mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-09-29 18:16:43 +00:00
Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
336 lines
13 KiB
Bash
336 lines
13 KiB
Bash
#!/bin/bash
|
|
# ==========================================================
|
|
# Proxmox VE 8.x Update Script
|
|
# ==========================================================
|
|
|
|
# Configuration
|
|
LOCAL_SCRIPTS="/usr/local/share/proxmenux/scripts"
|
|
BASE_DIR="/usr/local/share/proxmenux"
|
|
UTILS_FILE="$BASE_DIR/utils.sh"
|
|
TOOLS_JSON="/usr/local/share/proxmenux/installed_tools.json"
|
|
|
|
if [[ -f "$UTILS_FILE" ]]; then
|
|
source "$UTILS_FILE"
|
|
fi
|
|
if [[ -f "$LOCAL_SCRIPTS/global/pmx_journal.sh" ]]; then
|
|
source "$LOCAL_SCRIPTS/global/pmx_journal.sh"
|
|
fi
|
|
|
|
load_language
|
|
initialize_cache
|
|
|
|
APT_ENV="env DEBIAN_FRONTEND=noninteractive LC_ALL=C LANG=C"
|
|
|
|
ensure_tools_json() {
|
|
[ -f "$TOOLS_JSON" ] || echo "{}" > "$TOOLS_JSON"
|
|
}
|
|
|
|
register_tool() {
|
|
local tool="$1"
|
|
local state="$2"
|
|
ensure_tools_json
|
|
jq --arg t "$tool" --argjson v "$state" '.[$t]=$v' "$TOOLS_JSON" > "$TOOLS_JSON.tmp" && mv "$TOOLS_JSON.tmp" "$TOOLS_JSON"
|
|
}
|
|
|
|
download_common_functions() {
|
|
if ! source "$LOCAL_SCRIPTS/global/common-functions.sh"; then
|
|
return 1
|
|
fi
|
|
}
|
|
|
|
update_pve8() {
|
|
local FUNC_VERSION="1.0"
|
|
pmx_journal_context "update_pve8" "$FUNC_VERSION"
|
|
local start_time=$(date +%s)
|
|
local log_file="/var/log/proxmox-update-$(date +%Y%m%d-%H%M%S).log"
|
|
{
|
|
echo "=== ProxMenux — Proxmox VE update ==="
|
|
echo "Started: $(date -Iseconds)"
|
|
echo "Host: $(hostname)"
|
|
echo "Running: $(pveversion 2>/dev/null | head -1)"
|
|
} > "$log_file"
|
|
local changes_made=false
|
|
local OS_CODENAME="$(grep "VERSION_CODENAME=" /etc/os-release | cut -d"=" -f 2 | xargs)"
|
|
|
|
if [ -z "$OS_CODENAME" ]; then
|
|
OS_CODENAME=$(lsb_release -cs 2>/dev/null || echo "bookworm")
|
|
fi
|
|
|
|
download_common_functions
|
|
|
|
msg_info2 "$(translate "Detected: Proxmox VE 8.x (Debian $OS_CODENAME)")"
|
|
echo
|
|
|
|
local available_space=$(df /var/cache/apt/archives | awk 'NR==2 {print int($4/1024)}')
|
|
if [ "$available_space" -lt 1024 ]; then
|
|
msg_error "$(translate "Insufficient disk space. Available: ${available_space}MB")"
|
|
echo -e
|
|
msg_success "$(translate "Press Enter to return to menu...")"
|
|
read -r
|
|
return 1
|
|
fi
|
|
|
|
if ! ping -c 1 download.proxmox.com >/dev/null 2>&1; then
|
|
msg_error "$(translate "Cannot reach Proxmox repositories")"
|
|
echo -e
|
|
msg_success "$(translate "Press Enter to return to menu...")"
|
|
read -r
|
|
return 1
|
|
fi
|
|
|
|
|
|
if [ -f /etc/apt/sources.list.d/pve-enterprise.list ] && grep -q "^deb" /etc/apt/sources.list.d/pve-enterprise.list; then
|
|
pmx_edit_file /etc/apt/sources.list.d/pve-enterprise.list "s/^deb/#deb/g"
|
|
msg_ok "$(translate "Enterprise Proxmox repository disabled")"
|
|
changes_made=true
|
|
fi
|
|
|
|
if [ -f /etc/apt/sources.list.d/ceph.list ] && grep -q "^deb" /etc/apt/sources.list.d/ceph.list; then
|
|
pmx_edit_file /etc/apt/sources.list.d/ceph.list "s/^deb/#deb/g"
|
|
msg_ok "$(translate "Enterprise Proxmox Ceph repository disabled")"
|
|
changes_made=true
|
|
fi
|
|
|
|
|
|
if [ ! -f /etc/apt/sources.list.d/pve-public-repo.list ] || ! grep -q "pve-no-subscription" /etc/apt/sources.list.d/pve-public-repo.list; then
|
|
echo "deb http://download.proxmox.com/debian/pve $OS_CODENAME pve-no-subscription" | pmx_write_file /etc/apt/sources.list.d/pve-public-repo.list
|
|
msg_ok "$(translate "Free public Proxmox repository enabled")"
|
|
changes_made=true
|
|
fi
|
|
|
|
|
|
local sources_file="/etc/apt/sources.list"
|
|
cp "$sources_file" "${sources_file}.backup.$(date +%Y%m%d_%H%M%S)"
|
|
|
|
if grep -q -E "(debian-security -security|debian main$|debian -updates)" "$sources_file"; then
|
|
pmx_edit_file "$sources_file" \
|
|
-e '/^deb.*debian-security -security/d' \
|
|
-e '/^deb.*debian main$/d' \
|
|
-e '/^deb.*debian -updates/d'
|
|
changes_made=true
|
|
msg_ok "$(translate "Malformed repository entries cleaned")"
|
|
fi
|
|
|
|
pmx_write_file "$sources_file" << EOF
|
|
# Debian $OS_CODENAME repositories
|
|
deb http://deb.debian.org/debian $OS_CODENAME main contrib non-free non-free-firmware
|
|
deb http://deb.debian.org/debian $OS_CODENAME-updates main contrib non-free non-free-firmware
|
|
deb http://security.debian.org/debian-security $OS_CODENAME-security main contrib non-free non-free-firmware
|
|
EOF
|
|
|
|
msg_ok "$(translate "Debian repositories configured for $OS_CODENAME")"
|
|
|
|
local firmware_conf="/etc/apt/apt.conf.d/no-firmware-warnings.conf"
|
|
if [ ! -f "$firmware_conf" ]; then
|
|
echo 'APT::Get::Update::SourceListWarnings::NonFreeFirmware "false";' | pmx_write_file "$firmware_conf"
|
|
fi
|
|
|
|
cleanup_duplicate_repos
|
|
|
|
msg_info "$(translate "Updating package lists...")"
|
|
if apt-get update >> "$log_file" 2>&1; then
|
|
msg_ok "$(translate "Package lists updated successfully")"
|
|
else
|
|
msg_error "$(translate "Failed to update package lists. Check log: $log_file")"
|
|
return 1
|
|
fi
|
|
|
|
local current_pve_version=$(pveversion 2>/dev/null | grep -oP 'pve-manager/\K[0-9]+\.[0-9]+\.[0-9]+' | head -1)
|
|
local available_pve_version=$(apt-cache policy pve-manager 2>/dev/null | grep -oP 'Candidate: \K[0-9]+\.[0-9]+\.[0-9]+' | head -1)
|
|
local upgradable_raw=$($APT_ENV apt list --upgradable 2>/dev/null | sed '1d' | sed '/^\s*$/d')
|
|
local upgradable=$(printf '%s' "$upgradable_raw" | grep -c . )
|
|
local security_updates=$(printf '%s\n' "$upgradable_raw" | grep -ci '\-security')
|
|
local upgradable_list=$(printf '%s\n' "$upgradable_raw" | pmx_format_upgradable)
|
|
|
|
{
|
|
echo
|
|
echo "--- Packages to upgrade ($upgradable) ---"
|
|
[ "$upgradable" -gt 0 ] && printf '%s\n' "$upgradable_list"
|
|
} >> "$log_file"
|
|
|
|
show_update_menu() {
|
|
local current_version="$1"
|
|
local target_version="$2"
|
|
local upgradable_count="$3"
|
|
local security_count="$4"
|
|
|
|
local menu_text="$(translate "System Update Information")\n\n"
|
|
menu_text+="$(translate "Current PVE Version"): $current_version\n"
|
|
if [ -n "$target_version" ] && [ "$target_version" != "$current_version" ]; then
|
|
menu_text+="$(translate "Available PVE Version"): $target_version\n"
|
|
fi
|
|
menu_text+="\n$(translate "Package Updates Available"): $upgradable_count\n"
|
|
menu_text+="$(translate "Security Updates"): $security_count\n\n"
|
|
|
|
if [ "$upgradable_count" -eq 0 ]; then
|
|
menu_text+="$(translate "System is already up to date")"
|
|
whiptail --title "$(translate "Update Status")" --msgbox "$menu_text" 15 70
|
|
return 2
|
|
else
|
|
# The package list rides in the same dialog as the summary, so
|
|
# the decision is taken knowing what is about to be replaced.
|
|
# --scrolltext keeps the buttons reachable however long it is.
|
|
menu_text+="$(translate "Packages to be upgraded"):\n$upgradable_list\n\n"
|
|
menu_text+="$(translate "Do you want to proceed with the system update?")"
|
|
if whiptail --title "$(translate "Proxmox Update")" --scrolltext --yesno "$menu_text" 24 78; then
|
|
return 0
|
|
else
|
|
return 1
|
|
fi
|
|
fi
|
|
}
|
|
|
|
show_update_menu "$current_pve_version" "$available_pve_version" "$upgradable" "$security_updates"
|
|
MENU_RESULT=$?
|
|
|
|
if [[ $MENU_RESULT -eq 1 ]]; then
|
|
msg_info2 "$(translate "Update cancelled by user")"
|
|
pmx_record_execution "Remove unused packages" "apt-get -y autoremove"
|
|
apt-get -y autoremove > /dev/null 2>&1 || true
|
|
apt-get -y autoclean > /dev/null 2>&1 || true
|
|
return 0
|
|
elif [[ $MENU_RESULT -eq 2 ]]; then
|
|
msg_ok "$(translate "System is already up to date. No update needed.")"
|
|
echo -e "\nSystem is already up to date." >> "$log_file"
|
|
pmx_record_execution "Remove unused packages" "apt-get -y autoremove"
|
|
apt-get -y autoremove > /dev/null 2>&1 || true
|
|
apt-get -y autoclean > /dev/null 2>&1 || true
|
|
return 0
|
|
fi
|
|
|
|
|
|
local conflicting_packages=$(dpkg -l 2>/dev/null | grep -E "^ii.*(ntp|openntpd|systemd-timesyncd)" | awk '{print $2}')
|
|
if [ -n "$conflicting_packages" ]; then
|
|
msg_info "$(translate "Removing conflicting utilities...")"
|
|
pmx_record_execution "Purge conflicting time services" "apt-get -y purge $conflicting_packages"
|
|
DEBIAN_FRONTEND=noninteractive apt-get -y purge $conflicting_packages >> "$log_file" 2>&1
|
|
msg_ok "$(translate "Conflicting utilities removed")"
|
|
fi
|
|
|
|
|
|
export DEBIAN_FRONTEND=noninteractive
|
|
export APT_LISTCHANGES_FRONTEND=none
|
|
export NEEDRESTART_MODE=a
|
|
export UCF_FORCE_CONFOLD=1
|
|
export DPKG_OPTIONS="--force-confdef --force-confold"
|
|
|
|
msg_info "$(translate "Performing packages upgrade...")"
|
|
pmx_install_pkg pv
|
|
total_packages=$(apt-get -s dist-upgrade | grep "^Inst" | wc -l)
|
|
msg_ok "$(translate "Packages upgrade successfull")"
|
|
|
|
if [ "$total_packages" -eq 0 ]; then
|
|
total_packages=1
|
|
fi
|
|
|
|
tput civis
|
|
tput sc
|
|
|
|
# dpkg's log is read back from here on, so the transaction can be
|
|
# reported package by package.
|
|
local dpkg_mark
|
|
dpkg_mark=$(date '+%Y-%m-%d %H:%M:%S')
|
|
echo -e "\n--- apt-get dist-upgrade ---" >> "$log_file"
|
|
|
|
pmx_record_execution "Upgrade Proxmox VE 8 packages" "apt-get -y -o Dpkg::Options::=--force-confdef -o Dpkg::Options::=--force-confold dist-upgrade"
|
|
(
|
|
/usr/bin/env \
|
|
DEBIAN_FRONTEND=noninteractive \
|
|
APT_LISTCHANGES_FRONTEND=none \
|
|
NEEDRESTART_MODE=a \
|
|
UCF_FORCE_CONFOLD=1 \
|
|
apt-get -y \
|
|
-o Dpkg::Options::="--force-confdef" \
|
|
-o Dpkg::Options::="--force-confold" \
|
|
dist-upgrade 2>&1 | \
|
|
tee -a "$log_file" | \
|
|
while IFS= read -r line; do
|
|
if [[ "$line" =~ ^(Setting\ up|Unpacking|Preparing\ to\ unpack|Processing\ triggers\ for) ]]; then
|
|
package_name=$(echo "$line" | sed -E 's/.*(Setting up|Unpacking|Preparing to unpack|Processing triggers for) ([^ ]+).*/\2/')
|
|
[ -z "$package_name" ] && package_name="$(translate "Unknown")"
|
|
|
|
tput rc
|
|
tput ed
|
|
|
|
row=$(( $(tput lines) - 6 ))
|
|
tput cup $row 0; echo "$(translate "Installing packages...")"
|
|
tput cup $((row + 1)) 0; echo "──────────────────────────────────────────────"
|
|
tput cup $((row + 2)) 0; echo "Package: $package_name"
|
|
tput cup $((row + 3)) 0; echo "Progress: [ ] 0%"
|
|
tput cup $((row + 4)) 0; echo "──────────────────────────────────────────────"
|
|
|
|
for i in $(seq 1 10); do
|
|
progress=$((i * 10))
|
|
tput cup $((row + 3)) 9
|
|
printf "[%-50s] %3d%%" "$(printf "#%.0s" $(seq 1 $((progress/2))))" "$progress"
|
|
done
|
|
fi
|
|
done
|
|
)
|
|
|
|
local upgrade_exit_code=$?
|
|
{
|
|
echo
|
|
echo "--- Packages changed (exit $upgrade_exit_code) ---"
|
|
pmx_dpkg_changes_since "$dpkg_mark"
|
|
} >> "$log_file"
|
|
|
|
if [ $upgrade_exit_code -eq 0 ]; then
|
|
tput rc
|
|
tput ed
|
|
tput cnorm
|
|
msg_ok "$(translate "System upgrade completed")"
|
|
fi
|
|
|
|
|
|
|
|
local essential_packages=("zfsutils-linux" "proxmox-backup-restore-image" "chrony")
|
|
local missing_packages=()
|
|
|
|
for package in "${essential_packages[@]}"; do
|
|
if ! dpkg -l 2>/dev/null | grep -q "^ii $package "; then
|
|
missing_packages+=("$package")
|
|
fi
|
|
done
|
|
|
|
if [ ${#missing_packages[@]} -gt 0 ]; then
|
|
msg_info "$(translate "Installing essential Proxmox packages...")"
|
|
pmx_install_pkg "${missing_packages[@]}"
|
|
msg_ok "$(translate "Essential Proxmox packages installed")"
|
|
fi
|
|
|
|
lvm_repair_check
|
|
cleanup_duplicate_repos
|
|
|
|
msg_info "$(translate "Performing system cleanup...")"
|
|
pmx_record_execution "Remove unused packages" "apt-get -y autoremove"
|
|
apt-get -y autoremove > /dev/null 2>&1 || true
|
|
apt-get -y autoclean > /dev/null 2>&1 || true
|
|
msg_ok "$(translate "Cleanup finished")"
|
|
|
|
local end_time=$(date +%s)
|
|
local duration=$((end_time - start_time))
|
|
local minutes=$((duration / 60))
|
|
local seconds=$((duration % 60))
|
|
|
|
echo -e "${TAB}${BGN}$(translate "====== PVE UPDATE COMPLETED ======")${CL}"
|
|
echo -e "${TAB}${GN}⏱️ $(translate "Duration")${CL}: ${BL}${minutes}m ${seconds}s${CL}"
|
|
echo -e "${TAB}${GN}📄 $(translate "Log file")${CL}: ${BL}$log_file${CL}"
|
|
echo -e "${TAB}${GN}📦 $(translate "Packages upgraded")${CL}: ${BL}$upgradable${CL}"
|
|
echo -e "${TAB}${GN}🖥️ $(translate "Proxmox VE")${CL}: ${BL}$target_version (Debian $OS_CODENAME)${CL}"
|
|
|
|
|
|
|
|
{
|
|
echo
|
|
echo "Finished: $(date -Iseconds) — ${minutes}m ${seconds}s"
|
|
echo "Running: $(pveversion 2>/dev/null | head -1)"
|
|
} >> "$log_file"
|
|
|
|
msg_ok "$(translate "Proxmox VE 8 system update completed successfully")"
|
|
}
|
|
|
|
if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then
|
|
update_pve8
|
|
fi
|