Compare commits

...

19 Commits

Author SHA1 Message Date
MickLesk
9ecb055085 bambuddy: force asyncio loop, uvloop breaks camera proxy handlers 2026-08-31 08:58:50 +02:00
community-scripts-pr-app[bot]
ef89bd76f0 Update CHANGELOG.md (#16897)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-31 06:50:01 +00:00
CanbiZ (MickLesk)
97c00113be ntopng: use ntop.org's documented apt repo per Debian codename, not always apt-stable (#16862) 2026-08-31 08:49:57 +02:00
community-scripts-pr-app[bot]
a03866e79a Update CHANGELOG.md (#16896)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-31 06:49:51 +00:00
CanbiZ (MickLesk)
fd13dff335 Refactor: OpenGist (#16861) 2026-08-31 08:49:37 +02:00
community-scripts-pr-app[bot]
426244e384 Update CHANGELOG.md (#16895)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-31 06:49:28 +00:00
community-scripts-pr-app[bot]
27cb42d423 Update CHANGELOG.md (#16894)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-31 06:49:06 +00:00
CanbiZ (MickLesk)
3921f056f4 node-red: remove --unsafe-perm flag (#16859) 2026-08-31 08:49:03 +02:00
CanbiZ (MickLesk)
35b378761c directus: add build-essential dependency (#16858) 2026-08-31 08:48:43 +02:00
community-scripts-pr-app[bot]
c47b60e275 Update CHANGELOG.md (#16886)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-30 18:55:27 +00:00
push-app-to-main[bot]
dcf355097a SolidInvoice (#16869) 2026-08-30 20:55:03 +02:00
community-scripts-pr-app[bot]
fa45c6b28a Update CHANGELOG.md (#16885)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-30 18:54:28 +00:00
push-app-to-main[bot]
521fde3284 Super-Productivity (#16870) 2026-08-30 20:54:10 +02:00
community-scripts-pr-app[bot]
40373f17ae Update CHANGELOG.md (#16884)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-30 18:54:01 +00:00
community-scripts-pr-app[bot]
8e729543a0 Update CHANGELOG.md (#16883)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-30 18:53:37 +00:00
push-app-to-main[bot]
21b98a4d4d Defguard (#16871) 2026-08-30 20:53:34 +02:00
push-app-to-main[bot]
e6687be6e5 OpenBao (#16872) 2026-08-30 20:53:12 +02:00
community-scripts-pr-app[bot]
cd72073434 Update CHANGELOG.md (#16877)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-30 10:53:09 +00:00
CanbiZ (MickLesk)
c152912552 general: remove gitea links overall (#16863)
* docker-vm, pve-privilege-converter: source from GitHub raw instead of gitea mirror

* docker-vm, pve-privilege-converter, vm-core.func: source from GitHub raw instead of gitea mirror
2026-08-30 12:52:43 +02:00
28 changed files with 735 additions and 27 deletions

View File

@@ -530,8 +530,34 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-08-31
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- node-red: remove --unsafe-perm flag [@MickLesk](https://github.com/MickLesk) ([#16859](https://github.com/community-scripts/ProxmoxVE/pull/16859))
- directus: add build-essential dependency [@MickLesk](https://github.com/MickLesk) ([#16858](https://github.com/community-scripts/ProxmoxVE/pull/16858))
- #### 🔧 Refactor
- Refactor: OpenGist [@MickLesk](https://github.com/MickLesk) ([#16861](https://github.com/community-scripts/ProxmoxVE/pull/16861))
## 2026-08-30
### 🆕 New Scripts
- SolidInvoice ([#16869](https://github.com/community-scripts/ProxmoxVE/pull/16869))
- Super-Productivity ([#16870](https://github.com/community-scripts/ProxmoxVE/pull/16870))
- Defguard ([#16871](https://github.com/community-scripts/ProxmoxVE/pull/16871))
- OpenBao ([#16872](https://github.com/community-scripts/ProxmoxVE/pull/16872))
### 🚀 Updated Scripts
- #### 🔧 Refactor
- general: remove gitea links overall [@MickLesk](https://github.com/MickLesk) ([#16863](https://github.com/community-scripts/ProxmoxVE/pull/16863))
## 2026-08-29
### 📚 Documentation

View File

@@ -1,5 +1,7 @@
#!/usr/bin/env bash
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/build.func)
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Adrian-RDA
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
@@ -62,6 +64,11 @@ function update_script() {
restore_backup
if ! grep -q -- '--loop asyncio' /etc/systemd/system/bambuddy.service; then
sed -i 's|^ExecStart=.*|ExecStart=/opt/bambuddy/.venv/bin/uvicorn backend.app.main:app --host 0.0.0.0 --port 8000 --loop asyncio|' /etc/systemd/system/bambuddy.service
systemctl daemon-reload
fi
msg_info "Starting Service"
systemctl start bambuddy
msg_ok "Started Service"

54
ct/defguard.sh Normal file
View File

@@ -0,0 +1,54 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/DefGuard/defguard
APP="Defguard"
var_tags="${var_tags:-vpn;wireguard;sso}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /etc/defguard/core.conf ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
msg_info "Updating Defguard"
$STD apt update
$STD apt install -y defguard defguard-proxy
msg_ok "Updated Defguard"
msg_info "Restarting Services"
systemctl restart defguard defguard-proxy
msg_ok "Restarted Services"
msg_ok "Updated successfully!"
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}"

View File

@@ -41,6 +41,8 @@ function update_script() {
/opt/directus/uploads \
/opt/directus/extensions
ensure_dependencies build-essential
msg_info "Updating Directus"
cd /opt/directus
$STD npm install --omit=dev "directus@${CHECK_UPDATE_RELEASE#v}"

6
ct/headers/defguard Normal file
View File

@@ -0,0 +1,6 @@
____ ____ __
/ __ \___ / __/___ ___ ______ __________/ /
/ / / / _ \/ /_/ __ `/ / / / __ `/ ___/ __ /
/ /_/ / __/ __/ /_/ / /_/ / /_/ / / / /_/ /
/_____/\___/_/ \__, /\__,_/\__,_/_/ \__,_/
/____/

6
ct/headers/openbao Normal file
View File

@@ -0,0 +1,6 @@
____ ____
/ __ \____ ___ ____ / __ )____ _____
/ / / / __ \/ _ \/ __ \/ __ / __ `/ __ \
/ /_/ / /_/ / __/ / / / /_/ / /_/ / /_/ /
\____/ .___/\___/_/ /_/_____/\__,_/\____/
/_/

6
ct/headers/solidinvoice Normal file
View File

@@ -0,0 +1,6 @@
_____ ___ ______ _
/ ___/____ / (_)___/ / _/___ _ ______ (_)_______
\__ \/ __ \/ / / __ // // __ \ | / / __ \/ / ___/ _ \
___/ / /_/ / / / /_/ // // / / / |/ / /_/ / / /__/ __/
/____/\____/_/_/\__,_/___/_/ /_/|___/\____/_/\___/\___/

View File

@@ -0,0 +1,6 @@
_____ ____ __ __ _ _ __
/ ___/__ ______ ___ _____ / __ \_________ ____/ /_ _______/ /_(_) __(_) /___ __
\__ \/ / / / __ \/ _ \/ ___/_____/ /_/ / ___/ __ \/ __ / / / / ___/ __/ / | / / / __/ / / /
___/ / /_/ / /_/ / __/ / /_____/ ____/ / / /_/ / /_/ / /_/ / /__/ /_/ /| |/ / / /_/ /_/ /
/____/\__,_/ .___/\___/_/ /_/ /_/ \____/\__,_/\__,_/\___/\__/_/ |___/_/\__/\__, /
/_/ /____/

View File

@@ -49,7 +49,7 @@ update_deb_based() {
msg_ok "Stopped Service"
msg_info "Updating Node-Red"
$STD npm install -g --unsafe-perm node-red
$STD npm install -g node-red
msg_ok "Updated Node-Red"
msg_info "Starting Service"
@@ -106,7 +106,7 @@ update_alpine() {
msg_ok "Updated Node.js and npm"
msg_info "Updating Node-RED"
$STD npm install -g --unsafe-perm node-red
$STD npm install -g node-red
msg_ok "Updated Node-RED"
msg_info "Restarting Node-RED"

View File

@@ -1,5 +1,7 @@
#!/usr/bin/env bash
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/build.func)
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE

68
ct/openbao.sh Executable file
View File

@@ -0,0 +1,68 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Marc Went (Dunky13)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://openbao.org/
APP="OpenBao"
var_tags="${var_tags:-security;secrets}"
var_cpu="${var_cpu:-1}"
var_ram="${var_ram:-1024}"
var_disk="${var_disk:-4}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/bin/bao ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "openbao" "openbao/openbao"; then
msg_info "Stopping Service"
systemctl stop openbao
msg_ok "Stopped Service"
create_backup /etc/openbao
DPKG_FORCE_CONFOLD=1 fetch_and_deploy_gh_release "openbao" "openbao/openbao" "binary" "latest" "/opt/openbao" "openbao_*_linux_$(arch_resolve).deb"
restore_backup
msg_info "Starting Service"
$STD systemctl daemon-reload
systemctl start openbao
msg_ok "Started Service"
for _ in {1..15}; do
BAO_ADDR=https://127.0.0.1:8200 BAO_SKIP_VERIFY=true bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null && break
sleep 2
done
if ! BAO_ADDR=https://127.0.0.1:8200 BAO_SKIP_VERIFY=true bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null; then
msg_error "OpenBao did not unseal within 30 seconds"
exit 1
fi
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW} Access it using the following URL:${CL}"
echo -e "${TAB}${GATEWAY}${BGN}https://${IP}:8200${CL}"

View File

@@ -1,5 +1,7 @@
#!/usr/bin/env bash
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/build.func)
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Jonathan (jd-apprentice)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
@@ -33,15 +35,11 @@ function update_script() {
systemctl stop opengist
msg_ok "Stopped Service"
msg_info "Creating backup"
mv /opt/opengist /opt/opengist-backup
msg_ok "Backup created"
create_backup /opt/opengist/config.yml
fetch_and_deploy_gh_release "opengist" "thomiceli/opengist" "prebuild" "latest" "/opt/opengist" "opengist*linux-$(arch_resolve).tar.gz"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "opengist" "thomiceli/opengist" "prebuild" "latest" "/opt/opengist" "opengist*linux-$(arch_resolve).tar.gz"
msg_info "Restoring Configuration"
mv /opt/opengist-backup/config.yml /opt/opengist/config.yml
msg_ok "Configuration Restored"
restore_backup
msg_info "Starting Service"
systemctl start opengist

57
ct/solidinvoice.sh Normal file
View File

@@ -0,0 +1,57 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Pierre du Plessis
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/solidinvoice/solidinvoice
APP="SolidInvoice"
var_tags="${var_tags:-invoicing;finance;billing}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-4}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/bin/solidinvoice ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "solidinvoice" "SolidInvoice/SolidInvoice"; then
msg_info "Stopping Service"
systemctl stop solidinvoice
msg_ok "Stopped Service"
fetch_and_deploy_gh_release "solidinvoice" "SolidInvoice/SolidInvoice" "singlefile" "latest" "/usr/bin" "solidinvoice-linux-$(arch_resolve)"
msg_info "Starting Service"
systemctl start solidinvoice
msg_ok "Started Service"
msg_ok "Updated Successfully"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8765${CL}"

66
ct/super-productivity.sh Normal file
View File

@@ -0,0 +1,66 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://super-productivity.com/
APP="Super-Productivity"
var_tags="${var_tags:-productivity;todo}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-6144}"
var_disk="${var_disk:-12}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-no}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/super-productivity ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "super-productivity" "super-productivity/super-productivity"; then
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "super-productivity" "super-productivity/super-productivity" "tarball"
msg_info "Building Web App"
cd /opt/super-productivity
export HUSKY=0
export UNSPLASH_KEY=DUMMY_UNSPLASH_KEY
export UNSPLASH_CLIENT_ID=DUMMY_UNSPLASH_CLIENT_ID
export NODE_OPTIONS="--max-old-space-size=4096"
$STD git config --global url."https://github.com/".insteadOf ssh://git@github.com/
$STD npm ci
$STD npm run buildFrontend:prodWeb
msg_ok "Built Web App"
msg_info "Deploying Web App"
rm -rf /var/www/html/*
cp -r /opt/super-productivity/dist/browser/. /var/www/html/
systemctl reload nginx
msg_ok "Deployed Web App"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"

View File

@@ -52,7 +52,7 @@ After=network.target
[Service]
Type=simple
WorkingDirectory=/opt/bambuddy
ExecStart=/opt/bambuddy/.venv/bin/uvicorn backend.app.main:app --host 0.0.0.0 --port 8000
ExecStart=/opt/bambuddy/.venv/bin/uvicorn backend.app.main:app --host 0.0.0.0 --port 8000 --loop asyncio
Restart=on-failure
RestartSec=5

View File

@@ -0,0 +1,78 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/DefGuard/defguard
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
PG_VERSION="17" setup_postgresql
PG_DB_NAME="defguard" PG_DB_USER="defguard" setup_postgresql_db
setup_deb822_repo \
"defguard" \
"https://apt.defguard.net/defguard.asc" \
"https://apt.defguard.net" \
"$(get_os_info codename)" \
"release-2.0"
msg_info "Installing Defguard"
$STD apt install -y defguard
msg_ok "Installed Defguard"
msg_info "Configuring Defguard"
DEFGUARD_ADMIN_PASSWORD=$(openssl rand -base64 18)
cat <<EOF >/etc/defguard/core.conf
DEFGUARD_DB_HOST=localhost
DEFGUARD_DB_PORT=5432
DEFGUARD_DB_NAME=defguard
DEFGUARD_DB_USER=defguard
DEFGUARD_DB_PASSWORD=${PG_DB_PASS}
DEFGUARD_URL=http://${LOCAL_IP}:8000
DEFGUARD_HTTP_PORT=8000
DEFGUARD_GRPC_PORT=50055
DEFGUARD_DEFAULT_ADMIN_PASSWORD=${DEFGUARD_ADMIN_PASSWORD}
DEFGUARD_COOKIE_INSECURE=true
DEFGUARD_LOG_LEVEL=info
EOF
chown root:defguard /etc/defguard/core.conf
chmod 640 /etc/defguard/core.conf
systemctl restart defguard
msg_ok "Configured Defguard"
msg_info "Installing Defguard Edge"
$STD apt install -y defguard-proxy
mkdir -p /etc/defguard/certs
cat <<EOF >/etc/defguard/proxy.toml
# Defguard Edge (proxy) configuration
# Apply changes with: systemctl restart defguard-proxy
# Port the API/enrollment HTTP server listens on
http_port = 8080
# Port the HTTPS server listens on (used after Core provisions TLS)
https_port = 8443
# Port the gRPC server listens on. Core connects here to adopt and manage the Edge.
grpc_port = 50051
# Directory where adoption-provisioned mTLS certificates are stored
cert_dir = "/etc/defguard/certs"
log_level = "info"
rate_limit_per_second = 0
rate_limit_burst = 0
EOF
chown -R defguard:defguard /etc/defguard/certs /etc/defguard/proxy.toml
systemctl enable -q --now defguard-proxy
msg_ok "Installed Defguard Edge"
motd_ssh
customize
cleanup_lxc

View File

@@ -13,6 +13,10 @@ setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y build-essential
msg_ok "Installed Dependencies"
NODE_VERSION="22" setup_nodejs
PG_VERSION="17" setup_postgresql
PG_DB_NAME="directus" PG_DB_USER="directus" setup_postgresql_db

View File

@@ -23,7 +23,7 @@ setup_deb_based() {
NODE_VERSION="22" setup_nodejs
msg_info "Installing Node-Red"
$STD npm install -g --unsafe-perm node-red
$STD npm install -g node-red
echo "journalctl -f -n 100 -u nodered -o cat" >/usr/bin/node-red-log
chmod +x /usr/bin/node-red-log
echo "systemctl stop nodered" >/usr/bin/node-red-stop
@@ -71,7 +71,7 @@ setup_alpine() {
msg_ok "Created Node-RED User"
msg_info "Installing Node-RED"
$STD npm install -g --unsafe-perm node-red
$STD npm install -g node-red
msg_ok "Installed Node-RED"
msg_info "Creating /home/nodered"

View File

@@ -13,7 +13,15 @@ setting_up_container
network_check
update_os
fetch_and_deploy_from_url "https://packages.ntop.org/apt-stable/$(get_os_info codename)/all/apt-ntop-stable.deb" ""
NTOP_CODENAME="$(get_os_info codename)"
case "$NTOP_CODENAME" in
bookworm | trixie)
fetch_and_deploy_from_url "https://packages.ntop.org/apt/${NTOP_CODENAME}/all/apt-ntop.deb" ""
;;
*)
fetch_and_deploy_from_url "https://packages.ntop.org/apt-stable/${NTOP_CODENAME}/all/apt-ntop-stable.deb" ""
;;
esac
msg_info "Installing ntopng"
$STD apt update

67
install/openbao-install.sh Executable file
View File

@@ -0,0 +1,67 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Marc Went (Dunky13)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://openbao.org/
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
fetch_and_deploy_gh_release "openbao" "openbao/openbao" "binary" "latest" "/opt/openbao" "openbao_*_linux_$(arch_resolve).deb"
msg_info "Configuring CLI Environment"
cat <<EOF >/etc/profile.d/openbao.sh
export BAO_ADDR=https://127.0.0.1:8200
export BAO_SKIP_VERIFY=true
EOF
source /etc/profile.d/openbao.sh
msg_ok "Configured CLI Environment"
msg_info "Starting OpenBao"
systemctl enable -q --now openbao
for _ in {1..30}; do
curl -fsSk -o /dev/null "https://127.0.0.1:8200/v1/sys/seal-status" && break
sleep 2
done
msg_ok "Started OpenBao"
msg_info "Initializing OpenBao"
(
umask 077
cat <<'EOF' >/etc/openbao/openbao-init.json
EOF
)
bao operator init -key-shares=1 -key-threshold=1 -format=json >/etc/openbao/openbao-init.json
chmod 600 /etc/openbao/openbao.env
chown root:root /etc/openbao/openbao.env
cat <<EOF >>/etc/openbao/openbao.env
BAO_ADDR=https://127.0.0.1:8200
BAO_SKIP_VERIFY=true
BAO_UNSEAL_KEY=$(jq -r '.unseal_keys_b64[0]' /etc/openbao/openbao-init.json)
BAO_ROOT_TOKEN=$(jq -r '.root_token' /etc/openbao/openbao-init.json)
EOF
rm -f /etc/openbao/openbao-init.json
msg_ok "Initialized OpenBao"
msg_info "Enabling Auto-Unseal"
mkdir -p /etc/systemd/system/openbao.service.d
cat <<'EOF' >/etc/systemd/system/openbao.service.d/unseal.conf
[Service]
ExecStartPost=-/usr/bin/bao operator unseal ${BAO_UNSEAL_KEY}
EOF
systemctl daemon-reload
systemctl restart openbao
for _ in {1..15}; do
bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null && break
sleep 2
done
msg_ok "Enabled Auto-Unseal"
motd_ssh
customize
cleanup_lxc

View File

@@ -0,0 +1,190 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Pierre du Plessis
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/solidinvoice/solidinvoice
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Creating Directories"
mkdir -p /etc/solidinvoice /var/lib/solidinvoice
msg_ok "Created Directories"
fetch_and_deploy_gh_release "solidinvoice" "SolidInvoice/SolidInvoice" "singlefile" "latest" "/usr/bin" "solidinvoice-linux-$(arch_resolve)"
msg_info "Configuring SolidInvoice"
cat <<'EOF' >/etc/solidinvoice/solidinvoice.env
# SolidInvoice environment configuration
# This file is sourced by the systemd service unit.
# CLI flags always take precedence over values set here.
# ------------------------------------------------------------------
# Network
# ------------------------------------------------------------------
# Port to listen on (default: 8765)
#SOLIDINVOICE_PORT=8765
# IP address to bind to (default: auto-detected outbound IP)
#SOLIDINVOICE_SERVER_IP=0.0.0.0
# Domain name — required when using Let's Encrypt or custom certificates.
# When set, the application binds to https://<domain> instead of an IP.
#SOLIDINVOICE_DOMAIN=
# Bind the bundled webserver to every hostname so it answers regardless of the
# Host header — required behind a reverse proxy that forwards the original domain.
SOLIDINVOICE_DOCKER=true
# ------------------------------------------------------------------
# HTTPS / TLS
# ------------------------------------------------------------------
# Disable HTTPS and serve plain HTTP. Set to 1 when running behind a
# reverse proxy (nginx, Caddy, Traefik, etc.) that handles TLS termination.
# Remove or set to 0 when you want the application to manage its own certificates.
SOLIDINVOICE_DISABLE_HTTPS=1
# Enable automatic Let's Encrypt certificates (requires SOLIDINVOICE_DOMAIN).
# Incompatible with SOLIDINVOICE_DISABLE_HTTPS=1.
#SOLIDINVOICE_LETS_ENCRYPT=1
# Paths to a custom TLS certificate and private key (requires SOLIDINVOICE_DOMAIN).
# Incompatible with SOLIDINVOICE_DISABLE_HTTPS=1 and SOLIDINVOICE_LETS_ENCRYPT=1.
#SOLIDINVOICE_SSL_CERT=/etc/ssl/certs/solidinvoice.crt
#SOLIDINVOICE_SSL_KEY=/etc/ssl/private/solidinvoice.key
# ------------------------------------------------------------------
# Performance
# ------------------------------------------------------------------
# Enable FrankenPHP worker mode for improved performance (keeps PHP workers
# alive between requests). Recommended for high-traffic deployments.
# Set to 1 to enable.
#FRANKENPHP_WORKER_MODE=1
# Number of FrankenPHP worker threads when worker mode is enabled (default: 2).
#SOLIDINVOICE_WORKER_THREADS=2
# Number of background messenger worker processes (default: 1).
# Set to 0 to disable built-in workers (use the dedicated 'solidinvoice worker'
# command instead).
#SOLIDINVOICE_MESSENGER_WORKERS=1
# ------------------------------------------------------------------
# Application
# ------------------------------------------------------------------
# Application environment. Change to "dev" only for local development.
#SOLIDINVOICE_ENV=prod
# Enable debug mode (0 or 1). Never enable in production.
#SOLIDINVOICE_DEBUG=0
# Configuration directory — stores generated secrets, OAuth keys, and the
# SQLite database (when no external database is configured).
SOLIDINVOICE_CONFIG_DIR=/etc/solidinvoice
# Installation type identifier used for telemetry when opted in.
SOLIDINVOICE_INSTALL_TYPE=proxmox-community-scripts
# Skip the ASCII art / URL summary printed on startup.
SOLIDINVOICE_SKIP_INTRO=1
# Log format: "json" for structured logs (default for systemd), "console" for human-readable.
SOLIDINVOICE_LOG_FORMAT=json
# ------------------------------------------------------------------
# Database
# ------------------------------------------------------------------
# Database connection URL. Defaults to SQLite stored in SOLIDINVOICE_CONFIG_DIR
# when not set. Supported drivers: mysql, postgresql, sqlite.
#SOLIDINVOICE_DATABASE_URL=mysql://user:password@127.0.0.1:3306/solidinvoice
# ------------------------------------------------------------------
# Email
# ------------------------------------------------------------------
# Outbound mail transport DSN. Overrides the transport configured in the UI.
# See https://symfony.com/doc/current/mailer.html for DSN formats.
#SOLIDINVOICE_MAILER_DSN=smtp://user:password@localhost:25
# From address used for all outgoing emails. Overrides the address configured in the UI.
#SOLIDINVOICE_MAILER_SENDER=SolidInvoice <noreply@example.com>
# ------------------------------------------------------------------
# Async messaging
# ------------------------------------------------------------------
# Messenger transport DSN. Defaults to the database (doctrine) queue.
#SOLIDINVOICE_MESSENGER_DSN=doctrine://default?queue_name=async
# ------------------------------------------------------------------
# Search (optional)
# ------------------------------------------------------------------
# Meilisearch instance for full-text search. Leave blank to disable.
#SOLIDINVOICE_MEILISEARCH_URL=http://localhost:7700
#SOLIDINVOICE_MEILISEARCH_API_KEY=
# ------------------------------------------------------------------
# Localisation
# ------------------------------------------------------------------
# Default locale for the application interface (e.g. en, fr, de, nl).
#SOLIDINVOICE_LOCALE=en
# ------------------------------------------------------------------
# User registration
# ------------------------------------------------------------------
# Allow visitors to create their own accounts (0 = disabled, 1 = enabled).
#SOLIDINVOICE_ALLOW_REGISTRATION=0
# ------------------------------------------------------------------
# Monitoring (optional)
# ------------------------------------------------------------------
# Sentry DSN for error and performance monitoring.
#SOLIDINVOICE_SENTRY_DSN=
# Expose a Prometheus metrics endpoint on a dedicated port.
#SOLIDINVOICE_ENABLE_METRICS=1
#SOLIDINVOICE_METRICS_PORT=9090
EOF
chmod 640 /etc/solidinvoice/solidinvoice.env
msg_ok "Configured SolidInvoice"
msg_info "Creating Service"
cat <<'EOF' >/etc/systemd/system/solidinvoice.service
[Unit]
Description=SolidInvoice
Documentation=https://solidinvoice.co/docs
After=network.target
[Service]
Type=exec
User=root
WorkingDirectory=/var/lib/solidinvoice
ExecStart=/usr/bin/solidinvoice run
EnvironmentFile=/etc/solidinvoice/solidinvoice.env
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now solidinvoice
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc

View File

@@ -0,0 +1,61 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://super-productivity.com/
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
nginx \
git
msg_ok "Installed Dependencies"
NODE_VERSION="22" setup_nodejs
fetch_and_deploy_gh_release "super-productivity" "super-productivity/super-productivity" "tarball"
msg_info "Building Web App"
cd /opt/super-productivity
export HUSKY=0
export UNSPLASH_KEY=DUMMY_UNSPLASH_KEY
export UNSPLASH_CLIENT_ID=DUMMY_UNSPLASH_CLIENT_ID
export NODE_OPTIONS="--max-old-space-size=4096"
$STD git config --global url."https://github.com/".insteadOf ssh://git@github.com/
$STD npm ci
$STD npm run buildFrontend:prodWeb
msg_ok "Built Web App"
msg_info "Deploying Web App"
cp -r /opt/super-productivity/dist/browser/. /var/www/html/
msg_ok "Deployed Web App"
msg_info "Configuring Nginx"
cat <<'EOF' >/etc/nginx/sites-available/super-productivity.conf
server {
listen 80 default_server;
server_name _;
root /var/www/html;
index index.html;
location / {
try_files $uri $uri/ /index.html;
}
}
EOF
ln -sf /etc/nginx/sites-available/super-productivity.conf /etc/nginx/sites-enabled/super-productivity.conf
rm -f /etc/nginx/sites-enabled/default
systemctl reload nginx
msg_ok "Configured Nginx"
motd_ssh
customize
cleanup_lxc

View File

@@ -136,7 +136,7 @@ network_check() {
fi
# DNS resolution checks for GitHub-related domains
GIT_HOSTS=("github.com" "raw.githubusercontent.com" "api.github.com" "git.community-scripts.org")
GIT_HOSTS=("github.com" "raw.githubusercontent.com" "api.github.com")
GIT_STATUS="Git DNS:"
DNS_FAILED=false

View File

@@ -10,10 +10,6 @@
# including colors, formatting, validation checks, message output, and
# execution helpers used throughout the Community-Scripts ecosystem.
#
# Usage:
# source <(curl -fsSL https://git.community-scripts.org/.../core.func)
# load_functions
#
# ==============================================================================
[[ -n "${_CORE_FUNC_LOADED:-}" ]] && return

View File

@@ -211,7 +211,7 @@ network_check() {
fi
# DNS resolution checks for GitHub-related domains (IPv4 and/or IPv6)
GIT_HOSTS=("github.com" "raw.githubusercontent.com" "api.github.com" "git.community-scripts.org")
GIT_HOSTS=("github.com" "raw.githubusercontent.com" "api.github.com")
GIT_STATUS="Git DNS:"
DNS_FAILED=false

View File

@@ -14,7 +14,7 @@ declare -A MSG_INFO_SHOWN
[[ -n "${_CORE_FUNC_LOADED:-}" ]] && return
_CORE_FUNC_LOADED=1
COMMUNITY_SCRIPTS_URL="${COMMUNITY_SCRIPTS_URL:-https://git.community-scripts.org/community-scripts/ProxmoxVE/raw/branch/main}"
COMMUNITY_SCRIPTS_URL="${COMMUNITY_SCRIPTS_URL:-https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main}"
load_api_functions() {
if ! declare -f post_to_api_vm >/dev/null 2>&1; then

View File

@@ -10,7 +10,7 @@ if ! command -v curl >/dev/null 2>&1; then
apt-get update >/dev/null 2>&1
apt-get install -y curl >/dev/null 2>&1
fi
source <(curl -fsSL https://git.community-scripts.org/community-scripts/ProxmoxVE/raw/branch/main/misc/core.func)
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/core.func)
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/api.func) 2>/dev/null || true
load_functions
declare -f init_tool_telemetry &>/dev/null && init_tool_telemetry "pve-privilege-converter" "pve"

View File

@@ -8,9 +8,9 @@
# Docker VM - Creates a Docker-ready Virtual Machine
# ==============================================================================
source <(curl -fsSL https://git.community-scripts.org/community-scripts/ProxmoxVE/raw/branch/main/misc/api.func) 2>/dev/null
source <(curl -fsSL https://git.community-scripts.org/community-scripts/ProxmoxVE/raw/branch/main/misc/vm-core.func) 2>/dev/null
source <(curl -fsSL https://git.community-scripts.org/community-scripts/ProxmoxVE/raw/branch/main/misc/cloud-init.func) 2>/dev/null || true
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/api.func)
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/vm-core.func)
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/cloud-init.func) || true
# ==============================================================================
# SCRIPT VARIABLES