{ "schema_version": "0.5.0", "kind": "proxmenux.oci-template", "id": "image-weknora", "status": "generated-review-required", "catalog_ui": { "title": { "en_US": "WeKnora" }, "tagline": { "en_US": "WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval, especially for handling complex, heterogeneous documents." }, "description": { "en_US": "WeKnora is a deep document understanding and semantic retrieval framework based on Large Language Models (LLM), specifically designed for document scenarios with complex structures and heterogeneous content. It adopts a modular architecture, integrating key technologies such as multimodal preprocessing, semantic vector indexing, intelligent retrieval, and large model inference. Based on the Retrieval-Augmented Generation (RAG) paradigm, it achieves context-aware, high-quality Q&A capabilities. WeKnora can deeply understand document content in different formats, combine relevant document fragments with language model inference, and output accurate, coherent semantic results.\n\n**Key Features:**\n- Multimodal Deep Parsing: Supports structured content extraction from various formats such as PDF, Word, TXT, images, including OCR image text recognition.\n- Semantic Vector Indexing and Intelligent Retrieval: Achieves high-precision semantic matching and recall through a combination of vector retrieval, keyword retrieval, and even knowledge graph-enhanced retrieval.\n- RAG Closed-Loop Q&A Generation: Generates accurate and coherent content answers by leveraging large language model inference and retrieval fragment fusion.\n- Agent Mode Enhanced Capabilities: Supports ReACT Agent mode, which can call built-in tools, external web search, etc., during multi-round iterations, to improve complex task processing capabilities.\n- Multi-type Knowledge Base Management: Can create FAQ and document-type knowledge bases, and flexibly manage tags, batch import files or URLs.\n- Configurable Dialogue Strategy and UI: Provides an intuitive Web interface and REST API, allowing online adjustment of models, retrieval thresholds, and Prompt to control dialogue behavior.\n\n**Learn More:**\n- [Official Website](https://weknora.weixin.qq.com)\n- [GitHub Link](https://github.com/Tencent/WeKnora)\n" }, "category": "ai", "category_label": "AI / Coding & Dev-Tools", "author": "Tencent", "developer": "Tencent", "icon": null, "thumbnail": null, "screenshots": [], "architectures": [ "amd64", "arm64" ], "launch": { "scheme": "http", "port": 80, "path": "/" }, "website": "https://weknora.weixin.qq.com", "documentation": null, "repository": "https://hub.docker.com/r/wechatopenai/weknora-ui", "tips": [], "mini_changelog": [], "display_version": null, "updated_at": null, "hidden": true, "hidden_reason": "Pending multi-container adaptation; retained for future work" }, "source": { "provider": "wechatopenai", "repository": "https://hub.docker.com/r/wechatopenai/weknora-ui", "revision": "81f6e87d7c0bb716b9f019183ac34e4bff46599d904f6e81935e469145afc435", "image_repository_url": "https://hub.docker.com/r/wechatopenai/weknora-ui", "readme_pushed_at": "2026-09-11T10:43:22Z", "compose_sha256": "81f6e87d7c0bb716b9f019183ac34e4bff46599d904f6e81935e469145afc435", "generated_at": "2026-09-13T15:48:37+00:00" }, "container_contract": { "service_name": "weknora", "container_name": "weknora", "image": { "reference": "wechatopenai/weknora-ui:latest", "registry": "docker.io", "repository": "wechatopenai/weknora-ui", "tag": "latest", "digest": null, "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" }, "environment": [ { "name": "MAX_FILE_SIZE_MB", "example": "50", "required": true, "sensitive": false, "source": "docker-compose" } ], "volumes": [], "ports": [ { "container_port": 80, "published_example": 1080, "protocol": "tcp", "required": true, "proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat" } ], "related_services": [ { "name": "app", "image": "wechatopenai/weknora-app:latest" }, { "name": "weknora-docreader", "image": "wechatopenai/weknora-docreader:latest" }, { "name": "weknora-postgres", "image": "paradedb/paradedb:latest" }, { "name": "weknora-redis", "image": "redis:latest" }, { "name": "minio", "image": "minio/minio:latest" }, { "name": "jaeger", "image": "jaegertracing/all-in-one:latest" }, { "name": "neo4j", "image": "neo4j:latest" }, { "name": "qdrant", "image": "qdrant/qdrant:latest" } ], "restart": "unless-stopped", "stop_grace_period": null, "original_compose": "name: weknora\nservices:\n weknora:\n image: wechatopenai/weknora-ui:latest\n container_name: weknora\n ports:\n - target: 80\n published: '1080'\n protocol: tcp\n environment:\n - MAX_FILE_SIZE_MB=50\n depends_on:\n app:\n condition: service_healthy\n networks:\n - weknora-network\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 128M\n app:\n image: wechatopenai/weknora-app:latest\n container_name: weknora-app\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/files\n target: /data/files\n deploy:\n resources:\n reservations:\n memory: 512M\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:8080/health\n interval: 30s\n timeout: 10s\n retries: 3\n start_period: 60s\n environment:\n - OTEL_EXPORTER_OTLP_ENDPOINT=jaeger:4317\n - OTEL_SERVICE_NAME=WeKnora\n - OTEL_TRACES_EXPORTER=otlp\n - OTEL_METRICS_EXPORTER=none\n - OTEL_LOGS_EXPORTER=none\n - OTEL_PROPAGATORS=tracecontext,baggage\n - QDRANT_HOST=qdrant\n - QDRANT_PORT=6334\n - QDRANT_COLLECTION=weknora_embeddings\n - QDRANT_API_KEY=${GENERATED_QDRANT_API_KEY}\n - QDRANT_USE_TLS=false\n - MINIO_ENDPOINT=minio:9000\n - MINIO_ACCESS_KEY_ID=${GENERATED_MINIO_ACCESS_KEY_ID}\n - MINIO_SECRET_ACCESS_KEY=${GENERATED_MINIO_SECRET_ACCESS_KEY}\n - MINIO_BUCKET_NAME=weknora\n - GIN_MODE=release\n - DISABLE_REGISTRATION=false\n - DB_DRIVER=postgres\n - DB_HOST=weknora-postgres\n - DB_PORT=5432\n - DB_USER=postgres\n - DB_PASSWORD=${GENERATED_DB_PASSWORD}\n - DB_NAME=WeKnora\n - TZ=$TZ\n - RETRIEVE_DRIVER=postgres\n - DOCREADER_ADDR=weknora-docreader:50051\n - STORAGE_TYPE=minio\n - LOCAL_STORAGE_BASE_DIR=/data/files\n - AUTO_RECOVER_DIRTY=true\n - OLLAMA_BASE_URL=http://host.docker.internal:11434\n - STREAM_MANAGER_TYPE=redis\n - REDIS_ADDR=weknora-redis:6379\n - REDIS_PASSWORD=${GENERATED_REDIS_PASSWORD}\n - REDIS_DB=0\n - REDIS_PREFIX=\"stream:\"\n - TENANT_AES_KEY=${GENERATED_TENANT_AES_KEY}\n - CONCURRENCY_POOL_SIZE=5\n - JWT_SECRET=${GENERATED_JWT_SECRET}\n - MAX_FILE_SIZE_MB=50\n depends_on:\n weknora-redis:\n condition: service_started\n weknora-postgres:\n condition: service_healthy\n weknora-docreader:\n condition: service_healthy\n networks:\n - weknora-network\n restart: unless-stopped\n extra_hosts:\n - host.docker.internal:host-gateway\n weknora-docreader:\n image: wechatopenai/weknora-docreader:latest\n container_name: weknora-docreader\n environment:\n - MAX_FILE_SIZE_MB=50\n - MINIO_ENDPOINT=minio:9000\n - MINIO_ACCESS_KEY_ID=${GENERATED_MINIO_ACCESS_KEY_ID}\n - MINIO_SECRET_ACCESS_KEY=${GENERATED_MINIO_SECRET_ACCESS_KEY}\n - MINIO_BUCKET_NAME=weknora\n deploy:\n resources:\n reservations:\n memory: 256M\n healthcheck:\n test:\n - CMD\n - grpc_health_probe\n - -addr=:50051\n interval: 30s\n timeout: 10s\n retries: 3\n start_period: 60s\n networks:\n - weknora-network\n restart: unless-stopped\n extra_hosts:\n - host.docker.internal:host-gateway\n weknora-postgres:\n image: paradedb/paradedb:latest\n container_name: weknora-postgres\n environment:\n - POSTGRES_USER=postgres\n - POSTGRES_PASSWORD=${GENERATED_DB_PASSWORD}\n - POSTGRES_DB=WeKnora\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data\n target: /var/lib/postgresql/data\n networks:\n - weknora-network\n healthcheck:\n test:\n - CMD-SHELL\n - pg_isready -U postgres\n interval: 10s\n timeout: 10s\n retries: 3\n start_period: 30s\n deploy:\n resources:\n reservations:\n memory: 512M\n restart: unless-stopped\n stop_grace_period: 1m\n weknora-redis:\n image: redis:latest\n container_name: weknora-redis\n command:\n - redis-server\n - --requirepass redis123!@#\n - --appendonly\n - true\n deploy:\n resources:\n reservations:\n memory: 128M\n restart: unless-stopped\n networks:\n - weknora-network\n minio:\n image: minio/minio:latest\n container_name: weknora-minio\n ports:\n - target: 9000\n published: '19000'\n protocol: tcp\n - target: 9001\n published: '19001'\n protocol: tcp\n environment:\n - MINIO_ROOT_USER=minioadmin\n - MINIO_ROOT_PASSWORD=${GENERATED_MINIO_ROOT_PASSWORD}\n deploy:\n resources:\n reservations:\n memory: 512M\n command:\n - server\n - /data\n - --console-address\n - :9001\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/minio-data\n target: /data\n healthcheck:\n test:\n - CMD\n - curl\n - -f\n - http://localhost:9000/minio/health/live\n interval: 30s\n timeout: 20s\n retries: 3\n networks:\n - weknora-network\n restart: unless-stopped\n jaeger:\n image: jaegertracing/all-in-one:latest\n container_name: weknora-jaeger\n ports:\n - target: 6831\n published: '46831'\n protocol: udp\n - target: 6832\n published: '46832'\n protocol: udp\n - target: 5778\n published: '45778'\n protocol: tcp\n - target: 16686\n published: '16686'\n protocol: tcp\n - target: 4317\n published: '44317'\n protocol: tcp\n - target: 4318\n published: '44318'\n protocol: tcp\n - target: 14250\n published: '14250'\n protocol: tcp\n - target: 14268\n published: '14268'\n protocol: tcp\n - target: 9411\n published: '49411'\n protocol: tcp\n environment:\n - COLLECTOR_OTLP_ENABLED=true\n - COLLECTOR_ZIPKIN_HOST_PORT=:9411\n deploy:\n resources:\n reservations:\n memory: 512M\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/jaeger\n target: /var/lib/jaeger\n networks:\n - weknora-network\n restart: unless-stopped\n neo4j:\n image: neo4j:latest\n container_name: weknora-neo4j\n profiles:\n - neo4j\n - full\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/neo4j-data\n target: /data\n environment:\n - NEO4J_AUTH=neo4j/password\n - NEO4J_apoc_export_file_enabled=true\n - NEO4J_apoc_import_file_enabled=true\n - NEO4J_apoc_import_file_use__neo4j__config=true\n - NEO4JLABS_PLUGINS=[\"apoc\"]\n ports:\n - target: 7474\n published: '47474'\n protocol: tcp\n - target: 7687\n published: '47687'\n protocol: tcp\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 256M\n networks:\n - weknora-network\n qdrant:\n image: qdrant/qdrant:latest\n container_name: weknora-qdrant\n profiles:\n - qdrant\n - full\n ports:\n - target: 6333\n published: '46333'\n protocol: tcp\n - target: 6334\n published: '46334'\n protocol: tcp\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/storage\n target: /qdrant/storage\n networks:\n - weknora-network\n restart: unless-stopped\n deploy:\n resources:\n reservations:\n memory: 256M\nnetworks:\n weknora-network:\n driver: bridge\n" }, "compose_stack": { "project_name": "weknora", "deployment_model": "one-native-oci-lxc-per-compose-service", "user_experience": "single-application-install", "main_service": "weknora", "service_count": 9, "services": [ { "name": "weknora-docreader", "image": "wechatopenai/weknora-docreader:latest", "is_main": false, "role": "dependency", "vmid_offset": 1, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "wechatopenai/weknora-docreader:latest", "container_name": "weknora-docreader", "environment": [ "MAX_FILE_SIZE_MB=50", "MINIO_ENDPOINT=minio:9000", "MINIO_ACCESS_KEY_ID=${GENERATED_MINIO_ACCESS_KEY_ID}", "MINIO_SECRET_ACCESS_KEY=${GENERATED_MINIO_SECRET_ACCESS_KEY}", "MINIO_BUCKET_NAME=weknora" ], "deploy": { "resources": { "reservations": { "memory": "256M" } } }, "healthcheck": { "test": [ "CMD", "grpc_health_probe", "-addr=:50051" ], "interval": "30s", "timeout": "10s", "retries": 3, "start_period": "60s" }, "networks": [ "weknora-network" ], "restart": "unless-stopped", "extra_hosts": [ "host.docker.internal:host-gateway" ] } }, { "name": "weknora-postgres", "image": "paradedb/paradedb:latest", "is_main": false, "role": "dependency", "vmid_offset": 2, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "paradedb/paradedb:latest", "container_name": "weknora-postgres", "environment": [ "POSTGRES_USER=postgres", "POSTGRES_PASSWORD=${GENERATED_DB_PASSWORD}", "POSTGRES_DB=WeKnora" ], "volumes": [ { "type": "bind", "source": "/DATA/AppData/$AppID/data", "target": "/var/lib/postgresql/data" } ], "networks": [ "weknora-network" ], "healthcheck": { "test": [ "CMD-SHELL", "pg_isready -U postgres" ], "interval": "10s", "timeout": "10s", "retries": 3, "start_period": "30s" }, "deploy": { "resources": { "reservations": { "memory": "512M" } } }, "restart": "unless-stopped", "stop_grace_period": "1m" } }, { "name": "weknora-redis", "image": "redis:latest", "is_main": false, "role": "dependency", "vmid_offset": 3, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "redis:latest", "container_name": "weknora-redis", "command": [ "redis-server", "--requirepass redis123!@#", "--appendonly", true ], "deploy": { "resources": { "reservations": { "memory": "128M" } } }, "restart": "unless-stopped", "networks": [ "weknora-network" ] } }, { "name": "app", "image": "wechatopenai/weknora-app:latest", "is_main": false, "role": "dependency", "vmid_offset": 4, "depends_on": [ "weknora-docreader", "weknora-postgres", "weknora-redis" ], "frontend_network": false, "private_network": true, "compose": { "image": "wechatopenai/weknora-app:latest", "container_name": "weknora-app", "volumes": [ { "type": "bind", "source": "/DATA/AppData/$AppID/files", "target": "/data/files" } ], "deploy": { "resources": { "reservations": { "memory": "512M" } } }, "healthcheck": { "test": [ "CMD", "curl", "-f", "http://localhost:8080/health" ], "interval": "30s", "timeout": "10s", "retries": 3, "start_period": "60s" }, "environment": [ "OTEL_EXPORTER_OTLP_ENDPOINT=jaeger:4317", "OTEL_SERVICE_NAME=WeKnora", "OTEL_TRACES_EXPORTER=otlp", "OTEL_METRICS_EXPORTER=none", "OTEL_LOGS_EXPORTER=none", "OTEL_PROPAGATORS=tracecontext,baggage", "QDRANT_HOST=qdrant", "QDRANT_PORT=6334", "QDRANT_COLLECTION=weknora_embeddings", "QDRANT_API_KEY=${GENERATED_QDRANT_API_KEY}", "QDRANT_USE_TLS=false", "MINIO_ENDPOINT=minio:9000", "MINIO_ACCESS_KEY_ID=${GENERATED_MINIO_ACCESS_KEY_ID}", "MINIO_SECRET_ACCESS_KEY=${GENERATED_MINIO_SECRET_ACCESS_KEY}", "MINIO_BUCKET_NAME=weknora", "GIN_MODE=release", "DISABLE_REGISTRATION=false", "DB_DRIVER=postgres", "DB_HOST=weknora-postgres", "DB_PORT=5432", "DB_USER=postgres", "DB_PASSWORD=${GENERATED_DB_PASSWORD}", "DB_NAME=WeKnora", "TZ=$TZ", "RETRIEVE_DRIVER=postgres", "DOCREADER_ADDR=weknora-docreader:50051", "STORAGE_TYPE=minio", "LOCAL_STORAGE_BASE_DIR=/data/files", "AUTO_RECOVER_DIRTY=true", "OLLAMA_BASE_URL=http://host.docker.internal:11434", "STREAM_MANAGER_TYPE=redis", "REDIS_ADDR=weknora-redis:6379", "REDIS_PASSWORD=${GENERATED_REDIS_PASSWORD}", "REDIS_DB=0", "REDIS_PREFIX=\"stream:\"", "TENANT_AES_KEY=${GENERATED_TENANT_AES_KEY}", "CONCURRENCY_POOL_SIZE=5", "JWT_SECRET=${GENERATED_JWT_SECRET}", "MAX_FILE_SIZE_MB=50" ], "depends_on": { "weknora-redis": { "condition": "service_started" }, "weknora-postgres": { "condition": "service_healthy" }, "weknora-docreader": { "condition": "service_healthy" } }, "networks": [ "weknora-network" ], "restart": "unless-stopped", "extra_hosts": [ "host.docker.internal:host-gateway" ] } }, { "name": "jaeger", "image": "jaegertracing/all-in-one:latest", "is_main": false, "role": "dependency", "vmid_offset": 5, "depends_on": [], "frontend_network": true, "private_network": true, "compose": { "image": "jaegertracing/all-in-one:latest", "container_name": "weknora-jaeger", "ports": [ { "target": 6831, "published": "46831", "protocol": "udp" }, { "target": 6832, "published": "46832", "protocol": "udp" }, { "target": 5778, "published": "45778", "protocol": "tcp" }, { "target": 16686, "published": "16686", "protocol": "tcp" }, { "target": 4317, "published": "44317", "protocol": "tcp" }, { "target": 4318, "published": "44318", "protocol": "tcp" }, { "target": 14250, "published": "14250", "protocol": "tcp" }, { "target": 14268, "published": "14268", "protocol": "tcp" }, { "target": 9411, "published": "49411", "protocol": "tcp" } ], "environment": [ "COLLECTOR_OTLP_ENABLED=true", "COLLECTOR_ZIPKIN_HOST_PORT=:9411" ], "deploy": { "resources": { "reservations": { "memory": "512M" } } }, "volumes": [ { "type": "bind", "source": "/DATA/AppData/$AppID/jaeger", "target": "/var/lib/jaeger" } ], "networks": [ "weknora-network" ], "restart": "unless-stopped" } }, { "name": "minio", "image": "minio/minio:latest", "is_main": false, "role": "dependency", "vmid_offset": 6, "depends_on": [], "frontend_network": true, "private_network": true, "compose": { "image": "minio/minio:latest", "container_name": "weknora-minio", "ports": [ { "target": 9000, "published": "19000", "protocol": "tcp" }, { "target": 9001, "published": "19001", "protocol": "tcp" } ], "environment": [ "MINIO_ROOT_USER=minioadmin", "MINIO_ROOT_PASSWORD=${GENERATED_MINIO_ROOT_PASSWORD}" ], "deploy": { "resources": { "reservations": { "memory": "512M" } } }, "command": [ "server", "/data", "--console-address", ":9001" ], "volumes": [ { "type": "bind", "source": "/DATA/AppData/$AppID/minio-data", "target": "/data" } ], "healthcheck": { "test": [ "CMD", "curl", "-f", "http://localhost:9000/minio/health/live" ], "interval": "30s", "timeout": "20s", "retries": 3 }, "networks": [ "weknora-network" ], "restart": "unless-stopped" } }, { "name": "neo4j", "image": "neo4j:latest", "is_main": false, "role": "dependency", "vmid_offset": 7, "depends_on": [], "frontend_network": true, "private_network": true, "compose": { "image": "neo4j:latest", "container_name": "weknora-neo4j", "profiles": [ "neo4j", "full" ], "volumes": [ { "type": "bind", "source": "/DATA/AppData/$AppID/neo4j-data", "target": "/data" } ], "environment": [ "NEO4J_AUTH=neo4j/password", "NEO4J_apoc_export_file_enabled=true", "NEO4J_apoc_import_file_enabled=true", "NEO4J_apoc_import_file_use__neo4j__config=true", "NEO4JLABS_PLUGINS=[\"apoc\"]" ], "ports": [ { "target": 7474, "published": "47474", "protocol": "tcp" }, { "target": 7687, "published": "47687", "protocol": "tcp" } ], "restart": "unless-stopped", "deploy": { "resources": { "reservations": { "memory": "256M" } } }, "networks": [ "weknora-network" ] } }, { "name": "qdrant", "image": "qdrant/qdrant:latest", "is_main": false, "role": "dependency", "vmid_offset": 8, "depends_on": [], "frontend_network": true, "private_network": true, "compose": { "image": "qdrant/qdrant:latest", "container_name": "weknora-qdrant", "profiles": [ "qdrant", "full" ], "ports": [ { "target": 6333, "published": "46333", "protocol": "tcp" }, { "target": 6334, "published": "46334", "protocol": "tcp" } ], "volumes": [ { "type": "bind", "source": "/DATA/AppData/$AppID/storage", "target": "/qdrant/storage" } ], "networks": [ "weknora-network" ], "restart": "unless-stopped", "deploy": { "resources": { "reservations": { "memory": "256M" } } } } }, { "name": "weknora", "image": "wechatopenai/weknora-ui:latest", "is_main": true, "role": "frontend", "vmid_offset": 0, "depends_on": [ "app" ], "frontend_network": true, "private_network": true, "compose": { "image": "wechatopenai/weknora-ui:latest", "container_name": "weknora", "ports": [ { "target": 80, "published": "1080", "protocol": "tcp" } ], "environment": [ "MAX_FILE_SIZE_MB=50" ], "depends_on": { "app": { "condition": "service_healthy" } }, "networks": [ "weknora-network" ], "restart": "unless-stopped", "deploy": { "resources": { "reservations": { "memory": "128M" } } } } } ], "top_level": { "name": "weknora", "networks": { "weknora-network": { "driver": "bridge" } } }, "networking": { "frontend": "selected-proxmox-bridge", "private_required": true, "private_creation": "automatic-create-if-missing", "private_address_allocation": "automatic-static-address-per-service", "service_discovery": "private-addresses-with-compose-service-host-aliases", "dependency_external_access": "disabled-unless-service-publishes-ports", "prompt_user_for_private_network": false }, "storage": [ { "id": "app-volume-0", "service": "app", "container_path": "/data/files", "mode": "host-bind", "user_selectable": true, "backup": false, "shared_with_other_lxc": true, "source_path": null, "source_path_prompt": "Host directory for app:/data/files" }, { "id": "weknora-postgres-volume-0", "service": "weknora-postgres", "container_path": "/var/lib/postgresql/data", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "minio-volume-0", "service": "minio", "container_path": "/data", "mode": "host-bind", "user_selectable": true, "backup": false, "shared_with_other_lxc": true, "source_path": null, "source_path_prompt": "Host directory for minio:/data" }, { "id": "jaeger-volume-0", "service": "jaeger", "container_path": "/var/lib/jaeger", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "neo4j-volume-0", "service": "neo4j", "container_path": "/data", "mode": "host-bind", "user_selectable": true, "backup": false, "shared_with_other_lxc": true, "source_path": null, "source_path_prompt": "Host directory for neo4j:/data" }, { "id": "qdrant-volume-0", "service": "qdrant", "container_path": "/qdrant/storage", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null } ], "orchestration": { "reserve_vmids_atomically": 9, "start_order": [ "weknora-docreader", "weknora-postgres", "weknora-redis", "app", "jaeger", "minio", "neo4j", "qdrant", "weknora" ], "stop_order": [ "weknora", "qdrant", "neo4j", "minio", "jaeger", "app", "weknora-redis", "weknora-postgres", "weknora-docreader" ], "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" }, "installer_inputs": { "prompted": [ "stack_name", "base_vmid", "rootfs_storage", "persistent_data_destinations", "frontend_bridge", "frontend_ipv4_mode" ], "automatic": [ "dependent_vmids", "private_bridge", "private_subnet", "private_service_addresses", "compose_service_aliases", "generated_secrets", "dependency_start_and_stop_order" ], "generated_secrets": [ { "id": "db-password", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "app", "environment_variable": "DB_PASSWORD" }, { "service": "weknora-postgres", "environment_variable": "POSTGRES_PASSWORD" } ] }, { "id": "jwt-secret", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "app", "environment_variable": "JWT_SECRET" } ] }, { "id": "minio-access-key-id", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "app", "environment_variable": "MINIO_ACCESS_KEY_ID" }, { "service": "weknora-docreader", "environment_variable": "MINIO_ACCESS_KEY_ID" } ] }, { "id": "minio-root-password", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "minio", "environment_variable": "MINIO_ROOT_PASSWORD" } ] }, { "id": "minio-secret-access-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "app", "environment_variable": "MINIO_SECRET_ACCESS_KEY" }, { "service": "weknora-docreader", "environment_variable": "MINIO_SECRET_ACCESS_KEY" } ] }, { "id": "qdrant-api-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "app", "environment_variable": "QDRANT_API_KEY" } ] }, { "id": "redis-password", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "app", "environment_variable": "REDIS_PASSWORD" } ] }, { "id": "tenant-aes-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "app", "environment_variable": "TENANT_AES_KEY" } ] } ] } }, "first_run": { "endpoints": [ { "label": "Web UI", "scheme": "http", "port": 80, "path": "/", "source": "compose-metadata" } ], "credentials": [] }, "proxmox": { "runtime": "native-oci-lxc", "technology_status": "proxmox-technology-preview", "defaults": { "unprivileged": true, "ostype": "auto-from-image", "cores": 2, "memory_mb": 128, "swap_mb": 512, "rootfs_size_gb": 8, "rootfs_storage": "local-lvm", "volume_storage": "local-lvm", "template_storage": "local", "bridge": "vmbr0", "ipv4": "dhcp", "firewall": true, "host_managed_network": true, "onboot": false, "features": [ "nesting=1" ], "shutdown_timeout_seconds": 30 }, "image_metadata_policy": { "entrypoint": "import-from-oci-image", "cmd": "import-from-oci-image", "environment": "import-image-env-then-apply-compose-overrides", "user": "import-from-oci-image", "working_dir": "import-from-oci-image", "stop_signal": "import-from-oci-image" }, "adaptations": [ { "id": "imported-compose-source", "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", "reason": "Catalog import must not imply runtime compatibility.", "behavioral_impact": "No automatic installation before review.", "validation": "pending-per-application" }, { "id": "rolling-latest-image", "upstream_behavior": "A discovered Compose may pin a release tag or digest.", "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", "validation": "pending-per-application" }, { "id": "dedicated-lxc-network", "upstream_behavior": "Docker publishes selected container ports on the Docker host.", "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", "reason": "A native LXC has its own address and does not require Docker port NAT.", "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", "validation": "pending-per-application" }, { "id": "compose-shm-size", "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", "behavioral_impact": "None expected.", "validation": "not-requested-by-compose" }, { "id": "compose-command", "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", "reason": "Proxmox stores the effective OCI process as one entrypoint string.", "behavioral_impact": "None expected.", "validation": "not-requested-by-compose" }, { "id": "compose-privileged-mode", "upstream_behavior": "Compose selects whether the container runs in privileged mode.", "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", "validation": "native-equivalent" }, { "id": "compose-process-runtime", "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", "reason": "The OCI process must start with the same identity, command and working directory without Docker.", "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", "validation": "not-requested-by-compose" }, { "id": "compose-healthcheck", "upstream_behavior": "Docker periodically executes the declared container healthcheck.", "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", "behavioral_impact": "The check runs during installation rather than continuously after installation.", "validation": "not-requested-by-compose" }, { "id": "compose-cpu-priority", "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", "reason": "Both settings express relative CPU priority on different scales.", "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", "validation": "not-requested-by-compose" }, { "id": "compose-network-identity", "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", "validation": "pending-per-application" }, { "id": "compose-network-mode", "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", "reason": "The LXC is the application host and already has its own address and port namespace.", "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", "validation": "not-requested-by-compose" }, { "id": "compose-capabilities-and-sysctls", "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", "validation": "not-requested-by-compose" }, { "id": "docker-engine-metadata", "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", "validation": "not-requested-by-compose" }, { "id": "compose-device-passthrough", "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", "validation": "not-requested-by-compose" }, { "id": "compose-host-ipc", "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", "validation": "not-requested-by-compose" } ], "generic_stack_review": [ "app: credencial externa o booleano GENERATED_QDRANT_API_KEY pendiente", "app: extra_hosts necesita revision de pila", "app: perfil de salud y persistencia pendiente", "jaeger: perfil de salud y persistencia pendiente", "minio: perfil de salud y persistencia pendiente", "neo4j: compose-key:profiles", "neo4j: perfil de salud y persistencia pendiente", "neo4j: profiles necesita revision de pila", "qdrant: compose-key:profiles", "qdrant: perfil de salud y persistencia pendiente", "qdrant: profiles necesita revision de pila", "weknora-docreader: extra_hosts necesita revision de pila", "weknora-docreader: perfil de salud y persistencia pendiente", "weknora-postgres: perfil de salud y persistencia pendiente", "weknora-redis: comando de dependencia personalizado pendiente" ] }, "compatibility": { "automatic_install_candidate": false, "validated": false, "supported_compose_keys": [ "cap_add", "command", "container_name", "cpu_shares", "deploy", "devices", "entrypoint", "environment", "extra_hosts", "healthcheck", "hostname", "image", "init", "ipc", "labels", "logging", "mac_address", "network_mode", "networks", "ports", "privileged", "restart", "runtime", "shm_size", "stdin_open", "stop_grace_period", "sysctls", "tty", "user", "volumes", "working_dir" ], "untranslated_blockers": [ "multi-service-compose", "compose-key:depends_on", "service:app:compose-key:depends_on", "service:weknora-docreader:healthcheck-format", "service:weknora-postgres:healthcheck-format", "service:neo4j:compose-key:profiles", "service:qdrant:compose-key:profiles", "native-multi-lxc-orchestrator-not-yet-implemented" ], "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." }, "validation": { "schema": "passed-at-generation", "clean_install": "pending", "service_health": "pending", "restart_persistence": "pending", "backup_restore": "pending", "update_preserves_data": "pending" }, "lifecycle": { "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", "registry_state": { "resolved_architecture": null, "resolved_digest": null, "image_version_label": null, "image_created": null }, "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", "automatic_unattended_updates": false } }