mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-10-07 22:16:39 +00:00
feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,455 @@
|
||||
{
|
||||
"schema_version": "0.5.0",
|
||||
"kind": "proxmenux.oci-template",
|
||||
"id": "image-makemkv",
|
||||
"status": "generated-unvalidated",
|
||||
"catalog_ui": {
|
||||
"title": {
|
||||
"en_US": "MakeMKV"
|
||||
},
|
||||
"tagline": {
|
||||
"en_US": "Rip DVD and Blu-ray media from a browser"
|
||||
},
|
||||
"description": {
|
||||
"en_US": "The maintained jlesage MakeMKV image with persistent settings, shared input/output storage and optional native optical-drive passthrough."
|
||||
},
|
||||
"category": "media",
|
||||
"category_label": "Media & Streaming",
|
||||
"author": "jlesage",
|
||||
"developer": "jlesage",
|
||||
"icon": null,
|
||||
"thumbnail": null,
|
||||
"screenshots": [],
|
||||
"architectures": [
|
||||
"amd64",
|
||||
"arm64"
|
||||
],
|
||||
"launch": {
|
||||
"scheme": "http",
|
||||
"port": 5800,
|
||||
"path": "/"
|
||||
},
|
||||
"website": "https://github.com/jlesage/docker-makemkv",
|
||||
"documentation": "https://github.com/jlesage/docker-makemkv",
|
||||
"repository": "https://github.com/jlesage/docker-makemkv",
|
||||
"tips": [
|
||||
"To read an optical drive, select the /dev/sgX that matches the drive; /dev/srX is optional but improves performance.",
|
||||
"The /storage library is mounted read-only and /output read/write."
|
||||
],
|
||||
"mini_changelog": [],
|
||||
"display_version": null,
|
||||
"updated_at": "2026-08-26"
|
||||
},
|
||||
"source": {
|
||||
"provider": "jlesage",
|
||||
"repository": "https://github.com/jlesage/docker-makemkv",
|
||||
"default_branch": "master",
|
||||
"revision": "63373b8a76faeae246d73c5b070e8d97a2d018c5",
|
||||
"readme_raw_url": "https://raw.githubusercontent.com/jlesage/docker-makemkv/master/README.md",
|
||||
"image_repository_url": "https://hub.docker.com/r/jlesage/makemkv",
|
||||
"readme_pushed_at": "2026-08-26T22:06:48Z",
|
||||
"compose_sha256": "18936fa4593769be1a8bc9a81c05b35e4f905746b10e772749936c637d9a3f36",
|
||||
"generated_at": "2026-09-14T15:24:39+00:00"
|
||||
},
|
||||
"container_contract": {
|
||||
"service_name": "makemkv",
|
||||
"container_name": "makemkv",
|
||||
"image": {
|
||||
"reference": "jlesage/makemkv:latest",
|
||||
"registry": "docker.io",
|
||||
"repository": "jlesage/makemkv",
|
||||
"tag": "latest",
|
||||
"digest": null,
|
||||
"pull_policy": "resolve-selected-tag-to-architecture-digest-at-install"
|
||||
},
|
||||
"environment": [
|
||||
{
|
||||
"name": "USER_ID",
|
||||
"example": "1000",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "upstream-documentation"
|
||||
},
|
||||
{
|
||||
"name": "GROUP_ID",
|
||||
"example": "1000",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "upstream-documentation"
|
||||
},
|
||||
{
|
||||
"name": "TZ",
|
||||
"example": "Europe/Madrid",
|
||||
"required": true,
|
||||
"sensitive": false,
|
||||
"source": "upstream-documentation"
|
||||
},
|
||||
{
|
||||
"name": "SUP_GROUP_IDS",
|
||||
"example": null,
|
||||
"required": false,
|
||||
"sensitive": false,
|
||||
"source": "upstream-documentation",
|
||||
"prompt_user": false
|
||||
}
|
||||
],
|
||||
"volumes": [
|
||||
{
|
||||
"id": "config",
|
||||
"container_path": "/config",
|
||||
"compose_source_example": "makemkv-config",
|
||||
"read_only": false,
|
||||
"required": true,
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
],
|
||||
"default": "managed-volume",
|
||||
"managed_volume": {
|
||||
"backup": true,
|
||||
"default_size_gb": 4
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "storage",
|
||||
"container_path": "/storage",
|
||||
"compose_source_example": "/mnt/oci-shared/media",
|
||||
"read_only": true,
|
||||
"required": true,
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
],
|
||||
"default": "host-bind",
|
||||
"managed_volume": {
|
||||
"backup": true,
|
||||
"default_size_gb": 32
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "output",
|
||||
"container_path": "/output",
|
||||
"compose_source_example": "/mnt/oci-shared/makemkv/output",
|
||||
"read_only": false,
|
||||
"required": true,
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
],
|
||||
"default": "host-bind",
|
||||
"managed_volume": {
|
||||
"backup": true,
|
||||
"default_size_gb": 32
|
||||
}
|
||||
}
|
||||
],
|
||||
"ports": [
|
||||
{
|
||||
"container_port": 5800,
|
||||
"published_example": 5800,
|
||||
"protocol": "tcp",
|
||||
"required": true,
|
||||
"proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat"
|
||||
}
|
||||
],
|
||||
"related_services": [],
|
||||
"restart": "unless-stopped",
|
||||
"stop_grace_period": null,
|
||||
"original_compose": "{\n \"services\": {\n \"makemkv\": {\n \"image\": \"jlesage/makemkv:latest\",\n \"ports\": [\n \"5800:5800\"\n ],\n \"environment\": {\n \"USER_ID\": \"1000\",\n \"GROUP_ID\": \"1000\",\n \"TZ\": \"Europe/Madrid\"\n },\n \"volumes\": [\n \"makemkv-config:/config\",\n \"/mnt/oci-shared/media:/storage:ro\",\n \"/mnt/oci-shared/makemkv/output:/output\"\n ],\n \"restart\": \"unless-stopped\"\n }\n }\n}"
|
||||
},
|
||||
"compose_stack": {
|
||||
"project_name": "makemkv",
|
||||
"deployment_model": "one-native-oci-lxc-per-compose-service",
|
||||
"user_experience": "single-application-install",
|
||||
"main_service": "makemkv",
|
||||
"service_count": 1,
|
||||
"services": [
|
||||
{
|
||||
"name": "makemkv",
|
||||
"image": "jlesage/makemkv:latest",
|
||||
"is_main": true,
|
||||
"role": "frontend",
|
||||
"vmid_offset": 0,
|
||||
"depends_on": [],
|
||||
"frontend_network": true,
|
||||
"private_network": false,
|
||||
"compose": {
|
||||
"image": "jlesage/makemkv:latest",
|
||||
"ports": [
|
||||
"5800:5800"
|
||||
],
|
||||
"environment": {
|
||||
"USER_ID": "1000",
|
||||
"GROUP_ID": "1000",
|
||||
"TZ": "Europe/Madrid"
|
||||
},
|
||||
"volumes": [
|
||||
"makemkv-config:/config",
|
||||
"/mnt/oci-shared/media:/storage:ro",
|
||||
"/mnt/oci-shared/makemkv/output:/output"
|
||||
],
|
||||
"restart": "unless-stopped"
|
||||
}
|
||||
}
|
||||
],
|
||||
"top_level": {},
|
||||
"networking": {
|
||||
"frontend": "selected-proxmox-bridge",
|
||||
"private_required": false,
|
||||
"private_creation": "not-required",
|
||||
"private_address_allocation": "not-required",
|
||||
"service_discovery": "dedicated-lxc-address",
|
||||
"dependency_external_access": "not-applicable",
|
||||
"prompt_user_for_private_network": false
|
||||
},
|
||||
"storage": [
|
||||
{
|
||||
"id": "makemkv-config",
|
||||
"service": "makemkv",
|
||||
"container_path": "/config",
|
||||
"mode": "user-selectable",
|
||||
"user_selectable": true,
|
||||
"backup": true,
|
||||
"shared_with_other_lxc": false,
|
||||
"default": "managed-volume",
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "makemkv-storage",
|
||||
"service": "makemkv",
|
||||
"container_path": "/storage",
|
||||
"mode": "user-selectable",
|
||||
"user_selectable": true,
|
||||
"backup": true,
|
||||
"shared_with_other_lxc": true,
|
||||
"default": "host-bind",
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "makemkv-output",
|
||||
"service": "makemkv",
|
||||
"container_path": "/output",
|
||||
"mode": "user-selectable",
|
||||
"user_selectable": true,
|
||||
"backup": true,
|
||||
"shared_with_other_lxc": true,
|
||||
"default": "host-bind",
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
]
|
||||
}
|
||||
],
|
||||
"orchestration": {
|
||||
"reserve_vmids_atomically": 1,
|
||||
"start_order": [
|
||||
"makemkv"
|
||||
],
|
||||
"stop_order": [
|
||||
"makemkv"
|
||||
],
|
||||
"dependency_readiness": "mandatory-http-first-start-healthcheck",
|
||||
"rollback_on_failure": "remove-new-rootfs-preserve-external-host-data"
|
||||
},
|
||||
"installer_inputs": {
|
||||
"prompted": [
|
||||
"base_vmid",
|
||||
"rootfs_storage",
|
||||
"persistent_data_destinations",
|
||||
"frontend_bridge",
|
||||
"frontend_ipv4_mode"
|
||||
],
|
||||
"automatic": [
|
||||
"image_digest_resolution",
|
||||
"managed_volume_preparation"
|
||||
],
|
||||
"generated_secrets": []
|
||||
}
|
||||
},
|
||||
"proxmox": {
|
||||
"runtime": "native-oci-lxc",
|
||||
"technology_status": "proxmox-technology-preview",
|
||||
"catalog": {
|
||||
"replaces_discovered_ids": [
|
||||
"makemkv"
|
||||
]
|
||||
},
|
||||
"defaults": {
|
||||
"unprivileged": true,
|
||||
"ostype": "auto-from-image",
|
||||
"cores": 2,
|
||||
"memory_mb": 2048,
|
||||
"swap_mb": 512,
|
||||
"rootfs_size_gb": 8,
|
||||
"rootfs_storage": "local-lvm",
|
||||
"volume_storage": "local-lvm",
|
||||
"template_storage": "local",
|
||||
"bridge": "vmbr0",
|
||||
"ipv4": "dhcp",
|
||||
"firewall": true,
|
||||
"host_managed_network": true,
|
||||
"onboot": false,
|
||||
"features": [
|
||||
"nesting=1"
|
||||
],
|
||||
"shutdown_timeout_seconds": 30
|
||||
},
|
||||
"image_metadata_policy": {
|
||||
"entrypoint": "import-from-oci-image",
|
||||
"cmd": "import-from-oci-image",
|
||||
"environment": "import-image-env-then-apply-compose-overrides",
|
||||
"user": "import-from-oci-image",
|
||||
"working_dir": "import-from-oci-image",
|
||||
"stop_signal": "import-from-oci-image"
|
||||
},
|
||||
"adaptations": [
|
||||
{
|
||||
"id": "native-persistent-volumes",
|
||||
"upstream_behavior": "Docker bind mounts persistent directories into the image.",
|
||||
"native_lxc_behavior": "ProxMenux attaches native Proxmox volumes or explicit host bind mounts at the same container paths.",
|
||||
"reason": "Preserve the official image contract while making persistence visible to Proxmox backup policy.",
|
||||
"behavioral_impact": "None expected.",
|
||||
"validation": "pending-clean-install"
|
||||
},
|
||||
{
|
||||
"id": "native-device-passthrough",
|
||||
"upstream_behavior": "Docker exposes explicitly selected host devices to the container.",
|
||||
"native_lxc_behavior": "ProxMenux maps each selected device with the native Proxmox dev resource.",
|
||||
"reason": "The OCI process runs directly inside an LXC rather than through Docker.",
|
||||
"behavioral_impact": "Only devices explicitly selected by the user are exposed.",
|
||||
"validation": "pending-device-host-test"
|
||||
}
|
||||
],
|
||||
"installer_profile": {
|
||||
"network": {
|
||||
"compose_mode": "bridge"
|
||||
},
|
||||
"device_requests": [
|
||||
{
|
||||
"id": "optical-scsi-generic",
|
||||
"kind": "character-device",
|
||||
"purpose": "optical-drive-control",
|
||||
"enable_prompt": "Enable an optical drive for MakeMKV",
|
||||
"enabled_default": false,
|
||||
"required_by_compose": false,
|
||||
"path_prompt": "Generic SCSI device associated with the drive (e.g. /dev/sg2)",
|
||||
"host_path_default": "/dev/sg0",
|
||||
"container_path_strategy": "same-as-host",
|
||||
"mode": "0660",
|
||||
"deny_write": false,
|
||||
"gid_strategy": "host-device-gid",
|
||||
"append_host_device_gid_to_environment": "SUP_GROUP_IDS",
|
||||
"source_mapping": "/dev/sgX:/dev/sgX"
|
||||
},
|
||||
{
|
||||
"id": "optical-block-device",
|
||||
"kind": "block-device",
|
||||
"purpose": "optical-drive-performance",
|
||||
"enable_prompt": "Also add the /dev/srX optical device (recommended)",
|
||||
"enabled_default": false,
|
||||
"required_by_compose": false,
|
||||
"path_prompt": "Optical block device (e.g. /dev/sr0)",
|
||||
"host_path_default": "/dev/sr0",
|
||||
"container_path_strategy": "same-as-host",
|
||||
"mode": "0660",
|
||||
"deny_write": false,
|
||||
"gid_strategy": "host-device-gid",
|
||||
"append_host_device_gid_to_environment": "SUP_GROUP_IDS",
|
||||
"source_mapping": "/dev/srX:/dev/srX"
|
||||
}
|
||||
],
|
||||
"volume_preparations": [
|
||||
{
|
||||
"container_path": "/config",
|
||||
"remove_lost_found": true,
|
||||
"owner_strategy": "mapped-application-user",
|
||||
"only_when_mount_type": "managed-volume"
|
||||
},
|
||||
{
|
||||
"container_path": "/storage",
|
||||
"remove_lost_found": true,
|
||||
"owner_strategy": "mapped-application-user",
|
||||
"only_when_mount_type": "managed-volume"
|
||||
},
|
||||
{
|
||||
"container_path": "/output",
|
||||
"remove_lost_found": true,
|
||||
"owner_strategy": "mapped-application-user",
|
||||
"only_when_mount_type": "managed-volume"
|
||||
}
|
||||
],
|
||||
"startup_healthcheck": {
|
||||
"scheme": "http",
|
||||
"port": 5800,
|
||||
"path": "/",
|
||||
"timeout_seconds": 180,
|
||||
"request_timeout_seconds": 10,
|
||||
"stability_seconds": 4,
|
||||
"verify_tls": false
|
||||
}
|
||||
},
|
||||
"security_profile": {
|
||||
"requires_privileged_lxc": false,
|
||||
"source_requests_privileged_lxc": false,
|
||||
"optional_privileged_lxc": false,
|
||||
"requires_host_pid_namespace": false,
|
||||
"source_requests_relaxed_confinement": false,
|
||||
"requires_relaxed_confinement": false,
|
||||
"optional_relaxed_confinement": false,
|
||||
"risk_level": "normal",
|
||||
"confirmation_required": false,
|
||||
"warning": "No security relaxation is required for the reviewed profile."
|
||||
}
|
||||
},
|
||||
"compatibility": {
|
||||
"automatic_install_candidate": true,
|
||||
"validated": false,
|
||||
"supported_compose_keys": [
|
||||
"devices",
|
||||
"environment",
|
||||
"image",
|
||||
"ports",
|
||||
"restart",
|
||||
"volumes"
|
||||
],
|
||||
"untranslated_blockers": [],
|
||||
"policy": "The official single-image contract has a reviewed native OCI-LXC mapping; clean-install validation remains pending."
|
||||
},
|
||||
"first_run": {
|
||||
"endpoints": [
|
||||
{
|
||||
"label": "Web UI",
|
||||
"scheme": "http",
|
||||
"port": 5800,
|
||||
"path": "/",
|
||||
"source": "upstream-documentation"
|
||||
}
|
||||
],
|
||||
"credentials": []
|
||||
},
|
||||
"validation": {
|
||||
"schema": "passed-at-generation",
|
||||
"clean_install": "pending",
|
||||
"service_health": "pending",
|
||||
"restart_persistence": "pending",
|
||||
"backup_restore": "pending",
|
||||
"update_preserves_data": "pending"
|
||||
},
|
||||
"lifecycle": {
|
||||
"update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update",
|
||||
"registry_state": {
|
||||
"resolved_architecture": null,
|
||||
"resolved_digest": null,
|
||||
"image_version_label": null,
|
||||
"image_created": null
|
||||
},
|
||||
"change_detection": "compare-readme-revision-and-resolved-latest-image-digest",
|
||||
"automatic_unattended_updates": false
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user