Files
ProxMenux/oci/catalog/overlays/vaultwarden.json
T
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00

75 lines
2.0 KiB
JSON

{
"catalog_ui": {
"launch": {
"scheme": "https",
"port": 443,
"path": "/"
},
"tips": [
"The Web Vault requires a secure context. ProxMenux enables Vaultwarden's native Rocket TLS listener on port 443.",
"A persistent self-signed certificate is generated under /data/tls. Browsers must trust or explicitly accept it; a trusted reverse proxy certificate can replace these files later."
]
},
"container_contract": {
"environment": [
{
"name": "ROCKET_PORT",
"example": "443",
"required": true,
"sensitive": false,
"prompt_user": false,
"source": "vaultwarden-rocket-tls"
},
{
"name": "ROCKET_TLS",
"example": "{certs=\"/data/tls/vaultwarden.crt\",key=\"/data/tls/vaultwarden.key\"}",
"required": true,
"sensitive": false,
"prompt_user": false,
"source": "vaultwarden-rocket-tls"
}
],
"ports": [
{
"container_port": 443,
"published_example": 443,
"protocol": "tcp",
"required": true,
"proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat"
}
]
},
"proxmox": {
"installer_profile": {
"self_signed_tls": {
"certificate_path": "/data/tls/vaultwarden.crt",
"private_key_path": "/data/tls/vaultwarden.key",
"common_name_from": "deployment-hostname",
"valid_days": 3650,
"preserve_existing": true
},
"startup_healthcheck": {
"scheme": "https",
"port": 443,
"path": "/alive",
"timeout_seconds": 180,
"request_timeout_seconds": 10,
"stability_seconds": 4,
"verify_tls": false
}
}
},
"first_run": {
"endpoints": [
{
"label": "Vaultwarden Web Vault",
"scheme": "https",
"port": 443,
"path": "/",
"source": "vaultwarden-native-rocket-tls"
}
],
"credentials": []
}
}