feat(oci): run official container images as native LXC containers

Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
MacRimi
2026-09-22 18:24:59 +02:00
co-authored by Claude Opus 5
parent b36498f215
commit bcabcb618c
670 changed files with 221410 additions and 215 deletions
+37
View File
@@ -424,3 +424,40 @@ cleanup_duplicate_repos() {
cleanup_duplicate_repos_pve8
fi
}
# ==========================================================
# Update log helpers
# ==========================================================
# An update log is what is left once the terminal is gone: the Monitor
# runs the same update from a systemd unit with no terminal at all, and
# an operator reads the log days later to find out what moved.
# Reads `apt list --upgradable` on stdin and writes one aligned
# `name old → new` line per package. Lines that do not carry the
# "[upgradable from: …]" part are passed through as they came.
pmx_format_upgradable() {
awk 'NF == 0 { next }
$0 ~ /\[upgradable from: / {
name = $1; sub(/\/.*/, "", name)
from = $6; sub(/\]$/, "", from)
printf " %-30s %s → %s\n", name, from, $2
next
}
{ print " " $0 }'
}
# Writes what dpkg actually did since `$1` (a "YYYY-MM-DD HH:MM:SS"
# stamp taken before the upgrade). dpkg's own log is the authoritative
# record of the transaction — it carries both versions of every package
# replaced, which apt's console output does not spell out.
pmx_dpkg_changes_since() {
local since="$1"
[[ -n "$since" && -r /var/log/dpkg.log ]] || return 0
awk -v since="$since" '
($1 " " $2) < since { next }
$3 == "upgrade" { pkg = $4; sub(/:.*/, "", pkg); printf " %-30s %s → %s\n", pkg, $5, $6; next }
$3 == "install" { pkg = $4; sub(/:.*/, "", pkg); printf " %-30s installed %s\n", pkg, $6; next }
$3 == "remove" || $3 == "purge" { pkg = $4; sub(/:.*/, "", pkg); printf " %-30s %sd %s\n", pkg, $3, $5 }
' /var/log/dpkg.log
}
+48 -4
View File
@@ -80,6 +80,12 @@ update_pve_safe() {
local start_time
start_time=$(date +%s)
local log_file="/var/log/proxmox-update-$(date +%Y%m%d-%H%M%S).log"
{
echo "=== ProxMenux — Proxmox VE update ==="
echo "Started: $(date -Iseconds)"
echo "Host: $(hostname)"
echo "Running: $(pveversion 2>/dev/null | head -1)"
} > "$log_file"
# Screen capture: replay the pre-upgrade context lines after `clear`
# so the operator keeps the visual history around the noisy apt run.
local screen_capture="/tmp/proxmenux_screen_capture_$$.txt"
@@ -141,6 +147,11 @@ update_pve_safe() {
local update_output update_exit_code
update_output=$(apt-get update 2>&1)
update_exit_code=$?
{
echo
echo "--- apt-get update (exit $update_exit_code) ---"
printf '%s\n' "$update_output"
} >> "$log_file"
if [ $update_exit_code -eq 0 ]; then
msg_ok "$(translate "Package lists updated successfully")" | tee -a "$screen_capture"
@@ -163,7 +174,7 @@ update_pve_safe() {
apt-key adv --keyserver keyserver.ubuntu.com --recv-keys "$key" >/dev/null 2>&1 || true
fi
fi
if apt-get update > "$log_file" 2>&1; then
if apt-get update >> "$log_file" 2>&1; then
msg_ok "$(translate "Package lists updated after GPG fix")" | tee -a "$screen_capture"
else
msg_error "$(translate "Failed to update package lists. Check log: $log_file")"
@@ -188,10 +199,19 @@ update_pve_safe() {
# ── 5-6. Detect + confirm ──
local current_pve_version available_pve_version upgradable security_updates
local upgradable_raw upgradable_list
current_pve_version=$(pveversion 2>/dev/null | grep -oP 'pve-manager/\K[0-9]+\.[0-9]+\.[0-9]+' | head -1)
available_pve_version=$(apt-cache policy pve-manager 2>/dev/null | grep -oP 'Candidate: \K[0-9]+\.[0-9]+\.[0-9]+' | head -1)
upgradable=$($APT_ENV apt list --upgradable 2>/dev/null | sed '1d' | sed '/^\s*$/d' | wc -l)
security_updates=$($APT_ENV apt list --upgradable 2>/dev/null | sed '1d' | grep -ci '\-security')
upgradable_raw=$($APT_ENV apt list --upgradable 2>/dev/null | sed '1d' | sed '/^\s*$/d')
upgradable=$(printf '%s' "$upgradable_raw" | grep -c . )
security_updates=$(printf '%s\n' "$upgradable_raw" | grep -ci '\-security')
upgradable_list=$(printf '%s\n' "$upgradable_raw" | pmx_format_upgradable)
{
echo
echo "--- Packages to upgrade ($upgradable) ---"
[ "$upgradable" -gt 0 ] && printf '%s\n' "$upgradable_list"
} >> "$log_file"
local menu_text
menu_text="$(translate "System Update Information")\n\n"
@@ -207,12 +227,17 @@ update_pve_safe() {
whiptail --title "$(translate "Update Status")" --msgbox "$menu_text" 15 70
apt-get -y autoremove >/dev/null 2>&1 || true
apt-get -y autoclean >/dev/null 2>&1 || true
echo -e "\nSystem is already up to date." >> "$log_file"
rm -f "$screen_capture"
return 0
fi
# The package list rides in the same dialog as the summary, so the
# decision is taken knowing what is about to be replaced. --scrolltext
# keeps the buttons reachable however long the list is.
menu_text+="$(translate "Packages to be upgraded"):\n$upgradable_list\n\n"
menu_text+="$(translate "Do you want to proceed with the system update?")"
if ! whiptail --title "$(translate "Proxmox Update")" --yesno "$menu_text" 18 70; then
if ! whiptail --title "$(translate "Proxmox Update")" --scrolltext --yesno "$menu_text" 24 78; then
msg_info2 "$(translate "Update cancelled by user")"
apt-get -y autoremove >/dev/null 2>&1 || true
apt-get -y autoclean >/dev/null 2>&1 || true
@@ -228,6 +253,12 @@ update_pve_safe() {
msg_title "$(translate "$SCRIPT_TITLE")"
cat "$screen_capture"
# dpkg's log is read back from here on, so the transaction can be
# reported package by package without holding apt's output.
local dpkg_mark
dpkg_mark=$(date '+%Y-%m-%d %H:%M:%S')
echo -e "\n--- apt full-upgrade ---" >> "$log_file"
# apt's own progress bar (Progress: [ %]) prints on stderr and only
# when stdout is a TTY. We pipe stderr through tee to keep a log copy
# while letting apt keep its interactive stdout, so the native bar
@@ -239,6 +270,12 @@ update_pve_safe() {
local upgrade_exit_code=$?
echo -e
{
echo
echo "--- Packages changed (exit $upgrade_exit_code) ---"
pmx_dpkg_changes_since "$dpkg_mark"
} >> "$log_file"
# Redraw once more so the wrap-up (LVM check, cleanup, summary) reads
# cleanly instead of scrolling under half-a-screen of apt noise.
clear
@@ -248,6 +285,7 @@ update_pve_safe() {
if [ $upgrade_exit_code -ne 0 ]; then
msg_error "$(translate "System upgrade failed. Check log: $log_file")"
echo "Finished: $(date -Iseconds) — upgrade failed (exit $upgrade_exit_code)" >> "$log_file"
rm -f "$screen_capture"
return 1
fi
@@ -282,6 +320,12 @@ update_pve_safe() {
echo -e "${TAB}${GN}📦 $(translate "Packages upgraded")${CL}: ${BL}$upgradable${CL}"
echo -e "${TAB}${GN}🖥️ $(translate "Proxmox VE")${CL}: ${BL}${available_pve_version:-$current_pve_version}${CL}"
{
echo
echo "Finished: $(date -Iseconds) — ${minutes}m ${seconds}s"
echo "Running: $(pveversion 2>/dev/null | head -1)"
} >> "$log_file"
msg_ok "$(translate "Proxmox VE safe update completed")"
rm -f "$screen_capture"
}
+46 -5
View File
@@ -19,6 +19,8 @@ fi
load_language
initialize_cache
APT_ENV="env DEBIAN_FRONTEND=noninteractive LC_ALL=C LANG=C"
ensure_tools_json() {
[ -f "$TOOLS_JSON" ] || echo "{}" > "$TOOLS_JSON"
}
@@ -41,6 +43,12 @@ update_pve8() {
pmx_journal_context "update_pve8" "$FUNC_VERSION"
local start_time=$(date +%s)
local log_file="/var/log/proxmox-update-$(date +%Y%m%d-%H%M%S).log"
{
echo "=== ProxMenux — Proxmox VE update ==="
echo "Started: $(date -Iseconds)"
echo "Host: $(hostname)"
echo "Running: $(pveversion 2>/dev/null | head -1)"
} > "$log_file"
local changes_made=false
local OS_CODENAME="$(grep "VERSION_CODENAME=" /etc/os-release | cut -d"=" -f 2 | xargs)"
@@ -120,7 +128,7 @@ EOF
cleanup_duplicate_repos
msg_info "$(translate "Updating package lists...")"
if apt-get update > "$log_file" 2>&1; then
if apt-get update >> "$log_file" 2>&1; then
msg_ok "$(translate "Package lists updated successfully")"
else
msg_error "$(translate "Failed to update package lists. Check log: $log_file")"
@@ -129,8 +137,16 @@ EOF
local current_pve_version=$(pveversion 2>/dev/null | grep -oP 'pve-manager/\K[0-9]+\.[0-9]+\.[0-9]+' | head -1)
local available_pve_version=$(apt-cache policy pve-manager 2>/dev/null | grep -oP 'Candidate: \K[0-9]+\.[0-9]+\.[0-9]+' | head -1)
local upgradable=$(apt list --upgradable 2>/dev/null | grep -c "upgradable")
local security_updates=$(apt list --upgradable 2>/dev/null | grep -c "security")
local upgradable_raw=$($APT_ENV apt list --upgradable 2>/dev/null | sed '1d' | sed '/^\s*$/d')
local upgradable=$(printf '%s' "$upgradable_raw" | grep -c . )
local security_updates=$(printf '%s\n' "$upgradable_raw" | grep -ci '\-security')
local upgradable_list=$(printf '%s\n' "$upgradable_raw" | pmx_format_upgradable)
{
echo
echo "--- Packages to upgrade ($upgradable) ---"
[ "$upgradable" -gt 0 ] && printf '%s\n' "$upgradable_list"
} >> "$log_file"
show_update_menu() {
local current_version="$1"
@@ -151,8 +167,12 @@ EOF
whiptail --title "$(translate "Update Status")" --msgbox "$menu_text" 15 70
return 2
else
# The package list rides in the same dialog as the summary, so
# the decision is taken knowing what is about to be replaced.
# --scrolltext keeps the buttons reachable however long it is.
menu_text+="$(translate "Packages to be upgraded"):\n$upgradable_list\n\n"
menu_text+="$(translate "Do you want to proceed with the system update?")"
if whiptail --title "$(translate "Proxmox Update")" --yesno "$menu_text" 18 70; then
if whiptail --title "$(translate "Proxmox Update")" --scrolltext --yesno "$menu_text" 24 78; then
return 0
else
return 1
@@ -171,6 +191,7 @@ EOF
return 0
elif [[ $MENU_RESULT -eq 2 ]]; then
msg_ok "$(translate "System is already up to date. No update needed.")"
echo -e "\nSystem is already up to date." >> "$log_file"
pmx_record_execution "Remove unused packages" "apt-get -y autoremove"
apt-get -y autoremove > /dev/null 2>&1 || true
apt-get -y autoclean > /dev/null 2>&1 || true
@@ -205,6 +226,12 @@ EOF
tput civis
tput sc
# dpkg's log is read back from here on, so the transaction can be
# reported package by package.
local dpkg_mark
dpkg_mark=$(date '+%Y-%m-%d %H:%M:%S')
echo -e "\n--- apt-get dist-upgrade ---" >> "$log_file"
pmx_record_execution "Upgrade Proxmox VE 8 packages" "apt-get -y -o Dpkg::Options::=--force-confdef -o Dpkg::Options::=--force-confold dist-upgrade"
(
/usr/bin/env \
@@ -216,6 +243,7 @@ EOF
-o Dpkg::Options::="--force-confdef" \
-o Dpkg::Options::="--force-confold" \
dist-upgrade 2>&1 | \
tee -a "$log_file" | \
while IFS= read -r line; do
if [[ "$line" =~ ^(Setting\ up|Unpacking|Preparing\ to\ unpack|Processing\ triggers\ for) ]]; then
package_name=$(echo "$line" | sed -E 's/.*(Setting up|Unpacking|Preparing to unpack|Processing triggers for) ([^ ]+).*/\2/')
@@ -240,7 +268,14 @@ EOF
done
)
if [ $? -eq 0 ]; then
local upgrade_exit_code=$?
{
echo
echo "--- Packages changed (exit $upgrade_exit_code) ---"
pmx_dpkg_changes_since "$dpkg_mark"
} >> "$log_file"
if [ $upgrade_exit_code -eq 0 ]; then
tput rc
tput ed
tput cnorm
@@ -286,6 +321,12 @@ EOF
{
echo
echo "Finished: $(date -Iseconds) — ${minutes}m ${seconds}s"
echo "Running: $(pveversion 2>/dev/null | head -1)"
} >> "$log_file"
msg_ok "$(translate "Proxmox VE 8 system update completed successfully")"
}
+50 -11
View File
@@ -45,6 +45,12 @@ update_pve9() {
local start_time
start_time=$(date +%s)
local log_file="/var/log/proxmox-update-$(date +%Y%m%d-%H%M%S).log"
{
echo "=== ProxMenux — Proxmox VE update ==="
echo "Started: $(date -Iseconds)"
echo "Host: $(hostname)"
echo "Running: $(pveversion 2>/dev/null | head -1)"
} > "$log_file"
local changes_made=false
local OS_CODENAME
OS_CODENAME="$(grep "VERSION_CODENAME=" /etc/os-release | cut -d"=" -f 2 | xargs)"
@@ -166,6 +172,11 @@ EOF
# UPDATE: no progress bar here (dpkg is not involved); capture output to parse errors
update_output=$(apt-get update 2>&1)
update_exit_code=$?
{
echo
echo "--- apt-get update (exit $update_exit_code) ---"
printf '%s\n' "$update_output"
} >> "$log_file"
if [ $update_exit_code -eq 0 ]; then
msg_ok "$(translate "Package lists updated successfully")" | tee -a "$screen_capture"
@@ -196,7 +207,7 @@ EOF
fi
# Retry update after importing the key
if apt-get update > "$log_file" 2>&1; then
if apt-get update >> "$log_file" 2>&1; then
msg_ok "$(translate "Package lists updated after GPG fix")" | tee -a "$screen_capture"
else
msg_error "$(translate "Failed to update package lists. Check log: $log_file")"
@@ -224,16 +235,19 @@ EOF
available_pve_version=$(apt-cache policy pve-manager 2>/dev/null | grep -oP 'Candidate: \K[0-9]+\.[0-9]+\.[0-9]+' | head -1)
local upgradable
upgradable=$($APT_ENV apt list --upgradable 2>/dev/null \
local upgradable upgradable_raw upgradable_list security_updates
upgradable_raw=$($APT_ENV apt list --upgradable 2>/dev/null \
| sed '1d' \
| sed '/^\s*$/d' \
| wc -l)
| sed '/^\s*$/d')
upgradable=$(printf '%s' "$upgradable_raw" | grep -c . )
security_updates=$(printf '%s\n' "$upgradable_raw" | grep -ci '\-security')
upgradable_list=$(printf '%s\n' "$upgradable_raw" | pmx_format_upgradable)
local security_updates
security_updates=$($APT_ENV apt list --upgradable 2>/dev/null \
| sed '1d' \
| grep -ci '\-security')
{
echo
echo "--- Packages to upgrade ($upgradable) ---"
[ "$upgradable" -gt 0 ] && printf '%s\n' "$upgradable_list"
} >> "$log_file"
show_update_menu() {
@@ -256,8 +270,12 @@ EOF
whiptail --title "$(translate "Update Status")" --msgbox "$menu_text" 15 70
return 2
else
# The package list rides in the same dialog as the summary, so
# the decision is taken knowing what is about to be replaced.
# --scrolltext keeps the buttons reachable however long it is.
menu_text+="$(translate "Packages to be upgraded"):\n$upgradable_list\n\n"
menu_text+="$(translate "Do you want to proceed with the system update?")"
if whiptail --title "$(translate "Proxmox Update")" --yesno "$menu_text" 18 70; then
if whiptail --title "$(translate "Proxmox Update")" --scrolltext --yesno "$menu_text" 24 78; then
return 0
else
return 1
@@ -282,6 +300,7 @@ EOF
return 0
elif [[ $MENU_RESULT -eq 2 ]]; then
msg_ok "$(translate "System is already up to date. No update needed.")"
echo -e "\nSystem is already up to date." >> "$log_file"
pmx_record_execution "Remove unused packages" "apt-get -y autoremove"
apt-get -y autoremove > /dev/null 2>&1 || true
apt-get -y autoclean > /dev/null 2>&1 || true
@@ -301,6 +320,13 @@ EOF
pmx_record_execution "Upgrade Proxmox VE 9 packages" "apt -y -o Dpkg::Options::=--force-confdef -o Dpkg::Options::=--force-confold full-upgrade"
# dpkg's log is read back from here on, so the transaction can be
# reported package by package without holding apt's output.
local dpkg_mark
dpkg_mark=$(date '+%Y-%m-%d %H:%M:%S')
echo -e "\n--- apt full-upgrade ---" >> "$log_file"
DEBIAN_FRONTEND=noninteractive apt -y \
-o Dpkg::Options::='--force-confdef' \
-o Dpkg::Options::='--force-confold' \
@@ -309,6 +335,12 @@ EOF
upgrade_exit_code=$?
echo -e
{
echo
echo "--- Packages changed (exit $upgrade_exit_code) ---"
pmx_dpkg_changes_since "$dpkg_mark"
} >> "$log_file"
clear
show_proxmenux_logo
msg_title "$(translate "$SCRIPT_TITLE")"
@@ -316,6 +348,7 @@ EOF
if [ $upgrade_exit_code -ne 0 ]; then
msg_error "$(translate "System upgrade failed. Check log: $log_file")"
echo "Finished: $(date -Iseconds) — upgrade failed (exit $upgrade_exit_code)" >> "$log_file"
rm -f "$screen_capture"
return 1
fi
@@ -349,8 +382,14 @@ EOF
echo -e "${TAB}${GN}📦 $(translate "Packages upgraded")${CL}: ${BL}$upgradable${CL}"
echo -e "${TAB}${GN}🖥️ $(translate "Proxmox VE")${CL}: ${BL}$available_pve_version (Debian $OS_CODENAME)${CL}"
{
echo
echo "Finished: $(date -Iseconds) — ${minutes}m ${seconds}s"
echo "Running: $(pveversion 2>/dev/null | head -1)"
} >> "$log_file"
msg_ok "$(translate "Proxmox VE configuration completed.")"
rm -f "$screen_capture"
}