Compare commits

...

3 Commits

Author SHA1 Message Date
push-app-to-main[bot]
352111765d Add solidinvoice (ct) 2026-08-29 22:34:50 +00:00
community-scripts-pr-app[bot]
bddc28bb57 Update CHANGELOG.md (#16857)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-29 21:38:30 +00:00
CanbiZ (MickLesk)
ceb783d62c github action: post the command that tests a ct/ or install/ change (#16833)
* Post the command that tests a ct/ or install/ change

Reviewing a script change meant working out the URL yourself, and the
obvious guess is wrong: curling the branch URL alone gives you the ct/
script from the PR and the install/ script from main, because each script
pins _CS_DEFAULT_URL to main and that pin is what fills
COMMUNITY_SCRIPTS_URL when it is unset. Frequently the install script is
the only thing that changed.

So the comment spells out both lines, per changed app.

Only for scripts already on the core bootstrap. The older one-liner
resolves everything from ProxmoxVE/main and ignores the variable, so a
command built for it would install main and look like it passed --  worse
than no comment. Those are named instead, with what to do about them.

pull_request_target for fork PRs, and nothing from the PR is checked out
or executed: the file list and the bootstrap line come from the API, and
a branch name that is not [A-Za-z0-9._/-]+ stops the run rather than
reaching a fenced code block.

* Update .github/workflows/pr-test-command.yml

Co-authored-by: Sam Heinz <sam@samheinz.com>

---------

Co-authored-by: Sam Heinz <sam@samheinz.com>
2026-08-29 23:38:09 +02:00
5 changed files with 430 additions and 0 deletions

171
.github/workflows/pr-test-command.yml generated vendored Normal file
View File

@@ -0,0 +1,171 @@
name: PR test command
# Posts a ready-to-run test command for reviewers.
# It uses this PRs script branch with the production engine, since both resolve
# independently. Only scripts using community-scripts/core are supported.
#
# pull_request_target allows comments on fork PRs. No PR code is checked out or
# executed; API inputs are validated and the comment is assembled in JavaScript.
on:
pull_request_target:
branches: ["main"]
types: [opened, synchronize, reopened]
paths:
- "ct/**"
- "install/**"
jobs:
comment:
if: github.repository == 'community-scripts/ProxmoxVE'
runs-on: self-hosted
permissions:
pull-requests: write
contents: read
steps:
- uses: actions/github-script@v9
with:
script: |
const MARKER = '<!-- pr-test-command -->';
const MAX_APPS = 10;
const pr = context.payload.pull_request;
const head = pr.head.repo; // null when the fork is gone
if (!head) return;
const owner = context.repo.owner;
const repo = context.repo.repo;
// Git allows backticks in a ref name, and this one ends up inside a
// fenced block. Anything outside the ordinary set is not worth
// rendering, so bail rather than escape.
const ref = pr.head.ref;
if (!/^[A-Za-z0-9._\/-]+$/.test(ref)) return;
const base = `https://raw.githubusercontent.com/${head.full_name}/${ref}`;
const files = await github.paginate(github.rest.pulls.listFiles, {
owner, repo, pull_number: pr.number, per_page: 100,
});
// ct/foo.sh and install/foo-install.sh are the same app. A removed
// file has nothing left to run.
const apps = new Map(); // slug -> {ct, install}
for (const f of files) {
if (f.status === 'removed') continue;
let m = f.filename.match(/^ct\/([a-z0-9][a-z0-9._-]*)\.sh$/);
if (m) { apps.set(m[1], { ...apps.get(m[1]), ct: true }); continue; }
m = f.filename.match(/^install\/([a-z0-9][a-z0-9._-]*)-install\.sh$/);
if (m) apps.set(m[1], { ...apps.get(m[1]), install: true });
}
if (apps.size === 0) return;
// Read the ct script at the PR head to see which engine it loads.
// Read only -- it is never sourced or run.
async function bootstrapOf(slug) {
try {
const res = await github.rest.repos.getContent({
owner: head.owner.login, repo: head.name,
path: `ct/${slug}.sh`, ref: pr.head.sha,
});
if (!res.data.content) return 'unknown';
const text = Buffer.from(res.data.content, 'base64').toString('utf8');
const firstLines = text.split('\n').slice(0, 12).join('\n');
return /_cs_boot=/.test(firstLines) ? 'core' : 'legacy';
} catch (e) {
return e.status === 404 ? 'missing' : 'unknown';
}
}
const ready = [], legacy = [], missing = [];
for (const slug of [...apps.keys()].sort()) {
const kind = await bootstrapOf(slug);
if (kind === 'core') ready.push(slug);
else if (kind === 'legacy') legacy.push(slug);
else if (kind === 'missing') missing.push(slug);
}
const lines = [MARKER];
if (ready.length > 0) {
const shown = ready.slice(0, MAX_APPS);
lines.push(
'### Try this branch',
'',
'The engine and the scripts resolve independently, so this runs the changed',
'`ct/` and `install/` scripts against the **production** engine:',
'',
);
for (const slug of shown) {
lines.push(
'```bash',
`export COMMUNITY_SCRIPTS_URL=${base}`,
`bash -c "$(curl -fsSL "$COMMUNITY_SCRIPTS_URL/ct/${slug}.sh")"`,
'```',
'',
);
}
if (ready.length > shown.length) {
lines.push(
`${ready.length - shown.length} more script(s) changed; same command, different slug.`,
'',
);
}
lines.push(
'Both lines are needed. Each script pins `_CS_DEFAULT_URL` to `main`, and that',
'pin is what fills `COMMUNITY_SCRIPTS_URL` when the variable is unset — so',
'curling the branch URL on its own gives you the `ct/` script from this PR and',
'the `install/` script from `main`. Frequently the one you meant to test.',
'',
'The same command works on an Incus host: the engine detects the platform and',
'loads the matching backend, while the scripts still come from this branch.',
'',
'<details><summary>Useful while testing</summary>',
'',
'`dev_mode=net` logs every fetch with status and URL, which is the quickest way',
'to confirm the branch is really being used. `dev_mode=keep` stops a failed',
'build from deleting the container along with the evidence.',
'',
'```bash',
`export COMMUNITY_SCRIPTS_URL=${base}`,
`dev_mode=net,keep bash -c "$(curl -fsSL "$COMMUNITY_SCRIPTS_URL/ct/${shown[0]}.sh")"`,
'```',
'</details>',
);
}
if (legacy.length > 0) {
lines.push(
'',
ready.length > 0 ? '---' : '### Not testable this way yet',
'',
`\`${legacy.join('`, `')}\` still uses the older one-liner bootstrap, which`,
'resolves everything from `ProxmoxVE/main` and ignores `COMMUNITY_SCRIPTS_URL`.',
'There is no way to point it at this branch — test it from a checkout on the',
'host instead, or migrate the script to the `_cs_boot` bootstrap first.',
);
}
if (missing.length > 0) {
lines.push(
'',
`No \`ct/\` script found for \`${missing.join('`, `')}\`, so there is nothing to`,
'run. If the install script was renamed, its `ct/` counterpart needs the same',
'name.',
);
}
if (lines.length === 1) return; // marker only, nothing worth saying
const body = lines.join('\n');
// Update in place rather than posting again on every push.
const comments = await github.paginate(github.rest.issues.listComments, {
owner, repo, issue_number: pr.number, per_page: 100,
});
const mine = comments.find(c => c.body.includes(MARKER));
if (mine) {
if (mine.body !== body) {
await github.rest.issues.updateComment({ owner, repo, comment_id: mine.id, body });
}
} else {
await github.rest.issues.createComment({ owner, repo, issue_number: pr.number, body });
}

View File

@@ -527,6 +527,12 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-08-29
### 📚 Documentation
- github action: post the command that tests a ct/ or install/ change [@MickLesk](https://github.com/MickLesk) ([#16833](https://github.com/community-scripts/ProxmoxVE/pull/16833))
## 2026-08-28
### 🚀 Updated Scripts

6
ct/headers/solidinvoice Normal file
View File

@@ -0,0 +1,6 @@
_____ ___ ______ _
/ ___/____ / (_)___/ / _/___ _ ______ (_)_______
\__ \/ __ \/ / / __ // // __ \ | / / __ \/ / ___/ _ \
___/ / /_/ / / / /_/ // // / / / |/ / /_/ / / /__/ __/
/____/\____/_/_/\__,_/___/_/ /_/|___/\____/_/\___/\___/

57
ct/solidinvoice.sh Normal file
View File

@@ -0,0 +1,57 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Pierre du Plessis
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/solidinvoice/solidinvoice
APP="SolidInvoice"
var_tags="${var_tags:-invoicing;finance;billing}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-4}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/bin/solidinvoice ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "solidinvoice" "SolidInvoice/SolidInvoice"; then
msg_info "Stopping ${APP} Service"
systemctl stop solidinvoice
msg_ok "Stopped ${APP} Service"
fetch_and_deploy_gh_release "solidinvoice" "SolidInvoice/SolidInvoice" "singlefile" "latest" "/usr/bin" "solidinvoice-linux-$(arch_resolve)"
msg_info "Starting ${APP} Service"
systemctl start solidinvoice
msg_ok "Started ${APP} Service"
msg_ok "Updated Successfully"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8765${CL}"

View File

@@ -0,0 +1,190 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Pierre du Plessis
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/solidinvoice/solidinvoice
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Creating Directories"
mkdir -p /etc/solidinvoice /var/lib/solidinvoice
msg_ok "Created Directories"
fetch_and_deploy_gh_release "solidinvoice" "SolidInvoice/SolidInvoice" "singlefile" "latest" "/usr/bin" "solidinvoice-linux-$(arch_resolve)"
msg_info "Configuring SolidInvoice"
cat <<'EOF' >/etc/solidinvoice/solidinvoice.env
# SolidInvoice environment configuration
# This file is sourced by the systemd service unit.
# CLI flags always take precedence over values set here.
# ------------------------------------------------------------------
# Network
# ------------------------------------------------------------------
# Port to listen on (default: 8765)
#SOLIDINVOICE_PORT=8765
# IP address to bind to (default: auto-detected outbound IP)
#SOLIDINVOICE_SERVER_IP=0.0.0.0
# Domain name — required when using Let's Encrypt or custom certificates.
# When set, the application binds to https://<domain> instead of an IP.
#SOLIDINVOICE_DOMAIN=
# Bind the bundled webserver to every hostname so it answers regardless of the
# Host header — required behind a reverse proxy that forwards the original domain.
SOLIDINVOICE_DOCKER=true
# ------------------------------------------------------------------
# HTTPS / TLS
# ------------------------------------------------------------------
# Disable HTTPS and serve plain HTTP. Set to 1 when running behind a
# reverse proxy (nginx, Caddy, Traefik, etc.) that handles TLS termination.
# Remove or set to 0 when you want the application to manage its own certificates.
SOLIDINVOICE_DISABLE_HTTPS=1
# Enable automatic Let's Encrypt certificates (requires SOLIDINVOICE_DOMAIN).
# Incompatible with SOLIDINVOICE_DISABLE_HTTPS=1.
#SOLIDINVOICE_LETS_ENCRYPT=1
# Paths to a custom TLS certificate and private key (requires SOLIDINVOICE_DOMAIN).
# Incompatible with SOLIDINVOICE_DISABLE_HTTPS=1 and SOLIDINVOICE_LETS_ENCRYPT=1.
#SOLIDINVOICE_SSL_CERT=/etc/ssl/certs/solidinvoice.crt
#SOLIDINVOICE_SSL_KEY=/etc/ssl/private/solidinvoice.key
# ------------------------------------------------------------------
# Performance
# ------------------------------------------------------------------
# Enable FrankenPHP worker mode for improved performance (keeps PHP workers
# alive between requests). Recommended for high-traffic deployments.
# Set to 1 to enable.
#FRANKENPHP_WORKER_MODE=1
# Number of FrankenPHP worker threads when worker mode is enabled (default: 2).
#SOLIDINVOICE_WORKER_THREADS=2
# Number of background messenger worker processes (default: 1).
# Set to 0 to disable built-in workers (use the dedicated 'solidinvoice worker'
# command instead).
#SOLIDINVOICE_MESSENGER_WORKERS=1
# ------------------------------------------------------------------
# Application
# ------------------------------------------------------------------
# Application environment. Change to "dev" only for local development.
#SOLIDINVOICE_ENV=prod
# Enable debug mode (0 or 1). Never enable in production.
#SOLIDINVOICE_DEBUG=0
# Configuration directory — stores generated secrets, OAuth keys, and the
# SQLite database (when no external database is configured).
SOLIDINVOICE_CONFIG_DIR=/etc/solidinvoice
# Installation type identifier used for telemetry when opted in.
SOLIDINVOICE_INSTALL_TYPE=proxmox-community-scripts
# Skip the ASCII art / URL summary printed on startup.
SOLIDINVOICE_SKIP_INTRO=1
# Log format: "json" for structured logs (default for systemd), "console" for human-readable.
SOLIDINVOICE_LOG_FORMAT=json
# ------------------------------------------------------------------
# Database
# ------------------------------------------------------------------
# Database connection URL. Defaults to SQLite stored in SOLIDINVOICE_CONFIG_DIR
# when not set. Supported drivers: mysql, postgresql, sqlite.
#SOLIDINVOICE_DATABASE_URL=mysql://user:password@127.0.0.1:3306/solidinvoice
# ------------------------------------------------------------------
# Email
# ------------------------------------------------------------------
# Outbound mail transport DSN. Overrides the transport configured in the UI.
# See https://symfony.com/doc/current/mailer.html for DSN formats.
#SOLIDINVOICE_MAILER_DSN=smtp://user:password@localhost:25
# From address used for all outgoing emails. Overrides the address configured in the UI.
#SOLIDINVOICE_MAILER_SENDER=SolidInvoice <noreply@example.com>
# ------------------------------------------------------------------
# Async messaging
# ------------------------------------------------------------------
# Messenger transport DSN. Defaults to the database (doctrine) queue.
#SOLIDINVOICE_MESSENGER_DSN=doctrine://default?queue_name=async
# ------------------------------------------------------------------
# Search (optional)
# ------------------------------------------------------------------
# Meilisearch instance for full-text search. Leave blank to disable.
#SOLIDINVOICE_MEILISEARCH_URL=http://localhost:7700
#SOLIDINVOICE_MEILISEARCH_API_KEY=
# ------------------------------------------------------------------
# Localisation
# ------------------------------------------------------------------
# Default locale for the application interface (e.g. en, fr, de, nl).
#SOLIDINVOICE_LOCALE=en
# ------------------------------------------------------------------
# User registration
# ------------------------------------------------------------------
# Allow visitors to create their own accounts (0 = disabled, 1 = enabled).
#SOLIDINVOICE_ALLOW_REGISTRATION=0
# ------------------------------------------------------------------
# Monitoring (optional)
# ------------------------------------------------------------------
# Sentry DSN for error and performance monitoring.
#SOLIDINVOICE_SENTRY_DSN=
# Expose a Prometheus metrics endpoint on a dedicated port.
#SOLIDINVOICE_ENABLE_METRICS=1
#SOLIDINVOICE_METRICS_PORT=9090
EOF
chmod 640 /etc/solidinvoice/solidinvoice.env
msg_ok "Configured SolidInvoice"
msg_info "Creating Service"
cat <<'EOF' >/etc/systemd/system/solidinvoice.service
[Unit]
Description=SolidInvoice
Documentation=https://solidinvoice.co/docs
After=network.target
[Service]
Type=exec
User=root
WorkingDirectory=/var/lib/solidinvoice
ExecStart=/usr/bin/solidinvoice run
EnvironmentFile=/etc/solidinvoice/solidinvoice.env
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now solidinvoice
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc