Commit Graph
4710 Commits
Author SHA1 Message Date
CanbiZ (MickLesk) bb1ec9e608 Homarr: replace the musl better-sqlite3 that v2.3.0 ships for Debian (#17789)
The build-debian tarballs of v2.3.0 carry the Alpine build of
better_sqlite3.node, so the DB migration dies with ERR_DLOPEN_FAILED on
libc.musl and Homarr no longer starts after an update (#17783,
homarr-labs/homarr#7097). When the bundled module is musl, swap in
better-sqlite3's own glibc prebuild for the running Node ABI. The update runs
the check outside the release check, so containers already on 2.3.0 are
repaired too; it does nothing once upstream ships a correct tarball.
2026-10-08 15:13:16 +02:00
CanbiZ (MickLesk) c4879a1b72 CLIProxyAPI: keep plugins and data across updates (#17790)
The clean install wiped /opt/cliproxyapi including plugins/ and data/, so
every update removed installed plugins and their data (#17750).
2026-10-08 15:10:28 +02:00
CanbiZ (MickLesk) 84d2c964e6 Immich: Pin to 3.3.0 / Update ML Python to 3.13 (#17770)
* Immich: pin v3.3.0 again

Reapplies #17759, reverted in #17767 because machine learning broke on 3.3.0; the fixes follow.

* Immich: run machine learning on Python 3.13

3.3.0 requires Python >=3.12 for machine learning and upstream builds both its CPU and OpenVINO images on 3.13. The CPU path still pinned 3.11, so uv sync failed on every update and install (#17762).

* Immich: stop when uv sync keeps failing

After three failed attempts the loop still reported the machine-learning step as done, so an update ended in "Updated successfully" with no usable venv and immich-ml failing on start. Exit with an error instead.

* Immich: only mention the HEIC patch when it applies

On 3.3.0 the sharp call it rewrites is gone, so every run printed "pattern not found, skipped" into the spinner line and then "Patched". Check for the pattern first and stay silent otherwise.

* BookOrbit: retry the client build when the bundler crashes

Since rolldown 1.2.8, vite build dies at random with SIGSEGV or SIGBUS
(rolldown#10860, closed upstream), which stopped the 3.3.0 update with exit
139 (#17753). Retry the client build up to three times before giving up.
2026-10-08 11:47:06 +02:00
CanbiZ (MickLesk) 2a38085984 Revert "Immich: Pin to v3.3.0 (#17759)" (#17767)
This reverts commit a5431e295b.
2026-10-08 06:13:00 +02:00
Chris a5431e295b Immich: Pin to v3.3.0 (#17759)
* Immich: Pin version to 3.3.0

- New features
- Bugfixes

* Enable new Machine Learning models by default
2026-10-07 23:02:37 +02:00
CanbiZ (MickLesk) 096f0ba2db AudioMuse-AI: replace the venv on update without asking (#17738)
uv venv on an existing .venv asks before replacing it and refuses outright
without a terminal, so updates through update-apps.sh failed and left the
services stopped (#17734). --clear replaces it the way the interactive prompt
did.
2026-10-07 21:40:00 +02:00
CanbiZ (MickLesk) 46c0210af7 Pangolin: Unpin Release, stable enough, Bump to latest (#17740)
* Pangolin: Unpin Release, stable enough, Bump to latest

* Remove default PANGOLIN_VERSION in install script
2026-10-07 21:39:05 +02:00
samvandenbosscheandClaude Sonnet 5.5 b755ec70d5 paperclip: run service as a dedicated non-root user (#17707)
Claude Code refuses --dangerously-skip-permissions as root, which blocked
Paperclip onboarding. Run onboarding and the systemd service as a
non-root user (var_paperclip_user, default paperclip) with an optional
var_paperclip_pass (account locked if unset). Existing installs are
migrated on update.

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-07 14:06:14 +02:00
Sim Kai Long cec9f13da1 OpenCloud: bump to v8.1.0, rebuild search index on upgrade (#17710)
v8 changes the search index format; existing files are not found by
search until the index is rebuilt. When updating from 7.x or older, run
the reindex as a transient systemd unit (the CLI cancels the rebuild if
interrupted), wait for it, and report the outcome.
2026-10-07 14:05:30 +02:00
CerberusStyleandCanbiZ 13bfd8aa15 Thingsboard: update Java version from 17 to 25 (#17733)
* Update Java version from 17 to 25 in install script

* Set JAVA_VERSION before checking for gh release

---------

Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-07 08:32:22 +02:00
CanbiZ (MickLesk) 36078aa896 Webtrees: stop serving data/ and the source folders directly (#17724)
Caddy served all of /opt/webtrees through file_server, so media under
data/media could be fetched by URL without passing webtrees' privacy rules.
webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the
folders webtrees' own nginx guide keeps private, plus dotfiles.

update_script adds the rule to existing Caddyfiles on every update, not only
when a new release is out, and keeps the old file if the result fails
caddy validate.
2026-10-06 16:26:21 +02:00
push-app-to-main[bot] bf3fad3984 Add pricebuddy (ct) (#17708)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-06 10:48:36 +02:00
CanbiZ (MickLesk) 7d9648dc90 wanderer: set the proxy secret and install plugins in their own directories (#17698)
0.21 requires POCKETBASE_PROXY_SECRET on both services, or every
incoming federation request is rejected; both read the same .env.

Each plugin archive holds one directory, which the deploy strips, so all
three landed flat in plugins/ and overwrote each other. wanderer only
loads direct child directories, so it found none. Existing installs are
moved over on the next update.
2026-10-05 12:48:29 +02:00
CanbiZ (MickLesk) 231b2fb1b7 discourse: serve stylesheets and repair the update (#17697)
nginx passed X-Accel-Mapping on every request. Stylesheets are sent
from tmp/, outside that mapping, so Rack redirected nginx to their
filesystem path and the page loaded without CSS. Existing installs get
the line removed on update.

The update called yarn, which is not installed, ran Rails without the
production environment or rbenv on PATH, asked for PostgreSQL 16 on a
17 install and left sidekiq running.
2026-10-05 12:47:42 +02:00
CanbiZ (MickLesk) 1c1295a9fd Point to DevScripts, the renamed ProxmoxVED (#17694)
Contribution docs, the PR template and the workflows that talk to the
testing repository use the new name. Migration PRs are matched by either
name, and three license headers pointed at contributor forks.
2026-10-05 11:03:02 +02:00
github-actions[bot] 5b5e8dc4f3 wikijs: bump Node.js from 24 to 26 (#17689)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-10-05 08:50:27 +02:00
github-actions[bot] 7bde0ac8d9 jotty: bump Node.js from 22 to 24 (#17688)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-10-05 08:47:32 +02:00
CanbiZ (MickLesk) 63e2ce0849 immich: read the Intel runtime from the pinned release (#17677)
The URLs came from the ML Dockerfile on main, which upstream moved into
scripts/install-intel-runtime.sh, so update failed on the grep and
OpenVINO installs found no packages.
2026-10-04 14:03:24 +02:00
durzo a74f683fab Tracearr: workaround for failing map tiles download and data preservation (#17661) 2026-10-03 20:49:13 +02:00
push-app-to-main[bot] 01906fe930 Add keeper (ct) (#17659)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-03 16:58:20 +02:00
PsycoStea fa4e227f7b fix(nginxproxymanager): clean yarn cache after builds to prevent disk growth (#17653)
* fix(nginxproxymanager): clean yarn cache after builds

* fix(nginxproxymanager): clean yarn cache after builds
2026-10-03 08:21:16 +02:00
CanbiZ (MickLesk) 7f57d0998c Refactor/core qol adoption (#17655)
* Scripts: close every msg_info block with msg_ok

Past-tense msg_info calls that should have been msg_ok, notices that opened a block before a prompt, and blocks without a closing msg_ok. These already left a stale spinner; with core's block stack they would resume it after every later msg_ok.

* Generate passwords with random_password

openssl rand -base64 | tr -dc | head -c returned fewer characters than asked for, and the unfiltered | cut variants put / and + into passwords that end up in DSNs and sed expressions. Secrets an app decodes as base64 are unchanged. Requires community-scripts/core#61.

* Keep data directories through CLEAN_INSTALL instead of copying them

create_backup copied uploads, storage and similar directories twice per update and needed their size again in free space. CLEAN_INSTALL_KEEP moves them aside instead. Only directories the upstream release does not ship, in scripts that restored right after the fetch. Requires community-scripts/core#61.

* Drop the 300s uv timeout overrides

setup_uv exports UV_HTTP_TIMEOUT=600 now; the scripts' 300 only lowered it. Requires community-scripts/core#61.
2026-10-03 08:19:10 +02:00
CanbiZ (MickLesk) eead382524 zerobyte: upgrade Bun on update (#17646) 2026-10-02 08:06:43 +02:00
CanbiZ (MickLesk) 4277a26af6 sure: keep Active Storage uploads across updates (#17648) 2026-10-02 08:02:17 +02:00
CanbiZ (MickLesk) 826a5d9612 twenty: run upstream's upgrade command instead of the removed setup-db.ts (#17647) 2026-10-02 08:02:14 +02:00
CanbiZ (MickLesk) 435aaaa299 NPM: Refactor / Fix npm openresty user and certbot version (#17649)
* nginxproxymanager: repair the nginx user even when the release is current

* nginxproxymanager: read the certbot version from its own line
2026-10-02 08:01:51 +02:00
CanbiZ (MickLesk) b4bf7aacf3 several scripts: use the release helpers instead of hand-rolled version checks and downloads (#17625)
* Use the release helpers instead of hand-rolled version checks and downloads

Legacy /opt/*_version.txt files move to ~/.<app> on the next update.

* homeassistant: use get_latest_github_release
2026-10-02 08:01:49 +02:00
skilletfunandCanbiZ f86db843e2 feat(glance): add alpine os (#17605)
* feat(glance): add alpine os

* Increase default RAM and disk for Alpine OS

---------

Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-01 23:23:26 +02:00
skilletfunandCanbiZ e91f2abe21 feat(blocky): add alpine os (#17637)
* feat(blocky): add alpine os

* Increase default RAM and disk for Alpine OS

---------

Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-01 23:21:35 +02:00
CanbiZ (MickLesk) 21e8abf269 romm: keep the asset links in sync with ROMM_BASE_PATH (#17610) 2026-10-01 12:35:06 +02:00
CanbiZ (MickLesk) 2497c18bee Scripts: apt instead of apt-get, cleanup_lxc, nginx_enable_site, drop needless daemon-reloads (#17624) 2026-10-01 08:14:33 +02:00
CanbiZ (MickLesk) e773412791 Drop the local header generation; headers come from core (#17623) 2026-10-01 08:14:18 +02:00
CanbiZ (MickLesk) 6af075102c teslamate: build from the elixir directory since 4.3.0 (#17612) 2026-10-01 08:12:26 +02:00
community-scripts-pr-app[bot]andGitHub Actions 97c95f81d4 Update .app files (#17618)
Co-authored-by: GitHub Actions <github-actions[bot]@users.noreply.github.com>
2026-10-01 07:28:02 +02:00
push-app-to-main[bot] 2cf1457d70 Add shoko (ct) (#17617)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-09-30 19:40:34 +02:00
community-scripts-pr-app[bot]andGitHub Actions 7b6c174668 Update .app files (#17615)
Co-authored-by: GitHub Actions <github-actions[bot]@users.noreply.github.com>
2026-09-30 19:35:39 +02:00
push-app-to-main[bot] 413731eeaf Add silo (ct) (#17614)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-09-30 19:33:13 +02:00
Tin Sever 117feec84c fix(kaneo): build with Vite+ instead of Turbo (#17599) 2026-09-29 19:12:48 +02:00
CanbiZ (MickLesk) 5515363c84 Drop the scripts base pin from every ct/ script (#17585)
ProxmoxVE is the engine's default scripts base as of community-scripts/core#76,
so the pin no longer changes anything.
2026-09-29 15:23:32 +02:00
CanbiZ (MickLesk) 9b82dd4248 odoo: move to Debian 13 and stay on the installed major on update (#17581) 2026-09-29 15:18:24 +02:00
CanbiZ (MickLesk) 5da941e2ce manyfold: use upstream f3d for headless renders on amd64 (#17583) 2026-09-29 15:13:13 +02:00
Denislav DenevandMichel Roegl-Brunner 8a314a12be fix(romm): snapshot Redis hourly like the upstream image (#17562)
* fix(romm): snapshot Redis hourly like the upstream image

Redis' default save policy (3600 1 300 100 60 10000) rewrites the whole dump.rdb every 5 minutes on an idle RomM, because the RQ workers and scheduler change keys constantly. With the Switch TitleDB and PS2 serial caches the dump is ~50 MB, so an idle container writes ~14 GB/day. Upstream fixed this for the Docker image (rommapp/romm#3983, REDIS_SAVE_POLICY default "3600 1"), but that lives in docker/init_scripts/init, which the LXC install never runs. Apply the same policy on install and, for existing containers, on update unless a save policy is already set.

* Update ct/romm.sh

* Update install/romm-install.sh

---------

Co-authored-by: Michel Roegl-Brunner <73236783+michelroegl-brunner@users.noreply.github.com>
2026-09-29 14:02:51 +02:00
push-app-to-main[bot]andCanbiZ 098ce2dea0 Anki Sync Server (#17416)
* Add anki-sync-server (ct)

* Clean up comments in anki-sync-server.sh

Removed comments about local core checkout and credential storage.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-09-29 13:13:28 +02:00
Joren Guillaume 90827a0710 Change cp command (#17559)
Cover case where only dotfiles are inside the source directory.
2026-09-28 23:10:48 +02:00
CanbiZ (MickLesk) 096da0dff6 Borg-UI: start through upstream's start.sh so migrations run (#17563) 2026-09-28 23:09:08 +02:00
Chris cd7ac82058 Immich: Pin version to 3.2.4 (#17564)
- Upstream bugfixes
2026-09-28 21:55:12 +02:00
CanbiZ (MickLesk) 9312a32495 Serve linkding's favicons and preview images (#17557)
linkding stores them in data/favicons and data/previews and upstream maps both
under /static next to the collected assets, with a sandbox CSP. The nginx site
only aliased the collected assets, so every downloaded image answered 404; the
update rewrites that block even without a new release.
2026-09-28 09:13:57 +02:00
CanbiZ (MickLesk) 2ee7d13367 Fill in the nginx resolver SparkyFitness 1.7.3 added (#17556)
Upstream's nginx.conf gained a resolver ${NGINX_RESOLVER} line that its Docker
entrypoint fills from /etc/resolv.conf; the script substitutes a fixed list of
placeholders, so the literal variable reached nginx and the config test failed.
Take the nameservers from resolv.conf the same way.
2026-09-28 09:13:47 +02:00
Jody VandClaude Sonnet 5 56886bb053 fix(aurral): bump to Node 26 and bypass strict engine pin (#17543)
* fix: bump aurral Node.js requirement from 22 to 26

Upstream aurral now requires Node 26.x (engines: "26.8.x" in v2.10.0),
causing npm ci to fail with EBADENGINE when the install script sets up
Node 22.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix: bypass npm engine-strict check for aurral build

aurral's .npmrc sets engine-strict=true and pins an exact node patch
(26.8.x), which NodeSource can never satisfy since it only ships the
latest patch per major (currently 26.10.0). Disable engine-strict for
the build, matching the ignore-engines workaround already used for
yarn-based apps in this repo (dashy, monica, excalidraw,
elementsynapse).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 23:38:40 +02:00
durzo 989f064993 Tracearr: fetch map tiles on install/update (#17544) 2026-09-27 19:08:54 +02:00