mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-09-12 00:42:10 +00:00
Compare commits
7 Commits
add-script
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1b581bddea | ||
|
|
c1fc07d937 | ||
|
|
c98008cc16 | ||
|
|
8713dabc56 | ||
|
|
6b30d4462d | ||
|
|
fc40e198b6 | ||
|
|
b875f780bb |
@@ -544,12 +544,14 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
|||||||
|
|
||||||
### 🆕 New Scripts
|
### 🆕 New Scripts
|
||||||
|
|
||||||
- OneTimeSecret ([#17097](https://github.com/community-scripts/ProxmoxVE/pull/17097))
|
- Lemonade-Server ([#17190](https://github.com/community-scripts/ProxmoxVE/pull/17190))
|
||||||
|
- OneTimeSecret ([#17097](https://github.com/community-scripts/ProxmoxVE/pull/17097))
|
||||||
|
|
||||||
### 🚀 Updated Scripts
|
### 🚀 Updated Scripts
|
||||||
|
|
||||||
- #### 🐞 Bug Fixes
|
- #### 🐞 Bug Fixes
|
||||||
|
|
||||||
|
- update authentik to 2026.8.2 [@thieneret](https://github.com/thieneret) ([#17198](https://github.com/community-scripts/ProxmoxVE/pull/17198))
|
||||||
- passwordpusher: restore data before running migrations [@MickLesk](https://github.com/MickLesk) ([#17141](https://github.com/community-scripts/ProxmoxVE/pull/17141))
|
- passwordpusher: restore data before running migrations [@MickLesk](https://github.com/MickLesk) ([#17141](https://github.com/community-scripts/ProxmoxVE/pull/17141))
|
||||||
- paperclip: install the rust toolchain needed by the runner build [@MickLesk](https://github.com/MickLesk) ([#17142](https://github.com/community-scripts/ProxmoxVE/pull/17142))
|
- paperclip: install the rust toolchain needed by the runner build [@MickLesk](https://github.com/MickLesk) ([#17142](https://github.com/community-scripts/ProxmoxVE/pull/17142))
|
||||||
- homepage: run next directly instead of through pnpm [@MickLesk](https://github.com/MickLesk) ([#17155](https://github.com/community-scripts/ProxmoxVE/pull/17155))
|
- homepage: run next directly instead of through pnpm [@MickLesk](https://github.com/MickLesk) ([#17155](https://github.com/community-scripts/ProxmoxVE/pull/17155))
|
||||||
@@ -563,6 +565,8 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
|||||||
|
|
||||||
### 🧰 Tools
|
### 🧰 Tools
|
||||||
|
|
||||||
|
- Dockhand ([#17191](https://github.com/community-scripts/ProxmoxVE/pull/17191))
|
||||||
|
|
||||||
- #### 🐞 Bug Fixes
|
- #### 🐞 Bug Fixes
|
||||||
|
|
||||||
- update-apps: rewrite the retired Gitea base in every container before updating it [@MickLesk](https://github.com/MickLesk) ([#17156](https://github.com/community-scripts/ProxmoxVE/pull/17156))
|
- update-apps: rewrite the retired Gitea base in every container before updating it [@MickLesk](https://github.com/MickLesk) ([#17156](https://github.com/community-scripts/ProxmoxVE/pull/17156))
|
||||||
|
|||||||
@@ -49,7 +49,7 @@ function update_script() {
|
|||||||
RUST_PROFILE="minimal" RUST_TOOLCHAIN="stable" setup_rust
|
RUST_PROFILE="minimal" RUST_TOOLCHAIN="stable" setup_rust
|
||||||
setup_yq
|
setup_yq
|
||||||
|
|
||||||
AUTHENTIK_VERSION="version/2026.8.1"
|
AUTHENTIK_VERSION="version/2026.8.2"
|
||||||
# Source: https://github.com/goauthentik/fips/blob/main/Makefile#L26
|
# Source: https://github.com/goauthentik/fips/blob/main/Makefile#L26
|
||||||
XMLSEC_VERSION="1.3.12"
|
XMLSEC_VERSION="1.3.12"
|
||||||
|
|
||||||
@@ -184,8 +184,12 @@ EOF
|
|||||||
|
|
||||||
msg_info "Updating services"
|
msg_info "Updating services"
|
||||||
sed -i 's/authentik Go Server (API Gateway)/authentik Server/g' /etc/systemd/system/authentik-server.service
|
sed -i 's/authentik Go Server (API Gateway)/authentik Server/g' /etc/systemd/system/authentik-server.service
|
||||||
sed -i '/ExecStart=/i ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-server.service
|
if ! grep -qF -- 'ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-server.service; then
|
||||||
sed -i '/ExecStart=/i ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-worker.service
|
sed -i '/ExecStart=/i ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-server.service
|
||||||
|
fi
|
||||||
|
if ! grep -qF -- 'ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-worker.service; then
|
||||||
|
sed -i '/ExecStart=/i ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-worker.service
|
||||||
|
fi
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
msg_ok "Updated services"
|
msg_ok "Updated services"
|
||||||
|
|
||||||
@@ -224,8 +228,8 @@ for i in {1..10}; do
|
|||||||
sleep 1
|
sleep 1
|
||||||
done
|
done
|
||||||
$STD pct exec "$CTID" -- bash -c "mkdir -p /opt/authentik-data/{certs,media,geoip,templates}; \
|
$STD pct exec "$CTID" -- bash -c "mkdir -p /opt/authentik-data/{certs,media,geoip,templates}; \
|
||||||
cp /opt/authentik/tests/GeoLite2-ASN-Test.mmdb /opt/authentik-data/geoip/GeoLite2-ASN.mmdb; \
|
cp /opt/authentik/tests/geoip/GeoLite2-ASN-Test.mmdb /opt/authentik-data/geoip/GeoLite2-ASN.mmdb; \
|
||||||
cp /opt/authentik/tests/GeoLite2-City-Test.mmdb /opt/authentik-data/geoip/GeoLite2-City.mmdb; \
|
cp /opt/authentik/tests/geoip/GeoLite2-City-Test.mmdb /opt/authentik-data/geoip/GeoLite2-City.mmdb; \
|
||||||
cp -r /opt/authentik/blueprints /opt/authentik-data/; \
|
cp -r /opt/authentik/blueprints /opt/authentik-data/; \
|
||||||
rm -r /opt/authentik/blueprints; \
|
rm -r /opt/authentik/blueprints; \
|
||||||
find /opt/authentik-data -path '*/lost+found' -prune -o -exec chown authentik:authentik {} +"
|
find /opt/authentik-data -path '*/lost+found' -prune -o -exec chown authentik:authentik {} +"
|
||||||
|
|||||||
@@ -58,7 +58,7 @@ PG_VERSION="17" setup_postgresql
|
|||||||
PG_DB_NAME="authentik" PG_DB_USER="authentik" PG_DB_GRANT_SUPERUSER="true" setup_postgresql_db
|
PG_DB_NAME="authentik" PG_DB_USER="authentik" PG_DB_GRANT_SUPERUSER="true" setup_postgresql_db
|
||||||
|
|
||||||
XMLSEC_VERSION="1.3.12"
|
XMLSEC_VERSION="1.3.12"
|
||||||
AUTHENTIK_VERSION="version/2026.8.1"
|
AUTHENTIK_VERSION="version/2026.8.2"
|
||||||
fetch_and_deploy_gh_release "xmlsec" "lsh123/xmlsec" "tarball" "${XMLSEC_VERSION}" "/opt/xmlsec"
|
fetch_and_deploy_gh_release "xmlsec" "lsh123/xmlsec" "tarball" "${XMLSEC_VERSION}" "/opt/xmlsec"
|
||||||
fetch_and_deploy_gh_release "authentik" "goauthentik/authentik" "tarball" "${AUTHENTIK_VERSION}" "/opt/authentik"
|
fetch_and_deploy_gh_release "authentik" "goauthentik/authentik" "tarball" "${AUTHENTIK_VERSION}" "/opt/authentik"
|
||||||
GO_VERSION="$(grep -m1 '^go ' /opt/authentik/go.mod | awk '{print $2}')" setup_go
|
GO_VERSION="$(grep -m1 '^go ' /opt/authentik/go.mod | awk '{print $2}')" setup_go
|
||||||
|
|||||||
111
tools/addon/dockhand.sh
Normal file
111
tools/addon/dockhand.sh
Normal file
@@ -0,0 +1,111 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
# Copyright (c) 2021-2026 community-scripts ORG
|
||||||
|
# Author: MickLesk (CanbiZ)
|
||||||
|
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||||
|
# Source: https://github.com/Finsys/dockhand
|
||||||
|
|
||||||
|
if command -v curl >/dev/null 2>&1; then
|
||||||
|
source <(curl -fsSL ${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/core.func)
|
||||||
|
load_functions
|
||||||
|
elif command -v wget >/dev/null 2>&1; then
|
||||||
|
source <(wget -qO- ${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/core.func)
|
||||||
|
load_functions
|
||||||
|
fi
|
||||||
|
source <(curl -fsSL ${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/lib/tools.func)
|
||||||
|
|
||||||
|
color
|
||||||
|
catch_errors
|
||||||
|
|
||||||
|
APP="Dockhand"
|
||||||
|
APP_TYPE="addon"
|
||||||
|
INSTALL_PATH="/opt/dockhand"
|
||||||
|
COMPOSE_FILE="${INSTALL_PATH}/docker-compose.yaml"
|
||||||
|
DEFAULT_PORT=3000
|
||||||
|
|
||||||
|
header_info "$APP"
|
||||||
|
|
||||||
|
IP=$(_get_current_ip)
|
||||||
|
|
||||||
|
function check_docker() {
|
||||||
|
if ! command -v docker >/dev/null 2>&1; then
|
||||||
|
msg_error "Docker is not installed. This addon requires an existing Docker host/LXC. Exiting."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if ! docker compose version >/dev/null 2>&1; then
|
||||||
|
msg_error "Docker Compose plugin is not available. Install it before running this addon. Exiting."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
msg_ok "Docker $(docker --version | cut -d' ' -f3 | tr -d ',') and Docker Compose are available"
|
||||||
|
}
|
||||||
|
|
||||||
|
function install_dockhand() {
|
||||||
|
local port="${1:-$DEFAULT_PORT}"
|
||||||
|
check_docker
|
||||||
|
|
||||||
|
msg_info "Creating Compose Project"
|
||||||
|
mkdir -p "$INSTALL_PATH"
|
||||||
|
cat <<EOF >"$COMPOSE_FILE"
|
||||||
|
services:
|
||||||
|
dockhand:
|
||||||
|
image: fnsys/dockhand:latest
|
||||||
|
container_name: dockhand
|
||||||
|
restart: unless-stopped
|
||||||
|
ports:
|
||||||
|
- ${port}:3000
|
||||||
|
volumes:
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
- dockhand_data:/app/data
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
dockhand_data:
|
||||||
|
EOF
|
||||||
|
msg_ok "Created Compose Project"
|
||||||
|
|
||||||
|
msg_info "Starting ${APP}"
|
||||||
|
cd "$INSTALL_PATH"
|
||||||
|
$STD docker compose up -d
|
||||||
|
msg_ok "Started ${APP}"
|
||||||
|
|
||||||
|
msg_ok "${APP} is reachable at http://${IP}:${port}"
|
||||||
|
echo -e "${TAB}Open the URL and complete the first-run setup wizard to create the admin account."
|
||||||
|
}
|
||||||
|
|
||||||
|
function update_dockhand() {
|
||||||
|
msg_info "Pulling latest ${APP} image"
|
||||||
|
cd "$INSTALL_PATH"
|
||||||
|
$STD docker compose pull
|
||||||
|
msg_ok "Pulled latest image"
|
||||||
|
|
||||||
|
msg_info "Restarting ${APP}"
|
||||||
|
$STD docker compose up -d --remove-orphans
|
||||||
|
msg_ok "Restarted ${APP}"
|
||||||
|
|
||||||
|
msg_ok "${APP} updated successfully"
|
||||||
|
}
|
||||||
|
|
||||||
|
function uninstall_dockhand() {
|
||||||
|
msg_info "Removing ${APP}"
|
||||||
|
cd "$INSTALL_PATH"
|
||||||
|
$STD docker compose down --remove-orphans
|
||||||
|
cd /
|
||||||
|
rm -rf "$INSTALL_PATH"
|
||||||
|
msg_ok "${APP} uninstalled (the dockhand_data volume was kept; remove it with: docker volume rm dockhand_data)"
|
||||||
|
}
|
||||||
|
|
||||||
|
if [[ -f "$COMPOSE_FILE" ]]; then
|
||||||
|
read -r -p "Update (1), Uninstall (2), Cancel (3)? [1/2/3]: " action
|
||||||
|
action="${action//[[:space:]]/}"
|
||||||
|
case "$action" in
|
||||||
|
1) update_dockhand ;;
|
||||||
|
2) uninstall_dockhand ;;
|
||||||
|
3) msg_info "Cancelled" ;;
|
||||||
|
*) msg_error "Invalid input" ;;
|
||||||
|
esac
|
||||||
|
else
|
||||||
|
read -r -p "Enter port number (default: ${DEFAULT_PORT}): " PORT_INPUT
|
||||||
|
PORT="${PORT_INPUT:-$DEFAULT_PORT}"
|
||||||
|
read -r -p "Install ${APP}? (y/n): " answer
|
||||||
|
answer="${answer//[[:space:]]/}"
|
||||||
|
[[ "${answer,,}" =~ ^(y|yes)$ ]] && install_dockhand "$PORT" || msg_info "Installation skipped"
|
||||||
|
fi
|
||||||
6
tools/headers/dockhand
Normal file
6
tools/headers/dockhand
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
____ __ __ __
|
||||||
|
/ __ \____ _____/ /__/ /_ ____ _____ ____/ /
|
||||||
|
/ / / / __ \/ ___/ //_/ __ \/ __ `/ __ \/ __ /
|
||||||
|
/ /_/ / /_/ / /__/ ,< / / / / /_/ / / / / /_/ /
|
||||||
|
/_____/\____/\___/_/|_/_/ /_/\__,_/_/ /_/\__,_/
|
||||||
|
|
||||||
Reference in New Issue
Block a user