Files
ProxMenux/oci/catalog/overlays/swag.json
T
MacRimiandClaude Opus 5 bcabcb618c feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an
LXC definition, a catalog of 365 applications drawn from LinuxServer.io
and other container image sources, and a per-instance registry recording
what each container was built from. Reachable from the main menu.

Catalog text is translated like every other string in the project: the
taglines go through translate() and land in lang/*.json, so the entries
read in all eight languages instead of only English.

Translation cache builder:
- a failed translation leaves the key absent rather than writing English,
  which previously made the string count as translated forever
- a result identical to a 3+ word source is rejected, catching a provider
  that silently returns the text it was given
- strings that are nothing but glossary terms keep their source spelling
  instead of being discarded as failures
- no backoff between attempts when the provider is deterministic
- application names are protected so "HAOS One" survives translation
- argos joins the provider list, and the workflow reads the OCI sources

Audit & Report:
- findings that moved in the wrong direction between runs are reported
  alongside the ones that improved
- an accepted risk can carry a review date and is flagged when it falls due
- backup checks explain in plain language what they looked at and what to
  do next

Monitor:
- disks can be excluded from periodic reads, and an idle disk says so
  instead of showing a stale temperature
- per-disk identity survives a controller or enclosure change
- scheduled Borg backups resolve their SSH key from the repository entry
- PVE upgrades log the package list and the resulting dpkg changes

The web build no longer copies scripts/ into public/: the documentation
links to GitHub, so nothing read that folder.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 18:24:59 +02:00

146 lines
4.4 KiB
JSON

{
"container_contract": {
"environment": [
{
"name": "PUID",
"example": "1000",
"required": true,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "PGID",
"example": "1000",
"required": true,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "TZ",
"example": "Etc/UTC",
"required": true,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "URL",
"example": "",
"required": true,
"sensitive": false,
"prompt": "Domain for the certificate (example.com)",
"source": "linuxserver-swag-readme"
},
{
"name": "VALIDATION",
"example": "",
"required": true,
"sensitive": false,
"prompt": "Validation method: http (port 80 forwarded) or dns (DNS provider plugin)",
"source": "linuxserver-swag-readme"
},
{
"name": "SUBDOMAINS",
"example": "",
"required": false,
"sensitive": false,
"prompt": "Subdomains for the certificate, comma separated (wildcard for *.domain)",
"source": "linuxserver-swag-readme"
},
{
"name": "CERTPROVIDER",
"example": "",
"required": false,
"sensitive": false,
"prompt": "Certificate provider: empty for Let's Encrypt, zerossl for ZeroSSL",
"source": "linuxserver-swag-readme"
},
{
"name": "CERT_PROFILE",
"example": "",
"required": false,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "DNSPLUGIN",
"example": "cloudflare",
"required": false,
"sensitive": false,
"prompt": "DNS plugin used with dns validation (cloudflare, duckdns, ovh...)",
"source": "linuxserver-swag-readme"
},
{
"name": "PROPAGATION",
"example": "",
"required": false,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "EMAIL",
"example": "",
"required": false,
"sensitive": false,
"prompt": "Email address for certificate expiry notices (required by ZeroSSL)",
"source": "linuxserver-swag-readme"
},
{
"name": "ONLY_SUBDOMAINS",
"example": "false",
"required": false,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "EXTRA_DOMAINS",
"example": "",
"required": false,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "STAGING",
"example": "false",
"required": false,
"sensitive": false,
"prompt": "Request a staging certificate for testing: true or false",
"source": "linuxserver-swag-readme"
},
{
"name": "DISABLE_F2B",
"example": "",
"required": false,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "SWAG_AUTORELOAD",
"example": "",
"required": false,
"sensitive": false,
"source": "linuxserver-compose"
},
{
"name": "SWAG_AUTORELOAD_WATCHLIST",
"example": "",
"required": false,
"sensitive": false,
"source": "linuxserver-compose"
}
]
},
"proxmox": {
"installer_profile": {
"completion_notes": [
"The domain must resolve to the public address of this network before the certificate can be issued.",
"With http validation, port 80 of the router must be forwarded to port 80 of this container.",
"With dns validation, the DNSPLUGIN variable names the provider plugin. The advanced installation asks for it; otherwise add the line lxc.environment.runtime: DNSPLUGIN=<plugin> to /etc/pve/lxc/<CTID>.conf with the container stopped.",
"With dns validation, write the provider credentials in /config/dns-conf/<plugin>.ini inside the container and restart it.",
"Certificate errors are logged in /config/log/letsencrypt inside the container.",
"SWAG serves HTTPS on port 443. Plain HTTP on port 80 is disabled in /config/nginx/site-confs/default.conf.",
"Reverse proxy samples for other applications are in /config/nginx/proxy_confs inside the container."
]
}
}
}