mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-10-04 12:36:39 +00:00
feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Executable
+42
@@ -0,0 +1,42 @@
|
||||
# Sourced by the dedicated installers after image resolution, before CT creation.
|
||||
oci_native_begin() {
|
||||
OCI_NATIVE_PRIMARY=$1
|
||||
shift
|
||||
local root=/usr/local/share/proxmenux/oci/apps
|
||||
[[ ! -L $root && ! -L $root/.lock ]] || die "$(translate "The instance registry is not safe")"
|
||||
oci_quiet install -d -m 0700 "$root"
|
||||
exec 8>>"$root/.lock"
|
||||
chmod 600 "$root/.lock"
|
||||
flock -n 8 || die "$(translate "Another OCI operation is using the instance registry")"
|
||||
export PROXMENUX_INSTANCE_LOCK_FD=8
|
||||
oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" begin "$OCI_NATIVE_PRIMARY" \
|
||||
--template "$TEMPLATE_FILE" --deployment "$DEPLOYMENT_FILE" \
|
||||
--adapter "$0" "$@"
|
||||
OCI_NATIVE_ACTIVE=1
|
||||
}
|
||||
|
||||
# A failure returns to the caller instead of exiting inside a redirected call,
|
||||
# so the caller's error report reaches the terminal and not the log.
|
||||
pct() {
|
||||
if [[ ${1:-} == unmount && ${OCI_NATIVE_ACTIVE:-0} == 1 ]]; then
|
||||
if ! python3 "$SCRIPT_DIR/oci_native_stack.py" capture-rootfs "$2"; then
|
||||
command pct unmount "$2" 8>&- 9>&- || true
|
||||
return 1
|
||||
fi
|
||||
fi
|
||||
if [[ ${1:-} == create && ${OCI_NATIVE_ACTIVE:-0} == 1 ]]; then
|
||||
shift
|
||||
python3 "$SCRIPT_DIR/oci_native_stack.py" create "$@" || return
|
||||
else
|
||||
command pct "$@" 8>&- 9>&- || return
|
||||
fi
|
||||
}
|
||||
|
||||
oci_native_finalize() {
|
||||
oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" finalize "$OCI_NATIVE_PRIMARY"
|
||||
}
|
||||
|
||||
oci_native_failed() {
|
||||
[[ ${OCI_NATIVE_ACTIVE:-0} == 1 ]] || return 0
|
||||
oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" failed "$OCI_NATIVE_PRIMARY" || true
|
||||
}
|
||||
Reference in New Issue
Block a user