mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-10-01 19:17:10 +00:00
Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
100 lines
3.1 KiB
JSON
100 lines
3.1 KiB
JSON
{
|
|
"catalog_ui": {
|
|
"tips": [
|
|
"Intel/AMD acceleration is enabled by passing /dev/dri to the LXC; it does not require making the LXC privileged.",
|
|
"The privileged request from the imported Compose is discarded because it is not part of the official jlesage/handbrake requirements."
|
|
]
|
|
},
|
|
"container_contract": {
|
|
"environment": [
|
|
{
|
|
"name": "USER_ID",
|
|
"example": "1000",
|
|
"required": true,
|
|
"sensitive": false,
|
|
"source": "jlesage-documentation"
|
|
},
|
|
{
|
|
"name": "GROUP_ID",
|
|
"example": "1000",
|
|
"required": true,
|
|
"sensitive": false,
|
|
"source": "jlesage-documentation"
|
|
},
|
|
{
|
|
"name": "TZ",
|
|
"example": "Europe/Madrid",
|
|
"required": true,
|
|
"sensitive": false,
|
|
"source": "jlesage-documentation"
|
|
}
|
|
]
|
|
},
|
|
"proxmox": {
|
|
"security_profile": {
|
|
"requires_privileged_lxc": false,
|
|
"source_requests_privileged_lxc": true,
|
|
"optional_privileged_lxc": false,
|
|
"requires_host_pid_namespace": false,
|
|
"requires_relaxed_confinement": false,
|
|
"risk_level": "normal",
|
|
"confirmation_required": false,
|
|
"warning": "The imported Compose requests privileged, but the official jlesage/handbrake documentation does not require it; ProxMenux keeps the LXC unprivileged."
|
|
},
|
|
"installer_profile": {
|
|
"device_requests": [
|
|
{
|
|
"id": "vaapi-render",
|
|
"kind": "character-device",
|
|
"purpose": "vaapi",
|
|
"enable_prompt": "Enable Intel/AMD VA-API video acceleration",
|
|
"enabled_default": false,
|
|
"required_by_compose": false,
|
|
"path_prompt": "GPU render device",
|
|
"host_path_default": "/dev/dri/renderD128",
|
|
"container_path_strategy": "same-as-host",
|
|
"mode": "0660",
|
|
"deny_write": false,
|
|
"gid_strategy": "host-device-gid",
|
|
"source_mapping": "/dev/dri/renderD128:/dev/dri/renderD128"
|
|
}
|
|
],
|
|
"volume_preparations": [
|
|
{
|
|
"container_path": "/config",
|
|
"remove_lost_found": true,
|
|
"owner_strategy": "mapped-application-user",
|
|
"only_when_mount_type": "managed-volume"
|
|
},
|
|
{
|
|
"container_path": "/storage",
|
|
"remove_lost_found": true,
|
|
"owner_strategy": "mapped-application-user",
|
|
"only_when_mount_type": "managed-volume"
|
|
},
|
|
{
|
|
"container_path": "/watch",
|
|
"remove_lost_found": true,
|
|
"owner_strategy": "mapped-application-user",
|
|
"only_when_mount_type": "managed-volume"
|
|
},
|
|
{
|
|
"container_path": "/output",
|
|
"remove_lost_found": true,
|
|
"owner_strategy": "mapped-application-user",
|
|
"only_when_mount_type": "managed-volume"
|
|
}
|
|
],
|
|
"startup_healthcheck": {
|
|
"scheme": "http",
|
|
"port": 5800,
|
|
"path": "/",
|
|
"timeout_seconds": 180,
|
|
"request_timeout_seconds": 10,
|
|
"stability_seconds": 4,
|
|
"verify_tls": false
|
|
}
|
|
}
|
|
}
|
|
}
|