mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-10-08 22:46:41 +00:00
feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,159 @@
|
||||
{
|
||||
"status": "generated-unvalidated",
|
||||
"catalog_ui": {
|
||||
"tips": [
|
||||
"Monitors host processes, CPU, memory and network; uses the host IP, not its own IP.",
|
||||
"Privileged access to the host PID/network and unconfined AppArmor: requires confirmation. Trusted networks only; the host firewall is the one that applies.",
|
||||
"Neither docker.sock nor the host root directory is mounted. Docker inventory, SMART and capacity of all filesystems are not guaranteed.",
|
||||
"LXCFS is skipped only in the monitor CT so that the limited container RAM/CPU is not shown.",
|
||||
"Uses lxc.include with /etc/pve/lxc/proxmenux-host-monitor; this file is not included in vzdump and must be kept when restoring on another host.",
|
||||
"The CPU limit is applied as cpulimit, without hiding processors through affinity."
|
||||
]
|
||||
},
|
||||
"container_contract": {
|
||||
"volumes": [
|
||||
{
|
||||
"id": "volume-0",
|
||||
"container_path": "/etc/netdata",
|
||||
"compose_source_example": "/DATA/AppData/Netdata/config",
|
||||
"read_only": false,
|
||||
"required": true,
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
],
|
||||
"default": "managed-volume",
|
||||
"managed_volume": {
|
||||
"backup": true,
|
||||
"default_size_gb": 8
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "volume-1",
|
||||
"container_path": "/var/lib/netdata",
|
||||
"compose_source_example": "/DATA/AppData/Netdata/lib",
|
||||
"read_only": false,
|
||||
"required": true,
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
],
|
||||
"default": "managed-volume",
|
||||
"managed_volume": {
|
||||
"backup": true,
|
||||
"default_size_gb": 8
|
||||
}
|
||||
},
|
||||
{
|
||||
"id": "volume-2",
|
||||
"container_path": "/var/cache/netdata",
|
||||
"compose_source_example": "/DATA/AppData/Netdata/cache",
|
||||
"read_only": false,
|
||||
"required": true,
|
||||
"installation_choice": [
|
||||
"managed-volume",
|
||||
"host-bind"
|
||||
],
|
||||
"default": "managed-volume",
|
||||
"managed_volume": {
|
||||
"backup": true,
|
||||
"default_size_gb": 8
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
"proxmox": {
|
||||
"defaults": {
|
||||
"unprivileged": false,
|
||||
"ostype": "unmanaged",
|
||||
"memory_mb": 1024,
|
||||
"features": []
|
||||
},
|
||||
"security_profile": {
|
||||
"requires_privileged_lxc": true,
|
||||
"requires_host_pid_namespace": true,
|
||||
"optional_privileged_lxc": false,
|
||||
"requires_relaxed_confinement": true,
|
||||
"optional_relaxed_confinement": false,
|
||||
"confirmation_required": true,
|
||||
"risk_level": "high",
|
||||
"warning": "Host monitor: shared PID/network and privileged access. A compromised image could affect Proxmox. Use only on trusted networks."
|
||||
},
|
||||
"installer_profile": {
|
||||
"host_monitor": "netdata",
|
||||
"host_monitor_mounts": [
|
||||
{
|
||||
"source": "/proc",
|
||||
"target": "/host/proc"
|
||||
},
|
||||
{
|
||||
"source": "/sys",
|
||||
"target": "/host/sys"
|
||||
},
|
||||
{
|
||||
"source": "/etc/passwd",
|
||||
"target": "/host/etc/passwd"
|
||||
},
|
||||
{
|
||||
"source": "/etc/group",
|
||||
"target": "/host/etc/group"
|
||||
},
|
||||
{
|
||||
"source": "/etc/os-release",
|
||||
"target": "/host/etc/os-release"
|
||||
},
|
||||
{
|
||||
"source": "/sys/fs/cgroup",
|
||||
"target": "/host/sys/fs/cgroup"
|
||||
}
|
||||
],
|
||||
"startup_healthcheck": {
|
||||
"scheme": "http",
|
||||
"port": 19999,
|
||||
"path": "/",
|
||||
"timeout_seconds": 180,
|
||||
"request_timeout_seconds": 5,
|
||||
"verify_tls": false
|
||||
},
|
||||
"security": {
|
||||
"required_capabilities": [
|
||||
"SYS_PTRACE",
|
||||
"SYS_ADMIN"
|
||||
],
|
||||
"options": {
|
||||
"apparmor_profile": "unconfined"
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"compatibility": {
|
||||
"automatic_install_candidate": true,
|
||||
"validated": false,
|
||||
"untranslated_blockers": []
|
||||
},
|
||||
"validation": {
|
||||
"service_health": "passed-observed-2026-09-14",
|
||||
"restart_persistence": "passed-observed-2026-09-14",
|
||||
"backup_restore": "pending",
|
||||
"update_preserves_data": "pending",
|
||||
"latest_runtime_observation": {
|
||||
"date": "2026-09-14",
|
||||
"vmid": 105,
|
||||
"architecture": "amd64",
|
||||
"proxmox": "9.2.18",
|
||||
"image_digest": "sha256:9317b3621e0a1f7406051d2dda6b94bf81ecebc79f24447aedaa92405b0a171e",
|
||||
"image_version": "v2.11.0-340-nightly",
|
||||
"http_port": 19999,
|
||||
"host_pid_namespace": true,
|
||||
"host_network_namespace": true,
|
||||
"host_memory_bytes": 16110522368,
|
||||
"shutdown_start_passed": true,
|
||||
"companion_include": "/etc/pve/lxc/proxmenux-host-monitor",
|
||||
"companion_included_in_vzdump": false,
|
||||
"rolling_tag_validation": "only-observed-digest",
|
||||
"cgroup_charts_observed": 144,
|
||||
"persistent_registry_uid_unchanged": true,
|
||||
"managed_volumes_backup": true
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user