mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-09-29 18:16:43 +00:00
OCI manager Apps - App tab: containers installed from an OCI image are identified from their installation record; the application and image versions are shown and an update is detected by image digest; repository link; Refresh data. - Updates tab for OCI containers: Update and Recreate run the same flow as the OCI menu in the Monitor terminal; the pre-update backup can be kept in a backup storage; scheduled image updates with an optional minimum age. - Logs tab: console output of the application, kept on the host (lxc.console.logfile + logrotate) and followed live. - The Proxmox console opens a shell (cmode: shell) when the image has one. - A damaged image download is fetched again before failing. - Multi-container applications open at their LAN address; volume mount points on block storage report their usage. Monitor - Proxmox notifications are delivered to a loopback-only HTTP listener when HTTPS is enabled, so they no longer fail certificate verification. - Log persistence counts recurring patterns only; an ended burst is not reported as persistent and its warning clears on its own (#386). - Proxmox notification config backups are deduplicated and capped at three. - The update icon on the Apps page opens the container on its Updates tab. - Version 1.2.6.2-beta and its release notes in every Monitor language. Docs - OCI manager Apps and Audit & Report rebuilt as per-page message files, with a new page for OCI containers in the Monitor. - Seven pages fixed where rich-text tags were missing from t.rich. Translations - Spanish fixes across the OCI engine, the Monitor and the TUI menus. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
421 lines
18 KiB
JSON
421 lines
18 KiB
JSON
{
|
||
"schema_version": "0.5.0",
|
||
"kind": "proxmenux.oci-template",
|
||
"id": "image-n8n",
|
||
"status": "generated-unvalidated",
|
||
"catalog_ui": {
|
||
"title": {
|
||
"en_US": "n8n"
|
||
},
|
||
"tagline": {
|
||
"en_US": "Workflow automation tool"
|
||
},
|
||
"description": {
|
||
"en_US": "n8n is a powerful open-source workflow automation and conversational AI platform that blends the flexibility of coding with the simplicity of no-code development, empowering users to create efficient and secure automation workflows. It seamlessly connects any app with an API, leveraging native AI capabilities (like LangChain-based AI agent workflows) to process custom data, ideal for personal task management, team collaboration, or enterprise-grade automation. Its vibrant community offers over 400 integrations and 900+ ready-to-use templates, enabling users to deploy automations quickly.\n\nThe platform supports highly customizable workflow design, allowing users to write JavaScript/Python, add npm packages, or use an intuitive visual interface to manage data, catering to both simple tasks and complex processes. Enterprise-grade features like advanced permissions and air-gapped deployments ensure security, while multilingual support makes it accessible globally. n8n delivers a versatile and user-friendly automation solution.\n\nDiscover n8n’s Automation Scenarios\nn8n’s community resources provide extensive support and inspiration, helping users explore its scenario-based value and easily build automation workflows. Below are two key resources showcasing n8n’s capabilities across various use cases:\n\n1. [n8n Official Community Forum](https://community.n8n.io/): \nThe forum is a hub for user collaboration and learning, offering resources from beginner guides to advanced workflow designs. Shared use cases include automating social media posts or real-time data syncing, such as using n8n to pull data from Google Sheets and send Slack notifications, boosting team collaboration and data efficiency.\n\n2. [n8n Official Template Library](https://n8n.io/workflows/): \nThe template library offers over 900 ready-to-use workflows for scenarios like marketing automation, data analytics, and customer support. For example, a template can link Shopify to Mailchimp, automatically adding new customers to mailing lists and sending welcome emails, making automation accessible to non-technical users. AI-driven workflows, like handling customer queries with LangChain, highlight n8n’s strength in intelligent interactions.\n"
|
||
},
|
||
"category": "automation",
|
||
"category_label": "Automation & Scheduling",
|
||
"author": "n8n",
|
||
"developer": "n8n",
|
||
"icon": "https://cdn.jsdelivr.net/gh/selfhst/icons@main/webp/n8n.webp",
|
||
"thumbnail": null,
|
||
"screenshots": [],
|
||
"architectures": [
|
||
"amd64",
|
||
"arm64"
|
||
],
|
||
"launch": {
|
||
"scheme": "http",
|
||
"port": 5678,
|
||
"path": "/"
|
||
},
|
||
"website": "https://n8n.io",
|
||
"documentation": null,
|
||
"repository": "https://hub.docker.com/r/n8nio/n8n",
|
||
"tips": [],
|
||
"mini_changelog": [],
|
||
"display_version": null,
|
||
"updated_at": null
|
||
},
|
||
"source": {
|
||
"provider": "official",
|
||
"repository": "https://hub.docker.com/r/n8nio/n8n",
|
||
"revision": "82af44e6a55a8659184e8561c902136510f5e0f61b754f39ee5528a394903a7b",
|
||
"image_repository_url": "https://hub.docker.com/r/n8nio/n8n",
|
||
"readme_pushed_at": "2026-09-11T10:43:22Z",
|
||
"compose_sha256": "82af44e6a55a8659184e8561c902136510f5e0f61b754f39ee5528a394903a7b",
|
||
"generated_at": "2026-09-13T15:35:01+00:00"
|
||
},
|
||
"container_contract": {
|
||
"service_name": "n8n",
|
||
"container_name": "n8n",
|
||
"image": {
|
||
"reference": "n8nio/n8n:latest",
|
||
"registry": "docker.io",
|
||
"repository": "n8nio/n8n",
|
||
"tag": "latest",
|
||
"digest": null,
|
||
"pull_policy": "resolve-selected-tag-to-architecture-digest-at-install"
|
||
},
|
||
"environment": [
|
||
{
|
||
"name": "TZ",
|
||
"example": "$TZ",
|
||
"required": true,
|
||
"sensitive": false,
|
||
"source": "docker-compose"
|
||
},
|
||
{
|
||
"name": "N8N_SECURE_COOKIE",
|
||
"example": "false",
|
||
"required": true,
|
||
"sensitive": false,
|
||
"source": "docker-compose"
|
||
}
|
||
],
|
||
"volumes": [
|
||
{
|
||
"id": "volume-0",
|
||
"container_path": "/home/node/.n8n",
|
||
"compose_source_example": "/DATA/AppData/$AppID",
|
||
"read_only": false,
|
||
"required": true,
|
||
"installation_choice": [
|
||
"managed-volume",
|
||
"host-bind"
|
||
],
|
||
"default": "managed-volume",
|
||
"managed_volume": {
|
||
"backup": true,
|
||
"default_size_gb": 8
|
||
}
|
||
}
|
||
],
|
||
"ports": [
|
||
{
|
||
"container_port": 5678,
|
||
"published_example": 5678,
|
||
"protocol": "tcp",
|
||
"required": true,
|
||
"proxmox_behavior": "listener-on-dedicated-lxc-address-no-nat"
|
||
}
|
||
],
|
||
"related_services": [],
|
||
"restart": "unless-stopped",
|
||
"stop_grace_period": null,
|
||
"original_compose": "name: n8n\nservices:\n n8n:\n environment:\n TZ: $TZ\n N8N_SECURE_COOKIE: 'false'\n image: n8nio/n8n:latest\n deploy:\n resources:\n reservations:\n memory: 320M\n network_mode: bridge\n ports:\n - target: 5678\n published: '5678'\n protocol: tcp\n restart: unless-stopped\n volumes:\n - type: bind\n source: /DATA/AppData/$AppID\n target: /home/node/.n8n\n container_name: n8n\n"
|
||
},
|
||
"compose_stack": {
|
||
"project_name": "n8n",
|
||
"deployment_model": "one-native-oci-lxc-per-compose-service",
|
||
"user_experience": "single-application-install",
|
||
"main_service": "n8n",
|
||
"service_count": 1,
|
||
"services": [
|
||
{
|
||
"name": "n8n",
|
||
"image": "n8nio/n8n:latest",
|
||
"is_main": true,
|
||
"role": "frontend",
|
||
"vmid_offset": 0,
|
||
"depends_on": [],
|
||
"frontend_network": true,
|
||
"private_network": false,
|
||
"compose": {
|
||
"environment": {
|
||
"TZ": "$TZ",
|
||
"N8N_SECURE_COOKIE": "false"
|
||
},
|
||
"image": "n8nio/n8n:latest",
|
||
"deploy": {
|
||
"resources": {
|
||
"reservations": {
|
||
"memory": "320M"
|
||
}
|
||
}
|
||
},
|
||
"network_mode": "bridge",
|
||
"ports": [
|
||
{
|
||
"target": 5678,
|
||
"published": "5678",
|
||
"protocol": "tcp"
|
||
}
|
||
],
|
||
"restart": "unless-stopped",
|
||
"volumes": [
|
||
{
|
||
"type": "bind",
|
||
"source": "/DATA/AppData/$AppID",
|
||
"target": "/home/node/.n8n"
|
||
}
|
||
],
|
||
"container_name": "n8n"
|
||
}
|
||
}
|
||
],
|
||
"top_level": {
|
||
"name": "n8n"
|
||
},
|
||
"networking": {
|
||
"frontend": "selected-proxmox-bridge",
|
||
"private_required": false,
|
||
"private_creation": "automatic-create-if-missing",
|
||
"private_address_allocation": "automatic-static-address-per-service",
|
||
"service_discovery": "private-addresses-with-compose-service-host-aliases",
|
||
"dependency_external_access": "disabled-unless-service-publishes-ports",
|
||
"prompt_user_for_private_network": false
|
||
},
|
||
"storage": [
|
||
{
|
||
"id": "n8n-volume-0",
|
||
"service": "n8n",
|
||
"container_path": "/home/node/.n8n",
|
||
"mode": "managed-volume",
|
||
"user_selectable": false,
|
||
"backup": true,
|
||
"shared_with_other_lxc": false,
|
||
"source_path": null,
|
||
"source_path_prompt": null
|
||
}
|
||
],
|
||
"orchestration": {
|
||
"reserve_vmids_atomically": 1,
|
||
"start_order": [
|
||
"n8n"
|
||
],
|
||
"stop_order": [
|
||
"n8n"
|
||
],
|
||
"dependency_readiness": "compose-healthcheck-then-port-or-process-fallback",
|
||
"rollback_on_failure": "remove-new-rootfs-preserve-created-persistent-volumes"
|
||
},
|
||
"installer_inputs": {
|
||
"prompted": [
|
||
"stack_name",
|
||
"base_vmid",
|
||
"rootfs_storage",
|
||
"persistent_data_destinations",
|
||
"frontend_bridge",
|
||
"frontend_ipv4_mode"
|
||
],
|
||
"automatic": [
|
||
"dependent_vmids",
|
||
"private_bridge",
|
||
"private_subnet",
|
||
"private_service_addresses",
|
||
"compose_service_aliases",
|
||
"generated_secrets",
|
||
"dependency_start_and_stop_order"
|
||
],
|
||
"generated_secrets": []
|
||
}
|
||
},
|
||
"first_run": {
|
||
"endpoints": [
|
||
{
|
||
"label": "Web UI",
|
||
"scheme": "http",
|
||
"port": 5678,
|
||
"path": "/",
|
||
"source": "compose-metadata"
|
||
}
|
||
],
|
||
"credentials": []
|
||
},
|
||
"proxmox": {
|
||
"runtime": "native-oci-lxc",
|
||
"technology_status": "proxmox-technology-preview",
|
||
"defaults": {
|
||
"unprivileged": true,
|
||
"ostype": "auto-from-image",
|
||
"cores": 2,
|
||
"memory_mb": 320,
|
||
"swap_mb": 512,
|
||
"rootfs_size_gb": 8,
|
||
"rootfs_storage": "local-lvm",
|
||
"volume_storage": "local-lvm",
|
||
"template_storage": "local",
|
||
"bridge": "vmbr0",
|
||
"ipv4": "dhcp",
|
||
"firewall": true,
|
||
"host_managed_network": true,
|
||
"onboot": false,
|
||
"features": [
|
||
"nesting=1"
|
||
],
|
||
"shutdown_timeout_seconds": 30
|
||
},
|
||
"image_metadata_policy": {
|
||
"entrypoint": "import-from-oci-image",
|
||
"cmd": "import-from-oci-image",
|
||
"environment": "import-image-env-then-apply-compose-overrides",
|
||
"user": "import-from-oci-image",
|
||
"working_dir": "import-from-oci-image",
|
||
"stop_signal": "import-from-oci-image"
|
||
},
|
||
"adaptations": [
|
||
{
|
||
"id": "imported-compose-source",
|
||
"upstream_behavior": "The source definition deploys the complete Docker Compose application model.",
|
||
"native_lxc_behavior": "The source model is preserved and remains blocked until every service option has a reviewed native Proxmox mapping.",
|
||
"reason": "Catalog import must not imply runtime compatibility.",
|
||
"behavioral_impact": "No automatic installation before review.",
|
||
"validation": "pending-per-application"
|
||
},
|
||
{
|
||
"id": "rolling-latest-image",
|
||
"upstream_behavior": "A discovered Compose may pin a release tag or digest.",
|
||
"native_lxc_behavior": "ProxMenux selects the same image repository with the latest tag for catalog installations.",
|
||
"reason": "The automatic catalog intentionally offers rolling latest images; pinned versions belong to the future manual installer.",
|
||
"behavioral_impact": "The installed release can be newer than the discovered Compose revision.",
|
||
"validation": "pending-per-application"
|
||
},
|
||
{
|
||
"id": "dedicated-lxc-network",
|
||
"upstream_behavior": "Docker publishes selected container ports on the Docker host.",
|
||
"native_lxc_behavior": "A reviewed native application will listen on its original container ports at a dedicated LXC address.",
|
||
"reason": "A native LXC has its own address and does not require Docker port NAT.",
|
||
"behavioral_impact": "Published ports are metadata; ProxMenux URLs use the matching container target port.",
|
||
"validation": "pending-per-application"
|
||
},
|
||
{
|
||
"id": "compose-shm-size",
|
||
"upstream_behavior": "Compose sets the size of the container /dev/shm tmpfs.",
|
||
"native_lxc_behavior": "ProxMenux mounts a native LXC tmpfs at /dev/shm with the same requested capacity.",
|
||
"reason": "The OCI image runs directly as an LXC and therefore needs the equivalent Proxmox mount entry.",
|
||
"behavioral_impact": "None expected.",
|
||
"validation": "not-requested-by-compose"
|
||
},
|
||
{
|
||
"id": "compose-command",
|
||
"upstream_behavior": "Compose replaces the image Cmd while retaining its Entrypoint.",
|
||
"native_lxc_behavior": "ProxMenux reads the official OCI Entrypoint and combines it with the Compose command as the native LXC init command.",
|
||
"reason": "Proxmox stores the effective OCI process as one entrypoint string.",
|
||
"behavioral_impact": "None expected.",
|
||
"validation": "not-requested-by-compose"
|
||
},
|
||
{
|
||
"id": "compose-privileged-mode",
|
||
"upstream_behavior": "Compose selects whether the container runs in privileged mode.",
|
||
"native_lxc_behavior": "ProxMenux uses a privileged LXC only after an explicit high-risk confirmation; otherwise it keeps the LXC unprivileged.",
|
||
"reason": "The native OCI-LXC deployment must preserve the requested privilege level without silently weakening isolation.",
|
||
"behavioral_impact": "A privileged LXC has weaker isolation from the Proxmox host.",
|
||
"validation": "native-equivalent"
|
||
},
|
||
{
|
||
"id": "compose-process-runtime",
|
||
"upstream_behavior": "Compose can replace Entrypoint, User and WorkingDir and request an init process or interactive terminal.",
|
||
"native_lxc_behavior": "ProxMenux applies the process overrides through native LXC init directives; lxc-init provides PID 1 supervision and the CT console provides terminal access.",
|
||
"reason": "The OCI process must start with the same identity, command and working directory without Docker.",
|
||
"behavioral_impact": "Compose stdin_open and tty become access through the Proxmox LXC console.",
|
||
"validation": "not-requested-by-compose"
|
||
},
|
||
{
|
||
"id": "compose-healthcheck",
|
||
"upstream_behavior": "Docker periodically executes the declared container healthcheck.",
|
||
"native_lxc_behavior": "For a single-service LXC, ProxMenux translates HTTP localhost checks into a mandatory first-start service check.",
|
||
"reason": "Proxmox has no persistent Docker health state, while the installer still must detect a failed first boot.",
|
||
"behavioral_impact": "The check runs during installation rather than continuously after installation.",
|
||
"validation": "not-requested-by-compose"
|
||
},
|
||
{
|
||
"id": "compose-cpu-priority",
|
||
"upstream_behavior": "Docker cpu_shares sets a relative scheduling weight with 1024 as its neutral value.",
|
||
"native_lxc_behavior": "ProxMenux converts the relative weight to Proxmox cpuunits with 100 as its neutral value and lets the user review it.",
|
||
"reason": "Both settings express relative CPU priority on different scales.",
|
||
"behavioral_impact": "Rounding and Proxmox minimum limits can slightly change very low weights.",
|
||
"validation": "not-requested-by-compose"
|
||
},
|
||
{
|
||
"id": "compose-network-identity",
|
||
"upstream_behavior": "Compose can set hostname, MAC address, extra hosts and attach a service to Docker networks.",
|
||
"native_lxc_behavior": "ProxMenux applies hostname and MAC to net0, writes additional host aliases into the LXC and uses its dedicated bridge connection for single-service networks.",
|
||
"reason": "A dedicated LXC has its own network namespace and does not need a Docker bridge per service.",
|
||
"behavioral_impact": "host-gateway resolves to the IPv4 address of the selected Proxmox bridge.",
|
||
"validation": "not-requested-by-compose"
|
||
},
|
||
{
|
||
"id": "docker-engine-metadata",
|
||
"upstream_behavior": "Compose labels annotate Docker objects and the json-file logging driver rotates Docker-managed logs.",
|
||
"native_lxc_behavior": "Labels remain source metadata; Docker json-file settings are not applied because the OCI process runs directly under LXC.",
|
||
"reason": "There is no Docker object or Docker json-file log behind a native OCI-LXC application.",
|
||
"behavioral_impact": "Docker-only label consumers and Docker log-driver rotation do not exist in the native deployment.",
|
||
"validation": "not-requested-by-compose"
|
||
},
|
||
{
|
||
"id": "compose-device-passthrough",
|
||
"upstream_behavior": "Compose passes host character devices or requests an NVIDIA runtime GPU.",
|
||
"native_lxc_behavior": "ProxMenux converts recognized device declarations to native Proxmox dev resources; NVIDIA profiles also inject compatible host driver libraries read-only.",
|
||
"reason": "Native OCI-LXC does not execute Docker device or NVIDIA runtime hooks.",
|
||
"behavioral_impact": "Hardware is exposed only after explicit user confirmation and host-path validation.",
|
||
"validation": "not-requested-by-compose"
|
||
},
|
||
{
|
||
"id": "compose-host-ipc",
|
||
"upstream_behavior": "ipc: host shares the Docker host IPC namespace, commonly to avoid Docker's small default shared-memory allocation.",
|
||
"native_lxc_behavior": "The application keeps the LXC IPC namespace and receives a configurable 1 GiB /dev/shm instead of sharing Proxmox host IPC.",
|
||
"reason": "Processes in a single native LXC already share one IPC namespace; retaining isolation is safer than exposing host IPC.",
|
||
"behavioral_impact": "The application cannot exchange IPC objects with processes on the Proxmox host.",
|
||
"validation": "not-requested-by-compose"
|
||
}
|
||
]
|
||
},
|
||
"compatibility": {
|
||
"automatic_install_candidate": true,
|
||
"validated": false,
|
||
"supported_compose_keys": [
|
||
"command",
|
||
"container_name",
|
||
"cpu_shares",
|
||
"deploy",
|
||
"devices",
|
||
"entrypoint",
|
||
"environment",
|
||
"extra_hosts",
|
||
"healthcheck",
|
||
"hostname",
|
||
"image",
|
||
"init",
|
||
"ipc",
|
||
"labels",
|
||
"logging",
|
||
"mac_address",
|
||
"network_mode",
|
||
"networks",
|
||
"ports",
|
||
"privileged",
|
||
"restart",
|
||
"runtime",
|
||
"shm_size",
|
||
"stdin_open",
|
||
"stop_grace_period",
|
||
"tty",
|
||
"user",
|
||
"volumes",
|
||
"working_dir"
|
||
],
|
||
"untranslated_blockers": [],
|
||
"policy": "Single-image definitions are installable when every declared Compose option has a native Proxmox translation. Multi-image and unsupported runtime features remain blocked until their orchestrator or mapping is available."
|
||
},
|
||
"validation": {
|
||
"schema": "passed-at-generation",
|
||
"clean_install": "pending",
|
||
"service_health": "pending",
|
||
"restart_persistence": "pending",
|
||
"backup_restore": "pending",
|
||
"update_preserves_data": "pending"
|
||
},
|
||
"lifecycle": {
|
||
"update_strategy": "resolve-latest-image-then-apply-reviewed-native-lxc-update",
|
||
"registry_state": {
|
||
"resolved_architecture": null,
|
||
"resolved_digest": null,
|
||
"image_version_label": null,
|
||
"image_created": null
|
||
},
|
||
"change_detection": "compare-compose-sha256-and-resolved-latest-image-digest",
|
||
"automatic_unattended_updates": false
|
||
}
|
||
}
|