* Add unifi-os-server-vm (vm)
* Refactor UniFi OS Server VM setup script
Updated the script to set default OS and version, improved error handling, and modified the first-boot installer process.
---------
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
* Refactor: Ubuntu VM
Updated licensing information and improved error handling. Refactored OS selection logic and cloud-init prompts.
* Update license URL in ubuntu-vm.sh
* Immich: pin v3.3.0 again
Reapplies #17759, reverted in #17767 because machine learning broke on 3.3.0; the fixes follow.
* Immich: run machine learning on Python 3.13
3.3.0 requires Python >=3.12 for machine learning and upstream builds both its CPU and OpenVINO images on 3.13. The CPU path still pinned 3.11, so uv sync failed on every update and install (#17762).
* Immich: stop when uv sync keeps failing
After three failed attempts the loop still reported the machine-learning step as done, so an update ended in "Updated successfully" with no usable venv and immich-ml failing on start. Exit with an error instead.
* Immich: only mention the HEIC patch when it applies
On 3.3.0 the sharp call it rewrites is gone, so every run printed "pattern not found, skipped" into the spinner line and then "Patched". Check for the pattern first and stay silent otherwise.
* BookOrbit: retry the client build when the bundler crashes
Since rolldown 1.2.8, vite build dies at random with SIGSEGV or SIGBUS
(rolldown#10860, closed upstream), which stopped the 3.3.0 update with exit
139 (#17753). Retry the client build up to three times before giving up.
uv venv on an existing .venv asks before replacing it and refuses outright
without a terminal, so updates through update-apps.sh failed and left the
services stopped (#17734). --clear replaces it the way the interactive prompt
did.
* Refactor archlinux-vm.sh and update defaults
Refactor Arch Linux VM script to improve structure and update default settings.
* Update Arch Linux VM script to use dynamic ISO path
Claude Code refuses --dangerously-skip-permissions as root, which blocked
Paperclip onboarding. Run onboarding and the systemd service as a
non-root user (var_paperclip_user, default paperclip) with an optional
var_paperclip_pass (account locked if unset). Existing installs are
migrated on update.
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
v8 changes the search index format; existing files are not found by
search until the index is rebuilt. When updating from 7.x or older, run
the reindex as a transient systemd unit (the CLI cancels the rebuild if
interrupted), wait for it, and report the outcome.
* Update Java version from 17 to 25 in install script
* Set JAVA_VERSION before checking for gh release
---------
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
Caddy served all of /opt/webtrees through file_server, so media under
data/media could be fetched by URL without passing webtrees' privacy rules.
webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the
folders webtrees' own nginx guide keeps private, plus dotfiles.
update_script adds the rule to existing Caddyfiles on every update, not only
when a new release is out, and keeps the old file if the result fails
caddy validate.