100 Commits
Author SHA1 Message Date
MacRimi 72f77069ca fix(oci): limit Frigate's CPU by time instead of pinning it to threads 2026-09-28 23:08:45 +02:00
MacRimi 0b82e91dd7 i18n: fix spacing and capitalisation of the new removal messages 2026-09-28 22:34:02 +02:00
MacRimi 0ae601f5e7 fix(oci): remove everything an OCI installation leaves, and name cluster events 2026-09-28 22:31:00 +02:00
MacRimi 2922fc235d fix: quiet apt in the installers and fix the duplicate repository cleanup 2026-09-28 19:14:05 +02:00
MacRimi 7ec6d06dc3 i18n(es): drop an unused catalog tip translation 2026-09-28 19:09:30 +02:00
MacRimi 79547dec35 fix(oci): start OCI containers on any node of a cluster 2026-09-28 19:06:07 +02:00
MacRimi 297c026c95 fix: Health Monitor storage and disk notices, SELinux-safe host backup, Frigate detector keys 2026-09-28 18:18:09 +02:00
MacRimi bf07f0a8a9 feat(oci): offer an Intel NPU or a Coral as Frigate's object detector 2026-09-28 17:48:47 +02:00
MacRimi adc42caae3 feat(oci): community validation record, report form and generated list 2026-09-28 17:30:29 +02:00
MacRimi 3d2aff6c66 i18n(es): curate the new OCI messages and the dry-run wording 2026-09-28 17:19:28 +02:00
MacRimi 4a77d11bc4 fix(monitor): register every OCI service port and read versions from the guest 2026-09-28 17:05:52 +02:00
MacRimi 8aade0e55c feat(oci): show a single Verified status for tested applications 2026-09-28 10:26:18 +02:00
MacRimi 115295acb6 fix(oci): reuse the existing HTTP check message 2026-09-28 09:56:29 +02:00
MacRimi a0ff593241 i18n: fix Yes/No labels in German, Italian and Swedish 2026-09-27 23:01:47 +02:00
MacRimi cdedf3ed24 i18n(es): clarify the managed host firewall rule message 2026-09-27 22:12:46 +02:00
MacRimi 52bb982721 Clarify the host-monitor restore notice 2026-09-27 21:18:15 +02:00
MacRimi 687f446f00 Merge branch 'develop' of https://github.com/MacRimi/ProxMenux into develop 2026-09-27 21:05:04 +02:00
MacRimi 0948d7b078 Declare oci_console in the OCI removal wording test 2026-09-27 21:04:54 +02:00
MacRimi f3c4959fa4 OCI catalog verification, console start marks and log cleanup 2026-09-27 21:02:16 +02:00
MacRimi 24617f9924 fix(lang): curate the Spanish host-monitor firewall strings 2026-09-27 20:18:18 +02:00
MacRimi 8ab72b8bcc fix(lang): curate the OCI diagnostic strings from #389 2026-09-26 18:39:30 +02:00
MacRimi b69aeea360 Merge branch 'develop' of https://github.com/MacRimi/ProxMenux into develop 2026-09-26 17:20:22 +02:00
MacRimi 02c4206d49 Keep Monitor-started backups running across a Monitor restart 2026-09-26 17:20:09 +02:00
MacRimi dd4bcfa867 Fix the script terminal, Arr suite updates and OCI app tracking 2026-09-26 16:57:35 +02:00
MacRimi 93862abdb0 Update cli.py 2026-09-26 08:49:34 +02:00
MacRimi e14a9911fd Stop asking to confirm host directories before an OCI update 2026-09-26 02:21:35 +02:00
MacRimi 00bc122611 Update a multi-container OCI application from its main container 2026-09-26 02:11:22 +02:00
MacRimi 756851350a Update es.json 2026-09-26 01:32:15 +02:00
MacRimi cb5da6ce76 Update extra_devices.py 2026-09-26 01:28:29 +02:00
MacRimi f7266e7b44 Generalize OCI device setup and remove unused catalog hashes 2026-09-26 01:22:37 +02:00
MacRimi 88acceb8ef fix(installer): surface apt errors and prevent false success messages 2026-09-25 23:05:55 +02:00
MacRimi 14583ad9f6 Back up /var/lib/proxmenux whole in the default host profile 2026-09-25 22:53:35 +02:00
MacRimi d1bb843f67 Delete ProxMenux-1.2.6.AppImage 2026-09-25 22:37:22 +02:00
MacRimiandClaude Opus 5.5 c0fa75f404 Keep the Mounts tab in place when an LXC modal opens
- Apply the static mount list as soon as it arrives instead of waiting
  for the df/stat runtime probe.
- Refill a guest's mount seed after a lifecycle event rather than
  leaving it empty until the next modal open.
- Retry the bulk modal cache while the server is still warming guests.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 22:11:23 +02:00
MacRimiandClaude Opus 5.5 53b415b127 Drop catalog snapshot assertion from the TUI upgrade/GPU wording test
The translation workflow fills new keys in the shipped catalogs after
merge, so the fixture no longer asserts that lang/it.json lacks them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 22:03:47 +02:00
MacRimiandClaude Opus 5.5 91e62b16e0 Fix offline i18n tests: refresh semantics and complete Monitor catalogs
- Web docs test no longer passes the removed refresh argument.
- i18n messages tests assert that --refresh keeps existing values and
  that only keys listed in --refresh-keys are re-translated.
- Add the new Monitor keys to de, fr, it, pt, sk and sv.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 22:01:22 +02:00
MacRimi e8a7ba6f47 Merge remote-tracking branch 'origin/develop' into beta/1.2.6.2 2026-09-25 21:51:23 +02:00
MacRimiandClaude Opus 5.5 4437a671d2 ProxMenux 1.2.6.2-beta: OCI containers in the Monitor, docs and fixes
OCI manager Apps
- App tab: containers installed from an OCI image are identified from their
  installation record; the application and image versions are shown and an
  update is detected by image digest; repository link; Refresh data.
- Updates tab for OCI containers: Update and Recreate run the same flow as the
  OCI menu in the Monitor terminal; the pre-update backup can be kept in a
  backup storage; scheduled image updates with an optional minimum age.
- Logs tab: console output of the application, kept on the host
  (lxc.console.logfile + logrotate) and followed live.
- The Proxmox console opens a shell (cmode: shell) when the image has one.
- A damaged image download is fetched again before failing.
- Multi-container applications open at their LAN address; volume mount
  points on block storage report their usage.

Monitor
- Proxmox notifications are delivered to a loopback-only HTTP listener when
  HTTPS is enabled, so they no longer fail certificate verification.
- Log persistence counts recurring patterns only; an ended burst is not
  reported as persistent and its warning clears on its own (#386).
- Proxmox notification config backups are deduplicated and capped at three.
- The update icon on the Apps page opens the container on its Updates tab.
- Version 1.2.6.2-beta and its release notes in every Monitor language.

Docs
- OCI manager Apps and Audit & Report rebuilt as per-page message files,
  with a new page for OCI containers in the Monitor.
- Seven pages fixed where rich-text tags were missing from t.rich.

Translations
- Spanish fixes across the OCI engine, the Monitor and the TUI menus.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 21:51:12 +02:00
MacRimiandClaude Opus 5 32ffa63879 fix(i18n): put back the sk key the previous commit removed by accident
Staging AppImage/messages/sk/common.json for the Slovak wording also
carried an unrelated deletion that was in the working tree at the time.
The offline suite caught it: with the key gone the generator had work to
do on a clean checkout, and writes are forbidden there.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-23 21:57:47 +02:00
MacRimiandClaude Opus 5 72a38dbf38 fix(i18n): drop the string that named the removed script, take @Vaso73's Slovak
The argos run read a copy of lang/ from before #379, so the key naming
proxmenux-oci.sh came back with it — in all seven locales, pointing at a
file that no longer exists. Removed.

The Monitor category takes the Slovak @Vaso73 supplied: Správy a
upozornenia.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-23 18:17:16 +02:00
MacRimiandClaude Opus 5 fe46d3d4bc fix(i18n): protect the literals a reader copies, and name the OCI category
The glossary only holds what someone listed, and what reaches the reader
as a broken command was never on it. Paths, long options and Proxmox
subcommands are now recognised by shape:

    /dev/apex_0        came back as  /dev/apex 0
    --auto-uninstall                 desinstalación automática
    pct config 110                   configuration PCT 110   (fr)
    pct enter 101                    pct inserire 101        (it)

OCI joins the glossary as well. Read as a word it became "BEC" in French
across thirty-one strings — "Vérification du BEC" named nothing — and the
menu entry read "Gestionnaire du BEC Apps". The entry itself and "beta"
are protected too, so the name stays the same in every language.

A provider can also alter a token rather than carry it through: argos
returned MPXTERM000 for PMXTERM000, the restore found nothing, and the
token shipped. "MPXTERM000 configuré" is in the French catalogue today.
The restore now verifies its own tokens and fails the string instead,
which leaves the key absent for the next run to retry.

Spanish category labels: twenty-six were wrong. Seven collapsed two
categories into one — "Backup & Recovery" read only "Recuperación",
"Network & Firewall" read "Red de cortafuegos" — six were half
translated, and the connector alternated between "&", "y" and "e". They
now use "y" or "e" throughout. "IoT & Smart Home" and
"AI / Coding & Dev-Tools" stay in English by choice.

"Messaging & Queues" becomes "Messaging & Notifications": its only
application is Apprise, a notification gateway, not a queue. The
Helper-Scripts import still maps their name, so nothing breaks upstream.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-23 17:49:59 +02:00
MacRimiandClaude Opus 5 f3bda28338 refactor(oci): remove the shell entry point nothing runs
`oci/proxmenux-oci.sh` was installed on every Proxmox host and used on
none of them. The menu entry goes straight to the orchestrator:
scripts/oci/oci_manager_apps.sh runs `python3 -m proxmenux_oci` with
PYTHONPATH pointing at the engine.

Its only remaining caller was a message telling the reader to open it on
the Proxmox host — which is not how anyone gets in, and is what sent one
there to run it. That message now names the menu entry.

It could not be fetched and run either: it needs requirements.txt and
src/ beside it, so `wget | bash` resolved its own directory to the
working directory and failed on a path nobody chose. Making that work
would mean writing a second installer next to the one that already
ships the engine.

What it did offer was a virtualenv for a contributor generating the
catalog. The README now gives the direct invocation and names the two
distribution packages it needs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 23:22:51 +02:00
MacRimiandClaude Opus 5 41b999ffeb fix(oci): say where the converter entry point has to run
Fetched with wget and piped to bash, $0 is "bash" and the script resolves
its own directory to wherever the shell happens to be. It then reports
"shasum: /root/requirements.txt: No such file or directory", which names
a path the reader never chose and says nothing about the real problem.

It now checks for the files it needs and names both places it runs from:
the installed engine directory on a Proxmox host, or oci/ in a clone.

PACKAGE-CONTENTS.md called it the "installer entry point", which is what
invites fetching it over the network in the first place.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 23:13:28 +02:00
MacRimiandClaude Opus 5 7e39aa550c fix(i18n): repair strings the translator damaged in the TUI catalogue
Three faults, all user-visible in the released catalogue.

The context prompt survived into 13 translations. A reader of the
Italian TUI was told "Messaggio tecnico per Proxmox e IT.Traduzione:
impossibile aggiornare initramfs." — the instruction given to the
provider, printed as if it were the message. One in French, eight in
Italian, four in Portuguese. The text after the prefix is correct, so
only the prefix goes.

Fifteen strings carried HTML entities where the source had a plain
character: "Adblock &quot; DNS", "Affari &amp; ERP".

Three product names had been translated as words — "Vaultwarden Courbe
Web" in French, where courbe means curve — and now keep their published
spelling. Two German strings said Kunden, a commercial customer, for an
OAuth client. Existing translations of the category labels and the
descriptive taglines are left as they are.

Twelve strings had no value in some locale and were retried on every
run, about thirty-five minutes a time. A fresh extraction now reports
nothing pending in any of the seven.

The Monitor catalogues are clean: they send no context prompt.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 22:08:34 +02:00
MacRimiandClaude Opus 5 75f571ecdb i18n(sk): match the wording already used for the sibling message
Every other Slovak string renders "Completed" as "Dokončené", including
the device message these two sit beside. They came back with "Hotovo" and
"k" instead of "do", which reads as a different hand in a list of four
lines that differ only by the noun.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 21:48:42 +02:00
MacRimiandClaude Opus 5 eafc472279 fix(i18n): keep {placeholders} out of the translator in the TUI cache
The Monitor's generator protects them; this one did not, so a provider
read the word inside the braces and translated it. "{count}" came back
as "{conta}" in Portuguese and "{počet}" in Slovak, and the consumer —
finding no placeholder to substitute — fell back to English, which is
every message the recent batches introduced.

The token carries no underscores: argos splits on them and hands back
"PMX PH 0".

Two further fixes this depends on:

- protect_catalog_titles rebuilt the glossary pattern without the word
  boundaries the module-level one has, so a short term matched inside
  longer words once the catalogue was loaded.
- CT and VM join the glossary. Read as initials they get reordered —
  "CT" comes back as "TC" in Spanish — naming something Proxmox does not.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 21:45:54 +02:00
MacRimiandClaude Opus 5 44db612d01 i18n(sk): use the Slovak wording supplied by @Vaso73
The regenerated Slovak read as machine output. These carry the same
evidence boundary as the English and name VM and LXC the way a Slovak
reader expects.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 20:17:54 +02:00
MacRimiandClaude Opus 5 5f09af0162 fix(audit): state what the backup checks observed, not more
Two next steps in the backup area claimed more than the evidence behind
them supports, reported by @Vaso73 while reviewing the pattern.

A failed run is now treated as unsuccessful with a copy to confirm,
rather than asserted to have produced nothing usable — the task log does
not establish that. And a missing host-configuration record says no
backup is recorded here, leaving room for one this node cannot see.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 19:59:39 +02:00
MacRimiandClaude Opus 5 1858fd5c60 fix(oci): write the converter entry point messages in English
The four setup messages were in Spanish and one told the reader Python 3
was needed "en el Mac", which is the wrong machine for a script the
README documents as running on the Proxmox host.

They stay outside translate(): this script runs before the Python
environment it is preparing exists, so no catalogue is available yet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 19:29:06 +02:00
MacRimiandClaude Opus 5 ee12d421f0 Merge develop: combine the i18n test fixture with #367
Both batches seed the same block for their English-only additions. One
read and one write now cover the PBS key guidance and the Borg SSH keys
together.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 19:23:10 +02:00
MacRimiandClaude Opus 5 dda8deb6e4 fix(i18n): complete the Monitor catalogs so a rerun writes nothing
The 41 keys added for the audit explanations, disk exclusions and idle
disk state existed only in English, so build_i18n_messages had work to do
on a clean checkout and the offline suite rejected it.

Fills them in the six remaining locales with argos, which joins the
provider list here as it already had in build_translation_cache: it runs
locally with no quota, and this script stores the English on a provider
failure, where a remote quota refusal would have been recorded as a
translation.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:29:23 +02:00
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00
MacRimiandClaude Opus 5 2d25585faf Merge develop: combine the i18n test fixture with #363
Both message batches seeded locale copies at the same point of
test_command_descriptions.py. The two blocks are independent — one
seeds the backup messages, the other the storage ones — so they are
merged into a single block that reads and writes the fixture once.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 16:46:04 +02:00
MacRimi 44e91c4710 orrect the machine-translated notification catalogs 2026-09-18 21:13:18 +02:00
MacRimi d5bce37ed2 Leave untranslated notification keys for the i18n bot to fill 2026-09-18 18:55:14 +02:00
MacRimi 256f3232e4 Offer only NVIDIA drivers that can drive the GPU, and prove it before removing the working one 2026-09-16 23:19:39 +02:00
MacRimi 78971f4ed7 New version 1.2.6.1-beta 2026-09-14 18:34:53 +02:00
MacRimi 2308b4ddc1 Translate the network interface counters as statistics, not sentences 2026-09-12 18:39:10 +02:00
MacRimi cc7b38a141 Name host and cluster correctly in every language 2026-09-12 12:01:25 +02:00
MacRimi b5fb747271 Section icons in the change journal, and admin scope on secret reveal 2026-09-12 10:54:36 +02:00
MacRimi 78d2d84f20 Read the login-page version from APP_VERSION 2026-09-12 09:53:33 +02:00
MacRimi 0b64549230 Focus the Audit & Report tab, scope API tokens 2026-09-12 00:22:14 +02:00
MacRimi 2a672889bf Record GPU/TPU host changes in the change journal
Seven gpu_tpu scripts now write through the journal for host changes only — driver and package installs, vfio binding, modprobe.d, /etc/modules, GRUB and udev — while VM and LXC configuration stays out; add_gpu_vm and install_coral_lxc journal only their host writes. amd_gpu_tools records its install, and pmx_journal.sh gains pmx_record_uninstall while changes_journal.py retires an installed package when ProxMenux removes it. What each function writes is byte-identical to before, verified by tests/journal/verify_journal_migration.py.
2026-09-11 21:08:35 +02:00
MacRimi bee242afa9 record Monitor-side installs and dedupe config by file 2026-09-11 19:54:32 +02:00
MacRimi 1830852901 attribute post-install helpers to their feature and dedupe files 2026-09-11 19:33:23 +02:00
MacRimi 5d73cd4aec Update utils.sh 2026-09-11 19:12:56 +02:00
MacRimi 08810d4b16 Update changes_journal.py 2026-09-11 18:45:46 +02:00
MacRimi 6b8bb97922 Update utils.sh 2026-09-11 09:17:36 +02:00
MacRimi 91c453d33c Update audit-changes.tsx 2026-09-11 08:50:03 +02:00
MacRimi 8e0d4ff337 eep only package-changing executions and clean up entry presentation 2026-09-11 08:37:23 +02:00
MacRimi b68105e9f0 Update audit-changes.tsx 2026-09-10 15:31:53 +02:00
MacRimi 085cbf7e68 scope the change journal to host changes, in three sections
The change journal exists so a sysadmin sees what ProxMenux changed on the host — its own configuration, packages and services — not how it uses the host or configures a guest. Several scripts recorded operations that are neither: disk passthrough to a VM, container conversions, VM import/export, mounting a share into an LXC. Those are restored to their original, uninstrumented form. Scripts that operate on the host while also installing a package now record only the package: format-disk keeps its exFAT-tools install, the UUP ISO builder its build dependencies, and the share/host scripts their packages, services and /etc/fstab writes, while the mount and unmount operations they used to log are dropped.

The page now reads in three sections: what ProxMenux optimized after install (each function under its menu name), what its other host scripts changed (by script), and what it installed (packages and utilities, each referencing the script that installed it). A file reads as created or modified with its diff, a service shows its state transition, and the undo line appears only when a revert is possible.
2026-09-10 15:20:39 +02:00
MacRimi 4915d4044c tolerate flaky third-party apt repo in AppImage build workflows 2026-09-09 19:34:40 +02:00
MacRimi 90c4a720e3 group host changes by function with a truthful before/after 2026-09-09 19:26:22 +02:00
MacRimi 715f4195b2 require full_admin scope for terminal tickets and auth disable 2026-09-09 17:19:48 +02:00
MacRimi 023350d7e1 apply sentence spacing to every translation provider 2026-09-09 09:03:09 +02:00
MacRimi fb6c9bf22e capitalize audit socket message in Spanish 2026-09-08 21:12:55 +02:00
MacRimiandClaude Opus 5 da8a480eff Add audit and reports page, and a change journal
ProxMenux modifies the host: it rewrites configuration files, installs packages, enables services. Until now nobody could say afterwards what had changed, and showing the script does not answer that question — a four-hundred-line function may alter two values, and the reader has no way to know which two. This adds the two halves of an answer.

The change journal records what ProxMenux does as it does it. Eleven bash primitives capture the previous state, apply the change and record it in the same step, writing to a spool that the Monitor reads back. One hundred and thirteen functions across twenty-five scripts are instrumented, covering post-install, shared storage, security tooling, container conversions, disk operations and the PVE 8 to 9 upgrade path. The page shows the difference — rotate 7 becoming rotate 14 — and never the script. Restore and backup scripts are deliberately left out: a restore puts the host back to a state some other script already recorded.

The Audit and reports page answers the other half: what state is this host in, regardless of who put it there. Forty-three checks across seven areas read the host and classify each result as critical, warning, observation, conformant, unverified or not applicable, with the evidence they read attached to each one. A declared policy lets the reader say what this particular host is expected to do — which guests must have a backup, which storages are essential — so the report judges the host against its own intent rather than a generic template. An inventory records the hardware, network and guest topology behind those readings, a comparison shows what moved between two runs, and six report profiles produce a printable document scoped to what the reader needs. Everything is available in the eight supported languages.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-08 21:06:04 +02:00
MacRimi 337cb188c3 Fix Docker app version tracking, cache consistency and delegated updates 2026-09-05 17:01:02 +02:00
MacRimi 19c46a86d7 Merge develop into PR #337 and resolve shared app cache conflict 2026-09-05 16:51:41 +02:00
MacRimi 6644b62f63 Improve LXC updater selection, error handling and dashboard consistency 2026-09-05 16:10:31 +02:00
MacRimi 4f38d0e2e7 notification delivery gaps and locale corrections 2026-09-04 11:38:44 +02:00
MacRimi 25b5eaddc5 Fix restoration of custom Proxmox web certificates
Validate and restore pveproxy SSL certificate pairs during post-boot recovery, with fingerprint verification and automatic rollback on failure.
2026-09-03 23:46:03 +02:00
MacRimi 86305cf261 fix: harden post-install migrations and bundle multi-ABI Python runtimes
- safely migrate historical Bashrc and Log2RAM installations
- align post-install function versions across both flows
- bundle gevent runtimes for CPython 3.11 and 3.13
- select the correct Python ABI at runtime
- validate both supported Proxmox VE Python versions in AppImage workflows
- fix #327, #328 and #331
2026-09-03 11:55:39 +02:00
MacRimi cd40abc359 New version 1.2.6
Restores AI Assistant support for OpenAI-compatible endpoints on private IPs, loopback
and Docker networks (LiteLLM, LM Studio, LocalAI, vLLM, OmniRoute, self-hosted proxies)
and surfaces the server's error under the Load button (#325). Aligns the Secure Gateway
wizard's Alpine template selection and pct create with the host's real architecture on
x86_64 and arm64 (#324). Consolidates changes landing on develop: atomic notification
delivery, custom SSH port for Borg remote targets (#236), optional GitHub API token for
app version tracking (#306), and richer replication failure notifications.
2026-09-02 22:19:37 +02:00
MacRimi ea8c29ecbd New version 1.2.6
Restores AI Assistant support for OpenAI-compatible endpoints on private IPs, loopback
and Docker networks (LiteLLM, LM Studio, LocalAI, vLLM, OmniRoute, self-hosted proxies)
and surfaces the server's error under the Load button (#325). Aligns the Secure Gateway
wizard's Alpine template selection and pct create with the host's real architecture on
x86_64 and arm64 (#324). Consolidates changes landing on develop: atomic notification
delivery, custom SSH port for Borg remote targets (#236), optional GitHub API token for
app version tracking (#306), and richer replication failure notifications.
2026-09-02 22:18:52 +02:00
MacRimi eecd93bf1a prevent duplicate concurrent deliveries 2026-09-02 20:09:39 +02:00
MacRimi e7b69dae91 replication failure notifications 2026-09-02 16:28:03 +02:00
MacRimi 91b4200179 custom SSH port for Borg remote targets
feat(host-backup): custom SSH port for Borg remote targets

Add Borg destinations no longer assume port 22. The Monitor form and
the shell TUI both take an optional port (default 22, range 1-65535)
and embed it in the persisted ssh://user@host:port/path URL. BORG_RSH,
the sshpass key installer and the capacity probe all honour it.

Reported by @songochain in #236 — NAS-style Borg hosts on non-standard
SSH ports are now first-class targets.

Existing borg-targets.txt entries without a port keep working; the
port is only serialised into the URL when it differs from 22.
2026-09-02 14:43:28 +02:00
MacRimi 588d8f629d drop editorial preview/exp/experimental filter in Gemini provider 2026-09-02 14:11:24 +02:00
MacRimi 14823809d3 chore(ai-models): refresh catalog with 2026-09-02 verifier report 2026-09-02 13:42:08 +02:00
MacRimi 1bef36fb20 drop live AI catalog refresh + GH Action 2026-09-02 12:05:53 +02:00
MacRimi 20cf0a4a7f narrow _exclude to technical incapacity only 2026-09-02 11:32:17 +02:00
MacRimi 580fab6c78 Merge branch 'main' into develop — keep AI catalog fix from develop
Resolves the conflict on AppImage/config/verified_ai_models.json in favour
of develop's curated version with _exclude — main had the bot's first
naive refresh which surfaced allam-2-7b as the Groq recommended model.
develop also absorbs the bot-maintained files main had accumulated since
1.2.5 (helpers_cache, app_tracking_hints, project-growth, FUNDING).
2026-09-02 11:00:36 +02:00
MacRimi 1309654b4a AI models catalog — _exclude list + preserve recommended 2026-09-02 10:45:02 +02:00
MacRimi 674e9dba98 New version 1.2.5 2026-09-02 10:09:16 +02:00
MacRimi 220a670b46 AI models — live catalog with one-click refresh 2026-09-02 10:00:27 +02:00
MacRimi b88fd353a2 New version 1.2.5
Stable release consolidating the v1.2.4 beta cycle (1.2.4.1-beta and 1.2.4.2-beta) into 1.2.5.

Highlights:

- Apps dashboard: single launcher for every LXC-registered app and user-defined Custom Web Link, with category badges, search, sort and one-click deep-links back to the guest modal.
- LXC Apps & Updates end-to-end: App tab inside every guest modal, upstream version tracking, and Easy Updates that cover OS packages, registered apps, Docker Engine and per-image updates on the same 24-hour cycle.
- Application detection catalog with 380+ tracked workloads generated live from community-scripts across seven detector methods.
- Monitor now speaks 8 languages: English, Spanish, German, French, Italian, Portuguese, Slovak and Swedish (i18n scaffolding by @vaso73).
- NVIDIA multi-GPU passthrough by exact BDF so one card can be assigned to a VM while another stays operational on the host or LXC.
- Navigation reorder, Memory & Swap real memory-pressure signal, native Pushover channel, Actions API, plus wide-reaching improvements across health, hardware, network, backup and post-install.

Full release notes: see CHANGELOG.md and https://github.com/MacRimi/ProxMenux/releases
2026-09-01 19:43:10 +02:00
MacRimi 55603990b9 New version 1.2.5
Stable release consolidating the v1.2.4 beta cycle (1.2.4.1-beta and 1.2.4.2-beta) into 1.2.5.

Highlights:

- Apps dashboard: single launcher for every LXC-registered app and user-defined Custom Web Link, with category badges, search, sort and one-click deep-links back to the guest modal.
- LXC Apps & Updates end-to-end: App tab inside every guest modal, upstream version tracking, and Easy Updates that cover OS packages, registered apps, Docker Engine and per-image updates on the same 24-hour cycle.
- Application detection catalog with 380+ tracked workloads generated live from community-scripts across seven detector methods.
- Monitor now speaks 8 languages: English, Spanish, German, French, Italian, Portuguese, Slovak and Swedish (i18n scaffolding by @vaso73).
- NVIDIA multi-GPU passthrough by exact BDF so one card can be assigned to a VM while another stays operational on the host or LXC.
- Navigation reorder, Memory & Swap real memory-pressure signal, native Pushover channel, Actions API, plus wide-reaching improvements across health, hardware, network, backup and post-install.

Full release notes: see CHANGELOG.md and https://github.com/MacRimi/ProxMenux/releases
2026-09-01 19:42:09 +02:00
MacRimi 1262dafba8 New version 1.2.5 2026-09-01 19:21:29 +02:00