Compare commits

...
Author SHA1 Message Date
CanbiZ (MickLesk) 3e077a2c4a Clean up comments in hermesagent.sh
Removed comments regarding hermes update and matching patterns.
2026-10-11 08:54:11 +02:00
MickLesk 1624512db4 hermesagent: match the relaunched root gateway regardless of interpreter
Upstream now starts the gateway through its bundled python via runpy, so
the venv-path pattern from #17126 matched nothing and the root gateway
survived; its writes then raced chown -R and aborted the update.
2026-10-11 08:52:38 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] c80a171b36 Update CHANGELOG.md (#17840)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 00:05:37 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 699228f646 Archive old changelog entries (#17839)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-11 00:05:12 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 31597fa698 Update CHANGELOG.md (#17838)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 20:49:42 +00:00
push-app-to-main[bot] 0a8c97c765 Add weblate (ct) (#17837)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 22:49:16 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 1bcd22137e Update CHANGELOG.md (#17834)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 14:30:13 +00:00
Johann Grobe 1bc4191951 update endurain repo from codeberg to gh (#17831)
* fix: endurain repo

* fix: endurain release check
2026-10-10 16:29:43 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] d1bad678e9 Update CHANGELOG.md (#17832)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 10:28:07 +00:00
Clayton Faria 2d12d0e0b1 Immich: download countryInfo.txt into the geodata directory on update (#17823) 2026-10-10 12:27:40 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] cd06638952 Update CHANGELOG.md (#17829)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 07:11:43 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 65ee461b14 Update CHANGELOG.md (#17828)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 07:11:20 +00:00
push-app-to-main[bot] 9fdbb10a45 Add certmate (ct) (#17803)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 09:11:09 +02:00
push-app-to-main[bot] e274342a54 Add anythingllm (ct) (#17802)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-10 09:10:51 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 05fd051fb6 Update CHANGELOG.md (#17826)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-10 05:22:40 +00:00
c5c107c374 paperclip: honor custom PAPERCLIP_HOME on update (#17825)
The update path chowned a hardcoded /opt/paperclip-data and always moved
root-run services to a dedicated user. Installs that keep their data
elsewhere (for example an NFS bind mount reachable only by root) failed
with "chown: cannot access '/opt/paperclip-data'" after the rebuild, and a
non-root user could not have reached that data anyway.

Read PAPERCLIP_HOME from the install's .env. Keep the service as root when
it points somewhere other than /opt/paperclip-data, and only chown
/opt/paperclip-data when it is the configured data dir and exists.

Co-authored-by: root <root@paperclip.pilz.dev>
Co-authored-by: Claude <noreply@anthropic.com>
2026-10-10 07:22:13 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 8e11d877b9 Update CHANGELOG.md (#17818)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 19:27:09 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 623a7a1cf2 Update CHANGELOG.md (#17817)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 19:24:33 +00:00
CanbiZ (MickLesk) 969cc5e9b8 FileBrowser Quantum: migrate the config and database to v2 (#17815)
v2.0.0 reads the config strictly and stops at the v1 keys the addon
wrote (server.port, conditionals, indexingIntervalMinutes). It also only
imports the old BoltDB when server.database.migrateFrom names it and no
database.db is left in the working directory. The update now rewrites
the config, renames the database and points migrateFrom at it, keeping
a copy of the v1 config. New installs write the v2 layout.
2026-10-09 21:24:00 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 14cd4cb667 Update CHANGELOG.md (#17814)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 18:44:20 +00:00
Sim Kai Long 63cf41174f OpenCloud: allow OpenCloud to embed Collabora on 26.04.4 (#17810)
Collabora 26.04.4 ignores frame-ancestors set in content_security_policy,
so the editor iframe is blocked. Use net.frame_ancestors (as
opencloud-compose does) on install, and add it on update when missing.
2026-10-09 20:43:49 +02:00
16 changed files with 828 additions and 173 deletions
+187
View File
@@ -1,3 +1,190 @@
## 2026-10-10
### 🆕 New Scripts
- Weblate ([#17837](https://github.com/community-scripts/ProxmoxVE/pull/17837))
- CertMate ([#17803](https://github.com/community-scripts/ProxmoxVE/pull/17803))
- AnythingLLM ([#17802](https://github.com/community-scripts/ProxmoxVE/pull/17802))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- update endurain repo from codeberg to gh [@johanngrobe](https://github.com/johanngrobe) ([#17831](https://github.com/community-scripts/ProxmoxVE/pull/17831))
- Immich: download countryInfo.txt into the geodata directory on update [@claytonfaria](https://github.com/claytonfaria) ([#17823](https://github.com/community-scripts/ProxmoxVE/pull/17823))
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
## 2026-10-09
### 🆕 New Scripts
- FoldingAtHome ([#17799](https://github.com/community-scripts/ProxmoxVE/pull/17799))
- LocalAI ([#17801](https://github.com/community-scripts/ProxmoxVE/pull/17801))
- Tvheadend ([#17800](https://github.com/community-scripts/ProxmoxVE/pull/17800))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
### 💾 Core
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
### 🧰 Tools
- #### ✨ New Features
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
## 2026-10-08
### 🆕 New Scripts
- Unifi-OS-Server VM ([#17752](https://github.com/community-scripts/ProxmoxVE/pull/17752))
- ZimaOS VM ([#17778](https://github.com/community-scripts/ProxmoxVE/pull/17778))
### 🚀 Updated Scripts
- Revert "Immich: Pin to v3.3.0" [@MickLesk](https://github.com/MickLesk) ([#17767](https://github.com/community-scripts/ProxmoxVE/pull/17767))
- #### 🐞 Bug Fixes
- Homarr: replace the musl better-sqlite3 that v2.3.0 ships for Debian [@MickLesk](https://github.com/MickLesk) ([#17789](https://github.com/community-scripts/ProxmoxVE/pull/17789))
- CLIProxyAPI: keep plugins and data across updates [@MickLesk](https://github.com/MickLesk) ([#17790](https://github.com/community-scripts/ProxmoxVE/pull/17790))
- Kima-Hub: install the Python services into a uv venv [@MickLesk](https://github.com/MickLesk) ([#17791](https://github.com/community-scripts/ProxmoxVE/pull/17791))
- #### ✨ New Features
- Immich: Pin to 3.3.0 / Update ML Python to 3.13 [@MickLesk](https://github.com/MickLesk) ([#17770](https://github.com/community-scripts/ProxmoxVE/pull/17770))
- #### 🔧 Refactor
- Refactor: OPNsense VM [@MickLesk](https://github.com/MickLesk) ([#17785](https://github.com/community-scripts/ProxmoxVE/pull/17785))
- Refactor: Nextcloud VM (Turnkey) [@MickLesk](https://github.com/MickLesk) ([#17787](https://github.com/community-scripts/ProxmoxVE/pull/17787))
- Refactor: OpenWrt VM [@MickLesk](https://github.com/MickLesk) ([#17774](https://github.com/community-scripts/ProxmoxVE/pull/17774))
- Refactor: Ubuntu VM [@MickLesk](https://github.com/MickLesk) ([#17776](https://github.com/community-scripts/ProxmoxVE/pull/17776))
### 💾 Core
- Tolerate a missing datacenter.cfg in vm_keyboard_default [@MickLesk](https://github.com/MickLesk) ([core#124](https://github.com/community-scripts/core/pull/124))
- Take the ISO storage from the disk pool when it can hold ISOs [@MickLesk](https://github.com/MickLesk) ([core#122](https://github.com/community-scripts/core/pull/122))
- Shared VM helpers: disk import, releases, checksums, first boot, IP by MAC [@MickLesk](https://github.com/MickLesk) ([core#117](https://github.com/community-scripts/core/pull/117))
- tools: forge truncated release list [@MickLesk](https://github.com/MickLesk) ([core#118](https://github.com/community-scripts/core/pull/118))
- Remember a kept cached image until the upstream changes [@MickLesk](https://github.com/MickLesk) ([core#119](https://github.com/community-scripts/core/pull/119))
- Choose the VM keyboard layout and carry the host's timezone into prepared images [@MickLesk](https://github.com/MickLesk) ([core#120](https://github.com/community-scripts/core/pull/120))
- VM's: run first-boot units without debconf dialogs [@MickLesk](https://github.com/MickLesk) ([core#121](https://github.com/community-scripts/core/pull/121))
## 2026-10-07
### 🆕 New Scripts
- Fedora VM ([#17747](https://github.com/community-scripts/ProxmoxVE/pull/17747))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- AudioMuse-AI: replace the venv on update without asking [@MickLesk](https://github.com/MickLesk) ([#17738](https://github.com/community-scripts/ProxmoxVE/pull/17738))
- paperclip: run as a dedicated non-root user so Claude Code can skip permissions [@samvandenbossche](https://github.com/samvandenbossche) ([#17707](https://github.com/community-scripts/ProxmoxVE/pull/17707))
- Thingsboard: update Java version from 17 to 25 [@CerberusStyle](https://github.com/CerberusStyle) ([#17733](https://github.com/community-scripts/ProxmoxVE/pull/17733))
- #### ✨ New Features
- Immich: Pin to v3.3.0 [@vhsdream](https://github.com/vhsdream) ([#17759](https://github.com/community-scripts/ProxmoxVE/pull/17759))
- #### 💥 Breaking Changes
- OpenCloud: bump to v8.1.0, rebuild search index on upgrade [@SimKaiLong](https://github.com/SimKaiLong) ([#17710](https://github.com/community-scripts/ProxmoxVE/pull/17710))
- #### 🔧 Refactor
- Pangolin: Unpin Release, stable enough, Bump to latest [@MickLesk](https://github.com/MickLesk) ([#17740](https://github.com/community-scripts/ProxmoxVE/pull/17740))
- Refactor: Archlinux-VM [@MickLesk](https://github.com/MickLesk) ([#17741](https://github.com/community-scripts/ProxmoxVE/pull/17741))
- Refactor: MikroTik RouterOS [@MickLesk](https://github.com/MickLesk) ([#17748](https://github.com/community-scripts/ProxmoxVE/pull/17748))
### 💾 Core
- Fix Fedora and BLS cloud image console setup [@MickLesk](https://github.com/MickLesk) ([core#116](https://github.com/community-scripts/core/pull/116))
- Keep setup_nodejs alive when the caller's directory is gone [@MickLesk](https://github.com/MickLesk) ([core#114](https://github.com/community-scripts/core/pull/114))
## 2026-10-06
### 🆕 New Scripts
- Pricebuddy ([#17708](https://github.com/community-scripts/ProxmoxVE/pull/17708))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Webtrees: stop serving data/ and the source folders directly [@MickLesk](https://github.com/MickLesk) ([#17724](https://github.com/community-scripts/ProxmoxVE/pull/17724))
### 💾 Core
- Incus: check the architecture on Incus hosts too [@MickLesk](https://github.com/MickLesk) ([core#113](https://github.com/community-scripts/core/pull/113))
- Incus: Pass the app's var_* settings into Incus containers [@MickLesk](https://github.com/MickLesk) ([core#112](https://github.com/community-scripts/core/pull/112))
- Incus: stub storage_content_check on Incus [@MickLesk](https://github.com/MickLesk) ([core#104](https://github.com/community-scripts/core/pull/104))
- Incus: map Proxmox template versions to Incus image names [@MickLesk](https://github.com/MickLesk) ([core#111](https://github.com/community-scripts/core/pull/111))
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
- Incus: show the spinner inside containers again [@MickLesk](https://github.com/MickLesk) ([core#109](https://github.com/community-scripts/core/pull/109))
- Incus: set the hostname with sh, so it works before bash is installed [@MickLesk](https://github.com/MickLesk) ([core#102](https://github.com/community-scripts/core/pull/102))
- Incus: reserve a plain address on Incus, leave the gateway to the network [@MickLesk](https://github.com/MickLesk) ([core#101](https://github.com/community-scripts/core/pull/101))
- Incus: Wait for the network on Alpine OS too [@MickLesk](https://github.com/MickLesk) ([core#105](https://github.com/community-scripts/core/pull/105))
- Incus: do not fail the build when hostname -I is missing [@MickLesk](https://github.com/MickLesk) ([core#103](https://github.com/community-scripts/core/pull/103))
- Incus: Fuse always in unprivileged Containers, attach TUN only when container lacks it [@MickLesk](https://github.com/MickLesk) ([core#108](https://github.com/community-scripts/core/pull/108))
- Incus: accept mode=generated [@MickLesk](https://github.com/MickLesk) ([core#106](https://github.com/community-scripts/core/pull/106))
- Incus: pass the full install environment into Incus containers (quoted) [@MickLesk](https://github.com/MickLesk) ([core#107](https://github.com/community-scripts/core/pull/107))
## 2026-10-05
### 🚀 Updated Scripts
- Point to DevScripts, the renamed ProxmoxVED [@MickLesk](https://github.com/MickLesk) ([#17694](https://github.com/community-scripts/ProxmoxVE/pull/17694))
- #### 🐞 Bug Fixes
- wanderer: set the proxy secret and install plugins in their own directories [@MickLesk](https://github.com/MickLesk) ([#17698](https://github.com/community-scripts/ProxmoxVE/pull/17698))
- discourse: serve stylesheets and repair the update [@MickLesk](https://github.com/MickLesk) ([#17697](https://github.com/community-scripts/ProxmoxVE/pull/17697))
- wikijs: bump Node.js from 24 to 26 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17689](https://github.com/community-scripts/ProxmoxVE/pull/17689))
- jotty: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17688](https://github.com/community-scripts/ProxmoxVE/pull/17688))
### 💾 Core
- Read releases from github.com when the API is rate limited, resume stalled downloads [@MickLesk](https://github.com/MickLesk) ([core#99](https://github.com/community-scripts/core/pull/99))
- Check for template and container storage before the settings menu [@MickLesk](https://github.com/MickLesk) ([core#98](https://github.com/community-scripts/core/pull/98))
- Check /etc/pve before the settings menu [@MickLesk](https://github.com/MickLesk) ([core#97](https://github.com/community-scripts/core/pull/97))
- Check container settings before pct create rejects them [@MickLesk](https://github.com/MickLesk) ([core#96](https://github.com/community-scripts/core/pull/96))
- PVE: Smart Diagnosis - say why a container would not start [@MickLesk](https://github.com/MickLesk) ([core#95](https://github.com/community-scripts/core/pull/95))
- Retry template downloads that pveam reports as done but are not [@MickLesk](https://github.com/MickLesk) ([core#94](https://github.com/community-scripts/core/pull/94))
- Check the OS release against pve-container before creating anything [@MickLesk](https://github.com/MickLesk) ([core#93](https://github.com/community-scripts/core/pull/93))
- Rename "ProxmoxVED"-Links to "DevScripts" [@MickLesk](https://github.com/MickLesk) ([core#91](https://github.com/community-scripts/core/pull/91))
### 🧰 Tools
- #### 🐞 Bug Fixes
- monitor-all: read container IPs from the host side [@jasonobrien](https://github.com/jasonobrien) ([#17686](https://github.com/community-scripts/ProxmoxVE/pull/17686))
## 2026-10-04
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- immich: read the Intel runtime from the pinned release [@MickLesk](https://github.com/MickLesk) ([#17677](https://github.com/community-scripts/ProxmoxVE/pull/17677))
### 💾 Core
- better explain unsupported version & upgrade path for pve [@MickLesk](https://github.com/MickLesk) ([core#86](https://github.com/community-scripts/core/pull/86))
- Quote PostgreSQL identifiers and drop spaces from the creds file name [@MickLesk](https://github.com/MickLesk) ([core#89](https://github.com/community-scripts/core/pull/89))
- Find the default Rust toolchain in current rustup output [@MickLesk](https://github.com/MickLesk) ([core#88](https://github.com/community-scripts/core/pull/88))
## 2026-10-03
### 🆕 New Scripts
+37 -143
View File
@@ -113,6 +113,9 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
@@ -126,7 +129,7 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
<details>
<summary><h4>October (3 entries)</h4></summary>
<summary><h4>October (10 entries)</h4></summary>
[View October 2026 Changelog](.github/changelogs/2026/10.md)
@@ -559,6 +562,24 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-10-11
## 2026-10-10
### 🆕 New Scripts
- Weblate ([#17837](https://github.com/community-scripts/ProxmoxVE/pull/17837))
- CertMate ([#17803](https://github.com/community-scripts/ProxmoxVE/pull/17803))
- AnythingLLM ([#17802](https://github.com/community-scripts/ProxmoxVE/pull/17802))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- update endurain repo from codeberg to gh [@johanngrobe](https://github.com/johanngrobe) ([#17831](https://github.com/community-scripts/ProxmoxVE/pull/17831))
- Immich: download countryInfo.txt into the geodata directory on update [@claytonfaria](https://github.com/claytonfaria) ([#17823](https://github.com/community-scripts/ProxmoxVE/pull/17823))
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
## 2026-10-09
### 🆕 New Scripts
@@ -569,10 +590,24 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
### 💾 Core
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
### 🧰 Tools
- #### ✨ New Features
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
## 2026-10-08
### 🆕 New Scripts
@@ -1240,145 +1275,4 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
### 📚 Documentation
- issue template: add PVE release, execution context and phase; refresh distro list / pve versions [@MickLesk](https://github.com/MickLesk) ([#17160](https://github.com/community-scripts/ProxmoxVE/pull/17160))
## 2026-09-10
### 🆕 New Scripts
- Chevereto ([#17131](https://github.com/community-scripts/ProxmoxVE/pull/17131))
- Portabase ([#17111](https://github.com/community-scripts/ProxmoxVE/pull/17111))
- Logseq ([#17112](https://github.com/community-scripts/ProxmoxVE/pull/17112))
- Safebucket ([#17096](https://github.com/community-scripts/ProxmoxVE/pull/17096))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Immich v3.2.0 [@vhsdream](https://github.com/vhsdream) ([#17137](https://github.com/community-scripts/ProxmoxVE/pull/17137))
- fix(solidtime): prevent composer install from hanging on root prompt [@supersoju](https://github.com/supersoju) ([#17146](https://github.com/community-scripts/ProxmoxVE/pull/17146))
- fix(hermesagent): wait for root gateway cleanup [@steveonjava](https://github.com/steveonjava) ([#17147](https://github.com/community-scripts/ProxmoxVE/pull/17147))
### 💾 Core
- Keep the script name when regenerating the entrypoint [@MickLesk](https://github.com/MickLesk) ([core#35](https://github.com/community-scripts/core/pull/35))
- Rewrite the dead Gitea base onto GitHub instead of failing the update [@MickLesk](https://github.com/MickLesk) ([core#33](https://github.com/community-scripts/core/pull/33))
- core.func: fall back to a usable HOME when the shell has none [@MickLesk](https://github.com/MickLesk) ([core#32](https://github.com/community-scripts/core/pull/32))
## 2026-09-09
### 🆕 New Scripts
- Lingarr ([#17130](https://github.com/community-scripts/ProxmoxVE/pull/17130))
### 🚀 Updated Scripts
- vm: drop the discussions link from the summary [@MickLesk](https://github.com/MickLesk) ([#17117](https://github.com/community-scripts/ProxmoxVE/pull/17117))
- #### 🐞 Bug Fixes
- fix(hermesagent): stop spurious root gateway after update [@steveonjava](https://github.com/steveonjava) ([#17126](https://github.com/community-scripts/ProxmoxVE/pull/17126))
## 2026-09-08
### 🆕 New Scripts
- Decypharr ([#17108](https://github.com/community-scripts/ProxmoxVE/pull/17108))
- Stash ([#17106](https://github.com/community-scripts/ProxmoxVE/pull/17106))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Update Jellyfin FFmpeg dependency to version 8 [@MickLesk](https://github.com/MickLesk) ([#17109](https://github.com/community-scripts/ProxmoxVE/pull/17109))
### 💾 Core
- Treat a cut-short forge response as a failure, not as HTTP 200 [@MickLesk](https://github.com/MickLesk) ([core#31](https://github.com/community-scripts/core/pull/31))
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#28](https://github.com/community-scripts/core/pull/28))
- cloud-init: drop the "configure in Proxmox UI" hint [@MickLesk](https://github.com/MickLesk) ([core#30](https://github.com/community-scripts/core/pull/30))
- Survive an empty /usr/bin/update instead of aborting the run [@MickLesk](https://github.com/MickLesk) ([core#29](https://github.com/community-scripts/core/pull/29))
## 2026-09-07
### 🆕 New Scripts
- Chatwoot ([#17095](https://github.com/community-scripts/ProxmoxVE/pull/17095))
- whisparr-eros ([#17094](https://github.com/community-scripts/ProxmoxVE/pull/17094))
- Matter-Hub ([#17093](https://github.com/community-scripts/ProxmoxVE/pull/17093))
- Journiv ([#17092](https://github.com/community-scripts/ProxmoxVE/pull/17092))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- kaneo: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17086](https://github.com/community-scripts/ProxmoxVE/pull/17086))
- iobroker: bump Node.js from 24 to 26 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17085](https://github.com/community-scripts/ProxmoxVE/pull/17085))
- reactive-resume: repair any wrong WorkingDirectory on update [@MickLesk](https://github.com/MickLesk) ([#17068](https://github.com/community-scripts/ProxmoxVE/pull/17068))
- mediamtx: keep mediamtx.yml across updates [@MickLesk](https://github.com/MickLesk) ([#17069](https://github.com/community-scripts/ProxmoxVE/pull/17069))
- omnitools: allow remote action while npm ci [@MickLesk](https://github.com/MickLesk) ([#17070](https://github.com/community-scripts/ProxmoxVE/pull/17070))
- #### ✨ New Features
- netboot-xyz: add Secure Boot and Legacy assets [@MickLesk](https://github.com/MickLesk) ([#17066](https://github.com/community-scripts/ProxmoxVE/pull/17066))
- #### 🔧 Refactor
- flatnotes: follow upstream move to uv and Python 3.13 [@MickLesk](https://github.com/MickLesk) ([#17090](https://github.com/community-scripts/ProxmoxVE/pull/17090))
- heimdall: set up PHP 8.4 on update, keep only the database, run migrations [@MickLesk](https://github.com/MickLesk) ([#17067](https://github.com/community-scripts/ProxmoxVE/pull/17067))
### 📂 Github
- github: Open per-script Node bump PRs [@MickLesk](https://github.com/MickLesk) ([#17065](https://github.com/community-scripts/ProxmoxVE/pull/17065))
## 2026-09-06
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Fix Sonarqube update script to add +x on sonar.sh [@jarihu](https://github.com/jarihu) ([#17056](https://github.com/community-scripts/ProxmoxVE/pull/17056))
## 2026-09-05
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- authentik: scope blueprints chown to avoid recursing into the mp0 bind mount [@MickLesk](https://github.com/MickLesk) ([#17008](https://github.com/community-scripts/ProxmoxVE/pull/17008))
- iventoy: run iventoy.sh with bash instead of dash [@MickLesk](https://github.com/MickLesk) ([#17034](https://github.com/community-scripts/ProxmoxVE/pull/17034))
- frigate: restart go2rtc.service before frigate starts [@MickLesk](https://github.com/MickLesk) ([#17035](https://github.com/community-scripts/ProxmoxVE/pull/17035))
- snapotter: seed AI venv base packages on arm64, warn amd64 has no working CPU bundle [@MickLesk](https://github.com/MickLesk) ([#16903](https://github.com/community-scripts/ProxmoxVE/pull/16903))
- tolgee: bump required JDK from 21 to 25 [@MickLesk](https://github.com/MickLesk) ([#17005](https://github.com/community-scripts/ProxmoxVE/pull/17005))
- romm: write real version into backend/__version__.py placeholder [@MickLesk](https://github.com/MickLesk) ([#17009](https://github.com/community-scripts/ProxmoxVE/pull/17009))
- #### 🔧 Refactor
- Refactor FileFlows: Stop Spinner before read -rp / Switch from "Node" to "Agent" [@MickLesk](https://github.com/MickLesk) ([#17007](https://github.com/community-scripts/ProxmoxVE/pull/17007))
### 💾 Core
- update helper: follow renamed ct/ scripts instead of curling a 404 [@MickLesk](https://github.com/MickLesk) ([core#22](https://github.com/community-scripts/core/pull/22))
- Use Proxmox for a template before reaching for linuxcontainers.org [@MickLesk](https://github.com/MickLesk) ([core#23](https://github.com/community-scripts/core/pull/23))
- implement exponential backoff for curl retries in _cs_curl_retry function [@MickLesk](https://github.com/MickLesk) ([core#26](https://github.com/community-scripts/core/pull/26))
### 🧰 Tools
- #### 🐞 Bug Fixes
- update-apps: follow renamed ct/ scripts instead of erroring out [@MickLesk](https://github.com/MickLesk) ([#16991](https://github.com/community-scripts/ProxmoxVE/pull/16991))
## 2026-09-04
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(shlink): preserve servers.json across web-client updates [@Corgei](https://github.com/Corgei) ([#17023](https://github.com/community-scripts/ProxmoxVE/pull/17023))
- fix-update-authentik-2026.8.1 [@thieneret](https://github.com/thieneret) ([#16999](https://github.com/community-scripts/ProxmoxVE/pull/16999))
- Fix npm v12 allow-git/allow-remote restrictions across affected scripts [@MickLesk](https://github.com/MickLesk) ([#17014](https://github.com/community-scripts/ProxmoxVE/pull/17014))
- Fix/poznote - 1st party Docker parity [@lucas-at-3x-eye](https://github.com/lucas-at-3x-eye) ([#17011](https://github.com/community-scripts/ProxmoxVE/pull/17011))
### 💾 Core
- setup_go: resolve bare major.minor versions to the latest patch release [@MickLesk](https://github.com/MickLesk) ([core#24](https://github.com/community-scripts/core/pull/24))
- issue template: add PVE release, execution context and phase; refresh distro list / pve versions [@MickLesk](https://github.com/MickLesk) ([#17160](https://github.com/community-scripts/ProxmoxVE/pull/17160))
+78
View File
@@ -0,0 +1,78 @@
#!/usr/bin/env bash
# Engine comes from community-scripts/core; this repo only ships the scripts.
# A local core checkout wins (COMMUNITY_SCRIPTS_CORE_DIR, else a sibling ../core),
# so a fork or branch of core can be tested without editing this file.
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Mintplex-Labs/anything-llm
APP="AnythingLLM"
var_tags="${var_tags:-ai;rag}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-6144}"
var_disk="${var_disk:-20}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_gpu="${var_gpu:-yes}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/anythingllm ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "anythingllm" "Mintplex-Labs/anything-llm"; then
msg_info "Stopping Services"
systemctl stop anythingllm anythingllm-collector
msg_ok "Stopped Services"
create_backup /opt/anythingllm/server/.env /opt/anythingllm/collector/.env /opt/anythingllm/frontend/.env
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
restore_backup
msg_info "Building AnythingLLM (Patience)"
cd /opt/anythingllm
export PUPPETEER_SKIP_DOWNLOAD=true
export NODE_OPTIONS="--max-old-space-size=3072"
$STD yarn setup
cd /opt/anythingllm/frontend
$STD yarn build
rm -rf /opt/anythingllm/server/public
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
cd /opt/anythingllm/server
$STD npx prisma generate --schema=./prisma/schema.prisma
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
msg_ok "Built AnythingLLM"
msg_info "Starting Services"
systemctl start anythingllm anythingllm-collector
msg_ok "Started Services"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:3001${CL}"
+65
View File
@@ -0,0 +1,65 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: fabriziosalmi
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/fabriziosalmi/certmate
APP="CertMate"
var_tags="${var_tags:-ssl;certificates;acme}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/certmate ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "certmate" "fabriziosalmi/certmate"; then
msg_info "Stopping CertMate"
systemctl stop certmate
msg_ok "Stopped CertMate"
PYTHON_VERSION="3.12" setup_uv
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
msg_info "Installing CertMate Dependencies"
cd /opt/certmate
$STD uv venv --python 3.12 /opt/certmate/.venv
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
$STD /opt/certmate/.venv/bin/certbot --version
msg_ok "Installed CertMate Dependencies"
msg_info "Starting CertMate"
systemctl start certmate
msg_ok "Started CertMate"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8000${CL}"
echo -e "${INFO}${YW}The first page creates the admin account and asks for the API token: grep API_BEARER_TOKEN /opt/certmate_data/.env${CL}"
+2 -2
View File
@@ -30,14 +30,14 @@ function update_script() {
msg_error "No ${APP} installation found!"
exit 233
fi
if check_for_codeberg_release "endurain" "endurain-project/endurain"; then
if check_for_gh_release "endurain" "endurain-project/endurain"; then
msg_info "Stopping Service"
systemctl stop endurain
msg_ok "Stopped Service"
NODE_VERSION="24" setup_nodejs
create_backup /opt/endurain/.env /opt/endurain/frontend/dist/env.js
CLEAN_INSTALL=1 fetch_and_deploy_codeberg_release "endurain" "endurain-project/endurain" "tarball" "latest" "/opt/endurain"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "endurain" "endurain-project/endurain"
msg_info "Updating Endurain Frontend"
cd /opt/endurain
+9 -3
View File
@@ -51,8 +51,7 @@ function update_script() {
set -a; source /etc/default/hermes; set +a
/home/hermes/.local/bin/hermes update --yes
'
# See https://github.com/community-scripts/ProxmoxVE/issues/17123
mapfile -t root_gateway_pids < <(ps -eo user=,pid=,args= | awk '$1 == "root" && $0 ~ /\/home\/hermes\/\.hermes\/hermes-agent\/venv\/bin\/python -m hermes_cli\.main gateway run --replace$/ { print $2 }')
mapfile -t root_gateway_pids < <(ps -eo user=,pid=,args= | awk '$1 == "root" && /\/home\/hermes\/\.hermes\// && /hermes_cli[.]main/ && / gateway run --replace$/ { print $2 }')
if ((${#root_gateway_pids[@]})); then
kill -TERM "${root_gateway_pids[@]}"
for pid in "${root_gateway_pids[@]}"; do
@@ -61,7 +60,14 @@ function update_script() {
done
done
fi
chown -R hermes:hermes /home/hermes
if ps -eo user=,args= | awk '$1 == "root" && /\/home\/hermes\/\.hermes\// { found = 1 } END { exit !found }'; then
msg_warn "A root-owned Hermes process is still running; it may keep writing root-owned files"
fi
# A writer racing chown makes files vanish between readdir and chown; one retry covers it.
if ! chown -R hermes:hermes /home/hermes 2>/dev/null; then
sleep 1
chown -R hermes:hermes /home/hermes || msg_warn "Could not take ownership of everything under /home/hermes"
fi
msg_ok "Updated Hermes Agent"
msg_info "Starting Services"
+1 -1
View File
@@ -329,7 +329,7 @@ EOF
grep -rl /usr/src | xargs -n1 sed -i "s|\/usr/src|$INSTALL_DIR|g"
grep -rlE "'/build'" | xargs -n1 sed -i "s|'/build'|'$APP_DIR'|g"
sed -i "s@\"/cache\"@\"$INSTALL_DIR/cache\"@g" "$ML_DIR"/immich_ml/config.py
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "countryInfo.txt"
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "$GEO_DIR/countryInfo.txt"
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$APP_DIR"/upload
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$ML_DIR"/upload
ln -sfn "$GEO_DIR" "$APP_DIR/geodata"
+9
View File
@@ -31,6 +31,15 @@ function update_script() {
exit
fi
# Collabora 26.04.4 ignores frame-ancestors in content_security_policy; outside the release
# check so installs already on the current release get it too
if [[ -f /etc/coolwsd/coolwsd.xml ]] && ! grep -q '<frame_ancestors[^>]*>[^<[:space:]]' /etc/coolwsd/coolwsd.xml; then
msg_info "Allowing OpenCloud to embed Collabora"
$STD sudo -u cool coolconfig set net.frame_ancestors "$(sed -n 's/^OC_URL=//p' /etc/opencloud/opencloud.env)"
systemctl restart coolwsd
msg_ok "Allowed OpenCloud to embed Collabora"
fi
RELEASE="v8.1.0"
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"
+11 -2
View File
@@ -63,7 +63,13 @@ function update_script() {
# Claude Code refuses --dangerously-skip-permissions as root; migrate existing installs to a dedicated user
PAPERCLIP_USER=$(sed -n 's/^User=//p' /etc/systemd/system/paperclip.service)
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
PAPERCLIP_HOME=$(sed -n 's/^PAPERCLIP_HOME=//p' /opt/paperclip-ai/.env)
PAPERCLIP_HOME="${PAPERCLIP_HOME:-/opt/paperclip-data}"
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]] && [[ "$PAPERCLIP_HOME" != "/opt/paperclip-data" ]]; then
# A custom data dir (e.g. an NFS bind mount) may only be reachable by root; don't move the service off root
msg_warn "PAPERCLIP_HOME is ${PAPERCLIP_HOME}; keeping the service user as root"
PAPERCLIP_USER=root
elif [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
@@ -85,7 +91,10 @@ function update_script() {
fi
PAPERCLIP_USER_HOME=$(getent passwd "$PAPERCLIP_USER" | cut -d: -f6)
chmod 600 /opt/paperclip-ai/.env
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai "$PAPERCLIP_USER_HOME"
if [[ "$PAPERCLIP_HOME" == "/opt/paperclip-data" && -d /opt/paperclip-data ]]; then
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-data
fi
msg_info "Running Database Migrations"
set -a && source /opt/paperclip-ai/.env && set +a
+67
View File
@@ -0,0 +1,67 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/WeblateOrg/weblate
APP="Weblate"
var_tags="${var_tags:-translation;localization}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-3072}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/weblate ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "weblate" "WeblateOrg/weblate"; then
msg_info "Stopping Weblate"
systemctl stop weblate weblate-celery
msg_ok "Stopped Weblate"
PYTHON_VERSION="3.14" setup_uv
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "weblate" "WeblateOrg/weblate" "singlefile" "latest" "/opt/weblate" "weblate-*-py3-none-any.whl"
msg_info "Updating Weblate"
$STD uv pip install --python /opt/weblate/.venv/bin/python --compile-bytecode /opt/weblate/weblate-*.whl "weblate[all,wsgi]"
rm -f /opt/weblate/weblate-*.whl
set -a
source /opt/weblate_data/weblate.env
set +a
$STD /opt/weblate/.venv/bin/weblate migrate --noinput
$STD /opt/weblate/.venv/bin/weblate collectstatic --noinput
msg_ok "Updated Weblate"
msg_info "Starting Weblate"
systemctl start weblate-celery weblate
msg_ok "Started Weblate"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"
+107
View File
@@ -0,0 +1,107 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Mintplex-Labs/anything-llm
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
python3-dev \
libgomp1 \
git \
chromium
msg_ok "Installed Dependencies"
NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs
fetch_and_deploy_gh_release "anythingllm" "Mintplex-Labs/anything-llm" "tarball"
msg_info "Configuring AnythingLLM"
mkdir -p /opt/anythingllm_data/storage
cp -RTn /opt/anythingllm/server/storage /opt/anythingllm_data/storage 2>/dev/null || true
rm -rf /opt/anythingllm/server/storage
ln -sfn /opt/anythingllm_data/storage /opt/anythingllm/server/storage
cat <<EOF >/opt/anythingllm/server/.env
SERVER_PORT=3001
STORAGE_DIR="/opt/anythingllm/server/storage"
JWT_SECRET="$(openssl rand -hex 32)"
SIG_KEY="$(openssl rand -hex 32)"
SIG_SALT="$(openssl rand -hex 32)"
VECTOR_DB="lancedb"
EOF
cat <<EOF >/opt/anythingllm/collector/.env
STORAGE_DIR="/opt/anythingllm/server/storage"
EOF
cat <<EOF >/opt/anythingllm/frontend/.env
VITE_API_BASE='/api'
EOF
msg_ok "Configured AnythingLLM"
msg_info "Building AnythingLLM (Patience)"
cd /opt/anythingllm
export PUPPETEER_SKIP_DOWNLOAD=true
export NODE_OPTIONS="--max-old-space-size=3072"
$STD yarn setup
cd /opt/anythingllm/frontend
$STD yarn build
cp -R /opt/anythingllm/frontend/dist /opt/anythingllm/server/public
cd /opt/anythingllm/server
$STD npx prisma generate --schema=./prisma/schema.prisma
$STD npx prisma migrate deploy --schema=./prisma/schema.prisma
msg_ok "Built AnythingLLM"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/anythingllm.service
[Unit]
Description=AnythingLLM Server
Wants=network-online.target
After=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/anythingllm/server
Environment=NODE_ENV=production
ExecStart=/usr/bin/node index.js
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/anythingllm-collector.service
[Unit]
Description=AnythingLLM Collector
Wants=network-online.target
After=network-online.target anythingllm.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/anythingllm/collector
Environment=NODE_ENV=production
Environment=PUPPETEER_EXECUTABLE_PATH=/usr/bin/chromium
ExecStart=/usr/bin/node index.js
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now anythingllm anythingllm-collector
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc
+69
View File
@@ -0,0 +1,69 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: fabriziosalmi
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/fabriziosalmi/certmate
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
PYTHON_VERSION="3.12" setup_uv
fetch_and_deploy_gh_release "certmate" "fabriziosalmi/certmate" "tarball"
msg_info "Installing CertMate Dependencies"
cd /opt/certmate
$STD uv venv --python 3.12 /opt/certmate/.venv
# requirements.lock is the fully pinned set the official image is built from
$STD uv pip sync --python /opt/certmate/.venv/bin/python requirements.lock
$STD /opt/certmate/.venv/bin/certbot --version
msg_ok "Installed CertMate Dependencies"
msg_info "Configuring CertMate"
mkdir -p /opt/certmate_data/{certificates,data,backups,logs}
cat <<EOF >/opt/certmate_data/.env
API_BEARER_TOKEN=$(openssl rand -hex 32)
SECRET_KEY=$(openssl rand -hex 32)
CERTMATE_BACKUP_PASSPHRASE=$(openssl rand -hex 32)
BEHIND_PROXY=false
EOF
chmod 600 /opt/certmate_data/.env
msg_ok "Configured CertMate"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/certmate.service
[Unit]
Description=CertMate SSL Certificate Manager
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/certmate
Environment=PATH=/opt/certmate/.venv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
Environment=CERTMATE_CERT_DIR=/opt/certmate_data/certificates
Environment=CERTMATE_DATA_DIR=/opt/certmate_data/data
Environment=CERTMATE_BACKUP_DIR=/opt/certmate_data/backups
Environment=CERTMATE_LOGS_DIR=/opt/certmate_data/logs
Environment=ACME_CHALLENGES_DIR=/opt/certmate_data/data/acme-challenges
EnvironmentFile=/opt/certmate_data/.env
# One worker: the renewal scheduler, sessions and rate limits live in-process
ExecStart=/opt/certmate/.venv/bin/gunicorn --bind 0.0.0.0:8000 --workers 1 --threads 8 --timeout 300 --no-control-socket app:app
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now certmate
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc
+1 -1
View File
@@ -21,7 +21,7 @@ PYTHON_VERSION="3.13" setup_uv
NODE_VERSION="24" setup_nodejs
PG_VERSION="17" PG_MODULES="postgis" setup_postgresql
PG_DB_NAME="enduraindb" PG_DB_USER="endurain" setup_postgresql_db
fetch_and_deploy_codeberg_release "endurain" "endurain-project/endurain" "tarball" "latest" "/opt/endurain"
fetch_and_deploy_gh_release "endurain" "endurain-project/endurain"
msg_info "Setting up Endurain"
cd /opt/endurain
+1 -1
View File
@@ -207,7 +207,7 @@ EOF
$STD sudo -u cool coolconfig set ssl.enable false
$STD sudo -u cool coolconfig set ssl.termination true
$STD sudo -u cool coolconfig set ssl.ssl_verification true
sed -i "s|-Policy\">|&frame-ancestors https://${OPENCLOUD_FQDN}|" /etc/coolwsd/coolwsd.xml
$STD sudo -u cool coolconfig set net.frame_ancestors "https://${OPENCLOUD_FQDN}"
useradd -r -M -s /usr/sbin/nologin opencloud
chown -R opencloud:opencloud "$CONFIG_DIR" "$DATA_DIR"
sudo -u opencloud opencloud init --config-path "$CONFIG_DIR" --insecure no
+144
View File
@@ -0,0 +1,144 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/WeblateOrg/weblate
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
pkg-config \
libacl1-dev \
liblz4-dev \
libzstd-dev \
libxxhash-dev \
libssl-dev \
libldap2-dev \
libsasl2-dev \
git \
gettext \
nginx \
valkey-server
msg_ok "Installed Dependencies"
PG_VERSION="17" setup_postgresql
PG_DB_NAME="weblate" PG_DB_USER="weblate" setup_postgresql_db
PYTHON_VERSION="3.14" setup_uv
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "weblate" "WeblateOrg/weblate" "singlefile" "latest" "/opt/weblate" "weblate-*-py3-none-any.whl"
msg_info "Installing Weblate"
$STD uv venv --python 3.14 /opt/weblate/.venv
$STD uv pip install --python /opt/weblate/.venv/bin/python --compile-bytecode /opt/weblate/weblate-*.whl "weblate[all,wsgi]"
rm -f /opt/weblate/weblate-*.whl
msg_ok "Installed Weblate"
msg_info "Configuring Weblate"
mkdir -p /opt/weblate_data/python/customize /app
# weblate.settings_docker is upstream's env-driven settings; it reads the secret and
# settings-override.py from /app/data and loads the "customize" app from DATA_DIR/python
ln -sfn /opt/weblate_data /app/data
touch /opt/weblate_data/python/customize/{__init__,models}.py
/opt/weblate/.venv/bin/weblate-generate-secret-key >/opt/weblate_data/secret
cat <<EOF >/opt/weblate_data/weblate.env
DJANGO_SETTINGS_MODULE=weblate.settings_docker
PYTHONPATH=/opt/weblate_data/python
WEBLATE_SITE_DOMAIN=${LOCAL_IP}
WEBLATE_DATA_DIR=/opt/weblate_data
WEBLATE_CACHE_DIR=/opt/weblate/cache
WEBLATE_IP_PROXY_HEADER=HTTP_X_FORWARDED_FOR
POSTGRES_HOST=127.0.0.1
POSTGRES_DB=weblate
POSTGRES_USER=weblate
POSTGRES_PASSWORD=${PG_DB_PASS}
REDIS_HOST=127.0.0.1
# Password set for the "admin" account at install; Weblate does not read it
WEBLATE_ADMIN_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
EOF
chmod 600 /opt/weblate_data/secret /opt/weblate_data/weblate.env
set -a
source /opt/weblate_data/weblate.env
set +a
$STD /opt/weblate/.venv/bin/weblate migrate --noinput
$STD /opt/weblate/.venv/bin/weblate createadmin --password="${WEBLATE_ADMIN_PASSWORD}"
$STD /opt/weblate/.venv/bin/weblate collectstatic --noinput
msg_ok "Configured Weblate"
msg_info "Configuring Nginx"
cat <<EOF >/etc/nginx/sites-available/weblate
server {
listen 80;
server_name _;
client_max_body_size 1000M;
location = /favicon.ico {
alias /opt/weblate/cache/static/favicon.ico;
expires 30d;
}
location /static/ {
alias /opt/weblate/cache/static/;
expires 30d;
}
location / {
proxy_pass http://127.0.0.1:8888;
proxy_set_header Host \$http_host;
proxy_set_header X-Forwarded-For \$remote_addr;
proxy_set_header X-Forwarded-Proto \$scheme;
proxy_read_timeout 3600;
}
}
EOF
nginx_enable_site "weblate"
msg_ok "Configured Nginx"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/weblate.service
[Unit]
Description=Weblate
After=network.target postgresql.service valkey-server.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/weblate_data
EnvironmentFile=/opt/weblate_data/weblate.env
ExecStart=/opt/weblate/.venv/bin/granian --interface wsgi --host 127.0.0.1 --port 8888 --workers 2 --blocking-threads 8 --backlog 128 --backpressure 16 --runtime-mode mt --workers-max-rss 450 --no-ws weblate.wsgi:application
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/weblate-celery.service
[Unit]
Description=Weblate Celery Worker
After=network.target postgresql.service valkey-server.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/weblate_data
EnvironmentFile=/opt/weblate_data/weblate.env
ExecStart=/opt/weblate/.venv/bin/celery --app=weblate.utils worker --beat --loglevel=info --queues=celery,notify,memory,translate,backup --prefetch-multiplier=1 --concurrency=2
Restart=on-failure
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now weblate weblate-celery
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc
+40 -20
View File
@@ -96,6 +96,27 @@ if [[ -f "$LEGACY_DB" || -f "$LEGACY_BIN" && ! -f "$CONFIG_PATH" ]]; then
fi
fi
# v2 rejects v1 config keys and imports the BoltDB on its first start
migrate_v1_config() {
local dir="/usr/local/community-scripts" db=0
[[ -s "$dir/database.db" && ! -s "$dir/filebrowser.sqlite" ]] && db=1
((db)) || grep -qE 'conditionals:|indexingIntervalMinutes:' "$CONFIG_PATH" || return 0
cp "$CONFIG_PATH" "${CONFIG_PATH}.v1.bak"
((db)) && mv "$dir/database.db" "$dir/database.db.old"
awk -v db="$db" '
{ match($0, /^ */); ind = RLENGTH }
/^[^ #]/ { top = $1 }
cond && ind > ci { print substr($0, 3); next }
{ cond = 0 }
/^[[:space:]]*conditionals:[[:space:]]*$/ { cond = 1; ci = ind; next }
/^[[:space:]]*indexingIntervalMinutes:/ { next }
top == "server:" && /^ port:/ { port = $2; next }
{ print }
/^server:/ && db { print " database:"; print " migrateFrom: \"database.db.old\"" }
END { if (port != "") { print "http:"; print " port: " port } }
' "${CONFIG_PATH}.v1.bak" >"$CONFIG_PATH"
}
# Existing installation
if [[ -f "$INSTALL_PATH" ]]; then
msg_warn "${APP} is already installed."
@@ -126,6 +147,7 @@ if [[ -f "$INSTALL_PATH" ]]; then
mv -f /usr/local/bin/filebrowser-quantum "$INSTALL_PATH"
if [[ -f "$CONFIG_PATH" ]]; then
sed -i '/^\s*disableIndexing:/d' "$CONFIG_PATH"
migrate_v1_config
fi
if [[ "$OS" == "Debian" ]]; then
systemctl restart filebrowser.service
@@ -173,22 +195,21 @@ read -r noauth_prompt
# === YAML CONFIG GENERATION ===
if [[ "${noauth_prompt,,}" =~ ^(y|yes)$ ]]; then
cat <<EOF >"$CONFIG_PATH"
server:
http:
port: $PORT
server:
sources:
- path: "$SRC_DIR"
name: "RootFS"
config:
denyByDefault: false
indexingIntervalMinutes: 240
conditionals:
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth:
methods:
noauth: true
@@ -196,22 +217,21 @@ EOF
msg_ok "Configured with no authentication"
else
cat <<EOF >"$CONFIG_PATH"
server:
http:
port: $PORT
server:
sources:
- path: "$SRC_DIR"
name: "RootFS"
config:
denyByDefault: false
indexingIntervalMinutes: 240
conditionals:
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth:
adminUsername: admin
adminPassword: community-scripts.org