Files
ProxMenux/oci/remote/oci_native_stack.sh
T
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00

43 lines
1.5 KiB
Bash
Executable File

# Sourced by the dedicated installers after image resolution, before CT creation.
oci_native_begin() {
OCI_NATIVE_PRIMARY=$1
shift
local root=/usr/local/share/proxmenux/oci/apps
[[ ! -L $root && ! -L $root/.lock ]] || die "$(translate "The instance registry is not safe")"
oci_quiet install -d -m 0700 "$root"
exec 8>>"$root/.lock"
chmod 600 "$root/.lock"
flock -n 8 || die "$(translate "Another OCI operation is using the instance registry")"
export PROXMENUX_INSTANCE_LOCK_FD=8
oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" begin "$OCI_NATIVE_PRIMARY" \
--template "$TEMPLATE_FILE" --deployment "$DEPLOYMENT_FILE" \
--adapter "$0" "$@"
OCI_NATIVE_ACTIVE=1
}
# A failure returns to the caller instead of exiting inside a redirected call,
# so the caller's error report reaches the terminal and not the log.
pct() {
if [[ ${1:-} == unmount && ${OCI_NATIVE_ACTIVE:-0} == 1 ]]; then
if ! python3 "$SCRIPT_DIR/oci_native_stack.py" capture-rootfs "$2"; then
command pct unmount "$2" 8>&- 9>&- || true
return 1
fi
fi
if [[ ${1:-} == create && ${OCI_NATIVE_ACTIVE:-0} == 1 ]]; then
shift
python3 "$SCRIPT_DIR/oci_native_stack.py" create "$@" || return
else
command pct "$@" 8>&- 9>&- || return
fi
}
oci_native_finalize() {
oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" finalize "$OCI_NATIVE_PRIMARY"
}
oci_native_failed() {
[[ ${OCI_NATIVE_ACTIVE:-0} == 1 ]] || return 0
oci_quiet python3 "$SCRIPT_DIR/oci_native_stack.py" failed "$OCI_NATIVE_PRIMARY" || true
}