Files
ProxMenux/oci/catalog/apps/librechat.json
T
MacRimiandClaude Opus 5.5 4437a671d2 ProxMenux 1.2.6.2-beta: OCI containers in the Monitor, docs and fixes
OCI manager Apps
- App tab: containers installed from an OCI image are identified from their
  installation record; the application and image versions are shown and an
  update is detected by image digest; repository link; Refresh data.
- Updates tab for OCI containers: Update and Recreate run the same flow as the
  OCI menu in the Monitor terminal; the pre-update backup can be kept in a
  backup storage; scheduled image updates with an optional minimum age.
- Logs tab: console output of the application, kept on the host
  (lxc.console.logfile + logrotate) and followed live.
- The Proxmox console opens a shell (cmode: shell) when the image has one.
- A damaged image download is fetched again before failing.
- Multi-container applications open at their LAN address; volume mount
  points on block storage report their usage.

Monitor
- Proxmox notifications are delivered to a loopback-only HTTP listener when
  HTTPS is enabled, so they no longer fail certificate verification.
- Log persistence counts recurring patterns only; an ended burst is not
  reported as persistent and its warning clears on its own (#386).
- Proxmox notification config backups are deduplicated and capped at three.
- The update icon on the Apps page opens the container on its Updates tab.
- Version 1.2.6.2-beta and its release notes in every Monitor language.

Docs
- OCI manager Apps and Audit & Report rebuilt as per-page message files,
  with a new page for OCI containers in the Monitor.
- Seven pages fixed where rich-text tags were missing from t.rich.

Translations
- Spanish fixes across the OCI engine, the Monitor and the TUI menus.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-09-25 21:51:12 +02:00

1306 lines
47 KiB
JSON

{
"schema_version": "0.5.0",
"kind": "proxmenux.oci-template",
"id": "image-librechat",
"status": "generated-review-required",
"catalog_ui": {
"title": {
"en_US": "LibreChat"
},
"tagline": {
"en_US": "A full-featured, open-source AI chat interface"
},
"description": {
"en_US": "LibreChat is a full-featured, open-source AI chat interface that allows users to interact with multiple AI models through a unified platform. It supports various AI providers and offers advanced features like conversation management, plugin support, and customizable interfaces.\n**Key Features:**\n- Support for multiple AI models and providers\n- Conversation history and management\n- Plugin system for extended functionality\n- Customizable themes and interfaces\n- User authentication and management\n- API integrations for various services\n- Search functionality with MeiliSearch\n- RAG (Retrieval-Augmented Generation) support\n- File upload and processing capabilities\n- Multi-language support\n\n**Learn More:**\n- [LibreChat Official Website](https://www.librechat.ai)\n- [LibreChat GitHub Repository](https://github.com/danny-avila/LibreChat)\n\n**extra:**\nYou can refer to the [Custom AI Endpoints](https://www.librechat.ai/docs/configuration/librechat_yaml/ai_endpoints) documentation to configure the relevant files for calling the APIs of Anyscale, ApiPie, Cohere, Deepseek, Databricks, Fireworks, Groq, HuggingFace, Mistral, OpenRouter, Perplexity, ShuttleAI, TogetherAI, Unify, and xAI.\n"
},
"category": "ai",
"category_label": "AI / Coding & Dev-Tools",
"author": "LibreChat",
"developer": "LibreChat",
"icon": "https://cdn.jsdelivr.net/gh/selfhst/icons@main/webp/librechat.webp",
"thumbnail": null,
"screenshots": [],
"architectures": [
"amd64"
],
"launch": {
"scheme": "http",
"port": 3080,
"path": "/"
},
"website": "https://www.librechat.ai",
"documentation": null,
"repository": "https://ghcr.io/danny-avila/librechat-dev",
"tips": [],
"mini_changelog": [],
"display_version": null,
"updated_at": null,
"hidden": true,
"hidden_reason": "Pending multi-container adaptation; retained for future work"
},
"source": {
"provider": "danny-avila",
"repository": "https://ghcr.io/danny-avila/librechat-dev",
"revision": "317c5bd2b9967f7396645b303872ca02fa799531ad50c311a670d1d9d7af3db8",
"image_repository_url": "https://ghcr.io/danny-avila/librechat-dev",
"readme_pushed_at": "2026-09-11T10:43:22Z",
"compose_sha256": "317c5bd2b9967f7396645b303872ca02fa799531ad50c311a670d1d9d7af3db8",
"generated_at": "2026-09-13T15:48:30+00:00"
},
"container_contract": {
"service_name": "librechat-api",
"container_name": "librechat-api",
"image": {
"reference": "ghcr.io/danny-avila/librechat-dev:latest",
"registry": "ghcr.io",
"repository": "ghcr.io/danny-avila/librechat-dev",
"tag": "latest",
"digest": null,
"pull_policy": "resolve-selected-tag-to-architecture-digest-at-install"
},
"environment": [
{
"name": "ASSISTANTS_API_KEY",
"example": "${GENERATED_ASSISTANTS_API_KEY}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "OPENAI_API_KEY",
"example": "${GENERATED_OPENAI_API_KEY}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "GOOGLE_KEY",
"example": "${GENERATED_GOOGLE_KEY}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "ANTHROPIC_API_KEY",
"example": "${GENERATED_ANTHROPIC_API_KEY}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "HOST",
"example": "0.0.0.0",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "PORT",
"example": "3080",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "DOMAIN_CLIENT",
"example": "http://0.0.0.0:3080",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "DOMAIN_SERVER",
"example": "http://0.0.0.0:3080",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "NO_INDEX",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "TRUST_PROXY",
"example": "1",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "CONSOLE_JSON",
"example": "false",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "DEBUG_LOGGING",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "DEBUG_CONSOLE",
"example": "false",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "MONGO_URI",
"example": "mongodb://librechat-mongodb:27017/LibreChat",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "MEILI_HOST",
"example": "http://librechat-meilisearch:7700",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "RAG_PORT",
"example": "8000",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "RAG_API_URL",
"example": "http://librechat-rag-api:8000",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "SEARCH",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "MEILI_NO_ANALYTICS",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "OPENAI_MODERATION",
"example": "false",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "BAN_VIOLATIONS",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "BAN_DURATION",
"example": "1000 * 60 * 60 * 2",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "BAN_INTERVAL",
"example": "20",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "LOGIN_VIOLATION_SCORE",
"example": "1",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "REGISTRATION_VIOLATION_SCORE",
"example": "1",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "CONCURRENT_VIOLATION_SCORE",
"example": "1",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "MESSAGE_VIOLATION_SCORE",
"example": "1",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "NON_BROWSER_VIOLATION_SCORE",
"example": "20",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "TTS_VIOLATION_SCORE",
"example": "0",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "STT_VIOLATION_SCORE",
"example": "0",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "FORK_VIOLATION_SCORE",
"example": "0",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "IMPORT_VIOLATION_SCORE",
"example": "0",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "FILE_UPLOAD_VIOLATION_SCORE",
"example": "0",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "LOGIN_MAX",
"example": "7",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "LOGIN_WINDOW",
"example": "5",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "REGISTER_MAX",
"example": "5",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "REGISTER_WINDOW",
"example": "60",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "LIMIT_CONCURRENT_MESSAGES",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "CONCURRENT_MESSAGE_MAX",
"example": "2",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "LIMIT_MESSAGE_IP",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "MESSAGE_IP_MAX",
"example": "40",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "MESSAGE_IP_WINDOW",
"example": "1",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "LIMIT_MESSAGE_USER",
"example": "false",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "MESSAGE_USER_MAX",
"example": "40",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "MESSAGE_USER_WINDOW",
"example": "1",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "ILLEGAL_MODEL_REQ_SCORE",
"example": "5",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "ALLOW_EMAIL_LOGIN",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "ALLOW_REGISTRATION",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "ALLOW_SOCIAL_LOGIN",
"example": "false",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "ALLOW_SOCIAL_REGISTRATION",
"example": "false",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "ALLOW_PASSWORD_RESET",
"example": "${GENERATED_ALLOW_PASSWORD_RESET}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "ALLOW_UNVERIFIED_EMAIL_LOGIN",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "SESSION_EXPIRY",
"example": "1000 * 60 * 15",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "REFRESH_TOKEN_EXPIRY",
"example": "${GENERATED_REFRESH_TOKEN_EXPIRY}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "JWT_SECRET",
"example": "${GENERATED_JWT_SECRET}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "JWT_REFRESH_SECRET",
"example": "${GENERATED_JWT_REFRESH_SECRET}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "CREDS_KEY",
"example": "${GENERATED_CREDS_KEY}",
"required": true,
"sensitive": true,
"source": "docker-compose"
},
{
"name": "CREDS_IV",
"example": "e2341419ec3dd3d19b13a1a87fafcbfb",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "DEBUG_PLUGINS",
"example": "true",
"required": true,
"sensitive": false,
"source": "docker-compose"
},
{
"name": "DEBUG_OPENAI",
"example": "false",
"required": true,
"sensitive": false,
"source": "docker-compose"
}
],
"volumes": [
{
"id": "volume-0",
"container_path": "/app/client/public/images",
"compose_source_example": "/DATA/AppData/$AppID/images",
"read_only": false,
"required": true,
"installation_choice": [
"managed-volume",
"host-bind"
],
"default": "managed-volume",
"managed_volume": {
"backup": true,
"default_size_gb": 8
}
},
{
"id": "volume-1",
"container_path": "/app/uploads",
"compose_source_example": "/DATA/AppData/$AppID/uploads",
"read_only": false,
"required": true,
"installation_choice": [
"managed-volume",
"host-bind"
],
"default": "managed-volume",
"managed_volume": {
"backup": true,
"default_size_gb": 8
}
},
{
"id": "volume-2",
"container_path": "/app/api/logs",
"compose_source_example": "/DATA/AppData/$AppID/logs",
"read_only": false,
"required": true,
"installation_choice": [
"managed-volume",
"host-bind"
],
"default": "managed-volume",
"managed_volume": {
"backup": true,
"default_size_gb": 8
}
}
],
"ports": [
{
"container_port": 3080,
"published_example": 3080,
"protocol": "tcp",
"required": true,
"proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat"
}
],
"related_services": [
{
"name": "librechat-mongodb",
"image": "mongo:latest"
},
{
"name": "librechat-meilisearch",
"image": "getmeili/meilisearch:latest"
},
{
"name": "librechat-vectordb",
"image": "ankane/pgvector:latest"
},
{
"name": "librechat-rag-api",
"image": "ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest"
}
],
"restart": "unless-stopped",
"stop_grace_period": null,
"original_compose": "name: librechat\nservices:\n librechat-api:\n container_name: librechat-api\n ports:\n - 3080:3080\n depends_on:\n - librechat-mongodb\n - librechat-rag-api\n image: ghcr.io/danny-avila/librechat-dev:latest\n restart: unless-stopped\n extra_hosts:\n - host.docker.internal:host-gateway\n environment:\n - ASSISTANTS_API_KEY=${GENERATED_ASSISTANTS_API_KEY}\n - OPENAI_API_KEY=${GENERATED_OPENAI_API_KEY}\n - GOOGLE_KEY=${GENERATED_GOOGLE_KEY}\n - ANTHROPIC_API_KEY=${GENERATED_ANTHROPIC_API_KEY}\n - HOST=0.0.0.0\n - PORT=3080\n - DOMAIN_CLIENT=http://0.0.0.0:3080\n - DOMAIN_SERVER=http://0.0.0.0:3080\n - NO_INDEX=true\n - TRUST_PROXY=1\n - CONSOLE_JSON=false\n - DEBUG_LOGGING=true\n - DEBUG_CONSOLE=false\n - MONGO_URI=mongodb://librechat-mongodb:27017/LibreChat\n - MEILI_HOST=http://librechat-meilisearch:7700\n - RAG_PORT=8000\n - RAG_API_URL=http://librechat-rag-api:8000\n - SEARCH=true\n - MEILI_NO_ANALYTICS=true\n - OPENAI_MODERATION=false\n - BAN_VIOLATIONS=true\n - BAN_DURATION=1000 * 60 * 60 * 2\n - BAN_INTERVAL=20\n - LOGIN_VIOLATION_SCORE=1\n - REGISTRATION_VIOLATION_SCORE=1\n - CONCURRENT_VIOLATION_SCORE=1\n - MESSAGE_VIOLATION_SCORE=1\n - NON_BROWSER_VIOLATION_SCORE=20\n - TTS_VIOLATION_SCORE=0\n - STT_VIOLATION_SCORE=0\n - FORK_VIOLATION_SCORE=0\n - IMPORT_VIOLATION_SCORE=0\n - FILE_UPLOAD_VIOLATION_SCORE=0\n - LOGIN_MAX=7\n - LOGIN_WINDOW=5\n - REGISTER_MAX=5\n - REGISTER_WINDOW=60\n - LIMIT_CONCURRENT_MESSAGES=true\n - CONCURRENT_MESSAGE_MAX=2\n - LIMIT_MESSAGE_IP=true\n - MESSAGE_IP_MAX=40\n - MESSAGE_IP_WINDOW=1\n - LIMIT_MESSAGE_USER=false\n - MESSAGE_USER_MAX=40\n - MESSAGE_USER_WINDOW=1\n - ILLEGAL_MODEL_REQ_SCORE=5\n - ALLOW_EMAIL_LOGIN=true\n - ALLOW_REGISTRATION=true\n - ALLOW_SOCIAL_LOGIN=false\n - ALLOW_SOCIAL_REGISTRATION=false\n - ALLOW_PASSWORD_RESET=${GENERATED_ALLOW_PASSWORD_RESET}\n - ALLOW_UNVERIFIED_EMAIL_LOGIN=true\n - SESSION_EXPIRY=1000 * 60 * 15\n - REFRESH_TOKEN_EXPIRY=${GENERATED_REFRESH_TOKEN_EXPIRY}\n - JWT_SECRET=${GENERATED_JWT_SECRET}\n - JWT_REFRESH_SECRET=${GENERATED_JWT_REFRESH_SECRET}\n - CREDS_KEY=${GENERATED_CREDS_KEY}\n - CREDS_IV=e2341419ec3dd3d19b13a1a87fafcbfb\n - DEBUG_PLUGINS=true\n - DEBUG_OPENAI=false\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/images\n target: /app/client/public/images\n - type: bind\n source: /DATA/AppData/$AppID/uploads\n target: /app/uploads\n - type: bind\n source: /DATA/AppData/$AppID/logs\n target: /app/api/logs\n networks:\n - librechat-net\n deploy:\n resources:\n reservations:\n memory: 1024M\n librechat-mongodb:\n container_name: librechat-mongodb\n image: mongo:latest\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/data-node\n target: /data/db\n command:\n - mongod\n - --noauth\n networks:\n - librechat-net\n deploy:\n resources:\n reservations:\n memory: 1024M\n librechat-meilisearch:\n container_name: librechat-meilisearch\n image: getmeili/meilisearch:latest\n restart: unless-stopped\n user: 1000:1000\n environment:\n - MEILI_HOST=http://librechat-meilisearch:7700\n - MEILI_NO_ANALYTICS=true\n - MEILI_MASTER_KEY=${GENERATED_MEILI_MASTER_KEY}\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID/meili_data_v1.12\n target: /meili_data\n networks:\n - librechat-net\n librechat-vectordb:\n container_name: librechat-vectordb\n image: ankane/pgvector:latest\n environment:\n POSTGRES_DB: mydatabase\n POSTGRES_USER: myuser\n POSTGRES_PASSWORD: ${GENERATED_POSTGRES_PASSWORD}\n restart: unless-stopped\n volumes:\n - /DATA/AppData/$AppID/postgresql/data:/var/lib/postgresql/data\n networks:\n - librechat-net\n deploy:\n resources:\n reservations:\n memory: 500M\n librechat-rag-api:\n container_name: librechat-rag-api\n image: ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest\n environment:\n - DB_HOST=librechat-vectordb\n - RAG_PORT=8000\n restart: unless-stopped\n depends_on:\n - librechat-vectordb\n networks:\n - librechat-net\n deploy:\n resources:\n reservations:\n memory: 1024M\nnetworks:\n librechat-net:\n driver: bridge\n"
},
"compose_stack": {
"project_name": "librechat",
"deployment_model": "one-native-oci-lxc-per-compose-service",
"user_experience": "single-application-install",
"main_service": "librechat-api",
"service_count": 5,
"services": [
{
"name": "librechat-meilisearch",
"image": "getmeili/meilisearch:latest",
"is_main": false,
"role": "dependency",
"vmid_offset": 1,
"depends_on": [],
"frontend_network": false,
"private_network": true,
"compose": {
"container_name": "librechat-meilisearch",
"image": "getmeili/meilisearch:latest",
"restart": "unless-stopped",
"user": "1000:1000",
"environment": [
"MEILI_HOST=http://librechat-meilisearch:7700",
"MEILI_NO_ANALYTICS=true",
"MEILI_MASTER_KEY=${GENERATED_MEILI_MASTER_KEY}"
],
"volumes": [
{
"type": "bind",
"source": "/DATA/AppData/$AppID/meili_data_v1.12",
"target": "/meili_data"
}
],
"networks": [
"librechat-net"
]
}
},
{
"name": "librechat-mongodb",
"image": "mongo:latest",
"is_main": false,
"role": "dependency",
"vmid_offset": 2,
"depends_on": [],
"frontend_network": false,
"private_network": true,
"compose": {
"container_name": "librechat-mongodb",
"image": "mongo:latest",
"restart": "unless-stopped",
"volumes": [
{
"type": "bind",
"source": "/DATA/AppData/$AppID/data-node",
"target": "/data/db"
}
],
"command": [
"mongod",
"--noauth"
],
"networks": [
"librechat-net"
],
"deploy": {
"resources": {
"reservations": {
"memory": "1024M"
}
}
}
}
},
{
"name": "librechat-vectordb",
"image": "ankane/pgvector:latest",
"is_main": false,
"role": "dependency",
"vmid_offset": 3,
"depends_on": [],
"frontend_network": false,
"private_network": true,
"compose": {
"container_name": "librechat-vectordb",
"image": "ankane/pgvector:latest",
"environment": {
"POSTGRES_DB": "mydatabase",
"POSTGRES_USER": "myuser",
"POSTGRES_PASSWORD": "${GENERATED_POSTGRES_PASSWORD}"
},
"restart": "unless-stopped",
"volumes": [
"/DATA/AppData/$AppID/postgresql/data:/var/lib/postgresql/data"
],
"networks": [
"librechat-net"
],
"deploy": {
"resources": {
"reservations": {
"memory": "500M"
}
}
}
}
},
{
"name": "librechat-rag-api",
"image": "ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest",
"is_main": false,
"role": "dependency",
"vmid_offset": 4,
"depends_on": [
"librechat-vectordb"
],
"frontend_network": false,
"private_network": true,
"compose": {
"container_name": "librechat-rag-api",
"image": "ghcr.io/danny-avila/librechat-rag-api-dev-lite:latest",
"environment": [
"DB_HOST=librechat-vectordb",
"RAG_PORT=8000"
],
"restart": "unless-stopped",
"depends_on": [
"librechat-vectordb"
],
"networks": [
"librechat-net"
],
"deploy": {
"resources": {
"reservations": {
"memory": "1024M"
}
}
}
}
},
{
"name": "librechat-api",
"image": "ghcr.io/danny-avila/librechat-dev:latest",
"is_main": true,
"role": "frontend",
"vmid_offset": 0,
"depends_on": [
"librechat-mongodb",
"librechat-rag-api"
],
"frontend_network": true,
"private_network": true,
"compose": {
"container_name": "librechat-api",
"ports": [
"3080:3080"
],
"depends_on": [
"librechat-mongodb",
"librechat-rag-api"
],
"image": "ghcr.io/danny-avila/librechat-dev:latest",
"restart": "unless-stopped",
"extra_hosts": [
"host.docker.internal:host-gateway"
],
"environment": [
"ASSISTANTS_API_KEY=${GENERATED_ASSISTANTS_API_KEY}",
"OPENAI_API_KEY=${GENERATED_OPENAI_API_KEY}",
"GOOGLE_KEY=${GENERATED_GOOGLE_KEY}",
"ANTHROPIC_API_KEY=${GENERATED_ANTHROPIC_API_KEY}",
"HOST=0.0.0.0",
"PORT=3080",
"DOMAIN_CLIENT=http://0.0.0.0:3080",
"DOMAIN_SERVER=http://0.0.0.0:3080",
"NO_INDEX=true",
"TRUST_PROXY=1",
"CONSOLE_JSON=false",
"DEBUG_LOGGING=true",
"DEBUG_CONSOLE=false",
"MONGO_URI=mongodb://librechat-mongodb:27017/LibreChat",
"MEILI_HOST=http://librechat-meilisearch:7700",
"RAG_PORT=8000",
"RAG_API_URL=http://librechat-rag-api:8000",
"SEARCH=true",
"MEILI_NO_ANALYTICS=true",
"OPENAI_MODERATION=false",
"BAN_VIOLATIONS=true",
"BAN_DURATION=1000 * 60 * 60 * 2",
"BAN_INTERVAL=20",
"LOGIN_VIOLATION_SCORE=1",
"REGISTRATION_VIOLATION_SCORE=1",
"CONCURRENT_VIOLATION_SCORE=1",
"MESSAGE_VIOLATION_SCORE=1",
"NON_BROWSER_VIOLATION_SCORE=20",
"TTS_VIOLATION_SCORE=0",
"STT_VIOLATION_SCORE=0",
"FORK_VIOLATION_SCORE=0",
"IMPORT_VIOLATION_SCORE=0",
"FILE_UPLOAD_VIOLATION_SCORE=0",
"LOGIN_MAX=7",
"LOGIN_WINDOW=5",
"REGISTER_MAX=5",
"REGISTER_WINDOW=60",
"LIMIT_CONCURRENT_MESSAGES=true",
"CONCURRENT_MESSAGE_MAX=2",
"LIMIT_MESSAGE_IP=true",
"MESSAGE_IP_MAX=40",
"MESSAGE_IP_WINDOW=1",
"LIMIT_MESSAGE_USER=false",
"MESSAGE_USER_MAX=40",
"MESSAGE_USER_WINDOW=1",
"ILLEGAL_MODEL_REQ_SCORE=5",
"ALLOW_EMAIL_LOGIN=true",
"ALLOW_REGISTRATION=true",
"ALLOW_SOCIAL_LOGIN=false",
"ALLOW_SOCIAL_REGISTRATION=false",
"ALLOW_PASSWORD_RESET=${GENERATED_ALLOW_PASSWORD_RESET}",
"ALLOW_UNVERIFIED_EMAIL_LOGIN=true",
"SESSION_EXPIRY=1000 * 60 * 15",
"REFRESH_TOKEN_EXPIRY=${GENERATED_REFRESH_TOKEN_EXPIRY}",
"JWT_SECRET=${GENERATED_JWT_SECRET}",
"JWT_REFRESH_SECRET=${GENERATED_JWT_REFRESH_SECRET}",
"CREDS_KEY=${GENERATED_CREDS_KEY}",
"CREDS_IV=e2341419ec3dd3d19b13a1a87fafcbfb",
"DEBUG_PLUGINS=true",
"DEBUG_OPENAI=false"
],
"volumes": [
{
"type": "bind",
"source": "/DATA/AppData/$AppID/images",
"target": "/app/client/public/images"
},
{
"type": "bind",
"source": "/DATA/AppData/$AppID/uploads",
"target": "/app/uploads"
},
{
"type": "bind",
"source": "/DATA/AppData/$AppID/logs",
"target": "/app/api/logs"
}
],
"networks": [
"librechat-net"
],
"deploy": {
"resources": {
"reservations": {
"memory": "1024M"
}
}
}
}
}
],
"top_level": {
"name": "librechat",
"networks": {
"librechat-net": {
"driver": "bridge"
}
}
},
"networking": {
"frontend": "selected-proxmox-bridge",
"private_required": true,
"private_creation": "automatic-create-if-missing",
"private_address_allocation": "automatic-static-address-per-service",
"service_discovery": "private-addresses-with-compose-service-host-aliases",
"dependency_external_access": "disabled-unless-service-publishes-ports",
"prompt_user_for_private_network": false
},
"storage": [
{
"id": "librechat-api-volume-0",
"service": "librechat-api",
"container_path": "/app/client/public/images",
"mode": "managed-volume",
"user_selectable": false,
"backup": true,
"shared_with_other_lxc": false,
"source_path": null,
"source_path_prompt": null
},
{
"id": "librechat-api-volume-1",
"service": "librechat-api",
"container_path": "/app/uploads",
"mode": "host-bind",
"user_selectable": true,
"backup": false,
"shared_with_other_lxc": true,
"source_path": null,
"source_path_prompt": "Host directory for librechat-api:/app/uploads"
},
{
"id": "librechat-api-volume-2",
"service": "librechat-api",
"container_path": "/app/api/logs",
"mode": "managed-volume",
"user_selectable": false,
"backup": true,
"shared_with_other_lxc": false,
"source_path": null,
"source_path_prompt": null
},
{
"id": "librechat-mongodb-volume-0",
"service": "librechat-mongodb",
"container_path": "/data/db",
"mode": "host-bind",
"user_selectable": true,
"backup": false,
"shared_with_other_lxc": true,
"source_path": null,
"source_path_prompt": "Host directory for librechat-mongodb:/data/db"
},
{
"id": "librechat-meilisearch-volume-0",
"service": "librechat-meilisearch",
"container_path": "/meili_data",
"mode": "managed-volume",
"user_selectable": false,
"backup": true,
"shared_with_other_lxc": false,
"source_path": null,
"source_path_prompt": null
},
{
"id": "librechat-vectordb-volume-0",
"service": "librechat-vectordb",
"container_path": "/var/lib/postgresql/data",
"mode": "managed-volume",
"user_selectable": false,
"backup": true,
"shared_with_other_lxc": false,
"source_path": null,
"source_path_prompt": null
}
],
"orchestration": {
"reserve_vmids_atomically": 5,
"start_order": [
"librechat-meilisearch",
"librechat-mongodb",
"librechat-vectordb",
"librechat-rag-api",
"librechat-api"
],
"stop_order": [
"librechat-api",
"librechat-rag-api",
"librechat-vectordb",
"librechat-mongodb",
"librechat-meilisearch"
],
"dependency_readiness": "compose-healthcheck-then-port-or-process-fallback",
"rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes"
},
"installer_inputs": {
"prompted": [
"stack_name",
"base_vmid",
"rootfs_storage",
"persistent_data_destinations",
"frontend_bridge",
"frontend_ipv4_mode"
],
"automatic": [
"dependent_vmids",
"private_bridge",
"private_subnet",
"private_service_addresses",
"compose_service_aliases",
"generated_secrets",
"dependency_start_and_stop_order"
],
"generated_secrets": [
{
"id": "allow-password-reset",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "ALLOW_PASSWORD_RESET"
}
]
},
{
"id": "anthropic-api-key",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "ANTHROPIC_API_KEY"
}
]
},
{
"id": "assistants-api-key",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "ASSISTANTS_API_KEY"
}
]
},
{
"id": "creds-key",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "CREDS_KEY"
}
]
},
{
"id": "google-key",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "GOOGLE_KEY"
}
]
},
{
"id": "jwt-refresh-secret",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "JWT_REFRESH_SECRET"
}
]
},
{
"id": "jwt-secret",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "JWT_SECRET"
}
]
},
{
"id": "meili-master-key",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-meilisearch",
"environment_variable": "MEILI_MASTER_KEY"
}
]
},
{
"id": "openai-api-key",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "OPENAI_API_KEY"
}
]
},
{
"id": "postgres-password",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-vectordb",
"environment_variable": "POSTGRES_PASSWORD"
}
]
},
{
"id": "refresh-token-expiry",
"strategy": "generate-cryptographically-random-at-install",
"bindings": [
{
"service": "librechat-api",
"environment_variable": "REFRESH_TOKEN_EXPIRY"
}
]
}
]
}
},
"first_run": {
"endpoints": [
{
"label": "Web UI",
"scheme": "http",
"port": 3080,
"path": "/",
"source": "compose-metadata"
}
],
"credentials": []
},
"proxmox": {
"runtime": "native-oci-lxc",
"technology_status": "proxmox-technology-preview",
"defaults": {
"unprivileged": true,
"ostype": "auto-from-image",
"cores": 2,
"memory_mb": 1024,
"swap_mb": 512,
"rootfs_size_gb": 8,
"rootfs_storage": "local-lvm",
"volume_storage": "local-lvm",
"template_storage": "local",
"bridge": "vmbr0",
"ipv4": "dhcp",
"firewall": true,
"host_managed_network": true,
"onboot": false,
"features": [
"nesting=1"
],
"shutdown_timeout_seconds": 30
},
"image_metadata_policy": {
"entrypoint": "import-from-oci-image",
"cmd": "import-from-oci-image",
"environment": "import-image-env-then-apply-compose-overrides",
"user": "import-from-oci-image",
"working_dir": "import-from-oci-image",
"stop_signal": "import-from-oci-image"
},
"installer_profile": {
"extra_hosts": [
{
"hostname": "host.docker.internal",
"address": "host-gateway"
}
]
},
"adaptations": [
{
"id": "imported-compose-source",
"upstream_behavior": "The source definition deploys the complete Docker Compose application model.",
"native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.",
"reason": "Catalog import must not imply runtime compatibility.",
"behavioral_impact": "No automatic installation before review.",
"validation": "pending-per-application"
},
{
"id": "rolling-latest-image",
"upstream_behavior": "A discovered Compose may pin a release tag or digest.",
"native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.",
"reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.",
"behavioral_impact": "The installed release can be newer than the discovered Compose revision.",
"validation": "pending-per-application"
},
{
"id": "dedicated-lxc-network",
"upstream_behavior": "Docker publishes selected container ports on the Docker host.",
"native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.",
"reason": "A native LXC has its own address and does not require Docker port NAT.",
"behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.",
"validation": "pending-per-application"
},
{
"id": "compose-shm-size",
"upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.",
"native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.",
"reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.",
"behavioral_impact": "None expected.",
"validation": "not-requested-by-compose"
},
{
"id": "compose-command",
"upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.",
"native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.",
"reason": "Proxmox stores the effective OCI process as one entrypoint string.",
"behavioral_impact": "None expected.",
"validation": "not-requested-by-compose"
},
{
"id": "compose-privileged-mode",
"upstream_behavior": "Compose selects whether the container runs in privileged mode.",
"native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.",
"reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.",
"behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.",
"validation": "native-equivalent"
},
{
"id": "compose-process-runtime",
"upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.",
"native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.",
"reason": "The OCI process must start with the same identity, command and working directory without Docker.",
"behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.",
"validation": "not-requested-by-compose"
},
{
"id": "compose-healthcheck",
"upstream_behavior": "Docker periodically executes the declared container healthcheck.",
"native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.",
"reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.",
"behavioral_impact": "The check runs during installation rather than continuously after installation.",
"validation": "not-requested-by-compose"
},
{
"id": "compose-cpu-priority",
"upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.",
"native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.",
"reason": "Both settings express relative CPU priority on different scales.",
"behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.",
"validation": "not-requested-by-compose"
},
{
"id": "compose-network-identity",
"upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.",
"native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.",
"reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.",
"behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.",
"validation": "pending-per-application"
},
{
"id": "compose-network-mode",
"upstream_behavior": "Docker host mode removes Docker network isolation; bridge and default use a Docker-managed network.",
"native_lxc_behavior": "The OCI process uses the dedicated LXC network namespace directly, so host, bridge and default all listen on the LXC address without Docker NAT.",
"reason": "The LXC is the application host and already has its own address and port namespace.",
"behavioral_impact": "host means the LXC host, never the Proxmox host; this preserves Proxmox network isolation.",
"validation": "not-requested-by-compose"
},
{
"id": "compose-capabilities-and-sysctls",
"upstream_behavior": "Compose can add Linux capabilities and set kernel parameters in the container network namespace.",
"native_lxc_behavior": "ProxMenux validates requested capabilities against the native LXC capability set and writes namespaced network settings as lxc.sysctl directives.",
"reason": "A native OCI-LXC already starts with the namespaced capability set; lxc.cap.keep would incorrectly discard unrelated required capabilities.",
"behavioral_impact": "Host-global capabilities such as SYS_MODULE remain blocked until their host prerequisite is explicitly adapted.",
"validation": "not-requested-by-compose"
},
{
"id": "docker-engine-metadata",
"upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.",
"native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.",
"reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.",
"behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.",
"validation": "not-requested-by-compose"
},
{
"id": "compose-device-passthrough",
"upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.",
"native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.",
"reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.",
"behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.",
"validation": "not-requested-by-compose"
},
{
"id": "compose-host-ipc",
"upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.",
"native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.",
"reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.",
"behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.",
"validation": "not-requested-by-compose"
}
],
"generic_stack_review": [
"librechat-api: credencial externa o booleano GENERATED_ANTHROPIC_API_KEY pendiente",
"librechat-api: credencial externa o booleano GENERATED_ASSISTANTS_API_KEY pendiente",
"librechat-api: credencial externa o booleano GENERATED_OPENAI_API_KEY pendiente",
"librechat-api: extra_hosts necesita revision de pila",
"librechat-mongodb: comando de dependencia personalizado pendiente",
"librechat-rag-api: perfil de salud y persistencia pendiente",
"librechat-vectordb: perfil de salud y persistencia pendiente"
]
},
"compatibility": {
"automatic_install_candidate": false,
"validated": false,
"supported_compose_keys": [
"cap_add",
"command",
"container_name",
"cpu_shares",
"deploy",
"devices",
"entrypoint",
"environment",
"extra_hosts",
"healthcheck",
"hostname",
"image",
"init",
"ipc",
"labels",
"logging",
"mac_address",
"network_mode",
"networks",
"ports",
"privileged",
"restart",
"runtime",
"shm_size",
"stdin_open",
"stop_grace_period",
"sysctls",
"tty",
"user",
"volumes",
"working_dir"
],
"untranslated_blockers": [
"multi-service-compose",
"compose-key:depends_on",
"service:librechat-rag-api:compose-key:depends_on",
"native-multi-lxc-orchestrator-not-yet-implemented"
],
"policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available."
},
"validation": {
"schema": "passed-at-generation",
"clean_install": "pending",
"service_health": "pending",
"restart_persistence": "pending",
"backup_restore": "pending",
"update_preserves_data": "pending"
},
"lifecycle": {
"update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update",
"registry_state": {
"resolved_architecture": null,
"resolved_digest": null,
"image_version_label": null,
"image_created": null
},
"change_detection": "compare-compose-sha256-and-resolved-latest-image-digest",
"automatic_unattended_updates": false
}
}