Compare commits

..

1 Commits

Author SHA1 Message Date
MickLesk
0a8426d0c0 navidrome: restore data folder ownership on install and update
Upstream's deb postinstall runs chown navidrome:navidrome on
/var/lib/navidrome/cache without -R, and only behind an .installed
flag, so it never runs again on an upgrade. Every navidrome command
the packaging invokes as root creates cache content owned by root,
which the service then cannot write as the navidrome user - artwork
that was already cached keeps working while newly resolved album and
playlist covers fail.

Reassert ownership of the data folder after deploying the release.
The music folder is left alone, it is commonly a bind mount.
2026-09-14 16:03:47 +02:00
11 changed files with 56 additions and 365 deletions

View File

@@ -543,25 +543,6 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-09-15
### 🆕 New Scripts
- valhalla ([#17231](https://github.com/community-scripts/ProxmoxVE/pull/17231))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- tracearr: copy packages/emails into the deploy tree [@connorgallopo](https://github.com/connorgallopo) ([#17268](https://github.com/community-scripts/ProxmoxVE/pull/17268))
- Immich: Pin to v3.2.1 [@vhsdream](https://github.com/vhsdream) ([#17264](https://github.com/community-scripts/ProxmoxVE/pull/17264))
### 🧰 Tools
- #### 🔧 Refactor
- Refactor: monitor-all (decide on flag values, not on key presence) [@MickLesk](https://github.com/MickLesk) ([#17261](https://github.com/community-scripts/ProxmoxVE/pull/17261))
## 2026-09-14
### 🆕 New Scripts

View File

@@ -1,6 +0,0 @@
_ __ ____ ____
| | / /___ _/ / /_ ____ _/ / /___ _
| | / / __ `/ / __ \/ __ `/ / / __ `/
| |/ / /_/ / / / / / /_/ / / / /_/ /
|___/\__,_/_/_/ /_/\__,_/_/_/\__,_/

View File

@@ -112,7 +112,7 @@ EOF
msg_ok "Image-processing libraries up to date"
fi
RELEASE="v3.2.1"
RELEASE="v3.2.0"
if check_for_gh_release "Immich" "immich-app/immich" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
if [[ $(cat ~/.immich) > "2.5.1" ]]; then
msg_info "Enabling Maintenance Mode"

View File

@@ -38,6 +38,15 @@ function update_script() {
fetch_and_deploy_gh_release "navidrome" "navidrome/navidrome" "binary"
# The upstream postinstall only chowns the cache directory itself, and only
# on the very first install, so root-owned subdirectories survive upgrades
# and the service can no longer write its artwork there.
if id -u navidrome >/dev/null 2>&1; then
msg_info "Fixing Data Folder Ownership"
chown -R navidrome:navidrome /var/lib/navidrome
msg_ok "Fixed Data Folder Ownership"
fi
msg_info "Starting Services"
systemctl start navidrome
msg_ok "Started Services"

View File

@@ -124,7 +124,7 @@ EOF
$STD pnpm turbo telemetry disable
$STD pnpm turbo run build --no-daemon --filter=@tracearr/shared --filter=@tracearr/server --filter=@tracearr/web
rm -rf /opt/tracearr
mkdir -p /opt/tracearr/{packages/shared,packages/emails,apps/server,apps/web,apps/server/src/db}
mkdir -p /opt/tracearr/{packages/shared,apps/server,apps/web,apps/server/src/db}
cp -rf package.json /opt/tracearr/
cp -rf pnpm-workspace.yaml /opt/tracearr/
cp -rf pnpm-lock.yaml /opt/tracearr/
@@ -134,8 +134,6 @@ EOF
cp -rf apps/web/dist /opt/tracearr/apps/web/dist
cp -rf packages/shared/package.json /opt/tracearr/packages/shared/
cp -rf packages/shared/dist /opt/tracearr/packages/shared/dist
cp -rf packages/emails/package.json /opt/tracearr/packages/emails/
cp -rf packages/emails/dist /opt/tracearr/packages/emails/dist
cp -rf apps/server/src/db/migrations /opt/tracearr/apps/server/src/db/migrations
cp -rf data /opt/tracearr/data
mkdir -p /opt/tracearr/data/image-cache

View File

@@ -1,104 +0,0 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: CrazyWolf13
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/valhalla/valhalla
APP="Valhalla"
var_tags="${var_tags:-mapping;routing}"
var_cpu="${var_cpu:-6}"
var_ram="${var_ram:-6144}"
var_disk="${var_disk:-24}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /etc/systemd/system/valhalla.service ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "prime_server" "kevinkreiser/prime_server"; then
RELEASE="$CHECK_UPDATE_RELEASE"
msg_info "Stopping Service"
systemctl stop valhalla
msg_ok "Stopped Service"
msg_info "Building prime_server ${RELEASE} (Patience)"
rm -rf /tmp/prime_server
$STD git clone --recurse-submodules --depth 1 --branch "$RELEASE" https://github.com/kevinkreiser/prime_server /tmp/prime_server
cd /tmp/prime_server
$STD ./autogen.sh
$STD ./configure
$STD make -j"$(nproc)"
$STD make install
cd /
rm -rf /tmp/prime_server
ldconfig
echo "${RELEASE#v}" >"$HOME/.prime_server"
msg_ok "Built prime_server ${RELEASE}"
msg_info "Starting Service"
systemctl start valhalla
msg_ok "Started Service"
fi
if check_for_gh_release "valhalla" "valhalla/valhalla"; then
RELEASE="$CHECK_UPDATE_RELEASE"
msg_info "Stopping Service"
systemctl stop valhalla
msg_ok "Stopped Service"
msg_info "Fetching Valhalla ${RELEASE} (Patience)"
rm -rf /opt/valhalla
$STD git clone --recurse-submodules --depth 1 --branch "$RELEASE" https://github.com/valhalla/valhalla.git /opt/valhalla
msg_ok "Fetched Valhalla ${RELEASE}"
msg_info "Compiling Valhalla ${RELEASE} (this takes 20-45+ minutes, be patient)"
MEM_MB=$(awk '/MemTotal/{print int($2/1024)}' /proc/meminfo)
BUILD_JOBS=$((MEM_MB / 2000))
[[ $BUILD_JOBS -lt 1 ]] && BUILD_JOBS=1
[[ $BUILD_JOBS -gt $(nproc) ]] && BUILD_JOBS=$(nproc)
cd /opt/valhalla
$STD cmake -B build -DCMAKE_BUILD_TYPE=Release -DENABLE_PYTHON_BINDINGS=OFF -DENABLE_TESTS=OFF -DENABLE_SINGLE_FILES_WERROR=OFF
$STD cmake --build build -- -j"$BUILD_JOBS"
$STD cmake --install build
ldconfig
echo "${RELEASE#v}" >"$HOME/.valhalla"
msg_ok "Compiled Valhalla ${RELEASE}"
msg_info "Starting Service"
systemctl start valhalla
msg_ok "Started Service"
fi
msg_ok "Updated Successfully!\n"
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8002/status${CL}"
echo -e "${INFO}${YW}No routing tiles are built yet. Build them for your region with:${CL}"
echo -e "${TAB}${BGN}/opt/valhalla_data/build-tiles.sh https://download.geofabrik.de/<continent>/<region>-latest.osm.pbf${CL}"

View File

@@ -353,7 +353,7 @@ ML_DIR="${APP_DIR}/machine-learning"
GEO_DIR="${INSTALL_DIR}/geodata"
mkdir -p {"${APP_DIR}","${UPLOAD_DIR}","${GEO_DIR}","${INSTALL_DIR}"/cache}
fetch_and_deploy_gh_release "Immich" "immich-app/immich" "tarball" "v3.2.1" "$SRC_DIR"
fetch_and_deploy_gh_release "Immich" "immich-app/immich" "tarball" "v3.2.0" "$SRC_DIR"
PNPM_VERSION="$(jq -r '.packageManager | split("@")[1] | split("+")[0]' ${SRC_DIR}/package.json)"
export COREPACK_ENABLE_DOWNLOAD_PROMPT=0
NODE_VERSION="24" NODE_MODULE="corepack" setup_nodejs

View File

@@ -19,6 +19,10 @@ msg_ok "Installed Dependencies"
fetch_and_deploy_gh_release "navidrome" "navidrome/navidrome" "binary"
if id -u navidrome >/dev/null 2>&1; then
chown -R navidrome:navidrome /var/lib/navidrome
fi
msg_info "Starting Navidrome"
systemctl enable -q --now navidrome
msg_ok "Started Navidrome"

View File

@@ -67,7 +67,7 @@ cd /opt/tracearr.build
$STD pnpm install --frozen-lockfile --force
$STD pnpm turbo telemetry disable
$STD pnpm turbo run build --no-daemon --filter=@tracearr/shared --filter=@tracearr/server --filter=@tracearr/web
mkdir -p /opt/tracearr/{packages/shared,packages/emails,apps/server,apps/web,apps/server/src/db}
mkdir -p /opt/tracearr/{packages/shared,apps/server,apps/web,apps/server/src/db}
cp -rf package.json /opt/tracearr/
cp -rf pnpm-workspace.yaml /opt/tracearr/
cp -rf pnpm-lock.yaml /opt/tracearr/
@@ -77,8 +77,6 @@ cp -rf apps/server/scripts /opt/tracearr/apps/server/scripts
cp -rf apps/web/dist /opt/tracearr/apps/web/dist
cp -rf packages/shared/package.json /opt/tracearr/packages/shared/
cp -rf packages/shared/dist /opt/tracearr/packages/shared/dist
cp -rf packages/emails/package.json /opt/tracearr/packages/emails/
cp -rf packages/emails/dist /opt/tracearr/packages/emails/dist
cp -rf apps/server/src/db/migrations /opt/tracearr/apps/server/src/db/migrations
cp -rf data /opt/tracearr/data
mkdir -p /opt/tracearr/data/image-cache

View File

@@ -1,187 +0,0 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: CrazyWolf13
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/valhalla/valhalla
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
autoconf \
automake \
ccache \
clang \
clang-tidy \
coreutils \
cmake \
g++ \
gcc \
git \
jq \
lcov \
libboost-all-dev \
libcurl4-openssl-dev \
libczmq-dev \
libgdal-dev \
libgeos++-dev \
libgeos-dev \
libluajit-5.1-dev \
liblz4-dev \
libprotobuf-dev \
libspatialite-dev \
libsqlite3-dev \
libsqlite3-mod-spatialite \
libtool \
libzmq3-dev \
lld \
locales \
luajit \
make \
osmium-tool \
parallel \
pkgconf \
protobuf-compiler \
python3-all-dev \
python3-shapely \
python3-requests \
python3-pip \
spatialite-bin \
unzip \
zlib1g-dev
msg_ok "Installed Dependencies"
PRIME_SERVER_RELEASE=$(get_latest_github_release "kevinkreiser/prime_server" "false")
msg_info "Building prime_server ${PRIME_SERVER_RELEASE} (Patience)"
$STD git clone --recurse-submodules --depth 1 --branch "$PRIME_SERVER_RELEASE" https://github.com/kevinkreiser/prime_server /tmp/prime_server
cd /tmp/prime_server
$STD ./autogen.sh
$STD ./configure
$STD make -j"$(nproc)"
$STD make install
cd /
rm -rf /tmp/prime_server
echo "${PRIME_SERVER_RELEASE#v}" >"$HOME/.prime_server"
msg_ok "Built prime_server"
RELEASE=$(get_latest_github_release "valhalla/valhalla" "false")
msg_info "Cloning Valhalla ${RELEASE} (Patience)"
mkdir -p /opt/valhalla
$STD git clone --recurse-submodules --depth 1 --branch "$RELEASE" https://github.com/valhalla/valhalla.git /opt/valhalla
msg_ok "Cloned Valhalla ${RELEASE}"
msg_info "Compiling Valhalla ${RELEASE} (this takes 20-45+ minutes, be patient)"
MEM_MB=$(awk '/MemTotal/{print int($2/1024)}' /proc/meminfo)
BUILD_JOBS=$((MEM_MB / 2000))
[[ $BUILD_JOBS -lt 1 ]] && BUILD_JOBS=1
[[ $BUILD_JOBS -gt $(nproc) ]] && BUILD_JOBS=$(nproc)
cd /opt/valhalla
$STD cmake -B build -DCMAKE_BUILD_TYPE=Release -DENABLE_PYTHON_BINDINGS=OFF -DENABLE_TESTS=OFF -DENABLE_SINGLE_FILES_WERROR=OFF
$STD cmake --build build -- -j"$BUILD_JOBS"
$STD cmake --install build
ldconfig
echo "${RELEASE#v}" >"$HOME/.valhalla"
msg_ok "Compiled Valhalla ${RELEASE}"
msg_info "Configuring Valhalla"
useradd --system --no-create-home --shell /usr/sbin/nologin valhalla 2>/dev/null || true
mkdir -p /opt/valhalla_data/{valhalla_tiles,pbf}
THREADS=$(nproc)
valhalla_build_config \
--mjolnir-tile-dir /opt/valhalla_data/valhalla_tiles \
--mjolnir-tile-extract /opt/valhalla_data/valhalla_tiles.tar \
--mjolnir-admin /opt/valhalla_data/admins.sqlite \
--mjolnir-timezone /opt/valhalla_data/timezones.sqlite \
--mjolnir-concurrency "$THREADS" \
>/opt/valhalla_data/valhalla.json
cat <<'EOF' >/opt/valhalla_data/build-tiles.sh
#!/usr/bin/env bash
# (Re)builds Valhalla routing tiles from one or more OSM extracts.
# Usage: build-tiles.sh <pbf-url-or-path> [<pbf-url-or-path> ...]
# Example: build-tiles.sh https://download.geofabrik.de/europe/germany-latest.osm.pbf
set -euo pipefail
export PATH="/usr/local/bin:/usr/local/sbin:$PATH"
if [[ $# -eq 0 ]]; then
echo "Usage: $0 <pbf-url-or-path> [<pbf-url-or-path> ...]" >&2
exit 1
fi
DATA_DIR=/opt/valhalla_data
CONFIG="$DATA_DIR/valhalla.json"
mkdir -p "$DATA_DIR/pbf"
FILES=()
for src in "$@"; do
if [[ "$src" == http://* || "$src" == https://* ]]; then
fname="$DATA_DIR/pbf/$(basename "$src")"
echo "Downloading $src"
curl -fL --progress-bar -o "$fname" "$src"
else
fname="$src"
fi
FILES+=("$fname")
done
systemctl stop valhalla
echo "Building admin database"
valhalla_build_admins --config "$CONFIG" "${FILES[@]}"
echo "Building timezone database"
valhalla_build_timezones >"$DATA_DIR/timezones.sqlite"
echo "Building initial tile graph"
valhalla_build_tiles -c "$CONFIG" -e build "${FILES[@]}"
echo "Enhancing tile graph"
valhalla_build_tiles -c "$CONFIG" -s enhance "${FILES[@]}"
echo "Packing tiles into a single extract"
valhalla_build_extract -c "$CONFIG" -v
chown -R valhalla:valhalla "$DATA_DIR"
systemctl start valhalla
echo "Done. Tiles are in $DATA_DIR/valhalla_tiles (and packed at $DATA_DIR/valhalla_tiles.tar)."
EOF
chmod +x /opt/valhalla_data/build-tiles.sh
chown -R valhalla:valhalla /opt/valhalla_data
msg_ok "Configured Valhalla"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/valhalla.service
[Unit]
Description=Valhalla Routing Engine
After=network.target
[Service]
Type=simple
User=valhalla
Group=valhalla
WorkingDirectory=/opt/valhalla_data
ExecStart=/usr/local/bin/valhalla_service /opt/valhalla_data/valhalla.json ${THREADS}
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now valhalla
msg_ok "Created Service"
if [[ -n "${VALHALLA_PBF_URLS:-}" ]]; then
msg_info "Building Initial Tiles from VALHALLA_PBF_URLS (this can take a long time)"
$STD /opt/valhalla_data/build-tiles.sh $VALHALLA_PBF_URLS
msg_ok "Built Initial Tiles"
fi
motd_ssh
customize
cleanup_lxc

View File

@@ -45,8 +45,6 @@ add() {
excluded_instances=("$@")
echo "Excluded instances: ${excluded_instances[@]}"
value_of() { sed -n "s/^$1:[[:space:]]*//p" <<<"$config" | head -n1; }
while true; do
for instance in $(pct list | awk 'NR>1 {print $1}'; qm list | awk 'NR>1 {print $1}'); do
@@ -61,21 +59,21 @@ while true; do
if [ -r "/etc/pve/lxc/$instance.conf" ]; then
type="ct"
config_file="/etc/pve/lxc/$instance.conf"
elif [ -r "/etc/pve/qemu-server/$instance.conf" ]; then
else
type="vm"
config_file="/etc/pve/qemu-server/$instance.conf"
else
echo "Skipping $instance because its config is no longer readable"
continue
fi
config=$(sed '/^\[/,$d' "$config_file")
# Both are booleans that Proxmox also writes as 0, so the value decides and
# not the presence of the key.
[ "$(value_of onboot)" = "1" ] && onboot="true" || onboot="false"
[ "$(value_of template)" = "1" ] && template="true" || template="false"
# Skip templates and onboot-disabled
if grep -q "onboot: 0" <<<"$config" || ! grep -q "onboot" <<<"$config"; then
onboot="true"
else
onboot="false"
fi
template=$(grep -q "^template:" <<<"$config" && echo "true" || echo "false")
if [ "$onboot" != "true" ]; then
if [ "$onboot" == "true" ]; then
echo "Skipping $instance because it is set not to boot"
continue
elif [ "$template" == "true" ]; then
@@ -83,40 +81,34 @@ while true; do
continue
fi
# Tags are semicolon separated, so match a whole entry instead of a
# substring of a longer tag such as mon-restart-disabled.
tags=";$(value_of tags | tr -d '[:space:]');"
if [[ "$tags" != *";mon-restart;"* ]]; then
# Check for mon-restart tag
has_tag=$(grep -q "tags:.*mon-restart" <<<"$config" && echo "true" || echo "false")
if [ "$has_tag" != "true" ]; then
echo "Skipping $instance because it does not have 'mon-restart' tag"
continue
fi
# Responsiveness check and restart if needed
if [ "$type" == "vm" ]; then
if ! qm status "$instance" 2>/dev/null | grep -q "status: running"; then
echo "$(date): VM $instance is not running, starting..."
qm start "$instance" >/dev/null 2>&1
elif qm guest cmd "$instance" ping >/dev/null 2>&1; then
# Check if guest agent responds
if qm guest cmd $instance ping >/dev/null 2>&1; then
echo "VM $instance is responsive via guest agent"
else
echo "$(date): VM $instance is not responding to agent ping, restarting..."
qm stop "$instance" >/dev/null 2>&1
sleep 5
qm start "$instance" >/dev/null 2>&1
if qm status $instance | grep -q "status: running"; then
qm stop $instance >/dev/null 2>&1
sleep 5
fi
qm start $instance >/dev/null 2>&1
fi
else
if ! pct status "$instance" 2>/dev/null | grep -q "status: running"; then
echo "$(date): CT $instance is not running, starting..."
pct start "$instance" >/dev/null 2>&1
continue
fi
# Not every container names its interface eth0.
IP=$(pct exec "$instance" -- ip -4 -o addr show scope global 2>/dev/null | awk '{print $4}' | cut -d/ -f1 | head -n1)
if [ -z "$IP" ] || ! ping -c 1 -W 2 "$IP" >/dev/null 2>&1; then
# Container: get IP and ping
IP=$(pct exec $instance ip a s dev eth0 | awk '/inet / {print $2}' | cut -d/ -f1 | head -n1)
if ! ping -c 1 $IP >/dev/null 2>&1; then
echo "$(date): CT $instance is not responding, restarting..."
pct stop "$instance" >/dev/null 2>&1
pct stop $instance >/dev/null 2>&1
sleep 5
pct start "$instance" >/dev/null 2>&1
pct start $instance >/dev/null 2>&1
else
echo "CT $instance is responsive"
fi
@@ -132,18 +124,23 @@ EOF
touch /var/log/ping-instances.log
chmod +x /usr/local/bin/ping-instances.sh
# The service loops with its own five minute sleep, so the timer that earlier
# versions installed could only ever start a unit that was already running.
if [[ -f /etc/systemd/system/ping-instances.timer ]]; then
systemctl disable -q --now ping-instances.timer 2>/dev/null || true
rm -f /etc/systemd/system/ping-instances.timer
fi
cat <<EOF >/etc/systemd/system/ping-instances.timer
[Unit]
Description=Delay ping-instances.service by 5 minutes
[Timer]
OnBootSec=300
OnUnitActiveSec=300
[Install]
WantedBy=timers.target
EOF
cat <<EOF >/etc/systemd/system/ping-instances.service
[Unit]
Description=Ping instances every 5 minutes and restart if necessary
After=pve-cluster.service
Wants=pve-cluster.service
After=ping-instances.timer
Requires=ping-instances.timer
[Service]
Type=simple
@@ -161,6 +158,7 @@ WantedBy=multi-user.target
EOF
systemctl daemon-reload
systemctl enable -q --now ping-instances.timer
systemctl enable -q --now ping-instances.service
clear
echo -e "\n Monitor All installed."
@@ -169,7 +167,7 @@ EOF
}
remove() {
systemctl disable -q --now ping-instances.timer 2>/dev/null || true
systemctl disable -q --now ping-instances.timer
systemctl disable -q --now ping-instances.service
rm -f /etc/systemd/system/ping-instances.service
rm -f /etc/systemd/system/ping-instances.timer