mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-08-30 12:05:44 +00:00
Compare commits
1 Commits
add-script
...
add-script
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
352111765d |
@@ -1,6 +0,0 @@
|
||||
____ ____
|
||||
/ __ \____ ___ ____ / __ )____ _____
|
||||
/ / / / __ \/ _ \/ __ \/ __ / __ `/ __ \
|
||||
/ /_/ / /_/ / __/ / / / /_/ / /_/ / /_/ /
|
||||
\____/ .___/\___/_/ /_/_____/\__,_/\____/
|
||||
/_/
|
||||
6
ct/headers/solidinvoice
Normal file
6
ct/headers/solidinvoice
Normal file
@@ -0,0 +1,6 @@
|
||||
_____ ___ ______ _
|
||||
/ ___/____ / (_)___/ / _/___ _ ______ (_)_______
|
||||
\__ \/ __ \/ / / __ // // __ \ | / / __ \/ / ___/ _ \
|
||||
___/ / /_/ / / / /_/ // // / / / |/ / /_/ / / /__/ __/
|
||||
/____/\____/_/_/\__,_/___/_/ /_/|___/\____/_/\___/\___/
|
||||
|
||||
@@ -1,73 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: Marc Went (Dunky13)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://openbao.org/
|
||||
|
||||
APP="OpenBao"
|
||||
var_tags="${var_tags:-security;secrets}"
|
||||
var_cpu="${var_cpu:-1}"
|
||||
var_ram="${var_ram:-1024}"
|
||||
var_disk="${var_disk:-4}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -f /usr/bin/bao ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "openbao" "openbao/openbao"; then
|
||||
msg_info "Stopping Service"
|
||||
systemctl stop openbao
|
||||
msg_ok "Stopped Service"
|
||||
|
||||
create_backup /etc/openbao
|
||||
|
||||
DPKG_FORCE_CONFOLD=1 fetch_and_deploy_gh_release "openbao" "openbao/openbao" "binary" "latest" "/opt/openbao" "openbao_*_linux_$(arch_resolve).deb"
|
||||
|
||||
restore_backup
|
||||
systemctl daemon-reload
|
||||
|
||||
msg_info "Starting Service"
|
||||
systemctl start openbao
|
||||
msg_ok "Started Service"
|
||||
for _ in {1..15}; do
|
||||
BAO_ADDR=https://127.0.0.1:8200 BAO_SKIP_VERIFY=true bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null && break
|
||||
sleep 2
|
||||
done
|
||||
if ! BAO_ADDR=https://127.0.0.1:8200 BAO_SKIP_VERIFY=true bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null; then
|
||||
msg_error "OpenBao did not unseal within 30 seconds"
|
||||
exit 1
|
||||
fi
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW} Access it using the following URL:${CL}"
|
||||
echo -e "${TAB}${GATEWAY}${BGN}https://${IP}:8200${CL}"
|
||||
echo -e "${INFO}${YW} Credentials:${CL}"
|
||||
echo -e "${TAB}${DGN}Root Token: ${BGN}$(pct exec "$CTID" -- sed -n 's/^BAO_ROOT_TOKEN=//p' /etc/openbao/openbao.env)${CL}"
|
||||
echo -e "${TAB}${DGN}Unseal Key: ${BGN}$(pct exec "$CTID" -- sed -n 's/^BAO_UNSEAL_KEY=//p' /etc/openbao/openbao.env)${CL}"
|
||||
57
ct/solidinvoice.sh
Normal file
57
ct/solidinvoice.sh
Normal file
@@ -0,0 +1,57 @@
|
||||
#!/usr/bin/env bash
|
||||
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: Pierre du Plessis
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/solidinvoice/solidinvoice
|
||||
|
||||
APP="SolidInvoice"
|
||||
var_tags="${var_tags:-invoicing;finance;billing}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-2048}"
|
||||
var_disk="${var_disk:-4}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -f /usr/bin/solidinvoice ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "solidinvoice" "SolidInvoice/SolidInvoice"; then
|
||||
msg_info "Stopping ${APP} Service"
|
||||
systemctl stop solidinvoice
|
||||
msg_ok "Stopped ${APP} Service"
|
||||
|
||||
fetch_and_deploy_gh_release "solidinvoice" "SolidInvoice/SolidInvoice" "singlefile" "latest" "/usr/bin" "solidinvoice-linux-$(arch_resolve)"
|
||||
|
||||
msg_info "Starting ${APP} Service"
|
||||
systemctl start solidinvoice
|
||||
msg_ok "Started ${APP} Service"
|
||||
msg_ok "Updated Successfully"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}:8765${CL}"
|
||||
@@ -1,68 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: Marc Went (Dunky13)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://openbao.org/
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
fetch_and_deploy_gh_release "openbao" "openbao/openbao" "binary" "latest" "/opt/openbao" "openbao_*_linux_$(arch_resolve).deb"
|
||||
|
||||
msg_info "Configuring CLI Environment"
|
||||
cat <<EOF >/etc/profile.d/openbao.sh
|
||||
export BAO_ADDR=https://127.0.0.1:8200
|
||||
export BAO_SKIP_VERIFY=true
|
||||
EOF
|
||||
source /etc/profile.d/openbao.sh
|
||||
msg_ok "Configured CLI Environment"
|
||||
|
||||
msg_info "Starting OpenBao"
|
||||
systemctl enable -q --now openbao
|
||||
for _ in {1..30}; do
|
||||
curl -fsSk -o /dev/null "https://127.0.0.1:8200/v1/sys/seal-status" && break
|
||||
sleep 2
|
||||
done
|
||||
msg_ok "Started OpenBao"
|
||||
|
||||
msg_info "Initializing OpenBao"
|
||||
(
|
||||
umask 077
|
||||
cat <<'EOF' >/etc/openbao/openbao-init.json
|
||||
EOF
|
||||
)
|
||||
bao operator init -key-shares=1 -key-threshold=1 -format=json >/etc/openbao/openbao-init.json
|
||||
chmod 600 /etc/openbao/openbao.env
|
||||
chown root:root /etc/openbao/openbao.env
|
||||
cat <<EOF >>/etc/openbao/openbao.env
|
||||
BAO_ADDR=https://127.0.0.1:8200
|
||||
BAO_SKIP_VERIFY=true
|
||||
BAO_UNSEAL_KEY=$(jq -r '.unseal_keys_b64[0]' /etc/openbao/openbao-init.json)
|
||||
BAO_ROOT_TOKEN=$(jq -r '.root_token' /etc/openbao/openbao-init.json)
|
||||
EOF
|
||||
rm -f /etc/openbao/openbao-init.json
|
||||
msg_ok "Initialized OpenBao"
|
||||
|
||||
msg_info "Enabling Auto-Unseal"
|
||||
mkdir -p /etc/systemd/system/openbao.service.d
|
||||
cat <<'EOF' >/etc/systemd/system/openbao.service.d/unseal.conf
|
||||
[Service]
|
||||
ExecStartPost=-/usr/bin/bao operator unseal ${BAO_UNSEAL_KEY}
|
||||
EOF
|
||||
systemctl daemon-reload
|
||||
systemctl restart openbao
|
||||
for _ in {1..15}; do
|
||||
bao status -format=json 2>/dev/null | jq -e '.sealed == false' >/dev/null && break
|
||||
sleep 2
|
||||
done
|
||||
msg_ok "Enabled Auto-Unseal"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
190
install/solidinvoice-install.sh
Normal file
190
install/solidinvoice-install.sh
Normal file
@@ -0,0 +1,190 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: Pierre du Plessis
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/solidinvoice/solidinvoice
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Creating Directories"
|
||||
mkdir -p /etc/solidinvoice /var/lib/solidinvoice
|
||||
msg_ok "Created Directories"
|
||||
|
||||
fetch_and_deploy_gh_release "solidinvoice" "SolidInvoice/SolidInvoice" "singlefile" "latest" "/usr/bin" "solidinvoice-linux-$(arch_resolve)"
|
||||
|
||||
msg_info "Configuring SolidInvoice"
|
||||
cat <<'EOF' >/etc/solidinvoice/solidinvoice.env
|
||||
# SolidInvoice environment configuration
|
||||
# This file is sourced by the systemd service unit.
|
||||
# CLI flags always take precedence over values set here.
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Network
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Port to listen on (default: 8765)
|
||||
#SOLIDINVOICE_PORT=8765
|
||||
|
||||
# IP address to bind to (default: auto-detected outbound IP)
|
||||
#SOLIDINVOICE_SERVER_IP=0.0.0.0
|
||||
|
||||
# Domain name — required when using Let's Encrypt or custom certificates.
|
||||
# When set, the application binds to https://<domain> instead of an IP.
|
||||
#SOLIDINVOICE_DOMAIN=
|
||||
|
||||
# Bind the bundled webserver to every hostname so it answers regardless of the
|
||||
# Host header — required behind a reverse proxy that forwards the original domain.
|
||||
SOLIDINVOICE_DOCKER=true
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# HTTPS / TLS
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Disable HTTPS and serve plain HTTP. Set to 1 when running behind a
|
||||
# reverse proxy (nginx, Caddy, Traefik, etc.) that handles TLS termination.
|
||||
# Remove or set to 0 when you want the application to manage its own certificates.
|
||||
SOLIDINVOICE_DISABLE_HTTPS=1
|
||||
|
||||
# Enable automatic Let's Encrypt certificates (requires SOLIDINVOICE_DOMAIN).
|
||||
# Incompatible with SOLIDINVOICE_DISABLE_HTTPS=1.
|
||||
#SOLIDINVOICE_LETS_ENCRYPT=1
|
||||
|
||||
# Paths to a custom TLS certificate and private key (requires SOLIDINVOICE_DOMAIN).
|
||||
# Incompatible with SOLIDINVOICE_DISABLE_HTTPS=1 and SOLIDINVOICE_LETS_ENCRYPT=1.
|
||||
#SOLIDINVOICE_SSL_CERT=/etc/ssl/certs/solidinvoice.crt
|
||||
#SOLIDINVOICE_SSL_KEY=/etc/ssl/private/solidinvoice.key
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Performance
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Enable FrankenPHP worker mode for improved performance (keeps PHP workers
|
||||
# alive between requests). Recommended for high-traffic deployments.
|
||||
# Set to 1 to enable.
|
||||
#FRANKENPHP_WORKER_MODE=1
|
||||
|
||||
# Number of FrankenPHP worker threads when worker mode is enabled (default: 2).
|
||||
#SOLIDINVOICE_WORKER_THREADS=2
|
||||
|
||||
# Number of background messenger worker processes (default: 1).
|
||||
# Set to 0 to disable built-in workers (use the dedicated 'solidinvoice worker'
|
||||
# command instead).
|
||||
#SOLIDINVOICE_MESSENGER_WORKERS=1
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Application
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Application environment. Change to "dev" only for local development.
|
||||
#SOLIDINVOICE_ENV=prod
|
||||
|
||||
# Enable debug mode (0 or 1). Never enable in production.
|
||||
#SOLIDINVOICE_DEBUG=0
|
||||
|
||||
# Configuration directory — stores generated secrets, OAuth keys, and the
|
||||
# SQLite database (when no external database is configured).
|
||||
SOLIDINVOICE_CONFIG_DIR=/etc/solidinvoice
|
||||
|
||||
# Installation type identifier used for telemetry when opted in.
|
||||
SOLIDINVOICE_INSTALL_TYPE=proxmox-community-scripts
|
||||
|
||||
# Skip the ASCII art / URL summary printed on startup.
|
||||
SOLIDINVOICE_SKIP_INTRO=1
|
||||
|
||||
# Log format: "json" for structured logs (default for systemd), "console" for human-readable.
|
||||
SOLIDINVOICE_LOG_FORMAT=json
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Database
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Database connection URL. Defaults to SQLite stored in SOLIDINVOICE_CONFIG_DIR
|
||||
# when not set. Supported drivers: mysql, postgresql, sqlite.
|
||||
#SOLIDINVOICE_DATABASE_URL=mysql://user:password@127.0.0.1:3306/solidinvoice
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Email
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Outbound mail transport DSN. Overrides the transport configured in the UI.
|
||||
# See https://symfony.com/doc/current/mailer.html for DSN formats.
|
||||
#SOLIDINVOICE_MAILER_DSN=smtp://user:password@localhost:25
|
||||
|
||||
# From address used for all outgoing emails. Overrides the address configured in the UI.
|
||||
#SOLIDINVOICE_MAILER_SENDER=SolidInvoice <noreply@example.com>
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Async messaging
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Messenger transport DSN. Defaults to the database (doctrine) queue.
|
||||
#SOLIDINVOICE_MESSENGER_DSN=doctrine://default?queue_name=async
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Search (optional)
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Meilisearch instance for full-text search. Leave blank to disable.
|
||||
#SOLIDINVOICE_MEILISEARCH_URL=http://localhost:7700
|
||||
#SOLIDINVOICE_MEILISEARCH_API_KEY=
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Localisation
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Default locale for the application interface (e.g. en, fr, de, nl).
|
||||
#SOLIDINVOICE_LOCALE=en
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# User registration
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Allow visitors to create their own accounts (0 = disabled, 1 = enabled).
|
||||
#SOLIDINVOICE_ALLOW_REGISTRATION=0
|
||||
|
||||
# ------------------------------------------------------------------
|
||||
# Monitoring (optional)
|
||||
# ------------------------------------------------------------------
|
||||
|
||||
# Sentry DSN for error and performance monitoring.
|
||||
#SOLIDINVOICE_SENTRY_DSN=
|
||||
|
||||
# Expose a Prometheus metrics endpoint on a dedicated port.
|
||||
#SOLIDINVOICE_ENABLE_METRICS=1
|
||||
#SOLIDINVOICE_METRICS_PORT=9090
|
||||
EOF
|
||||
chmod 640 /etc/solidinvoice/solidinvoice.env
|
||||
msg_ok "Configured SolidInvoice"
|
||||
|
||||
msg_info "Creating Service"
|
||||
cat <<'EOF' >/etc/systemd/system/solidinvoice.service
|
||||
[Unit]
|
||||
Description=SolidInvoice
|
||||
Documentation=https://solidinvoice.co/docs
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=exec
|
||||
User=root
|
||||
WorkingDirectory=/var/lib/solidinvoice
|
||||
ExecStart=/usr/bin/solidinvoice run
|
||||
EnvironmentFile=/etc/solidinvoice/solidinvoice.env
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now solidinvoice
|
||||
msg_ok "Created Service"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
Reference in New Issue
Block a user