- Host restore notification: reports its tasks and no longer calls the node fully ready.
- Watchdog notification: covers an application that did not start as well as one that stopped again.
- OCI: Modify summary, Immich recognition preview, private network kept by another guest, empty USB list.
- gzip diagnostic no longer says that nothing changed.
Source questions from the Italian review by @f3rs3n.
- New service that starts again an OCI application that stopped on its own, such as Frigate after Save & Restart. A stop or shutdown asked by the user, a backup, a migration and a ProxMenux operation are never undone.
- The installer asks it in both modes and proposes what the recipe declares; it is changed from the management menu or with the Watchdog switch of the container modal in the Monitor.
- Notifications when the watchdog restarts an application and when it keeps stopping.
- The service is recorded in the change journal, and the feature is documented.
- The option that edits an installed application is Modify for one container and for a multi-container application, in the OCI menu and on the Monitor button. Recreate is only the rebuild of a multi-container application as it is.
- A stack recreation says "Recreating" and "Recreated" in its steps instead of "Updating".
- The notes of the GPU, Coral, disk and share menus no longer name the option.
- Spanish for the new texts; the English copies of the stack texts are removed from de, fr, pt and sv so the bot translates them.
The menu registers restored containers and refreshes the carried record
before it lists or manages an instance. The tests that run those menu
functions in isolation provide the new helpers they call.
An image published with a Docker-format manifest is saved for Proxmox
under another digest than the one its registry serves. The App tab reads
the installed version through the digest the registry served the image
under, and decides an update by comparing the platform manifest that
digest resolves to with the one the tag points at.
The installation record of an OCI application travels with its container:
a copy inside the container and another in /etc/pve, written together
with the one kept on the host. A container restored on a newly installed
Proxmox, restored with another ID or moved to another node of a cluster
is recognised and registered again, with its private network, hookscript,
Rclone mount, host firewall rule and NVIDIA runtime. The Monitor offers
the same recovery from the Updates tab.
AMD GPUs are offered by generation. A GPU the ROCm image supports takes
the profile as it is; one of a supported family (Radeon 680M, 780M) is an
experimental option that asks for confirmation and is never proposed; an
older one is not offered. The GPU is checked with a real inference before
the installation accepts it. Recreate changes what runs recognition in an
installed Immich, between the CPU and a GPU of the host.
Updates:
- A failed update that is restored and checked removes its temporary
container and the disks of the failed attempt.
- Every container volume is part of the backups, so Jellyfin, Plex and
Hugo update with their default installation.
- An image published with a Docker-format manifest is recognised by its
layers and build time and updates.
- The Proxmox notes of a multi-container application link to its LAN
address.
- Immich asks what runs its video and its recognition in one menu, in both
modes, and gives the GPU to the server and to Machine learning; AMD uses ROCm
- Frigate, Ollama, llama.cpp, Faster Whisper and Piper take the image built
for the chosen GPU
- The acceleration menu offers only what the host can run
- An update or a recreation sends one notification with its result instead of
the stop, backup and start of each container
- A private bridge with nothing connected is not reported as down
- Secondary containers of a stack appear in the App tab with their version and
logo; Secure Gateway shows the same update state in both views
- A mistyped value in the wizard asks the same question again
- Apply the static mount list as soon as it arrives instead of waiting
for the df/stat runtime probe.
- Refill a guest's mount seed after a lifecycle event rather than
leaving it empty until the next modal open.
- Retry the bulk modal cache while the server is still warming guests.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The translation workflow fills new keys in the shipped catalogs after
merge, so the fixture no longer asserts that lang/it.json lacks them.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Web docs test no longer passes the removed refresh argument.
- i18n messages tests assert that --refresh keeps existing values and
that only keys listed in --refresh-keys are re-translated.
- Add the new Monitor keys to de, fr, it, pt, sk and sv.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
OCI manager Apps
- App tab: containers installed from an OCI image are identified from their
installation record; the application and image versions are shown and an
update is detected by image digest; repository link; Refresh data.
- Updates tab for OCI containers: Update and Recreate run the same flow as the
OCI menu in the Monitor terminal; the pre-update backup can be kept in a
backup storage; scheduled image updates with an optional minimum age.
- Logs tab: console output of the application, kept on the host
(lxc.console.logfile + logrotate) and followed live.
- The Proxmox console opens a shell (cmode: shell) when the image has one.
- A damaged image download is fetched again before failing.
- Multi-container applications open at their LAN address; volume mount
points on block storage report their usage.
Monitor
- Proxmox notifications are delivered to a loopback-only HTTP listener when
HTTPS is enabled, so they no longer fail certificate verification.
- Log persistence counts recurring patterns only; an ended burst is not
reported as persistent and its warning clears on its own (#386).
- Proxmox notification config backups are deduplicated and capped at three.
- The update icon on the Apps page opens the container on its Updates tab.
- Version 1.2.6.2-beta and its release notes in every Monitor language.
Docs
- OCI manager Apps and Audit & Report rebuilt as per-page message files,
with a new page for OCI containers in the Monitor.
- Seven pages fixed where rich-text tags were missing from t.rich.
Translations
- Spanish fixes across the OCI engine, the Monitor and the TUI menus.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Staging AppImage/messages/sk/common.json for the Slovak wording also
carried an unrelated deletion that was in the working tree at the time.
The offline suite caught it: with the key gone the generator had work to
do on a clean checkout, and writes are forbidden there.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The argos run read a copy of lang/ from before #379, so the key naming
proxmenux-oci.sh came back with it — in all seven locales, pointing at a
file that no longer exists. Removed.
The Monitor category takes the Slovak @Vaso73 supplied: Správy a
upozornenia.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The glossary only holds what someone listed, and what reaches the reader
as a broken command was never on it. Paths, long options and Proxmox
subcommands are now recognised by shape:
/dev/apex_0 came back as /dev/apex 0
--auto-uninstall desinstalación automática
pct config 110 configuration PCT 110 (fr)
pct enter 101 pct inserire 101 (it)
OCI joins the glossary as well. Read as a word it became "BEC" in French
across thirty-one strings — "Vérification du BEC" named nothing — and the
menu entry read "Gestionnaire du BEC Apps". The entry itself and "beta"
are protected too, so the name stays the same in every language.
A provider can also alter a token rather than carry it through: argos
returned MPXTERM000 for PMXTERM000, the restore found nothing, and the
token shipped. "MPXTERM000 configuré" is in the French catalogue today.
The restore now verifies its own tokens and fails the string instead,
which leaves the key absent for the next run to retry.
Spanish category labels: twenty-six were wrong. Seven collapsed two
categories into one — "Backup & Recovery" read only "Recuperación",
"Network & Firewall" read "Red de cortafuegos" — six were half
translated, and the connector alternated between "&", "y" and "e". They
now use "y" or "e" throughout. "IoT & Smart Home" and
"AI / Coding & Dev-Tools" stay in English by choice.
"Messaging & Queues" becomes "Messaging & Notifications": its only
application is Apprise, a notification gateway, not a queue. The
Helper-Scripts import still maps their name, so nothing breaks upstream.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`oci/proxmenux-oci.sh` was installed on every Proxmox host and used on
none of them. The menu entry goes straight to the orchestrator:
scripts/oci/oci_manager_apps.sh runs `python3 -m proxmenux_oci` with
PYTHONPATH pointing at the engine.
Its only remaining caller was a message telling the reader to open it on
the Proxmox host — which is not how anyone gets in, and is what sent one
there to run it. That message now names the menu entry.
It could not be fetched and run either: it needs requirements.txt and
src/ beside it, so `wget | bash` resolved its own directory to the
working directory and failed on a path nobody chose. Making that work
would mean writing a second installer next to the one that already
ships the engine.
What it did offer was a virtualenv for a contributor generating the
catalog. The README now gives the direct invocation and names the two
distribution packages it needs.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Fetched with wget and piped to bash, $0 is "bash" and the script resolves
its own directory to wherever the shell happens to be. It then reports
"shasum: /root/requirements.txt: No such file or directory", which names
a path the reader never chose and says nothing about the real problem.
It now checks for the files it needs and names both places it runs from:
the installed engine directory on a Proxmox host, or oci/ in a clone.
PACKAGE-CONTENTS.md called it the "installer entry point", which is what
invites fetching it over the network in the first place.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three faults, all user-visible in the released catalogue.
The context prompt survived into 13 translations. A reader of the
Italian TUI was told "Messaggio tecnico per Proxmox e IT.Traduzione:
impossibile aggiornare initramfs." — the instruction given to the
provider, printed as if it were the message. One in French, eight in
Italian, four in Portuguese. The text after the prefix is correct, so
only the prefix goes.
Fifteen strings carried HTML entities where the source had a plain
character: "Adblock " DNS", "Affari & ERP".
Three product names had been translated as words — "Vaultwarden Courbe
Web" in French, where courbe means curve — and now keep their published
spelling. Two German strings said Kunden, a commercial customer, for an
OAuth client. Existing translations of the category labels and the
descriptive taglines are left as they are.
Twelve strings had no value in some locale and were retried on every
run, about thirty-five minutes a time. A fresh extraction now reports
nothing pending in any of the seven.
The Monitor catalogues are clean: they send no context prompt.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Every other Slovak string renders "Completed" as "Dokončené", including
the device message these two sit beside. They came back with "Hotovo" and
"k" instead of "do", which reads as a different hand in a list of four
lines that differ only by the noun.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The Monitor's generator protects them; this one did not, so a provider
read the word inside the braces and translated it. "{count}" came back
as "{conta}" in Portuguese and "{počet}" in Slovak, and the consumer —
finding no placeholder to substitute — fell back to English, which is
every message the recent batches introduced.
The token carries no underscores: argos splits on them and hands back
"PMX PH 0".
Two further fixes this depends on:
- protect_catalog_titles rebuilt the glossary pattern without the word
boundaries the module-level one has, so a short term matched inside
longer words once the catalogue was loaded.
- CT and VM join the glossary. Read as initials they get reordered —
"CT" comes back as "TC" in Spanish — naming something Proxmox does not.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The regenerated Slovak read as machine output. These carry the same
evidence boundary as the English and name VM and LXC the way a Slovak
reader expects.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Two next steps in the backup area claimed more than the evidence behind
them supports, reported by @Vaso73 while reviewing the pattern.
A failed run is now treated as unsuccessful with a copy to confirm,
rather than asserted to have produced nothing usable — the task log does
not establish that. And a missing host-configuration record says no
backup is recorded here, leaving room for one this node cannot see.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The four setup messages were in Spanish and one told the reader Python 3
was needed "en el Mac", which is the wrong machine for a script the
README documents as running on the Proxmox host.
They stay outside translate(): this script runs before the Python
environment it is preparing exists, so no catalogue is available yet.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Both batches seed the same block for their English-only additions. One
read and one write now cover the PBS key guidance and the Borg SSH keys
together.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The 41 keys added for the audit explanations, disk exclusions and idle
disk state existed only in English, so build_i18n_messages had work to do
on a clean checkout and the offline suite rejected it.
Fills them in the six remaining locales with argos, which joins the
provider list here as it already had in build_translation_cache: it runs
locally with no quota, and this script stores the English on a provider
failure, where a remote quota refusal would have been recorded as a
translation.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.
Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.
Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources
Audit & Report:
- findings that moved in the wrong direction between runs are reported
alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
do next
Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes
The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Both message batches seeded locale copies at the same point of
test_command_descriptions.py. The two blocks are independent — one
seeds the backup messages, the other the storage ones — so they are
merged into a single block that reads and writes the fixture once.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>