mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-10-03 20:16:42 +00:00
feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -50,7 +50,7 @@ fi
|
||||
root_fs="$(findmnt -no FSTYPE / 2>/dev/null || echo ext4)"
|
||||
|
||||
# ── CPU model / arch ──
|
||||
cpu_model="$(lscpu 2>/dev/null | awk -F: '/^Model name/{sub(/^[ \t]+/, "", $2); print $2; exit}')"
|
||||
cpu_model="$(LC_ALL=C lscpu 2>/dev/null | awk -F: '/^Model name/{sub(/^[ \t]+/, "", $2); print $2; exit}')"
|
||||
cpu_arch="$(uname -m)"
|
||||
# Normalize to schema enum
|
||||
case "$cpu_arch" in
|
||||
|
||||
@@ -2672,7 +2672,7 @@ hb_configure_borg_manual() {
|
||||
|
||||
_borg_repo_ref_new="$repo"
|
||||
if [[ -n "$ssh_key" ]]; then
|
||||
local rsh_cmd="ssh -i $ssh_key -o StrictHostKeyChecking=accept-new"
|
||||
local rsh_cmd="ssh -i $ssh_key -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new"
|
||||
[[ -n "${port:-}" && "$port" != "22" ]] && rsh_cmd="$rsh_cmd -p $port"
|
||||
export BORG_RSH="$rsh_cmd"
|
||||
elif [[ -n "${port:-}" && "$port" != "22" ]]; then
|
||||
@@ -2779,7 +2779,7 @@ hb_select_borg_repo() {
|
||||
_borg_repo_ref="${HB_BORG_REPOS[$sel]}"
|
||||
local key="${HB_BORG_KEYS[$sel]}"
|
||||
if [[ -n "$key" && -f "$key" ]]; then
|
||||
export BORG_RSH="ssh -i $key -o StrictHostKeyChecking=accept-new"
|
||||
export BORG_RSH="ssh -i $key -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new"
|
||||
else
|
||||
unset BORG_RSH
|
||||
fi
|
||||
|
||||
@@ -124,6 +124,24 @@ _sb_borg_resolve_password() {
|
||||
cat "$pf"
|
||||
}
|
||||
|
||||
# Same lookup for the SSH key, which lives on the 3rd field of
|
||||
# `borg-targets.txt`. Job .env files carry the repository but not the
|
||||
# key, so a remote repo has to read it back from the destination here.
|
||||
_sb_borg_resolve_ssh_key() {
|
||||
local repo="$1"
|
||||
local cfg="${HB_STATE_DIR:-/usr/local/share/proxmenux}/borg-targets.txt"
|
||||
[[ -f "$cfg" && -n "$repo" ]] || return 1
|
||||
local name target_repo key
|
||||
while IFS='|' read -r name target_repo key _; do
|
||||
[[ -z "$name" || -z "$target_repo" ]] && continue
|
||||
if [[ "$target_repo" == "$repo" ]]; then
|
||||
[[ -n "$key" ]] && printf '%s\n' "$key"
|
||||
return 0
|
||||
fi
|
||||
done < "$cfg"
|
||||
return 1
|
||||
}
|
||||
|
||||
_sb_run_borg() {
|
||||
local stage_root="$1"
|
||||
local archive_name="$2"
|
||||
@@ -156,6 +174,21 @@ _sb_run_borg() {
|
||||
# an explicit re-export, child `borg` calls drop back to ssh defaults
|
||||
# and a remote repo silently auth-fails with no log trail.
|
||||
export BORG_PASSPHRASE="$passphrase"
|
||||
# A remote repo needs the destination's SSH key. Without BORG_RSH ssh
|
||||
# falls back to the default identities and a key-only server answers
|
||||
# `Permission denied (publickey)`. borg appends `-p <port>` itself
|
||||
# from the ssh:// URL, so the port does not belong here.
|
||||
if [[ -z "${BORG_RSH:-}" && "$repo" == ssh://* ]]; then
|
||||
local ssh_key
|
||||
ssh_key=$(_sb_borg_resolve_ssh_key "$repo" 2>/dev/null || true)
|
||||
if [[ -n "$ssh_key" && -r "$ssh_key" ]]; then
|
||||
BORG_RSH="ssh -i $ssh_key -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new"
|
||||
elif [[ -n "$ssh_key" ]]; then
|
||||
echo "SSH key ${ssh_key} saved on this destination is missing or unreadable."
|
||||
echo " → generate it again from the destination, or point it at an existing key."
|
||||
return 1
|
||||
fi
|
||||
fi
|
||||
[[ -n "${BORG_RSH:-}" ]] && export BORG_RSH
|
||||
export BORG_RELOCATED_REPO_ACCESS_IS_OK=yes
|
||||
export BORG_UNKNOWN_UNENCRYPTED_REPO_ACCESS_IS_OK=yes
|
||||
|
||||
Reference in New Issue
Block a user