Compare commits

..
Author SHA1 Message Date
MickLesk 66d09bff36 FileBrowser Quantum: migrate the config and database to v2
v2.0.0 reads the config strictly and stops at the v1 keys the addon
wrote (server.port, conditionals, indexingIntervalMinutes). It also only
imports the old BoltDB when server.database.migrateFrom names it and no
database.db is left in the working directory. The update now rewrites
the config, renames the database and points migrateFrom at it, keeping
a copy of the v1 config. New installs write the v2 layout.
2026-10-09 21:15:21 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 14cd4cb667 Update CHANGELOG.md (#17814)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 18:44:20 +00:00
Sim Kai Long 63cf41174f OpenCloud: allow OpenCloud to embed Collabora on 26.04.4 (#17810)
Collabora 26.04.4 ignores frame-ancestors set in content_security_policy,
so the editor iframe is blocked. Use net.frame_ancestors (as
opencloud-compose does) on install, and add it on update when missing.
2026-10-09 20:43:49 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] daa4daa927 Update CHANGELOG.md (#17807)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 10:08:36 +00:00
CanbiZ (MickLesk) 227526cf55 Immich: survive an interrupted update and a failing ML build (#17798)
* Immich: survive an interrupted update and a failing ML build

An update cancelled midway leaves /opt/immich/app empty, and the next run
died at once on cd /opt/immich/app/bin to enable maintenance mode (#17796).
Maintenance mode is now only toggled when immich-admin exists.

uv sync fetching the ml-models git dependency failed with "Could not resolve
host" behind DNS filters such as AdGuard while DNS itself worked (#17797);
running uv one download at a time got through. Retries now do that.

If machine learning still cannot be built, the update no longer stops with
maintenance mode on and every service down: it finishes, starts the web
service, puts the previous version back into ~/.immich so the next update
retries, and exits with an error. Updates are also announced as taking
5-15 minutes, since the first report came from cancelling one that looked
stuck.

* Immich: point immich-ml at the moved ml_start.sh and clear failed units

The update moves ml_start.sh into app/machine-learning, but only rewrote
immich-web's ExecStart, so older containers kept starting ML from
/opt/immich/ml_start.sh and failed with 203/EXEC. Rewrite immich-ml the same
way. A crash loop before the update can also leave both units rate-limited,
which makes the final restart fail; reset them first.
2026-10-09 12:08:08 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] d271571ff7 Update CHANGELOG.md (#17806)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:32:19 +00:00
push-app-to-main[bot]andCanbiZ 7100f6521c FoldingAtHome (#17799)
* Add foldingathome (ct)

* Clean up comments in foldingathome.sh

Removed comments about Git tags and installation process.

* Clean up comments in foldingathome-install.sh

Removed outdated comments regarding package installation and configuration.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:31:48 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 387b8bf542 Update CHANGELOG.md (#17805)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:30:17 +00:00
push-app-to-main[bot]andCanbiZ a56510bf57 LocalAI (#17801)
* Add localai (ct)

* Refactor localai.sh to clean up comments and exports

Removed comments regarding ARM64 support and clarified install script export variables.

* Refactor variable assignments and clean up comments

Rearranged variable assignments and removed comments about SQLite and PostgreSQL.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:29:50 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 05bc39e623 Update CHANGELOG.md (#17804)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 06:27:55 +00:00
push-app-to-main[bot]andCanbiZ 6db1ebe154 Tvheadend (#17800)
* Add tvheadend (ct)

* Update Tvheadend installation messages in script

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-10-09 08:27:27 +02:00
13 changed files with 428 additions and 130 deletions
+18
View File
@@ -559,6 +559,24 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-10-09
### 🆕 New Scripts
- FoldingAtHome ([#17799](https://github.com/community-scripts/ProxmoxVE/pull/17799))
- LocalAI ([#17801](https://github.com/community-scripts/ProxmoxVE/pull/17801))
- Tvheadend ([#17800](https://github.com/community-scripts/ProxmoxVE/pull/17800))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
## 2026-10-08
### 🆕 New Scripts
+52
View File
@@ -0,0 +1,52 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ) | Co-Author: 007hacky007
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/FoldingAtHome/fah-client-bastet
APP="FoldingAtHome"
var_tags="${var_tags:-science;distributed-computing}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_gpu="${var_gpu:-yes}"
var_unprivileged="${var_unprivileged:-1}"
export var_fah_token="${var_fah_token:-}"
export var_fah_machine_name="${var_fah_machine_name:-}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/bin/fah-client ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
fetch_and_deploy_from_url "https://download.foldingathome.org/releases/public/fah-client/$(arch_resolve "debian-10-64bit" "debian-stable-arm64")/release/latest.deb"
msg_ok "Folding@home is at $(dpkg-query -W -f='${Version}' fah-client)"
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Manage it from the Folding@home Web Control:${CL}"
echo -e "${GATEWAY}${BGN}https://app.foldingathome.org/${CL}"
echo -e "${INFO}${YW}The client starts paused - press Fold once the machine shows up in your account${CL}"
echo -e "${INFO}${YW}Account token and machine name are in /etc/fah-client/config.xml${CL}"
+31 -10
View File
@@ -115,7 +115,10 @@ EOF
fi
if check_for_gh_release "Immich" "immich-app/immich" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
if [[ $(cat ~/.immich) > "2.5.1" ]]; then
msg_warn "The update takes 5-15 minutes, do not interrupt it"
PREV_IMMICH="$(cat ~/.immich)"
# An interrupted update leaves app/ empty, so there may be no immich-admin to call.
if [[ "$PREV_IMMICH" > "2.5.1" && -x /opt/immich/app/bin/immich-admin ]]; then
msg_info "Enabling Maintenance Mode"
cd /opt/immich/app/bin
$STD ./immich-admin enable-maintenance-mode || true
@@ -273,12 +276,14 @@ EOF
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Updating Intel OpenVINO machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { ML_FAILED=1; break; }
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
msg_ok "Updated Intel OpenVINO machine-learning"
[[ "${ML_FAILED:-0}" == 1 ]] || patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
[[ "${ML_FAILED:-0}" == 1 ]] || msg_ok "Updated Intel OpenVINO machine-learning"
else
ML_PYTHON="python3.13"
msg_info "Pre-installing Python ${ML_PYTHON} for machine-learning"
@@ -289,12 +294,15 @@ EOF
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Updating machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { ML_FAILED=1; break; }
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
msg_ok "Updated machine-learning"
[[ "${ML_FAILED:-0}" == 1 ]] || msg_ok "Updated machine-learning"
fi
[[ "${ML_FAILED:-0}" == 1 ]] && msg_warn "uv sync failed three times, machine learning was not updated"
cd "$SRC_DIR"
cp -a machine-learning/{ann,immich_ml} "$ML_DIR"
[[ -f "$INSTALL_DIR"/ml_start.sh ]] && mv "$INSTALL_DIR"/ml_start.sh "$ML_DIR"
@@ -345,6 +353,10 @@ EOF
sed -i "s|^ExecStart=.*|ExecStart=${APP_DIR}/bin/start.sh|" /etc/systemd/system/immich-web.service
systemctl daemon-reload
fi
if grep -q "^ExecStart=${INSTALL_DIR}/ml_start.sh" /etc/systemd/system/immich-ml.service; then
sed -i "s|^ExecStart=.*|ExecStart=${ML_DIR}/ml_start.sh|" /etc/systemd/system/immich-ml.service
systemctl daemon-reload
fi
# MickLesk temporary patch for HEIC thumbnail gen
MEDIA_REPO_JS="/opt/immich/app/dist/repositories/media.repository.js"
@@ -366,6 +378,15 @@ EOF
$STD cd -
msg_ok "Disabled Maintenance Mode"
fi
# A crash loop before the update leaves the units rate-limited, and restart would refuse.
systemctl reset-failed immich-ml immich-web 2>/dev/null || true
if [[ "${ML_FAILED:-0}" == 1 ]]; then
systemctl restart immich-web || true
[[ -f /etc/systemd/system/immich-proxy.service ]] && systemctl restart immich-proxy
echo "$PREV_IMMICH" >~/.immich
msg_error "Immich runs, but without machine learning (see the uv output above). Run update again to retry."
exit 1
fi
systemctl restart immich-ml immich-web
[[ -f /etc/systemd/system/immich-proxy.service ]] && systemctl restart immich-proxy
msg_ok "Updated successfully!"
+63
View File
@@ -0,0 +1,63 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Bryan Lieberman (BryanCLieberman)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://localai.io
APP="LocalAI"
var_tags="${var_tags:-ai;llm;api}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-8192}"
var_disk="${var_disk:-30}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_gpu="${var_gpu:-yes}"
var_unprivileged="${var_unprivileged:-1}"
# Values the install script accepts up front
export var_auth="${var_auth:-no}"
export var_api_key="${var_api_key:-}"
export var_port="${var_port:-8080}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/localai ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "localai" "mudler/LocalAI"; then
msg_info "Stopping Service"
systemctl stop localai
msg_ok "Stopped Service"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "localai" "mudler/LocalAI" "singlefile" "latest" "/opt/localai" "local-ai-v*-linux-$(arch_resolve amd64 arm64)"
msg_info "Starting Service"
systemctl start localai
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8080${CL}"
echo -e "${INFO}${YW}Install models from the gallery in the web UI or place GGUF files in /opt/localai_data/models${CL}"
+9
View File
@@ -31,6 +31,15 @@ function update_script() {
exit
fi
# Collabora 26.04.4 ignores frame-ancestors in content_security_policy; outside the release
# check so installs already on the current release get it too
if [[ -f /etc/coolwsd/coolwsd.xml ]] && ! grep -q '<frame_ancestors[^>]*>[^<[:space:]]' /etc/coolwsd/coolwsd.xml; then
msg_info "Allowing OpenCloud to embed Collabora"
$STD sudo -u cool coolconfig set net.frame_ancestors "$(sed -n 's/^OC_URL=//p' /etc/opencloud/opencloud.env)"
systemctl restart coolwsd
msg_ok "Allowed OpenCloud to embed Collabora"
fi
RELEASE="v8.1.0"
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"
+19 -26
View File
@@ -2,12 +2,12 @@
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: fabriziosalmi
# Author: Nicolas Pastorello (opastorello)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/fabriziosalmi/certmate
# Source: https://tvheadend.org/ | Github: https://github.com/tvheadend/tvheadend
APP="CertMate"
var_tags="${var_tags:-ssl;certificates;acme}"
APP="Tvheadend"
var_tags="${var_tags:-media;pvr;tv;dvr}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
@@ -16,6 +16,9 @@ var_version="${var_version:-13}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
export var_admin_user="${var_admin_user:-admin}"
export var_admin_pass="${var_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)}"
header_info "$APP"
variables
color
@@ -26,31 +29,20 @@ function update_script() {
check_container_storage
check_container_resources
if [[ ! -d /opt/certmate ]]; then
if [[ ! -d /var/lib/tvheadend ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "certmate" "fabriziosalmi/certmate"; then
msg_info "Stopping CertMate"
systemctl stop certmate
msg_ok "Stopped CertMate"
msg_info "Updating Tvheadend"
$STD apt update
$STD apt install -y tvheadend
msg_ok "Updated Tvheadend"
PYTHON_VERSION="3.12" setup_uv
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
msg_info "Installing CertMate Dependencies"
cd /opt/certmate
$STD uv venv --python 3.12 /opt/certmate/.venv
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
$STD /opt/certmate/.venv/bin/certbot --version
msg_ok "Installed CertMate Dependencies"
msg_info "Starting CertMate"
systemctl start certmate
msg_ok "Started CertMate"
msg_ok "Updated successfully!"
fi
msg_info "Restarting Service"
systemctl restart tvheadend
msg_ok "Restarted Service"
msg_ok "Updated successfully!"
exit
}
@@ -61,5 +53,6 @@ description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}"
echo -e "${INFO}${YW}The first page creates the admin account and asks for the API token: grep API_BEARER_TOKEN /opt/certmate_data/.env${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:9981${CL}"
echo -e "${INFO}${YW}Admin Username: ${var_admin_user}${CL}"
echo -e "${INFO}${YW}Admin Password: ${var_admin_pass}${CL}"
-69
View File
@@ -1,69 +0,0 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: fabriziosalmi
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/fabriziosalmi/certmate
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
PYTHON_VERSION="3.12" setup_uv
fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
msg_info "Installing CertMate Dependencies"
cd /opt/certmate
$STD uv venv --python 3.12 /opt/certmate/.venv
# requirements.lock is the fully pinned set the official image is built from
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
$STD /opt/certmate/.venv/bin/certbot --version
msg_ok "Installed CertMate Dependencies"
msg_info "Configuring CertMate"
mkdir -p /opt/certmate_data/{certificates,data,backups,logs}
cat <<EOF >/opt/certmate_data/.env
API_BEARER_TOKEN=$(openssl rand -hex 32)
SECRET_KEY=$(openssl rand -hex 32)
CERTMATE_BACKUP_PASSPHRASE=$(openssl rand -hex 32)
BEHIND_PROXY=false
EOF
chmod 600 /opt/certmate_data/.env
msg_ok "Configured CertMate"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/certmate.service
[Unit]
Description=CertMate SSL Certificate Manager
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/certmate
Environment=PATH=/opt/certmate/.venv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
Environment=CERTMATE_CERT_DIR=/opt/certmate_data/certificates
Environment=CERTMATE_DATA_DIR=/opt/certmate_data/data
Environment=CERTMATE_BACKUP_DIR=/opt/certmate_data/backups
Environment=CERTMATE_LOGS_DIR=/opt/certmate_data/logs
Environment=ACME_CHALLENGES_DIR=/opt/certmate_data/data/acme-challenges
EnvironmentFile=/opt/certmate_data/.env
# One worker: the renewal scheduler, sessions and rate limits live in-process
ExecStart=/opt/certmate/.venv/bin/gunicorn --bind 0.0.0.0:8000 --workers 1 --threads 8 --timeout 300 --no-control-socket app:app
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now certmate
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc
+49
View File
@@ -0,0 +1,49 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ) | Co-Author: 007hacky007
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/FoldingAtHome/fah-client-bastet
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
if [[ -z "${var_fah_token:-}" ]]; then
var_fah_token=$(prompt_password "Folding@home account token (Enter to skip):" "" 120)
fi
if [[ -z "${var_fah_machine_name:-}" ]]; then
var_fah_machine_name=$(prompt_input "Folding@home machine name:" "$(hostname)" 60)
fi
if [[ ${#var_fah_machine_name} -gt 64 || "$var_fah_machine_name" == *[\<\>\;\&\'\"]* ]]; then
msg_warn "Machine name must be 1-64 characters without <>;&'\" - using $(hostname)"
var_fah_machine_name=$(hostname)
fi
msg_info "Configuring Folding@home"
mkdir -p /etc/fah-client
cat <<EOF >/etc/fah-client/config.xml
<config>
<account-token v="${var_fah_token}"/>
<machine-name v="${var_fah_machine_name}"/>
</config>
EOF
msg_ok "Configured Folding@home"
fetch_and_deploy_from_url "https://download.foldingathome.org/releases/public/fah-client/$(arch_resolve "debian-10-64bit" "debian-stable-arm64")/release/latest.deb"
setup_hwaccel "fah-client"
# The client detects GPUs only at startup, so restart it after setup_hwaccel.
msg_info "Starting Folding@home"
systemctl enable -q fah-client
safe_service_restart fah-client
msg_ok "Started Folding@home"
motd_ssh
customize
cleanup_lxc
+8 -4
View File
@@ -441,9 +441,11 @@ if [[ -f ~/.openvino ]]; then
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Installing Intel OpenVINO machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
msg_ok "Installed Intel OpenVINO machine-learning"
@@ -457,9 +459,11 @@ else
msg_ok "Pre-installed Python ${ML_PYTHON}"
msg_info "Installing machine-learning"
for attempt in $(seq 1 3); do
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
done
msg_ok "Installed machine-learning"
fi
+92
View File
@@ -0,0 +1,92 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Bryan Lieberman (BryanCLieberman)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://localai.io
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
libgomp1 \
libopenblas0
msg_ok "Installed Dependencies"
setup_hwaccel
var_port="${var_port:-8080}"
var_auth="${var_auth:-no}"
var_api_key="${var_api_key:-}"
if [[ "$var_auth" == "yes" ]]; then
setup_postgresql
PG_DB_NAME="localai" PG_DB_USER="localai" setup_postgresql_db
fi
fetch_and_deploy_gh_release "localai" "mudler/LocalAI" "singlefile" "latest" "/opt/localai" "local-ai-v*-linux-$(arch_resolve amd64 arm64)"
msg_info "Configuring LocalAI"
mkdir -p /opt/localai_data/models /opt/localai_data/backends
cat <<EOF >/opt/localai.env
LOCALAI_ADDRESS=0.0.0.0:${var_port}
LOCALAI_DATA_PATH=/opt/localai_data
LOCALAI_MODELS_PATH=/opt/localai_data/models
LOCALAI_BACKENDS_PATH=/opt/localai_data/backends
LOCALAI_LOG_LEVEL=info
EOF
# LocalAI refuses to start on a wildcard bind with nothing to identify callers,
# and binding the wildcard is what makes the container reachable at all.
if [[ "$var_auth" == "yes" ]]; then
cat <<EOF >>/opt/localai.env
LOCALAI_AUTH=true
LOCALAI_AUTH_DATABASE_URL=postgres://${PG_DB_USER}:${PG_DB_PASS}@localhost/${PG_DB_NAME}
LOCALAI_REGISTRATION_MODE=approval
EOF
fi
# A static key grants admin access on its own, so when it is the only thing
# guarding the API, generate one rather than leaving the server open.
if [[ -z "$var_api_key" && "$var_auth" != "yes" ]]; then
var_api_key="sk-$(openssl rand -hex 24)"
{
echo "LocalAI Credentials"
echo "API Key: ${var_api_key}"
} >>~/localai.creds
fi
if [[ -n "$var_api_key" ]]; then
echo "LOCALAI_API_KEY=${var_api_key}" >>/opt/localai.env
else
echo "#LOCALAI_API_KEY=" >>/opt/localai.env
fi
chmod 600 /opt/localai.env
msg_ok "Configured LocalAI"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/localai.service
[Unit]
Description=LocalAI Server
Wants=network-online.target
After=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/localai
EnvironmentFile=/opt/localai.env
ExecStart=/opt/localai/localai run
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now localai
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc
+1 -1
View File
@@ -207,7 +207,7 @@ EOF
$STD sudo -u cool coolconfig set ssl.enable false
$STD sudo -u cool coolconfig set ssl.termination true
$STD sudo -u cool coolconfig set ssl.ssl_verification true
sed -i "s|-Policy\">|&frame-ancestors https://${OPENCLOUD_FQDN}|" /etc/coolwsd/coolwsd.xml
$STD sudo -u cool coolconfig set net.frame_ancestors "https://${OPENCLOUD_FQDN}"
useradd -r -M -s /usr/sbin/nologin opencloud
chown -R opencloud:opencloud "$CONFIG_DIR" "$DATA_DIR"
sudo -u opencloud opencloud init --config-path "$CONFIG_DIR" --insecure no
+46
View File
@@ -0,0 +1,46 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Nicolas Pastorello (opastorello)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://tvheadend.org/ | Github: https://github.com/tvheadend/tvheadend
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
setup_deb822_repo \
"tvheadend" \
"https://dl.cloudsmith.io/public/tvheadend/tvheadend/gpg.C6CC06BD69B430C6.key" \
"https://dl.cloudsmith.io/public/tvheadend/tvheadend/deb/debian" \
"$(get_os_info codename)" \
"main"
var_admin_user="${var_admin_user:-admin}"
var_admin_pass="${var_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-13)}"
msg_info "Installing Tvheadend"
echo "tvheadend tvheadend/admin_username string ${var_admin_user}" | debconf-set-selections
echo "tvheadend tvheadend/admin_password password ${var_admin_pass}" | debconf-set-selections
$STD apt install -y tvheadend
msg_ok "Installed Tvheadend"
msg_info "Starting Service"
systemctl enable -q --now tvheadend
msg_ok "Started Service"
msg_info "Saving Credentials"
cat <<EOF >~/tvheadend.creds
Tvheadend Admin Credentials
Username: ${var_admin_user}
Password: ${var_admin_pass}
EOF
msg_ok "Saved Credentials"
motd_ssh
customize
cleanup_lxc
+40 -20
View File
@@ -96,6 +96,27 @@ if [[ -f "$LEGACY_DB" || -f "$LEGACY_BIN" && ! -f "$CONFIG_PATH" ]]; then
fi
fi
# v2 rejects v1 config keys and imports the BoltDB on its first start
migrate_v1_config() {
local dir="/usr/local/community-scripts" db=0
[[ -s "$dir/database.db" && ! -s "$dir/filebrowser.sqlite" ]] && db=1
((db)) || grep -qE 'conditionals:|indexingIntervalMinutes:' "$CONFIG_PATH" || return 0
cp "$CONFIG_PATH" "${CONFIG_PATH}.v1.bak"
((db)) && mv "$dir/database.db" "$dir/database.db.old"
awk -v db="$db" '
{ match($0, /^ */); ind = RLENGTH }
/^[^ #]/ { top = $1 }
cond && ind > ci { print substr($0, 3); next }
{ cond = 0 }
/^[[:space:]]*conditionals:[[:space:]]*$/ { cond = 1; ci = ind; next }
/^[[:space:]]*indexingIntervalMinutes:/ { next }
top == "server:" && /^ port:/ { port = $2; next }
{ print }
/^server:/ && db { print " database:"; print " migrateFrom: \"database.db.old\"" }
END { if (port != "") { print "http:"; print " port: " port } }
' "${CONFIG_PATH}.v1.bak" >"$CONFIG_PATH"
}
# Existing installation
if [[ -f "$INSTALL_PATH" ]]; then
msg_warn "${APP} is already installed."
@@ -126,6 +147,7 @@ if [[ -f "$INSTALL_PATH" ]]; then
mv -f /usr/local/bin/filebrowser-quantum "$INSTALL_PATH"
if [[ -f "$CONFIG_PATH" ]]; then
sed -i '/^\s*disableIndexing:/d' "$CONFIG_PATH"
migrate_v1_config
fi
if [[ "$OS" == "Debian" ]]; then
systemctl restart filebrowser.service
@@ -173,22 +195,21 @@ read -r noauth_prompt
# === YAML CONFIG GENERATION ===
if [[ "${noauth_prompt,,}" =~ ^(y|yes)$ ]]; then
cat <<EOF >"$CONFIG_PATH"
server:
http:
port: $PORT
server:
sources:
- path: "$SRC_DIR"
name: "RootFS"
config:
denyByDefault: false
indexingIntervalMinutes: 240
conditionals:
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth:
methods:
noauth: true
@@ -196,22 +217,21 @@ EOF
msg_ok "Configured with no authentication"
else
cat <<EOF >"$CONFIG_PATH"
server:
http:
port: $PORT
server:
sources:
- path: "$SRC_DIR"
name: "RootFS"
config:
denyByDefault: false
indexingIntervalMinutes: 240
conditionals:
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth:
adminUsername: admin
adminPassword: community-scripts.org