
||||
"healthcheck",
|
||||
"hostname",
|
||||
"image",
|
||||
"init",
|
||||
"ipc",
|
||||
"labels",
|
||||
"logging",
|
||||
"mac_address",
|
||||
"network_mode",
|
||||
"networks",
|
||||
"ports",
|
||||
"privileged",
|
||||
"restart",
|
||||
"runtime",
|
||||
"shm_size",
|
||||
"stdin_open",
|
||||
"stop_grace_period",
|
||||
"sysctls",
|
||||
"tty",
|
||||
"user",
|
||||
"volumes",
|
||||
"working_dir"
|
||||
],
|
||||
"untranslated_blockers": [
|
||||
"multi-service-compose",
|
||||
"compose-key:depends_on",
|
||||
"service:archivebox_scheduler:compose-key:depends_on",
|
||||
"service:archivebox_sonic:compose-key:expose",
|
||||
"native-multi-lxc-orchestrator-not-yet-implemented"
|
||||
],
|
||||
"policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available."
|
||||
},
|
||||
"validation": {
|
||||
"schema": "passed-at-generation",
|
||||
"clean_install": "pending",
|
||||
"service_health": "pending",
|
||||
"restart_persistence": "pending",
|
||||
"backup_restore": "pending",
|
||||
"update_preserves_data": "pending"
|
||||
},
|
||||
"lifecycle": {
|
||||
"update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update",
|
||||
"registry_state": {
|
||||
"resolved_architecture": null,
|
||||
"resolved_digest": null,
|
||||
"image_version_label": null,
|
||||
"image_created": null
|
||||
},
|
||||
"change_detection": "compare-compose-sha256-and-resolved-latest-image-digest",
|
||||
"automatic_unattended_updates": false
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user