{ "schema_version": "0.5.0", "kind": "proxmenux.oci-template", "id": "image-dify", "status": "generated-review-required", "catalog_ui": { "title": { "en_US": "Dify" }, "tagline": { "en_US": "LLM App Development Platform" }, "description": { "en_US": "Dify is an open-source large language model (LLM) application development platform. It combines the concepts of Backend-as-a-Service and LLMOps to enable developers to quickly build production-grade generative AI applications. Even non-technical personnel can participate in the definition and data operations of AI applications." }, "category": "ai", "category_label": "AI / Coding & Dev-Tools", "author": "LangGenius", "developer": "LangGenius", "icon": "https://cdn.jsdelivr.net/gh/selfhst/icons@main/webp/dify.webp", "thumbnail": null, "screenshots": [], "architectures": [ "amd64" ], "launch": { "scheme": "http", "port": 3701, "path": "/" }, "website": "https://dify.ai", "documentation": null, "repository": "https://hub.docker.com/r/langgenius/dify-web", "tips": [], "mini_changelog": [], "display_version": null, "updated_at": null, "hidden": true, "hidden_reason": "Pending multi-container adaptation; retained for future work" }, "source": { "provider": "langgenius", "repository": "https://hub.docker.com/r/langgenius/dify-web", "revision": "4610bb3d0fdc309d1ac9020e20a0b9bac9bf84e9e30b2bccebc86873f4e6d177", "image_repository_url": "https://hub.docker.com/r/langgenius/dify-web", "readme_pushed_at": "2026-09-11T10:43:22Z", "compose_sha256": "4610bb3d0fdc309d1ac9020e20a0b9bac9bf84e9e30b2bccebc86873f4e6d177", "generated_at": "2026-09-13T15:48:24+00:00" }, "container_contract": { "service_name": "web", "container_name": "dify-web", "image": { "reference": "langgenius/dify-web:latest", "registry": "docker.io", "repository": "langgenius/dify-web", "tag": "latest", "digest": null, "pull_policy": "resolve-selected-tag-to-architecture-digest-at-install" }, "environment": [ { "name": "CONSOLE_API_URL", "example": "", "required": true, "sensitive": false, "source": "docker-compose" }, { "name": "APP_API_URL", "example": "", "required": true, "sensitive": false, "source": "docker-compose" } ], "volumes": [], "ports": [], "related_services": [ { "name": "config", "image": "ns2kracy/dify-config:latest" }, { "name": "api", "image": "langgenius/dify-api:latest" }, { "name": "worker", "image": "langgenius/dify-api:latest" }, { "name": "db", "image": "postgres:latest" }, { "name": "redis", "image": "redis:latest" }, { "name": "weaviate", "image": "semitechnologies/weaviate:latest" }, { "name": "sandbox", "image": "langgenius/dify-sandbox:latest" }, { "name": "ssrf_proxy", "image": "ubuntu/squid:latest" }, { "name": "nginx", "image": "nginx:latest" } ], "restart": "unless-stopped", "stop_grace_period": null, "original_compose": "name: dify\nservices:\n config:\n container_name: dify-config\n restart: unless-stopped\n image: ns2kracy/dify-config:latest\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data/nginx\n target: /configs/nginx\n - type: bind\n source: /DATA/AppData/$AppID/data/ssrf_proxy\n target: /configs/ssrf_proxy\n - type: bind\n source: /DATA/AppData/$AppID/data/sandbox\n target: /configs/sandbox\n networks:\n - dify\n api:\n image: langgenius/dify-api:latest\n container_name: dify-api\n restart: unless-stopped\n environment:\n MODE: api\n LOG_LEVEL: INFO\n SECRET_KEY: ${GENERATED_SECRET_KEY}\n CONSOLE_WEB_URL: ''\n INIT_PASSWORD: ${GENERATED_INIT_PASSWORD}\n CONSOLE_API_URL: ''\n SERVICE_API_URL: ''\n APP_WEB_URL: ''\n FILES_URL: ''\n FILES_ACCESS_TIMEOUT: '300'\n MIGRATION_ENABLED: 'true'\n DB_USERNAME: postgres\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n DB_HOST: db\n DB_PORT: '5432'\n DB_DATABASE: dify\n REDIS_HOST: redis\n REDIS_PORT: '6379'\n REDIS_PASSWORD: ${GENERATED_REDIS_PASSWORD}\n REDIS_DB: '0'\n CELERY_BROKER_URL: redis://:difyai123456@redis:6379/1\n WEB_API_CORS_ALLOW_ORIGINS: '*'\n CONSOLE_CORS_ALLOW_ORIGINS: '*'\n STORAGE_TYPE: local\n STORAGE_LOCAL_PATH: storage\n VECTOR_STORE: weaviate\n WEAVIATE_ENDPOINT: http://weaviate:8080\n WEAVIATE_API_KEY: ${GENERATED_WEAVIATE_API_KEY}\n CODE_EXECUTION_ENDPOINT: http://sandbox:8194\n CODE_EXECUTION_API_KEY: ${GENERATED_CODE_EXECUTION_API_KEY}\n CODE_MAX_NUMBER: '9223372036854775807'\n CODE_MIN_NUMBER: '-9223372036854775808'\n CODE_MAX_STRING_LENGTH: '80000'\n TEMPLATE_TRANSFORM_MAX_LENGTH: '80000'\n CODE_MAX_STRING_ARRAY_LENGTH: '30'\n CODE_MAX_OBJECT_ARRAY_LENGTH: '30'\n CODE_MAX_NUMBER_ARRAY_LENGTH: '1000'\n SSRF_PROXY_HTTP_URL: http://ssrf_proxy:3128\n SSRF_PROXY_HTTPS_URL: http://ssrf_proxy:3128\n INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH: ${GENERATED_INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH}\n depends_on:\n - db\n - redis\n volumes:\n - /DATA/AppData/$AppID/data/app/api/storage:/app/api/storage\n networks:\n - ssrf_proxy_network\n - dify\n worker:\n image: langgenius/dify-api:latest\n container_name: dify-worker\n restart: unless-stopped\n environment:\n MODE: worker\n LOG_LEVEL: INFO\n SECRET_KEY: ${GENERATED_SECRET_KEY}\n DB_USERNAME: postgres\n DB_PASSWORD: ${GENERATED_DB_PASSWORD}\n DB_HOST: db\n DB_PORT: '5432'\n DB_DATABASE: dify\n REDIS_HOST: redis\n REDIS_PORT: '6379'\n REDIS_PASSWORD: ${GENERATED_REDIS_PASSWORD}\n REDIS_DB: '0'\n REDIS_USE_SSL: 'false'\n CELERY_BROKER_URL: redis://:difyai123456@redis:6379/1\n STORAGE_TYPE: local\n STORAGE_LOCAL_PATH: storage\n VECTOR_STORE: weaviate\n WEAVIATE_ENDPOINT: http://weaviate:8080\n WEAVIATE_API_KEY: ${GENERATED_WEAVIATE_API_KEY}\n depends_on:\n - db\n - redis\n volumes:\n - /DATA/AppData/$AppID/data/app/api/storage:/app/api/storage\n networks:\n - ssrf_proxy_network\n - dify\n web:\n image: langgenius/dify-web:latest\n container_name: dify-web\n restart: unless-stopped\n environment:\n CONSOLE_API_URL: ''\n APP_API_URL: ''\n deploy:\n resources:\n reservations:\n memory: 2048M\n networks:\n - dify\n db:\n image: postgres:latest\n container_name: dify-db\n restart: unless-stopped\n environment:\n PGUSER: postgres\n POSTGRES_PASSWORD: ${GENERATED_DB_PASSWORD}\n POSTGRES_DB: dify\n PGDATA: /var/lib/postgresql/data/pgdata\n command: \"postgres -c 'max_connections=100'\\n -c 'shared_buffers=128MB'\\n\\\n \\ -c 'work_mem=4MB'\\n -c 'maintenance_work_mem=64MB'\\n \\\n \\ -c 'effective_cache_size=4096MB'\\n\"\n volumes:\n - /DATA/AppData/$AppID/data/db/data:/var/lib/postgresql/data\n healthcheck:\n test:\n - CMD\n - pg_isready\n interval: 1s\n timeout: 3s\n retries: 30\n networks:\n - dify\n redis:\n image: redis:latest\n container_name: dify-redis\n restart: unless-stopped\n environment:\n REDISCLI_AUTH: difyai123456\n volumes:\n - /DATA/AppData/$AppID/data/redis/data:/data\n command: redis-server --requirepass difyai123456\n healthcheck:\n test:\n - CMD\n - redis-cli\n - ping\n networks:\n - dify\n weaviate:\n image: semitechnologies/weaviate:latest\n container_name: dify-weaviate\n restart: unless-stopped\n volumes:\n - /DATA/AppData/$AppID/data/weaviate:/var/lib/weaviate\n environment:\n QUERY_DEFAULTS_LIMIT: '25'\n AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED: 'false'\n PERSISTENCE_DATA_PATH: /var/lib/weaviate\n DEFAULT_VECTORIZER_MODULE: none\n CLUSTER_HOSTNAME: node1\n AUTHENTICATION_APIKEY_ENABLED: ${GENERATED_AUTHENTICATION_APIKEY_ENABLED}\n AUTHENTICATION_APIKEY_ALLOWED_KEYS: ${GENERATED_AUTHENTICATION_APIKEY_ALLOWED_KEYS}\n AUTHENTICATION_APIKEY_USERS: ${GENERATED_AUTHENTICATION_APIKEY_USERS}\n AUTHORIZATION_ADMINLIST_ENABLED: 'true'\n AUTHORIZATION_ADMINLIST_USERS: hello@dify.ai\n networks:\n - dify\n sandbox:\n image: langgenius/dify-sandbox:latest\n container_name: dify-sandbox\n restart: unless-stopped\n environment:\n API_KEY: ${GENERATED_API_KEY}\n GIN_MODE: release\n WORKER_TIMEOUT: '15'\n ENABLE_NETWORK: 'true'\n HTTP_PROXY: http://ssrf_proxy:3128\n HTTPS_PROXY: http://ssrf_proxy:3128\n SANDBOX_PORT: '8194'\n volumes:\n - /DATA/AppData/$AppID/data/sandbox/dependencies:/dependencies\n networks:\n - ssrf_proxy_network\n depends_on:\n - config\n ssrf_proxy:\n image: ubuntu/squid:latest\n container_name: dify-ssrf_proxy\n restart: unless-stopped\n environment:\n HTTP_PORT: 3128\n COREDUMP_DIR: /var/spool/squid\n REVERSE_PROXY_PORT: 8194\n SANDBOX_HOST: sandbox\n SANDBOX_PORT: 8194\n volumes:\n - /DATA/AppData/$AppID/data/ssrf_proxy:/etc/squid\n networks:\n - ssrf_proxy_network\n - dify\n depends_on:\n - config\n nginx:\n image: nginx:latest\n container_name: dify-nginx\n restart: unless-stopped\n volumes:\n - /DATA/AppData/$AppID/data/nginx:/etc/nginx\n depends_on:\n - api\n - web\n - config\n ports:\n - 3701:80\n networks:\n - dify\nnetworks:\n ssrf_proxy_network:\n driver: bridge\n internal: true\n dify:\n name: dify\n" }, "compose_stack": { "project_name": "dify", "deployment_model": "one-native-oci-lxc-per-compose-service", "user_experience": "single-application-install", "main_service": "web", "service_count": 10, "services": [ { "name": "db", "image": "postgres:latest", "is_main": false, "role": "dependency", "vmid_offset": 1, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "postgres:latest", "container_name": "dify-db", "restart": "unless-stopped", "environment": { "PGUSER": "postgres", "POSTGRES_PASSWORD": "${GENERATED_DB_PASSWORD}", "POSTGRES_DB": "dify", "PGDATA": "/var/lib/postgresql/data/pgdata" }, "command": "postgres -c 'max_connections=100'\n -c 'shared_buffers=128MB'\n -c 'work_mem=4MB'\n -c 'maintenance_work_mem=64MB'\n -c 'effective_cache_size=4096MB'\n", "volumes": [ "/DATA/AppData/$AppID/data/db/data:/var/lib/postgresql/data" ], "healthcheck": { "test": [ "CMD", "pg_isready" ], "interval": "1s", "timeout": "3s", "retries": 30 }, "networks": [ "dify" ] } }, { "name": "redis", "image": "redis:latest", "is_main": false, "role": "dependency", "vmid_offset": 2, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "redis:latest", "container_name": "dify-redis", "restart": "unless-stopped", "environment": { "REDISCLI_AUTH": "difyai123456" }, "volumes": [ "/DATA/AppData/$AppID/data/redis/data:/data" ], "command": "redis-server --requirepass difyai123456", "healthcheck": { "test": [ "CMD", "redis-cli", "ping" ] }, "networks": [ "dify" ] } }, { "name": "api", "image": "langgenius/dify-api:latest", "is_main": false, "role": "dependency", "vmid_offset": 3, "depends_on": [ "db", "redis" ], "frontend_network": false, "private_network": true, "compose": { "image": "langgenius/dify-api:latest", "container_name": "dify-api", "restart": "unless-stopped", "environment": { "MODE": "api", "LOG_LEVEL": "INFO", "SECRET_KEY": "${GENERATED_SECRET_KEY}", "CONSOLE_WEB_URL": "", "INIT_PASSWORD": "${GENERATED_INIT_PASSWORD}", "CONSOLE_API_URL": "", "SERVICE_API_URL": "", "APP_WEB_URL": "", "FILES_URL": "", "FILES_ACCESS_TIMEOUT": "300", "MIGRATION_ENABLED": "true", "DB_USERNAME": "postgres", "DB_PASSWORD": "${GENERATED_DB_PASSWORD}", "DB_HOST": "db", "DB_PORT": "5432", "DB_DATABASE": "dify", "REDIS_HOST": "redis", "REDIS_PORT": "6379", "REDIS_PASSWORD": "${GENERATED_REDIS_PASSWORD}", "REDIS_DB": "0", "CELERY_BROKER_URL": "redis://:difyai123456@redis:6379/1", "WEB_API_CORS_ALLOW_ORIGINS": "*", "CONSOLE_CORS_ALLOW_ORIGINS": "*", "STORAGE_TYPE": "local", "STORAGE_LOCAL_PATH": "storage", "VECTOR_STORE": "weaviate", "WEAVIATE_ENDPOINT": "http://weaviate:8080", "WEAVIATE_API_KEY": "${GENERATED_WEAVIATE_API_KEY}", "CODE_EXECUTION_ENDPOINT": "http://sandbox:8194", "CODE_EXECUTION_API_KEY": "${GENERATED_CODE_EXECUTION_API_KEY}", "CODE_MAX_NUMBER": "9223372036854775807", "CODE_MIN_NUMBER": "-9223372036854775808", "CODE_MAX_STRING_LENGTH": "80000", "TEMPLATE_TRANSFORM_MAX_LENGTH": "80000", "CODE_MAX_STRING_ARRAY_LENGTH": "30", "CODE_MAX_OBJECT_ARRAY_LENGTH": "30", "CODE_MAX_NUMBER_ARRAY_LENGTH": "1000", "SSRF_PROXY_HTTP_URL": "http://ssrf_proxy:3128", "SSRF_PROXY_HTTPS_URL": "http://ssrf_proxy:3128", "INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH": "${GENERATED_INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH}" }, "depends_on": [ "db", "redis" ], "volumes": [ "/DATA/AppData/$AppID/data/app/api/storage:/app/api/storage" ], "networks": [ "ssrf_proxy_network", "dify" ] } }, { "name": "config", "image": "ns2kracy/dify-config:latest", "is_main": false, "role": "dependency", "vmid_offset": 4, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "container_name": "dify-config", "restart": "unless-stopped", "image": "ns2kracy/dify-config:latest", "volumes": [ { "type": "bind", "source": "/DATA/AppData/$AppID/data/nginx", "target": "/configs/nginx" }, { "type": "bind", "source": "/DATA/AppData/$AppID/data/ssrf_proxy", "target": "/configs/ssrf_proxy" }, { "type": "bind", "source": "/DATA/AppData/$AppID/data/sandbox", "target": "/configs/sandbox" } ], "networks": [ "dify" ] } }, { "name": "web", "image": "langgenius/dify-web:latest", "is_main": true, "role": "frontend", "vmid_offset": 0, "depends_on": [], "frontend_network": true, "private_network": true, "compose": { "image": "langgenius/dify-web:latest", "container_name": "dify-web", "restart": "unless-stopped", "environment": { "CONSOLE_API_URL": "", "APP_API_URL": "" }, "deploy": { "resources": { "reservations": { "memory": "2048M" } } }, "networks": [ "dify" ] } }, { "name": "nginx", "image": "nginx:latest", "is_main": false, "role": "dependency", "vmid_offset": 5, "depends_on": [ "api", "config", "web" ], "frontend_network": true, "private_network": true, "compose": { "image": "nginx:latest", "container_name": "dify-nginx", "restart": "unless-stopped", "volumes": [ "/DATA/AppData/$AppID/data/nginx:/etc/nginx" ], "depends_on": [ "api", "web", "config" ], "ports": [ "3701:80" ], "networks": [ "dify" ] } }, { "name": "sandbox", "image": "langgenius/dify-sandbox:latest", "is_main": false, "role": "dependency", "vmid_offset": 6, "depends_on": [ "config" ], "frontend_network": false, "private_network": true, "compose": { "image": "langgenius/dify-sandbox:latest", "container_name": "dify-sandbox", "restart": "unless-stopped", "environment": { "API_KEY": "${GENERATED_API_KEY}", "GIN_MODE": "release", "WORKER_TIMEOUT": "15", "ENABLE_NETWORK": "true", "HTTP_PROXY": "http://ssrf_proxy:3128", "HTTPS_PROXY": "http://ssrf_proxy:3128", "SANDBOX_PORT": "8194" }, "volumes": [ "/DATA/AppData/$AppID/data/sandbox/dependencies:/dependencies" ], "networks": [ "ssrf_proxy_network" ], "depends_on": [ "config" ] } }, { "name": "ssrf_proxy", "image": "ubuntu/squid:latest", "is_main": false, "role": "dependency", "vmid_offset": 7, "depends_on": [ "config" ], "frontend_network": false, "private_network": true, "compose": { "image": "ubuntu/squid:latest", "container_name": "dify-ssrf_proxy", "restart": "unless-stopped", "environment": { "HTTP_PORT": 3128, "COREDUMP_DIR": "/var/spool/squid", "REVERSE_PROXY_PORT": 8194, "SANDBOX_HOST": "sandbox", "SANDBOX_PORT": 8194 }, "volumes": [ "/DATA/AppData/$AppID/data/ssrf_proxy:/etc/squid" ], "networks": [ "ssrf_proxy_network", "dify" ], "depends_on": [ "config" ] } }, { "name": "weaviate", "image": "semitechnologies/weaviate:latest", "is_main": false, "role": "dependency", "vmid_offset": 8, "depends_on": [], "frontend_network": false, "private_network": true, "compose": { "image": "semitechnologies/weaviate:latest", "container_name": "dify-weaviate", "restart": "unless-stopped", "volumes": [ "/DATA/AppData/$AppID/data/weaviate:/var/lib/weaviate" ], "environment": { "QUERY_DEFAULTS_LIMIT": "25", "AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED": "false", "PERSISTENCE_DATA_PATH": "/var/lib/weaviate", "DEFAULT_VECTORIZER_MODULE": "none", "CLUSTER_HOSTNAME": "node1", "AUTHENTICATION_APIKEY_ENABLED": "${GENERATED_AUTHENTICATION_APIKEY_ENABLED}", "AUTHENTICATION_APIKEY_ALLOWED_KEYS": "${GENERATED_AUTHENTICATION_APIKEY_ALLOWED_KEYS}", "AUTHENTICATION_APIKEY_USERS": "${GENERATED_AUTHENTICATION_APIKEY_USERS}", "AUTHORIZATION_ADMINLIST_ENABLED": "true", "AUTHORIZATION_ADMINLIST_USERS": "hello@dify.ai" }, "networks": [ "dify" ] } }, { "name": "worker", "image": "langgenius/dify-api:latest", "is_main": false, "role": "dependency", "vmid_offset": 9, "depends_on": [ "db", "redis" ], "frontend_network": false, "private_network": true, "compose": { "image": "langgenius/dify-api:latest", "container_name": "dify-worker", "restart": "unless-stopped", "environment": { "MODE": "worker", "LOG_LEVEL": "INFO", "SECRET_KEY": "${GENERATED_SECRET_KEY}", "DB_USERNAME": "postgres", "DB_PASSWORD": "${GENERATED_DB_PASSWORD}", "DB_HOST": "db", "DB_PORT": "5432", "DB_DATABASE": "dify", "REDIS_HOST": "redis", "REDIS_PORT": "6379", "REDIS_PASSWORD": "${GENERATED_REDIS_PASSWORD}", "REDIS_DB": "0", "REDIS_USE_SSL": "false", "CELERY_BROKER_URL": "redis://:difyai123456@redis:6379/1", "STORAGE_TYPE": "local", "STORAGE_LOCAL_PATH": "storage", "VECTOR_STORE": "weaviate", "WEAVIATE_ENDPOINT": "http://weaviate:8080", "WEAVIATE_API_KEY": "${GENERATED_WEAVIATE_API_KEY}" }, "depends_on": [ "db", "redis" ], "volumes": [ "/DATA/AppData/$AppID/data/app/api/storage:/app/api/storage" ], "networks": [ "ssrf_proxy_network", "dify" ] } } ], "top_level": { "name": "dify", "networks": { "ssrf_proxy_network": { "driver": "bridge", "internal": true }, "dify": { "name": "dify" } } }, "networking": { "frontend": "selected-proxmox-bridge", "private_required": true, "private_creation": "automatic-create-if-missing", "private_address_allocation": "automatic-static-address-per-service", "service_discovery": "private-addresses-with-compose-service-host-aliases", "dependency_external_access": "disabled-unless-service-publishes-ports", "prompt_user_for_private_network": false }, "storage": [ { "id": "config-volume-0", "service": "config", "container_path": "/configs/nginx", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "config-volume-1", "service": "config", "container_path": "/configs/ssrf_proxy", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "config-volume-2", "service": "config", "container_path": "/configs/sandbox", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "api-volume-0", "service": "api", "container_path": "/app/api/storage", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "worker-volume-0", "service": "worker", "container_path": "/app/api/storage", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "db-volume-0", "service": "db", "container_path": "/var/lib/postgresql/data", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "redis-volume-0", "service": "redis", "container_path": "/data", "mode": "host-bind", "user_selectable": true, "backup": false, "shared_with_other_lxc": true, "source_path": null, "source_path_prompt": "Host directory for redis:/data" }, { "id": "weaviate-volume-0", "service": "weaviate", "container_path": "/var/lib/weaviate", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "sandbox-volume-0", "service": "sandbox", "container_path": "/dependencies", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "ssrf-proxy-volume-0", "service": "ssrf_proxy", "container_path": "/etc/squid", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null }, { "id": "nginx-volume-0", "service": "nginx", "container_path": "/etc/nginx", "mode": "managed-volume", "user_selectable": false, "backup": true, "shared_with_other_lxc": false, "source_path": null, "source_path_prompt": null } ], "orchestration": { "reserve_vmids_atomically": 10, "start_order": [ "db", "redis", "api", "config", "web", "nginx", "sandbox", "ssrf_proxy", "weaviate", "worker" ], "stop_order": [ "worker", "weaviate", "ssrf_proxy", "sandbox", "nginx", "web", "config", "api", "redis", "db" ], "dependency_readiness": "compose-healthcheck-then-port-or-process-fallback", "rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes" }, "installer_inputs": { "prompted": [ "stack_name", "base_vmid", "rootfs_storage", "persistent_data_destinations", "frontend_bridge", "frontend_ipv4_mode" ], "automatic": [ "dependent_vmids", "private_bridge", "private_subnet", "private_service_addresses", "compose_service_aliases", "generated_secrets", "dependency_start_and_stop_order" ], "generated_secrets": [ { "id": "api-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "sandbox", "environment_variable": "API_KEY" } ] }, { "id": "authentication-apikey-allowed-keys", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "weaviate", "environment_variable": "AUTHENTICATION_APIKEY_ALLOWED_KEYS" } ] }, { "id": "authentication-apikey-enabled", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "weaviate", "environment_variable": "AUTHENTICATION_APIKEY_ENABLED" } ] }, { "id": "authentication-apikey-users", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "weaviate", "environment_variable": "AUTHENTICATION_APIKEY_USERS" } ] }, { "id": "code-execution-api-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "api", "environment_variable": "CODE_EXECUTION_API_KEY" } ] }, { "id": "db-password", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "api", "environment_variable": "DB_PASSWORD" }, { "service": "worker", "environment_variable": "DB_PASSWORD" }, { "service": "db", "environment_variable": "POSTGRES_PASSWORD" } ] }, { "id": "indexing-max-segmentation-tokens-length", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "api", "environment_variable": "INDEXING_MAX_SEGMENTATION_TOKENS_LENGTH" } ] }, { "id": "init-password", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "api", "environment_variable": "INIT_PASSWORD" } ] }, { "id": "redis-password", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "api", "environment_variable": "REDIS_PASSWORD" }, { "service": "worker", "environment_variable": "REDIS_PASSWORD" } ] }, { "id": "secret-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "api", "environment_variable": "SECRET_KEY" }, { "service": "worker", "environment_variable": "SECRET_KEY" } ] }, { "id": "weaviate-api-key", "strategy": "generate-cryptographically-random-at-install", "bindings": [ { "service": "api", "environment_variable": "WEAVIATE_API_KEY" }, { "service": "worker", "environment_variable": "WEAVIATE_API_KEY" } ] } ] } }, "first_run": { "endpoints": [ { "label": "Web UI", "scheme": "http", "port": 3701, "path": "/", "source": "compose-metadata" } ], "credentials": [] }, "proxmox": { "runtime": "native-oci-lxc", "technology_status": "proxmox-technology-preview", "defaults": { "unprivileged": true, "ostype": "auto-from-image", "cores": 2, "memory_mb": 2048, "swap_mb": 512, "rootfs_size_gb": 8, "rootfs_storage": "local-lvm", "volume_storage": "local-lvm", "template_storage": "local", "bridge": "vmbr0", "ipv4": "dhcp", "firewall": true, "host_managed_network": true, "onboot": false, "features": [ "nesting=1" ], "shutdown_timeout_seconds": 30 }, "image_metadata_policy": { "entrypoint": "import-from-oci-image", "cmd": "import-from-oci-image", "environment": "import-image-env-then-apply-compose-overrides", "user": "import-from-oci-image", "working_dir": "import-from-oci-image", "stop_signal": "import-from-oci-image" }, "adaptations": [ { "id": "imported-compose-source", "upstream_behavior": "The source definition deploys the complete Docker Compose application model.", "native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.", "reason": "Catalog import must not imply runtime compatibility.", "behavioral_impact": "No automatic installation before review.", "validation": "pending-per-application" }, { "id": "rolling-latest-image", "upstream_behavior": "A discovered Compose may pin a release tag or digest.", "native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.", "reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.", "behavioral_impact": "The installed release can be newer than the discovered Compose revision.", "validation": "pending-per-application" }, { "id": "dedicated-lxc-network", "upstream_behavior": "Docker publishes selected container ports on the Docker host.", "native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.", "reason": "A native LXC has its own address and does not require Docker port NAT.", "behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.", "validation": "pending-per-application" }, { "id": "compose-shm-size", "upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.", "native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.", "reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.", "behavioral_impact": "None expected.", "validation": "not-requested-by-compose" }, { "id": "compose-command", "upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.", "native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.", "reason": "Proxmox stores the effective OCI process as one entrypoint string.", "behavioral_impact": "None expected.", "validation": "not-requested-by-compose" }, { "id": "compose-privileged-mode", "upstream_behavior": "Compose selects whether the container runs in privileged mode.", "native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.", "reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.", "behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.", "validation": "native-equivalent" }, { "id": "compose-process-runtime", "upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.", "native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.", "reason": "The OCI process must start with the same identity, command and working directory without Docker.", "behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.", "validation": "not-requested-by-compose" }, { "id": "compose-healthcheck", "upstream_behavior": "Docker periodically executes the declared container healthcheck.", "native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.", "reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.", "behavioral_impact": "The check runs during installation rather than continuously after installation.", "validation": "not-requested-by-compose" }, { "id": "compose-cpu-priority", "upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.", "native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.", "reason": "Both settings express relative CPU priority on different scales.", "behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.", "validation": "not-requested-by-compose" }, { "id": "compose-network-identity", "upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.", "native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.", "reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.", "behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.", "validation": "pending-per-application" }, { "id": "compose-network-mode", "upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.", "native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.", "reason": "The LXC is the application host and already has its own address and port namespace.", "behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.", "validation": "not-requested-by-compose" }, { "id": "compose-capabilities-and-sysctls", "upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.", "native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.", "reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.", "behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.", "validation": "not-requested-by-compose" }, { "id": "docker-engine-metadata", "upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.", "native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.", "reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.", "behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.", "validation": "not-requested-by-compose" }, { "id": "compose-device-passthrough", "upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.", "native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.", "reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.", "behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.", "validation": "not-requested-by-compose" }, { "id": "compose-host-ipc", "upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.", "native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.", "reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.", "behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.", "validation": "not-requested-by-compose" } ], "generic_stack_review": [ "servicios que dependen del principal pendientes" ] }, "compatibility": { "automatic_install_candidate": false, "validated": false, "supported_compose_keys": [ "cap_add", "command", "container_name", "cpu_shares", "deploy", "devices", "entrypoint", "environment", "extra_hosts", "healthcheck", "hostname", "image", "init", "ipc", "labels", "logging", "mac_address", "network_mode", "networks", "ports", "privileged", "restart", "runtime", "shm_size", "stdin_open", "stop_grace_period", "sysctls", "tty", "user", "volumes", "working_dir" ], "untranslated_blockers": [ "multi-service-compose", "service:api:compose-key:depends_on", "service:worker:compose-key:depends_on", "service:db:healthcheck-format", "service:redis:healthcheck-format", "service:sandbox:compose-key:depends_on", "service:ssrf_proxy:compose-key:depends_on", "service:nginx:compose-key:depends_on", "native-multi-lxc-orchestrator-not-yet-implemented" ], "policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available." }, "validation": { "schema": "passed-at-generation", "clean_install": "pending", "service_health": "pending", "restart_persistence": "pending", "backup_restore": "pending", "update_preserves_data": "pending" }, "lifecycle": { "update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update", "registry_state": { "resolved_architecture": null, "resolved_digest": null, "image_version_label": null, "image_created": null }, "change_detection": "compare-compose-sha256-and-resolved-latest-image-digest", "automatic_unattended_updates": false } }