feat(oci): run official container images as native LXC containers

Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
MacRimi
2026-09-22 18:24:59 +02:00
co-authored by Claude Opus 5
parent b36498f215
commit bcabcb618c
670 changed files with 221410 additions and 215 deletions
+37
View File
@@ -424,3 +424,40 @@ cleanup_duplicate_repos() {
cleanup_duplicate_repos_pve8
fi
}
# ==========================================================
# Update log helpers
# ==========================================================
# An update log is what is left once the terminal is gone: the Monitor
# runs the same update from a systemd unit with no terminal at all, and
# an operator reads the log days later to find out what moved.
# Reads `apt list --upgradable` on stdin and writes one aligned
# `name old → new` line per package. Lines that do not carry the
# "[upgradable from: …]" part are passed through as they came.
pmx_format_upgradable() {
awk 'NF == 0 { next }
$0 ~ /\[upgradable from: / {
name = $1; sub(/\/.*/, "", name)
from = $6; sub(/\]$/, "", from)
printf " %-30s %s → %s\n", name, from, $2
next
}
{ print " " $0 }'
}
# Writes what dpkg actually did since `$1` (a "YYYY-MM-DD HH:MM:SS"
# stamp taken before the upgrade). dpkg's own log is the authoritative
# record of the transaction — it carries both versions of every package
# replaced, which apt's console output does not spell out.
pmx_dpkg_changes_since() {
local since="$1"
[[ -n "$since" && -r /var/log/dpkg.log ]] || return 0
awk -v since="$since" '
($1 " " $2) < since { next }
$3 == "upgrade" { pkg = $4; sub(/:.*/, "", pkg); printf " %-30s %s → %s\n", pkg, $5, $6; next }
$3 == "install" { pkg = $4; sub(/:.*/, "", pkg); printf " %-30s installed %s\n", pkg, $6; next }
$3 == "remove" || $3 == "purge" { pkg = $4; sub(/:.*/, "", pkg); printf " %-30s %sd %s\n", pkg, $3, $5 }
' /var/log/dpkg.log
}