Commit Graph
89 Commits
Author SHA1 Message Date
MacRimiandClaude Opus 5 5f09af0162 fix(audit): state what the backup checks observed, not more
Two next steps in the backup area claimed more than the evidence behind
them supports, reported by @Vaso73 while reviewing the pattern.

A failed run is now treated as unsuccessful with a copy to confirm,
rather than asserted to have produced nothing usable — the task log does
not establish that. And a missing host-configuration record says no
backup is recorded here, leaving room for one this node cannot see.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 19:59:39 +02:00
ProxMenuxBot 3f3e3f05d9 chore(i18n): auto-fill missing translations in messages/{locale}/common.json
Source: 6fc893d
Triggered by: push
2026-09-22 17:28:25 +00:00
ProxMenuxBot f6bc0ea969 chore(i18n): auto-fill missing translations in messages/{locale}/common.json
Source: ce60060
Triggered by: push
2026-09-22 17:25:47 +00:00
ProxMenuxBot 4594177035 chore(i18n): auto-fill missing translations in messages/{locale}/common.json
Source: 60505a7
Triggered by: push
2026-09-22 17:23:06 +00:00
MacRimiandClaude Opus 5 dda8deb6e4 fix(i18n): complete the Monitor catalogs so a rerun writes nothing
The 41 keys added for the audit explanations, disk exclusions and idle
disk state existed only in English, so build_i18n_messages had work to do
on a clean checkout and the offline suite rejected it.

Fills them in the six remaining locales with argos, which joins the
provider list here as it already had in build_translation_cache: it runs
locally with no quota, and this script stores the English on a provider
failure, where a remote quota refusal would have been recorded as a
translation.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:29:23 +02:00
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00
ProxMenuxBot b36498f215 chore(i18n): auto-fill missing translations in messages/{locale}/common.json
Source: 94c3da0
Triggered by: push
2026-09-22 14:58:47 +00:00
ProxMenuxBot 4d4828e7c8 chore(i18n): auto-fill missing translations in messages/{locale}/common.json
Source: 3b18e3e
Triggered by: push
2026-09-22 14:40:45 +00:00
VAIO73 22c569dc41 i18n: align Slovak terminal command descriptions 2026-09-21 17:31:13 +02:00
VAIO73 10a69947dc i18n: localize health degradation alerts 2026-09-17 13:31:58 +02:00
VAIO73 661b944e0c fix: localize batched app update notifications 2026-09-17 13:12:02 +02:00
VAIO73 ad23a1167f i18n: localize LXC update notification results 2026-09-17 12:40:54 +02:00
VAIO73 dc283bed9a i18n: localize runtime notification delivery 2026-09-17 11:59:48 +02:00
Vaso73andVAIO73 38ac46460e fix: add notification language UI labels 2026-09-17 11:46:29 +02:00
VAIO73 36bca5908b i18n: upravený sprievodca systémovými záznamami 2026-09-12 11:36:49 +02:00
VAIO73 cbc5b9d953 i18n: upravené systémové záznamy 2026-09-12 11:36:49 +02:00
VAIO73 e61fdbf84f i18n: upravené texty karty Sieť 2026-09-12 11:36:49 +02:00
VAIO73 e67d5f1617 i18n: upravené texty úložiska 2026-09-12 11:36:49 +02:00
VAIO73 991cf732e5 i18n: upravené texty na Prehľade 2026-09-12 11:36:49 +02:00
VAIO73 8918675393 i18n: lokalizované kategórie aplikácií 2026-09-12 11:36:49 +02:00
VAIO73 e0c5740a47 i18n: zjednotené VM a LXC v Aplikáciách 2026-09-12 11:36:49 +02:00
VAIO73 9ff1fa1bda i18n: spresnené uzly v Termináli 2026-09-12 11:36:49 +02:00
VAIO73 7b06c90040 i18n: zjednotené pojmy na karte Záloha 2026-09-12 11:36:49 +02:00
VAIO73 f6a3dc2f24 i18n: zjednotené pojmy na karte Hardvér 2026-09-12 11:36:49 +02:00
VAIO73 9bdd0cb9fc i18n: zjednotené pojmy v Nastaveniach 2026-09-12 11:36:49 +02:00
VAIO73 6f7e94d095 i18n: zjednotené pojmy na karte Bezpečnosť 2026-09-12 11:36:49 +02:00
VAIO73 8c67f883c9 i18n: zjednotené pojmy na karte VM a LXC 2026-09-12 11:36:49 +02:00
MacRimiandGitHub 9d3285d0df Merge pull request #344 from Vaso73/i18n/sk-audit-report-pr
i18n: add Slovak Audit & Report copy
2026-09-12 11:05:49 +02:00
MacRimi b5fb747271 Section icons in the change journal, and admin scope on secret reveal 2026-09-12 10:54:36 +02:00
VAIO73 abef0c0303 i18n: zjednotené označenie kontroly auditu 2026-09-12 10:18:25 +02:00
VAIO73 bd6d1e323e i18n: zjednotené stavy auditu 2026-09-12 10:18:25 +02:00
VAIO73 9db1696d5a i18n: zjednotené názvy v úvodných novinkách 2026-09-12 10:18:25 +02:00
VAIO73 c6cb14c651 i18n: rozlíšené VM a LXC v audite 2026-09-12 10:18:25 +02:00
VAIO73 57b77eb212 i18n: spresnené pravidlá auditu 2026-09-12 10:18:25 +02:00
VAIO73 8d843c90e9 i18n: prirodzenejšie úvodné novinky 1.2.6.1 2026-09-12 10:18:25 +02:00
VAIO73 9c3f5feda1 i18n: prirodzenejšie texty auditu 2026-09-12 10:18:25 +02:00
VAIO73 e4f78a1227 i18n: preložené úvodné novinky 1.2.6.1 2026-09-12 10:18:25 +02:00
VAIO73 983bf5c610 i18n: preložená záložka Audit a správy 2026-09-12 10:18:25 +02:00
MacRimi 78d2d84f20 Read the login-page version from APP_VERSION 2026-09-12 09:53:33 +02:00
MacRimi 0b64549230 Focus the Audit & Report tab, scope API tokens 2026-09-12 00:22:14 +02:00
MacRimi bee242afa9 record Monitor-side installs and dedupe config by file 2026-09-11 19:54:32 +02:00
MacRimi 8e0d4ff337 eep only package-changing executions and clean up entry presentation 2026-09-11 08:37:23 +02:00
MacRimi 085cbf7e68 scope the change journal to host changes, in three sections
The change journal exists so a sysadmin sees what ProxMenux changed on the host — its own configuration, packages and services — not how it uses the host or configures a guest. Several scripts recorded operations that are neither: disk passthrough to a VM, container conversions, VM import/export, mounting a share into an LXC. Those are restored to their original, uninstrumented form. Scripts that operate on the host while also installing a package now record only the package: format-disk keeps its exFAT-tools install, the UUP ISO builder its build dependencies, and the share/host scripts their packages, services and /etc/fstab writes, while the mount and unmount operations they used to log are dropped.

The page now reads in three sections: what ProxMenux optimized after install (each function under its menu name), what its other host scripts changed (by script), and what it installed (packages and utilities, each referencing the script that installed it). A file reads as created or modified with its diff, a service shows its state transition, and the undo line appears only when a revert is possible.
2026-09-10 15:20:39 +02:00
MacRimi 90c4a720e3 group host changes by function with a truthful before/after 2026-09-09 19:26:22 +02:00
MacRimiandClaude Opus 5 da8a480eff Add audit and reports page, and a change journal
ProxMenux modifies the host: it rewrites configuration files, installs packages, enables services. Until now nobody could say afterwards what had changed, and showing the script does not answer that question — a four-hundred-line function may alter two values, and the reader has no way to know which two. This adds the two halves of an answer.

The change journal records what ProxMenux does as it does it. Eleven bash primitives capture the previous state, apply the change and record it in the same step, writing to a spool that the Monitor reads back. One hundred and thirteen functions across twenty-five scripts are instrumented, covering post-install, shared storage, security tooling, container conversions, disk operations and the PVE 8 to 9 upgrade path. The page shows the difference — rotate 7 becoming rotate 14 — and never the script. Restore and backup scripts are deliberately left out: a restore puts the host back to a state some other script already recorded.

The Audit and reports page answers the other half: what state is this host in, regardless of who put it there. Forty-three checks across seven areas read the host and classify each result as critical, warning, observation, conformant, unverified or not applicable, with the evidence they read attached to each one. A declared policy lets the reader say what this particular host is expected to do — which guests must have a backup, which storages are essential — so the report judges the host against its own intent rather than a generic template. An inventory records the hardware, network and guest topology behind those readings, a comparison shows what moved between two runs, and six report profiles produce a printable document scoped to what the reader needs. Everything is available in the eight supported languages.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-08 21:06:04 +02:00
MacRimiandGitHub b4e34d0902 Merge pull request #338 from MacRimi/fix/pr337-docker-update-hardening
Fix Docker app version tracking, cache consistency and delegated updates
2026-09-05 17:02:08 +02:00
MacRimi 337cb188c3 Fix Docker app version tracking, cache consistency and delegated updates 2026-09-05 17:01:02 +02:00
ProxMenuxBot f1d8b299db chore(i18n): auto-fill missing translations in messages/{locale}/common.json
Source: 3a49648
Triggered by: push
2026-09-05 14:56:42 +00:00
MacRimi 6644b62f63 Improve LXC updater selection, error handling and dashboard consistency 2026-09-05 16:10:31 +02:00
MacRimi 4f38d0e2e7 notification delivery gaps and locale corrections 2026-09-04 11:38:44 +02:00