Two changes, both scoped to scripts/backup_restore/backup_scheduler.sh, worth
shipping to main ahead of the full v1.2.3 release PR:
1. Attached-mode PBS jobs never asked about encryption. `_create_job_attached`
ran `hb_select_pbs_repository` and jumped straight to writing the .env with
PBS_REPOSITORY / PBS_PASSWORD / PBS_BACKUP_ID — no `hb_ask_pbs_encryption`
call, no PBS_KEYFILE / PBS_ENCRYPTION_PASSWORD emitted. The runner then
invoked `proxmox-backup-client backup` without `--keyfile`, so every
attached-mode backup landed on PBS unencrypted regardless of what the
operator would have picked. Confirmed via `git show` on eight historical
commits back to 61ff665c (beta 1.2.2.2) — the encryption call has NEVER
been in the attached branch; the standalone `_create_job_new` branch had
it since day one, they just diverged silently.
Fix mirrors `_create_job_new` exactly (lines 413-443):
hb_ask_pbs_encryption || return 1 # abort on cancel
local pbs_kf_val=""
[[ -n "${HB_PBS_KEYFILE_OPT:-}" ]] && pbs_kf_val="$HB_STATE_DIR/pbs-key.conf"
lines+=(... "PBS_KEYFILE=${pbs_kf_val}" "PBS_ENCRYPTION_PASSWORD=${HB_PBS_ENC_PASS:-}")
The Monitor Web path (flask_server.py::api_host_backups_job_create)
already accepted pbs_encrypt_mode for both modes and passed it through
correctly, so the fix is confined to the CLI wizard.
2. Backend selection menu reordered from `local | borg | pbs` to
`pbs (recommended) | borg | local` so the recommended default sits at the
top of the list. PBS gets the "(recommended)" suffix in its label.
Deployed and verified on the four test hosts (.50, .55, .89, .1.10) —
attached-mode wizard now shows the encryption dialog immediately after the
PBS job picker, and the .env carries PBS_KEYFILE + PBS_ENCRYPTION_PASSWORD
when the operator opts in.
Consolidates the /web changes that were made on develop for the v1.2.3 stable
release, so the release PR (develop → main) can focus on version.txt +
AppImage + shell scripts without web conflicts.
Contents:
- CHANGELOG.md + web/data/changelog/es.md — v1.2.3 stable entry prepended
(bullets + tables, not paragraphs) with the release header image.
- images/ProxMenux_backup.png — new v1.2.3 release header image.
- web/app/[locale]/docs/backup-restore/page.tsx +
web/messages/{en,es}/docs/backup-restore/index.json — new Video walkthrough
block for the YouTube demo of the Backups feature (videoId K7A1KtOe4IQ),
embedded high on the overview page via the shared YouTubeEmbed component.
- web/app/[locale]/docs/installation/page.tsx +
web/messages/{en,es}/docs/installation.json +
web/public/install/install.png — stale Translation-flavour and Python-from-
PyPI mentions removed from the install page; screenshot refreshed and moved
to local /install/install.png (was pointing at the legacy GitHub Pages URL).
- web/messages/es/docs/backup-restore/destinations/pbs.json — minor polish
aligned with PR #247 already on main.
- web/public/images/docs/backup-restore/pbs-paired-backup-groups.png — updated
screenshot to match the reworked PBS-paired-group naming shipped in the beta
cycle.
- images/logos_txt/jc_channel.txt — new asset for the contributors page.
The recovery envelope no longer lands in /root/ — code was cleaned up
earlier this cycle to keep the keyfile and its envelope exclusively at
/usr/local/share/proxmenux/. The glossary entries for "Recovery envelope"
(EN) / "Sobre de recuperación" (ES) still described the /root/ mirror
as an "offsite backup" / "respaldo local", which is now inaccurate.
Removes the trailing sentence from both entries.
- Explicit yes/no escrow choice reinforced ("nothing gets uploaded to PBS
until the operator answers Yes") in intro + recoveryTitle + recoveryBody
- Wrong-key detection: recoverBody extended to describe the structured
amber panel that Monitor shows on View contents / Download / Restore
when the installed keyfile doesn't match the backup's manifest, with
the required fingerprint rendered prominently
- New encryption.monitorManagement section: describes the Download /
Upload / Delete inline actions in each PBS destination row, plus the
Yes/No + passphrase + contextual Apply escrow toggle
- ES: "operador" → "usuario" throughout (glossary rule)
- page.tsx: renders the new subsection and passes {code, em, strong} to
the extended recoveryBody