Compare commits

...
Author SHA1 Message Date
community-scripts-pr-app[bot]andgithub-actions[bot] 33f516930b Update CHANGELOG.md (#17859)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 13:07:05 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] bbcea041e7 Update CHANGELOG.md (#17856)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:20:11 +00:00
push-app-to-main[bot] 386bb80e1e Add cinephage (ct) (#17852)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-11 14:19:42 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 61336cd55e Update CHANGELOG.md (#17855)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:18:10 +00:00
CanbiZ (MickLesk) 6b8698fe87 hermesagent: match the relaunched root gateway regardless of interpreter (#17847)
* hermesagent: match the relaunched root gateway regardless of interpreter

Upstream now starts the gateway through its bundled python via runpy, so
the venv-path pattern from #17126 matched nothing and the root gateway
survived; its writes then raced chown -R and aborted the update.

* Clean up comments in hermesagent.sh

Removed comments regarding hermes update and matching patterns.
2026-10-11 14:17:43 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 548e855118 Update CHANGELOG.md (#17853)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 12:03:34 +00:00
CanbiZ (MickLesk) de19f51761 Radicale: install the bcrypt and argon2 extras (#17813)
* Radicale: install the bcrypt and argon2 extras

The update replaces pyproject.toml and the venv, so a bcrypt or argon2
module added by hand was gone afterwards and Radicale refused to start
with htpasswd_encryption = bcrypt, argon2 or autodetect. The service now
runs uv with --extra bcrypt --extra argon2, which upstream already
defines. The update patches existing units and restarts the service.

* Radicale: enable the extras only once the code defines them

argon2 is an extra since v3.5.4 and uv refuses unknown extras, so patching
before the release update broke older installs. Patch after it instead,
and only when pyproject.toml defines the extra.
2026-10-11 14:03:06 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] ad700e9691 Update CHANGELOG.md (#17851)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 11:24:54 +00:00
CanbiZ (MickLesk) 91bc5b3835 docker: take the lxcfs toggle, TCP socket and Compose choice from app variables (#17850)
* docker: take the lxcfs toggle, TCP socket and Compose choice from app variables

var_docker_lxcfs is exported for the core helper; var_docker_tcp_socket
(no/local/all) and var_docker_compose replace the prompts when set, so
the website generator can offer them. Alpine wrote daemon.json through
silent(), which captured the output and left the file empty.

* docker: use var_docker_socket, the name the catalog record already carries
2026-10-11 13:24:31 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 701268bff4 Update CHANGELOG.md (#17849)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 08:28:49 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] c1c7437ddc Update CHANGELOG.md (#17848)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 07:16:36 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 9c11f496c7 Update CHANGELOG.md (#17846)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 07:12:28 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 46196d179e Update CHANGELOG.md (#17844)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 06:50:36 +00:00
petermnt 3035f9216e fix(zigbee2mqtt): preserve backup stream and prevent filename collisions (#17751)
* fix(zigbee2mqtt): preserve backup tar stream in quiet mode

* fix(zigbee2mqtt): avoid backup collisions on repeated updates
2026-10-11 08:50:08 +02:00
9 changed files with 235 additions and 18 deletions
+24
View File
@@ -564,6 +564,30 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
## 2026-10-11
### 🆕 New Scripts
- Cinephage ([#17852](https://github.com/community-scripts/ProxmoxVE/pull/17852))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- hermesagent: match the relaunched root gateway regardless of interpreter [@MickLesk](https://github.com/MickLesk) ([#17847](https://github.com/community-scripts/ProxmoxVE/pull/17847))
- Radicale: install the bcrypt and argon2 extras [@MickLesk](https://github.com/MickLesk) ([#17813](https://github.com/community-scripts/ProxmoxVE/pull/17813))
- fix(zigbee2mqtt): preserve backup stream and prevent filename collisions [@petermnt](https://github.com/petermnt) ([#17751](https://github.com/community-scripts/ProxmoxVE/pull/17751))
- #### ✨ New Features
- docker: take the lxcfs toggle, TCP socket and Compose choice from app variables [@MickLesk](https://github.com/MickLesk) ([#17850](https://github.com/community-scripts/ProxmoxVE/pull/17850))
### 💾 Core
- Add confirm_external_installer [@MickLesk](https://github.com/MickLesk) ([core#130](https://github.com/community-scripts/core/pull/130))
- setup_docker: make LXC resource limits visible to nested containers [@andrebrait](https://github.com/andrebrait) ([core#9](https://github.com/community-scripts/core/pull/9))
- Incus: fix ENABLE_FUSE / TUN vars [@MickLesk](https://github.com/MickLesk) ([core#127](https://github.com/community-scripts/core/pull/127))
- Resolve a uv required-version range to the newest release inside it [@MickLesk](https://github.com/MickLesk) ([core#126](https://github.com/community-scripts/core/pull/126))
- Upgrade MongoDB in place when an app package depends on it [@MickLesk](https://github.com/MickLesk) ([core#128](https://github.com/community-scripts/core/pull/128))
## 2026-10-10
### 🆕 New Scripts
+69
View File
@@ -0,0 +1,69 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/MoldyTaint/Cinephage
APP="Cinephage"
var_tags="${var_tags:-arr;media;torrent;usenet}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-4096}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/cinephage ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "cinephage" "MoldyTaint/Cinephage"; then
msg_info "Stopping Cinephage"
systemctl stop cinephage
msg_ok "Stopped Cinephage"
NODE_VERSION="24" setup_nodejs
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "cinephage" "MoldyTaint/Cinephage" "tarball"
msg_info "Building Cinephage"
cd /opt/cinephage
$STD npm ci
$STD npm run build
$STD npm prune --omit=dev
sed -i "s/^APP_VERSION=.*/APP_VERSION=$(cat ~/.cinephage)/" /opt/cinephage_data/.env
msg_ok "Built Cinephage"
msg_info "Updating Camoufox"
$STD /opt/cinephage/node_modules/.bin/camoufox-js fetch
msg_ok "Updated Camoufox"
msg_info "Starting Cinephage"
systemctl start cinephage
msg_ok "Started Cinephage"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:3000${CL}"
+4
View File
@@ -27,6 +27,10 @@ else
var_disk="${var_disk:-4}"
var_version="${var_version:-13}"
fi
# Only exported variables reach the install through lxc-attach.
export var_docker_socket="${var_docker_socket:-}"
export var_docker_compose="${var_docker_compose:-}"
export var_docker_lxcfs="${var_docker_lxcfs:-}"
header_info "$APP"
variables
+9 -3
View File
@@ -51,8 +51,7 @@ function update_script() {
set -a; source /etc/default/hermes; set +a
/home/hermes/.local/bin/hermes update --yes
'
# See https://github.com/community-scripts/ProxmoxVE/issues/17123
mapfile -t root_gateway_pids < <(ps -eo user=,pid=,args= | awk '$1 == "root" && $0 ~ /\/home\/hermes\/\.hermes\/hermes-agent\/venv\/bin\/python -m hermes_cli\.main gateway run --replace$/ { print $2 }')
mapfile -t root_gateway_pids < <(ps -eo user=,pid=,args= | awk '$1 == "root" && /\/home\/hermes\/\.hermes\// && /hermes_cli[.]main/ && / gateway run --replace$/ { print $2 }')
if ((${#root_gateway_pids[@]})); then
kill -TERM "${root_gateway_pids[@]}"
for pid in "${root_gateway_pids[@]}"; do
@@ -61,7 +60,14 @@ function update_script() {
done
done
fi
chown -R hermes:hermes /home/hermes
if ps -eo user=,args= | awk '$1 == "root" && /\/home\/hermes\/\.hermes\// { found = 1 } END { exit !found }'; then
msg_warn "A root-owned Hermes process is still running; it may keep writing root-owned files"
fi
# A writer racing chown makes files vanish between readdir and chown; one retry covers it.
if ! chown -R hermes:hermes /home/hermes 2>/dev/null; then
sleep 1
chown -R hermes:hermes /home/hermes || msg_warn "Could not take ownership of everything under /home/hermes"
fi
msg_ok "Updated Hermes Agent"
msg_info "Starting Services"
+9 -1
View File
@@ -41,7 +41,7 @@ function update_script() {
if grep -q 'start.sh' /etc/systemd/system/radicale.service; then
sed -i -e '/^Description/i[Unit]' \
-e '\|^ExecStart|iWorkingDirectory=/opt/radicale' \
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
systemctl daemon-reload
fi
if [[ ! -f /etc/radicale/config ]]; then
@@ -70,6 +70,14 @@ EOF
msg_ok "Started service"
msg_ok "Updated Successfully!"
fi
if grep -q 'uv run -m radicale' /etc/systemd/system/radicale.service && grep -q '^argon2 *=' /opt/radicale/pyproject.toml; then
msg_info "Enabling bcrypt/argon2 support"
sed -i 's|uv run -m radicale|uv run --extra bcrypt --extra argon2 -m radicale|' /etc/systemd/system/radicale.service
systemctl daemon-reload
systemctl restart radicale
msg_ok "Enabled bcrypt/argon2 support"
fi
exit
}
+6 -2
View File
@@ -49,8 +49,12 @@ update_deb_based() {
ensure_dependencies zstd
mkdir -p /opt/backups
BACKUP_VERSION="$(<"$HOME/.zigbee2mqtt")"
BACKUP_FILE="/opt/backups/${APP}_backup_${BACKUP_VERSION}.tar.zst"
$STD tar -cf - -C /opt zigbee2mqtt | zstd -q -o "$BACKUP_FILE"
BACKUP_FILE="$(mktemp "/opt/backups/${APP}_backup_${BACKUP_VERSION}_XXXXXX.tar.zst")"
tar -cf - -C /opt zigbee2mqtt | $STD zstd -q -f -o "$BACKUP_FILE" || {
local backup_exit_code=$?
rm -f "$BACKUP_FILE"
return "$backup_exit_code"
}
ls -t /opt/backups/${APP}_backup_*.tar.zst 2>/dev/null | tail -n +6 | xargs -r rm -f
msg_ok "Backup Created (${BACKUP_VERSION})"
+84
View File
@@ -0,0 +1,84 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/MoldyTaint/Cinephage
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
python3 \
libasound2t64 \
libgtk-3-0t64 \
libx11-xcb1 \
xvfb
msg_ok "Installed Dependencies"
setup_ffmpeg
NODE_VERSION="24" setup_nodejs
fetch_and_deploy_gh_release "cinephage" "MoldyTaint/Cinephage" "tarball"
msg_info "Building Cinephage"
cd /opt/cinephage
$STD npm ci
$STD npm run build
$STD npm prune --omit=dev
msg_ok "Built Cinephage"
msg_info "Installing Camoufox"
$STD /opt/cinephage/node_modules/.bin/camoufox-js fetch
msg_ok "Installed Camoufox"
msg_info "Configuring Cinephage"
mkdir -p /opt/cinephage_data/indexers/custom /opt/cinephage_data/external-lists/custom
cat <<EOF >/opt/cinephage_data/.env
NODE_ENV=production
HOST=0.0.0.0
PORT=3000
APP_VERSION=$(cat ~/.cinephage)
BETTER_AUTH_SECRET=$(openssl rand -base64 32)
DATA_DIR=/opt/cinephage_data
INDEXER_DEFINITIONS_PATH=/opt/cinephage/data/indexers/definitions
INDEXER_CUSTOM_DEFINITIONS_PATH=/opt/cinephage_data/indexers/custom
EXTERNAL_LISTS_PRESETS_PATH=/opt/cinephage/data/external-lists/presets
EXTERNAL_LISTS_CUSTOM_PRESETS_PATH=/opt/cinephage_data/external-lists/custom
CAPTCHA_ADDON_PATH=/opt/cinephage/src/lib/server/captcha/browser/addon
FFPROBE_PATH=/usr/bin/ffprobe
EOF
chmod 600 /opt/cinephage_data/.env
msg_ok "Configured Cinephage"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/cinephage.service
[Unit]
Description=Cinephage
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/cinephage
EnvironmentFile=/opt/cinephage_data/.env
Environment=NODE_OPTIONS=--max-old-space-size=2048
ExecStart=/usr/bin/node server.js
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now cinephage
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc
+29 -11
View File
@@ -15,12 +15,16 @@ update_os
setup_deb_based() {
setup_docker
read -r -p "${TAB3}Expose Docker TCP socket (insecure) ? [n = No, l = Local only (127.0.0.1), a = All interfaces (0.0.0.0)] <n/l/a>: " socket_choice
if [[ -n "${var_docker_socket:-}" ]]; then
socket_choice="$var_docker_socket"
else
read -r -p "${TAB3}Expose Docker TCP socket (insecure) ? [n = No, l = Local only (127.0.0.1), a = All interfaces (0.0.0.0)] <n/l/a>: " socket_choice
fi
case "${socket_choice,,}" in
l)
l | local)
socket="tcp://127.0.0.1:2375"
;;
a)
a | all)
socket="tcp://0.0.0.0:2375"
;;
*)
@@ -66,8 +70,12 @@ setup_alpine() {
msg_ok "Installed Docker"
DOCKER_COMPOSE_LATEST_VERSION=$(get_latest_github_release "docker/compose" false)
read -r -p "${TAB3}Would you like to add Docker Compose? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
if [[ -n "${var_docker_compose:-}" ]]; then
prompt="$var_docker_compose"
else
read -r -p "${TAB3}Would you like to add Docker Compose? <y/N> " prompt
fi
if [[ "${prompt,,}" =~ ^(y|yes|true)$ ]]; then
msg_info "Installing Docker Compose $DOCKER_COMPOSE_LATEST_VERSION"
DOCKER_CONFIG=${DOCKER_CONFIG:-$HOME/.docker}
mkdir -p "$DOCKER_CONFIG"/cli-plugins
@@ -75,13 +83,23 @@ setup_alpine() {
chmod +x "$DOCKER_CONFIG"/cli-plugins/docker-compose
msg_ok "Installed Docker Compose $DOCKER_COMPOSE_LATEST_VERSION"
fi
read -r -p "${TAB3}Would you like to expose the Docker TCP socket? <y/N> " prompt
if [[ "${prompt,,}" =~ ^(y|yes)$ ]]; then
msg_info "Exposing Docker TCP socket"
$STD mkdir -p /etc/docker
$STD echo '{ "hosts": ["unix:///var/run/docker.sock", "tcp://0.0.0.0:2375"] }' >/etc/docker/daemon.json
if [[ -n "${var_docker_socket:-}" ]]; then
prompt="$var_docker_socket"
else
read -r -p "${TAB3}Would you like to expose the Docker TCP socket? <y/N> " prompt
fi
case "${prompt,,}" in
y | yes | a | all) socket="tcp://0.0.0.0:2375" ;;
l | local) socket="tcp://127.0.0.1:2375" ;;
*) socket="" ;;
esac
if [[ -n "$socket" ]]; then
msg_info "Exposing Docker TCP socket on $socket"
mkdir -p /etc/docker
# No $STD here: silent() captures stdout, which left daemon.json empty.
printf '{ "hosts": ["unix:///var/run/docker.sock", "%s"] }\n' "$socket" >/etc/docker/daemon.json
$STD rc-service docker restart
msg_ok "Exposed Docker TCP socket at tcp://+:2375"
msg_ok "Exposed Docker TCP socket on $socket"
fi
}
+1 -1
View File
@@ -58,7 +58,7 @@ Requires=network.target
[Service]
WorkingDirectory=/opt/radicale
ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config
ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config
Restart=on-failure
# User=radicale
# Deny other users access to the calendar data