Compare commits

..

8 Commits

Author SHA1 Message Date
github-actions[bot]
976160e5ff Update CHANGELOG.md 2026-09-12 15:17:56 +00:00
community-scripts-pr-app[bot]
95d80a4941 Update CHANGELOG.md (#17217)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-12 15:15:09 +00:00
community-scripts-pr-app[bot]
5f1b71a85e Update CHANGELOG.md (#17213)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-12 12:31:07 +00:00
eXistC
2c6a578343 fix(dispatcharr): add comskip installation and build dependencies (#16224) 2026-09-12 14:30:42 +02:00
community-scripts-pr-app[bot]
b068e7cd8a Update CHANGELOG.md (#17212)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-12 12:25:32 +00:00
Kevin Langhans
02cf8a0a8f feat(jitsi-meet): optional public setup (FQDN, Let's Encrypt, NAT, secure domain) (#17132)
Adds five optional var_jitsi_* settings to the install script. All default
to empty, which keeps the previous LAN-only behaviour (container IP,
self-signed certificate):

- var_jitsi_domain     public hostname instead of the container IP
- var_jitsi_le_email   Let's Encrypt via the packaged debconf option
- var_jitsi_public_ip  static NAT mapping in jvb.conf (JVB 2.3+)
- var_jitsi_admin_user secure domain: only authenticated users create rooms
- var_jitsi_admin_pass password for that user (generated when empty)

Tested on Proxmox VE 9.2 as unprivileged Debian 13 LXC, both with all
variables set (self-signed) and with none set.

Co-authored-by: klanghans <13657862+klanghans@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-12 14:25:09 +02:00
community-scripts-pr-app[bot]
9580c0f5bd Update CHANGELOG.md (#17211)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-12 12:24:23 +00:00
push-app-to-main[bot]
3dbfe54701 Add hammer (ct) (#17189)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-09-12 14:24:00 +02:00
10 changed files with 305 additions and 13 deletions

View File

@@ -544,15 +544,26 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
### 🆕 New Scripts
- gotenberg ([#17205](https://github.com/community-scripts/ProxmoxVE/pull/17205))
- Hammer ([#17189](https://github.com/community-scripts/ProxmoxVE/pull/17189))
- gotenberg ([#17205](https://github.com/community-scripts/ProxmoxVE/pull/17205))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(dispatcharr): add comskip installation and build dependencies [@eXistC](https://github.com/eXistC) ([#16224](https://github.com/community-scripts/ProxmoxVE/pull/16224))
- poznote: serve from src/public docroot [@MickLesk](https://github.com/MickLesk) ([#17187](https://github.com/community-scripts/ProxmoxVE/pull/17187))
- calibre-web: use calibreweb release identifier to avoid version file collision [@MickLesk](https://github.com/MickLesk) ([#17186](https://github.com/community-scripts/ProxmoxVE/pull/17186))
- #### ✨ New Features
- feat(jitsi-meet): optional public setup (FQDN, Let's Encrypt, NAT, secure domain) [@klanghans](https://github.com/klanghans) ([#17132](https://github.com/community-scripts/ProxmoxVE/pull/17132))
### 💾 Core
- VM's: show the selected CPU model instead of doubling it [@MickLesk](https://github.com/MickLesk) ([core#37](https://github.com/community-scripts/core/pull/37))
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#36](https://github.com/community-scripts/core/pull/36))
## 2026-09-11
### 🆕 New Scripts

View File

@@ -106,7 +106,18 @@ EOF
msg_ok "Migrated Nginx Configuration"
fi
ensure_dependencies vlc-bin vlc-plugin-base
ensure_dependencies vlc-bin vlc-plugin-base build-essential autoconf libtool libargtable2-dev libavformat-dev libsdl2-dev libswscale-dev
if ! command -v comskip &> /dev/null; then
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "Comskip" "erikkaashoek/Comskip" "tarball"
msg_info "Compiling Comskip"
cd /opt/Comskip
$STD ./autogen.sh
$STD ./configure
$STD make
$STD make install
msg_ok "Compiled and Installed Comskip"
fi
if check_for_gh_release "Dispatcharr" "Dispatcharr/Dispatcharr"; then
msg_info "Stopping Services"

58
ct/hammer.sh Normal file
View File

@@ -0,0 +1,58 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Darkrock-Studios/hammer-editor
APP="Hammer"
var_tags="${var_tags:-writing;sync-server}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_unprivileged="${var_unprivileged:-1}"
var_arm64="${var_arm64:-yes}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/hammer ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "hammer" "Darkrock-Studios/hammer-editor"; then
msg_info "Stopping Service"
systemctl stop hammer
msg_ok "Stopped Service"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "hammer" "Darkrock-Studios/hammer-editor" "prebuild" "latest" "/opt/hammer" "server.zip"
chmod +x /opt/hammer/bin/server
msg_info "Starting Service"
systemctl start hammer
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8080${CL}"

6
ct/headers/hammer Normal file
View File

@@ -0,0 +1,6 @@
__ __
/ / / /___ _____ ___ ____ ___ ___ _____
/ /_/ / __ `/ __ `__ \/ __ `__ \/ _ \/ ___/
/ __ / /_/ / / / / / / / / / / / __/ /
/_/ /_/\__,_/_/ /_/ /_/_/ /_/ /_/\___/_/

View File

@@ -17,6 +17,14 @@ var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
# Optional public setup, read by the install script (all empty = LAN-only install as before).
# Without the export they never reach the container.
export var_jitsi_domain="${var_jitsi_domain:-}"
export var_jitsi_le_email="${var_jitsi_le_email:-}"
export var_jitsi_public_ip="${var_jitsi_public_ip:-}"
export var_jitsi_admin_user="${var_jitsi_admin_user:-}"
export var_jitsi_admin_pass="${var_jitsi_admin_pass:-}"
header_info "$APP"
variables
color
@@ -50,4 +58,7 @@ description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}https://${IP}${CL}"
echo -e "${GATEWAY}${BGN}https://${var_jitsi_domain:-$IP}${CL}"
if [[ -n "${var_jitsi_domain}" ]]; then
echo -e "${INFO}${YW}Forward TCP 80/443 and UDP 10000 to the container. Secure-domain credentials (if enabled) are in ~/jitsi-meet.creds inside the container.${CL}"
fi

View File

@@ -169,13 +169,9 @@ function update_script() {
if ((BRIDGE_UPDATE == 0)); then
sed -i 's|^ExecStart=.*|ExecStart=uv run --no-sync -- granian --interface asginl --ws --loop uvloop "paperless.asgi:application"|' /etc/systemd/system/paperless-webserver.service
grep -q "document_index reindex" /etc/systemd/system/paperless-webserver.service ||
sed -i '/^ExecStart=/i ExecStartPre=uv run --no-sync -- python manage.py document_index reindex --if-needed --no-progress-bar' /etc/systemd/system/paperless-webserver.service
sed -i '/^ExecStart=/i ExecStartPre=uv run -- python manage.py document_index reindex --if-needed --no-progress-bar' /etc/systemd/system/paperless-webserver.service
$STD systemctl daemon-reload
fi
for svc in consumer scheduler task-queue webserver; do
unit="/etc/systemd/system/paperless-${svc}.service"
[[ -f "$unit" ]] && sed -i 's|uv run -- |uv run --no-sync -- |g' "$unit"
done
$STD systemctl daemon-reload
cd /opt/paperless
$STD uv sync --all-extras
cd /opt/paperless/src

View File

@@ -25,7 +25,13 @@ $STD apt install -y \
procps \
vlc-bin \
vlc-plugin-base \
streamlink
streamlink \
autoconf \
libtool \
libargtable2-dev \
libavformat-dev \
libsdl2-dev \
libswscale-dev
msg_ok "Installed Dependencies"
setup_uv
@@ -33,6 +39,15 @@ NODE_VERSION="24" setup_nodejs
PG_VERSION="16" setup_postgresql
PG_DB_NAME="dispatcharr_db" PG_DB_USER="dispatcharr_usr" setup_postgresql_db
fetch_and_deploy_gh_release "dispatcharr" "Dispatcharr/Dispatcharr" "tarball"
fetch_and_deploy_gh_release "Comskip" "erikkaashoek/Comskip" "tarball"
msg_info "Compiling Comskip"
cd /opt/Comskip
$STD ./autogen.sh
$STD ./configure
$STD make
$STD make install
msg_ok "Compiled and Installed Comskip"
msg_info "Installing Python Dependencies with uv"
cd /opt/dispatcharr

100
install/hammer-install.sh Normal file
View File

@@ -0,0 +1,100 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Darkrock-Studios/hammer-editor
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
unzip \
fontconfig \
libfreetype6
msg_ok "Installed Dependencies"
JAVA_VERSION="21" setup_java
fetch_and_deploy_gh_release "hammer" "Darkrock-Studios/hammer-editor" "prebuild" "latest" "/opt/hammer" "server.zip"
msg_info "Configuring Hammer Sync Server"
chmod +x /opt/hammer/bin/server
mkdir -p /opt/hammer_data
cat <<EOF >/opt/hammer_data/config.toml
# Hammer Sync Server configuration
# Reference: https://github.com/Darkrock-Studios/hammer-editor/blob/develop/docs/HOW-TO-RUN-A-SERVER.md
# Loaded automatically from the data directory. Apply changes with:
# systemctl restart hammer
host = "${LOCAL_IP}"
port = 8080
# Hammer clients speak https only and will not connect to plain HTTP. Either put
# a TLS reverse proxy in front of this port, or let Hammer terminate TLS itself
# with a real certificate (self-signed certs are rejected by the clients).
#
# Behind a reverse proxy on this host, restrict the plain port to loopback and
# set the URL the clients actually use:
# bindHosts = ["127.0.0.1", "::1"]
# publicUrl = "https://hammer.example.com"
#
# Hammer terminating TLS itself:
# sslPort = 443
# [sslCert]
# certChainPath = "/etc/letsencrypt/live/hammer.example.com/fullchain.pem"
# privateKeyPath = "/etc/letsencrypt/live/hammer.example.com/privkey.pem"
# forceHttps = true
# Per-page social share images. fontconfig and libfreetype6 are already installed.
# richLinkPreviews = true
# communityEnabled = true
# Storage defaults to an in-process PostgreSQL under /opt/hammer_data/pgdata.
# To use an external PostgreSQL instead:
# [storage]
# type = "remote"
# [storage.remote]
# host = "db.example.com"
# port = 5432
# database = "hammer"
# user = "hammer"
# password = "change-me"
# useSsl = true
# Regenerable render/preview caches, default <data dir>/cache.
# [cache]
# directory = "/var/tmp/hammer-cache"
# maxSizeMb = 200
EOF
cat <<EOF >/etc/systemd/system/hammer.service
[Unit]
Description=Hammer Sync Server
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/hammer
Environment=SERVER_OPTS=-Duser.home=/opt
ExecStart=/opt/hammer/bin/server
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now hammer
msg_ok "Configured Hammer Sync Server"
motd_ssh
customize
cleanup_lxc

View File

@@ -13,6 +13,29 @@ setting_up_container
network_check
update_os
# Optional public setup. Leave the hostname empty for a LAN-only install
# (container IP, self-signed certificate) - the previous default behaviour.
if [[ -z "${var_jitsi_domain:-}" ]]; then
read -rp "${TAB3}Public hostname (FQDN, leave empty to use the container IP): " var_jitsi_domain || true
fi
var_jitsi_domain="${var_jitsi_domain:-$LOCAL_IP}"
if [[ "$var_jitsi_domain" != "$LOCAL_IP" ]]; then
if [[ -z "${var_jitsi_le_email:-}" ]]; then
read -rp "${TAB3}E-mail for Let's Encrypt (leave empty for a self-signed certificate): " var_jitsi_le_email || true
fi
if [[ -z "${var_jitsi_public_ip:-}" ]]; then
read -rp "${TAB3}Public IP behind NAT (leave empty to detect via STUN): " var_jitsi_public_ip || true
fi
if [[ -z "${var_jitsi_admin_user:-}" ]]; then
read -rp "${TAB3}Admin user for secure domain (leave empty to let anyone create rooms): " var_jitsi_admin_user || true
fi
if [[ -n "${var_jitsi_admin_user:-}" && -z "${var_jitsi_admin_pass:-}" ]]; then
read -rsp "${TAB3}Admin password (leave empty to generate): " var_jitsi_admin_pass || true
echo
fi
fi
msg_info "Installing Dependencies"
$STD apt install -y nginx
msg_ok "Installed Dependencies"
@@ -25,11 +48,72 @@ setup_deb822_repo "jitsi" \
""
msg_info "Installing Jitsi Meet"
echo "jitsi-videobridge2 jitsi-videobridge/jvb-hostname string ${LOCAL_IP}" | debconf-set-selections
echo "jitsi-meet-web-config jitsi-meet/cert-choice select Generate a new self-signed certificate" | debconf-set-selections
echo "jitsi-videobridge2 jitsi-videobridge/jvb-hostname string ${var_jitsi_domain}" | debconf-set-selections
if [[ -n "${var_jitsi_le_email:-}" ]]; then
# acme.sh (used by the packaged Let's Encrypt helper) refuses to install without cron
$STD apt install -y cron
echo "jitsi-meet-web-config jitsi-meet/cert-choice select Let's Encrypt certificates" | debconf-set-selections
echo "jitsi-meet-web-config jitsi-meet/email string ${var_jitsi_le_email}" | debconf-set-selections
else
echo "jitsi-meet-web-config jitsi-meet/cert-choice select Generate a new self-signed certificate" | debconf-set-selections
fi
echo "jitsi-meet-web-config jitsi-meet/jaas-choice boolean false" | debconf-set-selections
DEBIAN_FRONTEND=noninteractive $STD apt install -y jitsi-meet
msg_ok "Installed Jitsi Meet"
if [[ -n "${var_jitsi_public_ip:-}" ]]; then
msg_info "Configuring NAT mapping"
# JVB 2.3+ reads this from jvb.conf; sip-communicator.properties is no longer used
cat <<EOF >>/etc/jitsi/videobridge/jvb.conf
ice4j {
harvest {
mapping {
static-mappings = [
{ local-address = "${LOCAL_IP}", public-address = "${var_jitsi_public_ip}" }
]
}
}
}
EOF
systemctl restart jitsi-videobridge2
msg_ok "Configured NAT mapping"
fi
if [[ -n "${var_jitsi_admin_user:-}" ]]; then
msg_info "Configuring Secure Domain"
# Only authenticated users may create rooms; guests join via the anonymous domain.
# https://jitsi.github.io/handbook/docs/devops-guide/secure-domain/
var_jitsi_admin_pass="${var_jitsi_admin_pass:-$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | cut -c1-16)}"
sed -i "0,/authentication = \"jitsi-anonymous\"/s//authentication = \"internal_hashed\"/" \
"/etc/prosody/conf.avail/${var_jitsi_domain}.cfg.lua"
cat <<EOF >>"/etc/prosody/conf.avail/${var_jitsi_domain}.cfg.lua"
VirtualHost "guest.${var_jitsi_domain}"
authentication = "anonymous"
c2s_require_encryption = false
EOF
cat <<EOF >>/etc/jitsi/jicofo/jicofo.conf
jicofo {
authentication {
enabled = true
type = XMPP
login-url = "${var_jitsi_domain}"
}
}
EOF
sed -i "s|^\s*// anonymousdomain: 'guest.example.com',| anonymousdomain: 'guest.${var_jitsi_domain}',|" \
"/etc/jitsi/meet/${var_jitsi_domain}-config.js"
$STD prosodyctl register "${var_jitsi_admin_user}" "${var_jitsi_domain}" "${var_jitsi_admin_pass}"
cat <<EOF >~/jitsi-meet.creds
Jitsi Meet Secure Domain
Admin User: ${var_jitsi_admin_user}
Admin Password: ${var_jitsi_admin_pass}
Add more users: prosodyctl register <name> ${var_jitsi_domain} <password>
EOF
systemctl restart prosody jicofo jitsi-videobridge2
msg_ok "Configured Secure Domain"
fi
motd_ssh
customize
cleanup_lxc

View File

@@ -151,7 +151,7 @@ Requires=redis.service
[Service]
WorkingDirectory=/opt/paperless/src
#ExecStartPre=uv run --no-sync -- python manage.py document_index reindex --if-needed --no-progress-bar
#ExecStartPre=uv run -- python manage.py document_index reindex --if-needed --no-progress-bar
ExecStart=uv run --no-sync -- granian --interface asginl --ws --loop uvloop "paperless.asgi:application"
Environment=GRANIAN_HOST=::
Environment=GRANIAN_PORT=8000