{ "schema_version": "0.5.0", "kind": "proxmenux.oci-template", "id": "image-taskingai", "status": "generated-review-required", "catalog_ui": { "title": { "en_US": "TaskingAI" }, "tagline": { "en_US": "The developer-friendly cloud platform for building and running LLM agents for AI-native applications." }, "description": { "en_US": "The developer-friendly cloud platform for building and running LLM agents for AI-native applications." }, "category": "ai", "category_label": "AI / Coding & Dev-Tools", "author": "TaskingAI Team", "developer": "TaskingAI Team", "icon": null, "thumbnail": null, "screenshots": [], "architectures": [ "amd64", "arm64" ], "launch": { "scheme": "http", "port": 3080, "path": "/" }, "website": "https://docs.tasking.ai/", "documentation": null, "repository": "https://hub.docker.com/r/taskingai/taskingai-console", "tips": [], "mini_changelog": [], "display_version": null, "updated_at": null, "hidden": true, "hidden_reason": "Pending multi-container adaptation; retained for future work" }, "source": { "provider": "official", "repository": "https://hub.docker.com/r/taskingai/taskingai-console", "revision": "a40cf6e5813b67c10f46b567adb72239e37ee1e862b949d80d41d19bf95caaf9", "image_repository_url": "https://hub.docker.com/r/taskingai/taskingai-console", "readme_pushed_at": "2026-09-11T10:43:22Z", "compose_sha256": "a40cf6e5813b67c10f46b567adb72239e37ee1e862b949d80d41d19bf95caaf9", "generated_at": "2026-09-13T15:48:36+00:00" }, "container_contract": { "service_name": "frontend", "container_name": "frontend", "image": { "reference": "taskingai/taskingai-console:latest", "registry": "docker.io", "repository": "taskingai/taskingai-console", "tag": "latest", "digest": null, "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" }, "environment": [], "volumes": [], "ports": [], "related_services": [ { "name": "backend-inference", "image": "taskingai/taskingai-inference:latest" }, { "name": "backend-plugin", "image": "taskingai/taskingai-plugin:latest" }, { "name": "backend-api", "image": "taskingai/taskingai-server:latest" }, { "name": "backend-web", "image": "taskingai/taskingai-server:latest" }, { "name": "db", "image": "ankane/pgvector:latest" }, { "name": "cache", "image": "redis:latest" }, { "name": "nginx", "image": "nginx:latest" } ], "restart": null, "stop_grace_period": null, "original_compose": "name: taskingai\nservices:\n frontend:\n image: taskingai/taskingai-console:latest\n depends_on:\n - backend-web\n - backend-api\n networks:\n - taskingai_network\n backend-inference:\n image: taskingai/taskingai-inference:latest\n environment:\n AES_ENCRYPTION_KEY: ${GENERATED_AES_ENCRYPTION_KEY}\n ICON_URL_PREFIX: http://nginx:3080\n PROJECT_ID: taskingai\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8000/v1/health_check\n interval: 15s\n timeout: 10s\n retries: 5\n networks:\n - taskingai_network\n backend-plugin:\n image: taskingai/taskingai-plugin:latest\n environment:\n AES_ENCRYPTION_KEY: ${GENERATED_AES_ENCRYPTION_KEY}\n ICON_URL_PREFIX: http://nginx:3080\n OBJECT_STORAGE_TYPE: local\n HOST_URL: http://nginx:3080\n PATH_TO_VOLUME: /var/lib/data\n PROJECT_ID: taskingai\n volumes:\n - /DATA/AppData/$AppID/data/object_storage:/var/lib/data\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8000/v1/health_check\n interval: 15s\n timeout: 10s\n retries: 5\n networks:\n - taskingai_network\n backend-api:\n image: taskingai/taskingai-server:latest\n environment:\n POSTGRES_URL: postgres://postgres:TaskingAI321@db:5432/taskingai\n REDIS_URL: redis://:TaskingAI321@cache:6379/0\n TASKINGAI_INFERENCE_URL: http://backend-inference:8000\n TASKINGAI_PLUGIN_URL: http://backend-plugin:8000\n AES_ENCRYPTION_KEY: ${GENERATED_AES_ENCRYPTION_KEY}\n OBJECT_STORAGE_TYPE: local\n HOST_URL: http://nginx:3080\n PATH_TO_VOLUME: /var/lib/data\n PROJECT_ID: taskingai\n volumes:\n - /DATA/AppData/$AppID/data/object_storage:/var/lib/data\n depends_on:\n - db\n - cache\n - backend-inference\n - backend-plugin\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8000/v1/health_check\n interval: 15s\n timeout: 10s\n retries: 5\n networks:\n - taskingai_network\n backend-web:\n image: taskingai/taskingai-server:latest\n environment:\n POSTGRES_URL: postgres://postgres:TaskingAI321@db:5432/taskingai\n REDIS_URL: redis://:TaskingAI321@cache:6379/0\n TASKINGAI_INFERENCE_URL: http://backend-inference:8000\n TASKINGAI_PLUGIN_URL: http://backend-plugin:8000\n AES_ENCRYPTION_KEY: ${GENERATED_AES_ENCRYPTION_KEY}\n JWT_SECRET_KEY: ${GENERATED_JWT_SECRET_KEY}\n PURPOSE: WEB\n DEFAULT_ADMIN_USERNAME: admin\n DEFAULT_ADMIN_PASSWORD: ${GENERATED_DEFAULT_ADMIN_PASSWORD}\n OBJECT_STORAGE_TYPE: local\n HOST_URL: http://nginx:3080\n PATH_TO_VOLUME: /var/lib/data\n PROJECT_ID: taskingai\n volumes:\n - /DATA/AppData/$AppID/data/object_storage:/var/lib/data\n depends_on:\n - db\n - cache\n - backend-inference\n - backend-plugin\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8000/v1/health_check\n interval: 15s\n timeout: 10s\n retries: 5\n networks:\n - taskingai_network\n db:\n image: ankane/pgvector:latest\n environment:\n POSTGRES_DB: taskingai\n POSTGRES_USER: postgres\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n volumes:\n - /DATA/AppData/$AppID/data/postgres:/var/lib/postgresql/data\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U postgres\n interval: 5s\n timeout: 5s\n retries: 10\n restart: always\n networks:\n - taskingai_network\n cache:\n image: redis:latest\n command:\n - redis-server\n - --requirepass\n - TaskingAI321\n volumes:\n - /DATA/AppData/$AppID/data/redis:/data\n healthcheck:\n test:\n - CMD\n - redis-cli\n - auth\n - TaskingAI321\n - ping\n interval: 5s\n timeout: 5s\n retries: 10\n restart: always\n networks:\n - taskingai_network\n nginx:\n image: nginx:latest\n ports:\n - 3080:80\n volumes:\n - /DATA/AppData/$AppID/data/nginx_cache:/var/cache/nginx\n depends_on:\n - frontend\n - backend-web\n - backend-api\n networks:\n - taskingai_network\n configs:\n - source: nginx_config\n target: /etc/nginx/conf.d/default.conf\nnetworks:\n taskingai_network:\n driver: bridge\nconfigs:\n nginx_config:\n content: \"server {\\n listen 80;\\n\\n client_max_body_size 20M;\\n\\n location\\\n \\ /images/providers/icons/ {\\n proxy_pass http://backend-inference:8000;\\n\\\n \\ }\\n\\n location /images/plugins/bundles/icons/ {\\n proxy_pass http://backend-plugin:8000;\\n\\\n \\ }\\n\\n location /api/v1/ {\\n proxy_pass http://backend-web:8000;\\n \\\n \\ proxy_http_version 1.1;\\n proxy_set_header Connection '';\\n \\\n \\ proxy_buffering off;\\n proxy_cache off;\\n proxy_read_timeout 24h;\\n\\\n \\ }\\n\\n location /v1/ {\\n proxy_pass http://backend-api:8000;\\n \\\n \\ proxy_http_version 1.1;\\n proxy_set_header Connection '';\\n proxy_buffering\\\n \\ off;\\n proxy_cache off;\\n proxy_read_timeout 24h;\\n }\\n\\n location\\\n \\ /imgs/ {\\n proxy_pass http://backend-web:8000;\\n }\\n\\n location / {\\n\\\n \\ proxy_pass http://frontend:80;\\n }\\n}\\n\"\n" }, "compose_stack": { "project_name": "taskingai", "deployment_model": "one-native-oci-lxc-per-compose-service", "user_experience": "single-application-install", "main_service": "frontend", "service_count": 8, "services": [ { "name": "backend-inference", "image": "taskingai/taskingai-inference:latest", "is_main": false, "role": "dependency", "vmid_offset": 1, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "taskingai/taskingai-inference:latest", "environment": { "AES_ENCRYPTION_KEY": "${GENERATED_AES_ENCRYPTION_KEY}", "ICON_URL_PREFIX": "http://nginx:3080", "PROJECT_ID": "taskingai" }, "healthcheck": { "test": [ "CMD", "curl", "-f", "http://localhost:8000/v1/health_check" ], "interval": "15s", "timeout": "10s", "retries": 5 }, "networks": [ "taskingai_network" ] } }, { "name": "backend-plugin", "image": "taskingai/taskingai-plugin:latest", "is_main": false, "role": "dependency", "vmid_offset": 2, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "taskingai/taskingai-plugin:latest", "environment": { "AES_ENCRYPTION_KEY": "${GENERATED_AES_ENCRYPTION_KEY}", "ICON_URL_PREFIX": "http://nginx:3080", "OBJECT_STORAGE_TYPE": "local", "HOST_URL": "http://nginx:3080", "PATH_TO_VOLUME": "/var/lib/data", "PROJECT_ID": "taskingai" }, "volumes": [ "/DATA/AppData/$AppID/data/object_storage:/var/lib/data" ], "healthcheck": { "test": [ "CMD", "curl", "-f", "http://localhost:8000/v1/health_check" ], "interval": "15s", "timeout": "10s", "retries": 5 }, "networks": [ "taskingai_network" ] } }, { "name": "cache", "image": "redis:latest", "is_main": false, "role": "dependency", "vmid_offset": 3, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "redis:latest", "command": [ "redis-server", "--requirepass", "TaskingAI321" ], "volumes": [ "/DATA/AppData/$AppID/data/redis:/data" ], "healthcheck": { "test": [ "CMD", "redis-cli", "auth", "TaskingAI321", "ping" ], "interval": "5s", "timeout": "5s", "retries": 10 }, "restart": "always", "networks": [ "taskingai_network" ] } }, { "name": "db", "image": "ankane/pgvector:latest", "is_main": false, "role": "dependency", "vmid_offset": 4, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "ankane/pgvector:latest", "environment": { "POSTGRES_DB": "taskingai", "POSTGRES_USER": "postgres", "POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}" }, "volumes": [ "/DATA/AppData/$AppID/data/postgres:/var/lib/postgresql/data" ], "healthcheck": { "test": [ "CMD-SHELL", "pg_isready -U postgres" ], "interval": "5s", "timeout": "5s", "retries": 10 }, "restart": "always", "networks": [ "taskingai_network" ] } }, { "name": "backend-api", "image": "taskingai/taskingai-server:latest", "is_main": false, "role": "dependency", "vmid_offset": 5, "depends_on": [ "backend-inference", "backend-plugin", "cache", "db" ], "frontend_network": false, "private_network": true, "compose": { "image": "taskingai/taskingai-server:latest", "environment": { "POSTGRES_URL": "postgres://postgres:TaskingAI321@db:5432/taskingai", "REDIS_URL": "redis://:TaskingAI321@cache:6379/0", "TASKINGAI_INFERENCE_URL": "http://backend-inference:8000", "TASKINGAI_PLUGIN_URL": "http://backend-plugin:8000", "AES_ENCRYPTION_KEY": "${GENERATED_AES_ENCRYPTION_KEY}", "OBJECT_STORAGE_TYPE": "local", "HOST_URL": "http://nginx:3080", "PATH_TO_VOLUME": "/var/lib/data", "PROJECT_ID": "taskingai" }, "volumes": [ "/DATA/AppData/$AppID/data/object_storage:/var/lib/data" ], "depends_on": [ "db", "cache", "backend-inference", "backend-plugin" ], "healthcheck": { "test": [ "CMD", "curl", "-f", "http://localhost:8000/v1/health_check" ], "interval": "15s", "timeout": "10s", "retries": 5 }, "networks": [ "taskingai_network" ] } }, { "name": "backend-web", "image": "taskingai/taskingai-server:latest", "is_main": false, "role": "dependency", "vmid_offset": 6, "depends_on": [ "backend-inference", "backend-plugin", "cache", "db" ], "frontend_network": false, "private_network": true, "compose": { "image": "taskingai/taskingai-server:latest", "environment": { "POSTGRES_URL": "postgres://postgres:TaskingAI321@db:5432/taskingai", "REDIS_URL": "redis://:TaskingAI321@cache:6379/0", "TASKINGAI_INFERENCE_URL": "http://backend-inference:8000", "TASKINGAI_PLUGIN_URL": "http://backend-plugin:8000", "AES_ENCRYPTION_KEY": "${GENERATED_AES_ENCRYPTION_KEY}", "JWT_SECRET_KEY": "${GENERATED_JWT_SECRET_KEY}", "PURPOSE": "WEB", "DEFAULT_ADMIN_USERNAME": "admin", "DEFAULT_ADMIN_PASSWORD": "${GENERATED_DEFAULT_ADMIN_PASSWORD}", "OBJECT_STORAGE_TYPE": "local", "HOST_URL": "http://nginx:3080", "PATH_TO_VOLUME": "/var/lib/data", "PROJECT_ID": "taskingai" }, "volumes": [ "/DATA/AppData/$AppID/data/object_storage:/var/lib/data" ], "depends_on": [ "db", "cache", "backend-inference", "backend-plugin" ], "healthcheck": { "test": [ "CMD", "curl", "-f", "http://localhost:8000/v1/health_check" ], "interval": "15s", "timeout": "10s", "retries": 5 }, "networks": [ "taskingai_network" ] } }, { "name": "frontend", "image": "taskingai/taskingai-console:latest", "is_main": true, "role": "frontend", "vmid_offset": 0, "depends_on": [ "backend-api", "backend-web" ], "frontend_network": true, "private_network": true, "compose": { "image": "taskingai/taskingai-console:latest", "depends_on": [ "backend-web", "backend-api" ], "networks": [ "taskingai_network" ] } }, { "name": "nginx", "image": "nginx:latest", "is_main": false, "role": "dependency", "vmid_offset": 7, "depends_on": [ "backend-api", "backend-web", "frontend" ], "frontend_network": true, "private_network": true, "compose": { "image": "nginx:latest", "ports": [ "3080:80" ], "volumes": [ "/DATA/AppData/$AppID/data/nginx_cache:/var/cache/nginx" ], "depends_on": [ "frontend", "backend-web", "backend-api" ], "networks": [ "taskingai_network" ], "configs": [ { "source": "nginx_config", "target": "/etc/nginx/conf.d/default.conf" } ] } } ], "top_level": { "name": "taskingai", "networks": { "taskingai_network": { "driver": "bridge" } }, "configs": { "nginx_config": { "content": "server {\n listen 80;\n\n client_max_body_size 20M;\n\n location /images/providers/icons/ {\n proxy_pass http://backend-inference:8000;\n }\n\n location /images/plugins/bundles/icons/ {\n proxy_pass http://backend-plugin:8000;\n }\n\n location /api/v1/ {\n proxy_pass http://backend-web:8000;\n proxy_http_version 1.1;\n proxy_set_header Connection '';\n proxy_buffering off;\n proxy_cache off;\n proxy_read_timeout 24h;\n }\n\n location /v1/ {\n proxy_pass http://backend-api:8000;\n proxy_http_version 1.1;\n proxy_set_header Connection '';\n proxy_buffering off;\n proxy_cache off;\n proxy_read_timeout 24h;\n }\n\n location /imgs/ {\n proxy_pass http://backend-web:8000;\n }\n\n location / {\n proxy_pass http://frontend:80;\n }\n}\n" } } }, "networking": { "frontend": "selected-proxmox-bridge", "private_required": true, "private_creation": "automatic-create-if-missing", "private_address_allocation": "automatic-static-address-per-service", "service_discovery": "private-addresses-with-compose-service-host-aliases", "dependency_external_access": "disabled-unless-service-publishes-ports", "prompt_user_for_private_network": false }, "storage": [ { "id": "backend-plugin-volume-0", "service": "backend-plugin", "container_path": "/var/lib/data", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "backend-api-volume-0", "service": "backend-api", "container_path": "/var/lib/data", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "backend-web-volume-0", "service": "backend-web", "container_path": "/var/lib/data", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "db-volume-0", "service": "db", "container_path": "/var/lib/postgresql/data", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "cache-volume-0", "service": "cache", "container_path": "/data", "mode": "host-bind", "user_selectable": true, "backup": false, "shared_with_other_lxc": true, "source_path": null, "source_path_prompt": "Host directory for cache:/data" }, { "id": "nginx-volume-0", "service": "nginx", "container_path": "/var/cache/nginx", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null } ], "orchestration": { "reserve_vmids_atomically": 8, "start_order": [ "backend-inference", "backend-plugin", "cache", "db", "backend-api", "backend-web", "frontend", "nginx" ], "stop_order": [ "nginx", "frontend", "backend-web", "backend-api", "db", "cache", "backend-plugin", "backend-inference" ], "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" }, "installer_inputs": { "prompted": [ "stack_name", "base_vmid", "rootfs_storage", "persistent_data_destinations", "frontend_bridge", "frontend_ipv4_mode" ], "automatic": [ "dependent_vmids", "private_bridge", "private_subnet", "private_service_addresses", "compose_service_aliases", "generated_secrets", "dependency_start_and_stop_order" ], "generated_secrets": [ { "id": "aes-encryption-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "backend-inference", "environment_variable": "AES_ENCRYPTION_KEY" }, { "service": "backend-plugin", "environment_variable": "AES_ENCRYPTION_KEY" }, { "service": "backend-api", "environment_variable": "AES_ENCRYPTION_KEY" }, { "service": "backend-web", "environment_variable": "AES_ENCRYPTION_KEY" } ] }, { "id": "default-admin-password", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "backend-web", "environment_variable": "DEFAULT_ADMIN_PASSWORD" } ] }, { "id": "jwt-secret-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "backend-web", "environment_variable": "JWT_SECRET_KEY" } ] }, { "id": "postgres-password", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "db", "environment_variable": "POSTGRES_PASSWORD" } ] } ] } }, "first_run": { "endpoints": [ { "label": "Web UI", "scheme": "http", "port": 3080, "path": "/", "source": "compose-metadata" } ], "credentials": [] }, "proxmox": { "runtime": "native-oci-lxc", "technology_status": "proxmox-technology-preview", "defaults": { "unprivileged": true, "ostype": "auto-from-image", "cores": 2, "memory_mb": 1024, "swap_mb": 512, "rootfs_size_gb": 8, "rootfs_storage": "local-lvm", "volume_storage": "local-lvm", "template_storage": "local", "bridge": "vmbr0", "ipv4": "dhcp", "firewall": true, "host_managed_network": true, "onboot": false, "features": [ "nesting=1" ], "shutdown_timeout_seconds": 30 }, "image_metadata_policy": { "entrypoint": "import-from-oci-image", "cmd": "import-from-oci-image", "environment": "import-image-env-then-apply-compose-overrides", "user": "import-from-oci-image", "working_dir": "import-from-oci-image", "stop_signal": "import-from-oci-image" }, "adaptations": [ { "id": "imported-compose-source", "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", "reason": "Catalog import must not imply runtime compatibility.", "behavioral_impact": "No automatic installation before review.", "validation": "pending-per-application" }, { "id": "rolling-latest-image", "upstream_behavior": "A discovered Compose may pin a release tag or digest.", "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", "validation": "pending-per-application" }, { "id": "dedicated-lxc-network", "upstream_behavior": "Docker publishes selected container ports on the Docker host.", "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", "reason": "A native LXC has its own address and does not require Docker port NAT.", "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", "validation": "pending-per-application" }, { "id": "compose-shm-size", "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", "behavioral_impact": "None expected.", "validation": "not-requested-by-compose" }, { "id": "compose-command", "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", "reason": "Proxmox stores the effective OCI process as one entrypoint string.", "behavioral_impact": "None expected.", "validation": "not-requested-by-compose" }, { "id": "compose-privileged-mode", "upstream_behavior": "Compose selects whether the container runs in privileged mode.", "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", "validation": "native-equivalent" }, { "id": "compose-process-runtime", "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", "reason": "The OCI process must start with the same identity, command and working directory without Docker.", "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", "validation": "not-requested-by-compose" }, { "id": "compose-healthcheck", "upstream_behavior": "Docker periodically executes the declared container healthcheck.", "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", "behavioral_impact": "The check runs during installation rather than continuously after installation.", "validation": "not-requested-by-compose" }, { "id": "compose-cpu-priority", "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", "reason": "Both settings express relative CPU priority on different scales.", "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", "validation": "not-requested-by-compose" }, { "id": "compose-network-identity", "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", "validation": "pending-per-application" }, { "id": "compose-network-mode", "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", "reason": "The LXC is the application host and already has its own address and port namespace.", "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", "validation": "not-requested-by-compose" }, { "id": "compose-capabilities-and-sysctls", "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", "validation": "not-requested-by-compose" }, { "id": "docker-engine-metadata", "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", "validation": "not-requested-by-compose" }, { "id": "compose-device-passthrough", "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", "validation": "not-requested-by-compose" }, { "id": "compose-host-ipc", "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", "validation": "not-requested-by-compose" } ], "generic_stack_review": [ "servicios que dependen del principal pendientes" ] }, "compatibility": { "automatic_install_candidate": false, "validated": false, "supported_compose_keys": [ "cap_add", "command", "container_name", "cpu_shares", "deploy", "devices", "entrypoint", "environment", "extra_hosts", "healthcheck", "hostname", "image", "init", "ipc", "labels", "logging", "mac_address", "network_mode", "networks", "ports", "privileged", "restart", "runtime", "shm_size", "stdin_open", "stop_grace_period", "sysctls", "tty", "user", "volumes", "working_dir" ], "untranslated_blockers": [ "multi-service-compose", "compose-key:depends_on", "service:backend-api:compose-key:depends_on", "service:backend-web:compose-key:depends_on", "service:db:healthcheck-format", "service:cache:healthcheck-format", "service:nginx:compose-key:configs", "service:nginx:compose-key:depends_on", "top-level-configs", "native-multi-lxc-orchestrator-not-yet-implemented" ], "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." }, "validation": { "schema": "passed-at-generation", "clean_install": "pending", "service_health": "pending", "restart_persistence": "pending", "backup_restore": "pending", "update_preserves_data": "pending" }, "lifecycle": { "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", "registry_state": { "resolved_architecture": null, "resolved_digest": null, "image_version_label": null, "image_created": null }, "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", "automatic_unattended_updates": false } }