mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-10-09 20:25:13 +00:00
Compare commits
10
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
12d81fa9d6 | ||
|
|
d34989be9f | ||
|
|
daa4daa927 | ||
|
|
227526cf55 | ||
|
|
d271571ff7 | ||
|
|
7100f6521c | ||
|
|
387b8bf542 | ||
|
|
a56510bf57 | ||
|
|
05bc39e623 | ||
|
|
6db1ebe154 |
@@ -559,6 +559,20 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
||||
|
||||
</details>
|
||||
|
||||
## 2026-10-09
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
- FoldingAtHome ([#17799](https://github.com/community-scripts/ProxmoxVE/pull/17799))
|
||||
- LocalAI ([#17801](https://github.com/community-scripts/ProxmoxVE/pull/17801))
|
||||
- Tvheadend ([#17800](https://github.com/community-scripts/ProxmoxVE/pull/17800))
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
- #### 🔧 Refactor
|
||||
|
||||
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
|
||||
|
||||
## 2026-10-08
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
@@ -0,0 +1,52 @@
|
||||
#!/usr/bin/env bash
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ) | Co-Author: 007hacky007
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/FoldingAtHome/fah-client-bastet
|
||||
|
||||
APP="FoldingAtHome"
|
||||
var_tags="${var_tags:-science;distributed-computing}"
|
||||
var_cpu="${var_cpu:-4}"
|
||||
var_ram="${var_ram:-2048}"
|
||||
var_disk="${var_disk:-8}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
var_gpu="${var_gpu:-yes}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
export var_fah_token="${var_fah_token:-}"
|
||||
export var_fah_machine_name="${var_fah_machine_name:-}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -f /usr/bin/fah-client ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
fetch_and_deploy_from_url "https://download.foldingathome.org/releases/public/fah-client/$(arch_resolve "debian-10-64bit" "debian-stable-arm64")/release/latest.deb"
|
||||
msg_ok "Folding@home is at $(dpkg-query -W -f='${Version}' fah-client)"
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Manage it from the Folding@home Web Control:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}https://app.foldingathome.org/${CL}"
|
||||
echo -e "${INFO}${YW}The client starts paused - press Fold once the machine shows up in your account${CL}"
|
||||
echo -e "${INFO}${YW}Account token and machine name are in /etc/fah-client/config.xml${CL}"
|
||||
+31
-10
@@ -115,7 +115,10 @@ EOF
|
||||
fi
|
||||
|
||||
if check_for_gh_release "Immich" "immich-app/immich" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
|
||||
if [[ $(cat ~/.immich) > "2.5.1" ]]; then
|
||||
msg_warn "The update takes 5-15 minutes, do not interrupt it"
|
||||
PREV_IMMICH="$(cat ~/.immich)"
|
||||
# An interrupted update leaves app/ empty, so there may be no immich-admin to call.
|
||||
if [[ "$PREV_IMMICH" > "2.5.1" && -x /opt/immich/app/bin/immich-admin ]]; then
|
||||
msg_info "Enabling Maintenance Mode"
|
||||
cd /opt/immich/app/bin
|
||||
$STD ./immich-admin enable-maintenance-mode || true
|
||||
@@ -273,12 +276,14 @@ EOF
|
||||
msg_ok "Pre-installed Python ${ML_PYTHON}"
|
||||
msg_info "Updating Intel OpenVINO machine-learning"
|
||||
for attempt in $(seq 1 3); do
|
||||
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
|
||||
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
|
||||
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
|
||||
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
|
||||
[[ $attempt -eq 3 ]] && { ML_FAILED=1; break; }
|
||||
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
|
||||
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
|
||||
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
|
||||
done
|
||||
patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
|
||||
msg_ok "Updated Intel OpenVINO machine-learning"
|
||||
[[ "${ML_FAILED:-0}" == 1 ]] || patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
|
||||
[[ "${ML_FAILED:-0}" == 1 ]] || msg_ok "Updated Intel OpenVINO machine-learning"
|
||||
else
|
||||
ML_PYTHON="python3.13"
|
||||
msg_info "Pre-installing Python ${ML_PYTHON} for machine-learning"
|
||||
@@ -289,12 +294,15 @@ EOF
|
||||
msg_ok "Pre-installed Python ${ML_PYTHON}"
|
||||
msg_info "Updating machine-learning"
|
||||
for attempt in $(seq 1 3); do
|
||||
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
|
||||
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
|
||||
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
|
||||
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
|
||||
[[ $attempt -eq 3 ]] && { ML_FAILED=1; break; }
|
||||
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
|
||||
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
|
||||
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
|
||||
done
|
||||
msg_ok "Updated machine-learning"
|
||||
[[ "${ML_FAILED:-0}" == 1 ]] || msg_ok "Updated machine-learning"
|
||||
fi
|
||||
[[ "${ML_FAILED:-0}" == 1 ]] && msg_warn "uv sync failed three times, machine learning was not updated"
|
||||
cd "$SRC_DIR"
|
||||
cp -a machine-learning/{ann,immich_ml} "$ML_DIR"
|
||||
[[ -f "$INSTALL_DIR"/ml_start.sh ]] && mv "$INSTALL_DIR"/ml_start.sh "$ML_DIR"
|
||||
@@ -345,6 +353,10 @@ EOF
|
||||
sed -i "s|^ExecStart=.*|ExecStart=${APP_DIR}/bin/start.sh|" /etc/systemd/system/immich-web.service
|
||||
systemctl daemon-reload
|
||||
fi
|
||||
if grep -q "^ExecStart=${INSTALL_DIR}/ml_start.sh" /etc/systemd/system/immich-ml.service; then
|
||||
sed -i "s|^ExecStart=.*|ExecStart=${ML_DIR}/ml_start.sh|" /etc/systemd/system/immich-ml.service
|
||||
systemctl daemon-reload
|
||||
fi
|
||||
|
||||
# MickLesk temporary patch for HEIC thumbnail gen
|
||||
MEDIA_REPO_JS="/opt/immich/app/dist/repositories/media.repository.js"
|
||||
@@ -366,6 +378,15 @@ EOF
|
||||
$STD cd -
|
||||
msg_ok "Disabled Maintenance Mode"
|
||||
fi
|
||||
# A crash loop before the update leaves the units rate-limited, and restart would refuse.
|
||||
systemctl reset-failed immich-ml immich-web 2>/dev/null || true
|
||||
if [[ "${ML_FAILED:-0}" == 1 ]]; then
|
||||
systemctl restart immich-web || true
|
||||
[[ -f /etc/systemd/system/immich-proxy.service ]] && systemctl restart immich-proxy
|
||||
echo "$PREV_IMMICH" >~/.immich
|
||||
msg_error "Immich runs, but without machine learning (see the uv output above). Run update again to retry."
|
||||
exit 1
|
||||
fi
|
||||
systemctl restart immich-ml immich-web
|
||||
[[ -f /etc/systemd/system/immich-proxy.service ]] && systemctl restart immich-proxy
|
||||
msg_ok "Updated successfully!"
|
||||
|
||||
@@ -0,0 +1,63 @@
|
||||
#!/usr/bin/env bash
|
||||
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
|
||||
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: Bryan Lieberman (BryanCLieberman)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://localai.io
|
||||
|
||||
APP="LocalAI"
|
||||
var_tags="${var_tags:-ai;llm;api}"
|
||||
var_cpu="${var_cpu:-4}"
|
||||
var_ram="${var_ram:-8192}"
|
||||
var_disk="${var_disk:-30}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
var_gpu="${var_gpu:-yes}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
# Values the install script accepts up front
|
||||
export var_auth="${var_auth:-no}"
|
||||
export var_api_key="${var_api_key:-}"
|
||||
export var_port="${var_port:-8080}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/localai ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "localai" "mudler/LocalAI"; then
|
||||
msg_info "Stopping Service"
|
||||
systemctl stop localai
|
||||
msg_ok "Stopped Service"
|
||||
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "localai" "mudler/LocalAI" "singlefile" "latest" "/opt/localai" "local-ai-v*-linux-$(arch_resolve amd64 arm64)"
|
||||
|
||||
msg_info "Starting Service"
|
||||
systemctl start localai
|
||||
msg_ok "Started Service"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
|
||||
echo -e "${GATEWAY}${BGN}http://${IP}:8080${CL}"
|
||||
echo -e "${INFO}${YW}Install models from the gallery in the web UI or place GGUF files in /opt/localai_data/models${CL}"
|
||||
+9
-1
@@ -41,7 +41,7 @@ function update_script() {
|
||||
if grep -q 'start.sh' /etc/systemd/system/radicale.service; then
|
||||
sed -i -e '/^Description/i[Unit]' \
|
||||
-e '\|^ExecStart|iWorkingDirectory=/opt/radicale' \
|
||||
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
|
||||
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
|
||||
systemctl daemon-reload
|
||||
fi
|
||||
if [[ ! -f /etc/radicale/config ]]; then
|
||||
@@ -70,6 +70,14 @@ EOF
|
||||
msg_ok "Started service"
|
||||
msg_ok "Updated Successfully!"
|
||||
fi
|
||||
|
||||
if grep -q 'uv run -m radicale' /etc/systemd/system/radicale.service && grep -q '^argon2 *=' /opt/radicale/pyproject.toml; then
|
||||
msg_info "Enabling bcrypt/argon2 support"
|
||||
sed -i 's|uv run -m radicale|uv run --extra bcrypt --extra argon2 -m radicale|' /etc/systemd/system/radicale.service
|
||||
systemctl daemon-reload
|
||||
systemctl restart radicale
|
||||
msg_ok "Enabled bcrypt/argon2 support"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ) | Co-Author: 007hacky007
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/FoldingAtHome/fah-client-bastet
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
if [[ -z "${var_fah_token:-}" ]]; then
|
||||
var_fah_token=$(prompt_password "Folding@home account token (Enter to skip):" "" 120)
|
||||
fi
|
||||
if [[ -z "${var_fah_machine_name:-}" ]]; then
|
||||
var_fah_machine_name=$(prompt_input "Folding@home machine name:" "$(hostname)" 60)
|
||||
fi
|
||||
if [[ ${#var_fah_machine_name} -gt 64 || "$var_fah_machine_name" == *[\<\>\;\&\'\"]* ]]; then
|
||||
msg_warn "Machine name must be 1-64 characters without <>;&'\" - using $(hostname)"
|
||||
var_fah_machine_name=$(hostname)
|
||||
fi
|
||||
|
||||
msg_info "Configuring Folding@home"
|
||||
mkdir -p /etc/fah-client
|
||||
cat <<EOF >/etc/fah-client/config.xml
|
||||
<config>
|
||||
<account-token v="${var_fah_token}"/>
|
||||
<machine-name v="${var_fah_machine_name}"/>
|
||||
</config>
|
||||
EOF
|
||||
msg_ok "Configured Folding@home"
|
||||
|
||||
fetch_and_deploy_from_url "https://download.foldingathome.org/releases/public/fah-client/$(arch_resolve "debian-10-64bit" "debian-stable-arm64")/release/latest.deb"
|
||||
|
||||
setup_hwaccel "fah-client"
|
||||
|
||||
# The client detects GPUs only at startup, so restart it after setup_hwaccel.
|
||||
msg_info "Starting Folding@home"
|
||||
systemctl enable -q fah-client
|
||||
safe_service_restart fah-client
|
||||
msg_ok "Started Folding@home"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -441,9 +441,11 @@ if [[ -f ~/.openvino ]]; then
|
||||
msg_ok "Pre-installed Python ${ML_PYTHON}"
|
||||
msg_info "Installing Intel OpenVINO machine-learning"
|
||||
for attempt in $(seq 1 3); do
|
||||
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
|
||||
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra openvino --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
|
||||
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
|
||||
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
|
||||
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
|
||||
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
|
||||
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
|
||||
done
|
||||
patchelf --clear-execstack "${VIRTUAL_ENV}/lib/python3.13/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-313-$(arch_resolve "x86_64" "aarch64")-linux-gnu.so"
|
||||
msg_ok "Installed Intel OpenVINO machine-learning"
|
||||
@@ -457,9 +459,11 @@ else
|
||||
msg_ok "Pre-installed Python ${ML_PYTHON}"
|
||||
msg_info "Installing machine-learning"
|
||||
for attempt in $(seq 1 3); do
|
||||
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
|
||||
$STD sudo --preserve-env=VIRTUAL_ENV,UV_HTTP_TIMEOUT,UV_CONCURRENT_DOWNLOADS,UV_CONCURRENT_BUILDS,UV_CONCURRENT_INSTALLS -Pnu immich uv sync --extra cpu --no-dev --active --link-mode copy -n -p "${ML_PYTHON}" --managed-python && break
|
||||
[[ $attempt -eq 3 ]] && { msg_error "uv sync failed three times, the machine-learning environment was not built"; exit 1; }
|
||||
msg_warn "uv sync attempt $attempt failed, retrying..." && sleep 10
|
||||
# Parallel fetches can trip DNS rate limits (AdGuard, Pi-hole); retry one at a time.
|
||||
export UV_CONCURRENT_DOWNLOADS=1 UV_CONCURRENT_BUILDS=1 UV_CONCURRENT_INSTALLS=1
|
||||
msg_warn "uv sync attempt $attempt failed, retrying one download at a time..." && sleep 10
|
||||
done
|
||||
msg_ok "Installed machine-learning"
|
||||
fi
|
||||
|
||||
@@ -0,0 +1,92 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: Bryan Lieberman (BryanCLieberman)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://localai.io
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
libgomp1 \
|
||||
libopenblas0
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
setup_hwaccel
|
||||
var_port="${var_port:-8080}"
|
||||
var_auth="${var_auth:-no}"
|
||||
var_api_key="${var_api_key:-}"
|
||||
if [[ "$var_auth" == "yes" ]]; then
|
||||
setup_postgresql
|
||||
PG_DB_NAME="localai" PG_DB_USER="localai" setup_postgresql_db
|
||||
fi
|
||||
|
||||
fetch_and_deploy_gh_release "localai" "mudler/LocalAI" "singlefile" "latest" "/opt/localai" "local-ai-v*-linux-$(arch_resolve amd64 arm64)"
|
||||
|
||||
msg_info "Configuring LocalAI"
|
||||
mkdir -p /opt/localai_data/models /opt/localai_data/backends
|
||||
cat <<EOF >/opt/localai.env
|
||||
LOCALAI_ADDRESS=0.0.0.0:${var_port}
|
||||
LOCALAI_DATA_PATH=/opt/localai_data
|
||||
LOCALAI_MODELS_PATH=/opt/localai_data/models
|
||||
LOCALAI_BACKENDS_PATH=/opt/localai_data/backends
|
||||
LOCALAI_LOG_LEVEL=info
|
||||
EOF
|
||||
# LocalAI refuses to start on a wildcard bind with nothing to identify callers,
|
||||
# and binding the wildcard is what makes the container reachable at all.
|
||||
if [[ "$var_auth" == "yes" ]]; then
|
||||
cat <<EOF >>/opt/localai.env
|
||||
LOCALAI_AUTH=true
|
||||
LOCALAI_AUTH_DATABASE_URL=postgres://${PG_DB_USER}:${PG_DB_PASS}@localhost/${PG_DB_NAME}
|
||||
LOCALAI_REGISTRATION_MODE=approval
|
||||
EOF
|
||||
fi
|
||||
# A static key grants admin access on its own, so when it is the only thing
|
||||
# guarding the API, generate one rather than leaving the server open.
|
||||
if [[ -z "$var_api_key" && "$var_auth" != "yes" ]]; then
|
||||
var_api_key="sk-$(openssl rand -hex 24)"
|
||||
{
|
||||
echo "LocalAI Credentials"
|
||||
echo "API Key: ${var_api_key}"
|
||||
} >>~/localai.creds
|
||||
fi
|
||||
if [[ -n "$var_api_key" ]]; then
|
||||
echo "LOCALAI_API_KEY=${var_api_key}" >>/opt/localai.env
|
||||
else
|
||||
echo "#LOCALAI_API_KEY=" >>/opt/localai.env
|
||||
fi
|
||||
chmod 600 /opt/localai.env
|
||||
msg_ok "Configured LocalAI"
|
||||
|
||||
msg_info "Creating Service"
|
||||
cat <<EOF >/etc/systemd/system/localai.service
|
||||
[Unit]
|
||||
Description=LocalAI Server
|
||||
Wants=network-online.target
|
||||
After=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/localai
|
||||
EnvironmentFile=/opt/localai.env
|
||||
ExecStart=/opt/localai/localai run
|
||||
Restart=on-failure
|
||||
RestartSec=10
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now localai
|
||||
msg_ok "Created Service"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -58,7 +58,7 @@ Requires=network.target
|
||||
|
||||
[Service]
|
||||
WorkingDirectory=/opt/radicale
|
||||
ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config
|
||||
ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config
|
||||
Restart=on-failure
|
||||
# User=radicale
|
||||
# Deny other users access to the calendar data
|
||||
|
||||
Reference in New Issue
Block a user