Files
ProxMenux/oci/catalog/overlays/2fauth.json
T
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00

52 lines
1.1 KiB
JSON

{
"container_contract": {
"environment": [
{
"name": "APP_KEY",
"example": "",
"required": true,
"sensitive": true,
"source": "2fauth-env-example"
}
]
},
"proxmox": {
"installer_profile": {
"generated_sensitive_environment": {
"APP_KEY": {
"strategy": "token-hex",
"bytes": 16,
"prompt": true
}
},
"volume_preparations": [
{
"container_path": "/2fauth",
"remove_lost_found": true,
"owner_strategy": "mapped-application-user",
"only_when_mount_type": "managed-volume"
}
],
"volume_owner": {
"uid": 1000,
"gid": 1000
},
"tmpfs_mounts": [
{
"id": "2fauth-nginx-run",
"container_path": "/run/nginx",
"default_size_mb": 8,
"minimum_size_mb": 1,
"prompt_size": false,
"mount_options": [
"rw",
"nosuid",
"nodev",
"mode=0777"
]
}
]
}
}
}