Fix the script terminal, Arr suite updates and OCI app tracking

This commit is contained in:
MacRimi
2026-09-26 16:57:35 +02:00
parent 93862abdb0
commit dd4bcfa867
14 changed files with 220 additions and 39 deletions
+14
View File
@@ -757,6 +757,19 @@ apply_extra_hosts() {
(( failed == 0 )) || die "$(translate "Could not apply the Compose extra hosts")"
}
# Settings an update gives back to the rebuilt container before it starts:
# the LAN leg of a suite or stack member and its start order.
apply_kept_settings() {
local key value
while IFS=$'\t' read -r key value; do
[[ -n $key ]] || continue
[[ $key == net1 || $key == startup ]] \
|| die "$(translate "Unsupported kept setting:") $key"
oci_quiet pct set "$VMID" "--$key" "$value" \
|| die "$(translate "Could not restore the container setting:") $key"
done < <(jq -r '.kept_proxmox_settings // {} | to_entries[] | [.key, .value] | @tsv' "$DEPLOYMENT_FILE")
}
apply_runtime_user() {
local user_spec=$1 rootfs passwd_file group_file user_part group_part uid gid failed=0
rootfs="/var/lib/lxc/${VMID}/rootfs"
@@ -1653,6 +1666,7 @@ apply_extra_hosts
apply_installer_profile
apply_rlimits
apply_host_monitor
apply_kept_settings
while IFS= read -r REPAIR_ENCODED; do
[[ -n $REPAIR_ENCODED ]] || continue
+2 -1
View File
@@ -102,7 +102,8 @@ def propose(record, config):
if 'description' in changed:
changed.remove('description')
new_keys = [key for key in changed if key not in before and re.fullmatch(r'(mp|dev)[0-9]+', key)]
unsupported = [key for key in changed if key not in new_keys and key not in transaction.ADOPTABLE]
unsupported = [key for key in changed if key not in new_keys and key not in transaction.ADOPTABLE
and key not in transaction.KEPT_AS_IS]
if unsupported:
raise ValueError(f"{translate('These manual changes cannot be adopted safely:')} {', '.join(unsupported)}")
if not new_keys:
+10 -5
View File
@@ -357,6 +357,9 @@ def candidate_contract(record, operation, proposal=None):
# Resource settings edited in Proxmox that the new container keeps.
# Proxmox settings the rebuilt container gets back exactly as they are: the
# LAN leg ProxMenux adds to a suite or stack member, and the start order.
KEPT_AS_IS = ('net1', 'startup')
ADOPTABLE = {'memory': ('resources', 'memory_mb'), 'swap': ('resources', 'swap_mb'),
'cores': ('resources', 'cores'), 'cpulimit': ('resources', 'cores'),
'cpuunits': ('resources', 'cpu_units'), 'onboot': (None, 'onboot')}
@@ -384,7 +387,7 @@ def external_changes(record, config, adopt=True):
elif key in ('memory', 'swap', 'cpuunits', cores_key) and value and re.fullmatch(r'[0-9]+', value):
if int(value) > 0 or key == 'swap':
values[key] = int(value)
refused = [key for key in changed if key not in values]
refused = [key for key in changed if key not in values and key not in KEPT_AS_IS]
if refused:
raise ValueError(f"{translate('The container was changed outside ProxMenux and an update would discard those changes:')} "
f"{', '.join(refused)}")
@@ -421,14 +424,13 @@ def preflight(record, candidate, config, coordinated=None):
if deployment.get('security', {}).get('sysctls'):
runtime_keys.add('lxc.include')
runtime_settings.check(config, deployment, record['vmid'])
coordinated_keys = {'net1', 'startup', 'hookscript'} if coordinated else set()
coordinated_keys = {'hookscript', *KEPT_AS_IS} if coordinated else set(KEPT_AS_IS)
if '[' in config.decode() or keys - BASIC - runtime_keys - coordinated_keys - {k for k in keys if re.fullmatch(r'(mp|dev)[0-9]+', k)}:
raise ValueError(translate('The container has advanced Proxmox settings outside the supported profile'))
for plan in (deployment, desired):
security = plan.get('security', {})
if (security.get('unprivileged') is not True
or security.get('options') or plan.get('host_monitor')
or plan.get('extra_hosts')
or plan.get('resources', {}).get('rlimits')):
raise ValueError(translate('Updates are not available yet in this beta for applications that use '
'a privileged container or advanced LXC settings'))
@@ -900,6 +902,11 @@ def apply(root, vmid, archive, operation, proposal=None, registry_digest=None, i
'external_data_acknowledged': acknowledge_external_data,
'original_gpu_devices': original_gpu, 'desired_gpu_devices': desired_gpu,
'was_running': run('pct', 'status', str(vmid)).strip() == b'status: running'}
state['kept_config'] = {key: cfg[key] for key in KEPT_AS_IS if key in cfg}
if not coordinated and state['kept_config']:
# Applied by the installer before the new container starts, so the
# application has its LAN leg from the first second.
state['runtime_deployment']['kept_proxmox_settings'] = state['kept_config']
if coordinated:
state['coordinated'] = coordinated
state['preserved_stack_config'] = {key: cfg[key] for key in ('net1', 'startup', 'hookscript') if key in cfg}
@@ -919,8 +926,6 @@ def apply(root, vmid, archive, operation, proposal=None, registry_digest=None, i
gpu_devices.verify(desired_gpu)
if show:
msg_ok(translate('Update prepared') if update else translate('Recreation prepared'))
if original_sources or desired_sources:
msg_warn(translate('Host directories are not included in the backup and are not reverted by a recovery.'))
msg_info(translate('Stopping the container...'))
stop(vmid)
if show:
-3
View File
@@ -672,9 +672,6 @@ def run(vmid, recover=False, acknowledge_external_data=False, keep_backup=None):
msg_ok(f"{translate('Backup created in')} {keep_backup}")
else:
adapter.keep_backup = keep_backup
if any(mount['type'] == 'host-bind' for member in plan['members']
for mount in member.get('deployment', {}).get('mounts', [])):
msg_warn(translate('Host directories are not included in the backups and are not reverted by a recovery.'))
result = stack_tx.execute(journal, adapter, plan)
msg_ok(translate('Stack update completed. Data kept.'))
return result