Files
ProxMenux/oci/remote/nvidia_lxc_mount_lab.sh
T
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00

31 lines
1.5 KiB
Bash
Executable File

#!/bin/bash
# Experimental native LXC mount hook: PVE devN owns device creation/cgroups.
set -euo pipefail
[[ ${LXC_HOOK_TYPE:-${3:-}} == mount ]] || exit 1
[[ ${LXC_HOOK_SECTION:-${2:-}} == lxc ]] || exit 1
[[ ${NVIDIA_VISIBLE_DEVICES:-void} != void && -n ${NVIDIA_VISIBLE_DEVICES:-} ]] || exit 0
[[ -n ${LXC_ROOTFS_MOUNT:-} && -d $LXC_ROOTFS_MOUNT ]] || exit 1
# Do not use this hook outside an unprivileged user namespace.
awk '$1 == 0 && $2 == 0 && $3 == 4294967295 {exit 1}' /proc/self/uid_map || exit 1
# Same process-only transition used by the upstream LXC NVIDIA mount hook.
# Fail closed if it is denied; do not disable host or container AppArmor.
if [[ -d /sys/kernel/security/apparmor ]]; then
printf 'changeprofile unconfined\n' > /proc/self/attr/current
fi
args=(--no-cgroups --no-devbind --ldconfig=@/usr/sbin/ldconfig)
args+=("--device=${NVIDIA_VISIBLE_DEVICES}")
capabilities=${NVIDIA_DRIVER_CAPABILITIES:-utility}
[[ $capabilities != all ]] || capabilities=compute,utility,video,graphics,display,compat32
while [[ -n $capabilities ]]; do
capability=${capabilities%%,*}
if [[ $capabilities == *,* ]]; then capabilities=${capabilities#*,}; else capabilities=; fi
case "$capability" in
compute|utility|video|graphics|display|compat32) args+=("--${capability}") ;;
*) printf 'Unsupported NVIDIA capability: %s\n' "$capability" >&2; exit 1 ;;
esac
done
for requirement in $(compgen -e NVIDIA_REQUIRE_ || true); do
args+=("--require=${!requirement}")
done
exec nvidia-container-cli --user configure "${args[@]}" "$LXC_ROOTFS_MOUNT"