diff --git a/.github/changelogs/2026/07.md b/.github/changelogs/2026/07.md index 2ecd58f89..36a2207bc 100644 --- a/.github/changelogs/2026/07.md +++ b/.github/changelogs/2026/07.md @@ -1,3 +1,173 @@ +## 2026-07-18 + +### 💾 Core + + - #### ✨ New Features + + - core: add configurable host CA inheritance during bootstrap [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15840](https://github.com/community-scripts/ProxmoxVE/pull/15840)) + + - #### 🔧 Refactor + + - tools.func: Safe Delete Directorys & Update PYTHON_VERSION with setup_uv [@MickLesk](https://github.com/MickLesk) ([#15870](https://github.com/community-scripts/ProxmoxVE/pull/15870)) + +### 🧰 Tools + + - #### ✨ New Features + + - [tools.update-lxcs] feat: optional reporting success/failures to heathchecks.io (or others) [@sir106](https://github.com/sir106) ([#15701](https://github.com/community-scripts/ProxmoxVE/pull/15701)) + +## 2026-07-17 + +### 🆕 New Scripts + + - Invidious ([#15824](https://github.com/community-scripts/ProxmoxVE/pull/15824)) +- OxiCloud ([#15823](https://github.com/community-scripts/ProxmoxVE/pull/15823)) + +### 🚀 Updated Scripts + + - #### 🐞 Bug Fixes + + - webtrees: initialize database schema before admin user creation [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15837](https://github.com/community-scripts/ProxmoxVE/pull/15837)) + - Fix DocuSeal missing Leptonica deps on install and update [@Copilot](https://github.com/Copilot) ([#15858](https://github.com/community-scripts/ProxmoxVE/pull/15858)) + - apache-guacamole: detect installed extensions during update [@TowyTowy](https://github.com/TowyTowy) ([#15841](https://github.com/community-scripts/ProxmoxVE/pull/15841)) + - CLIProxyAPI: fix update deleting config.yaml [@austinpilz](https://github.com/austinpilz) ([#15834](https://github.com/community-scripts/ProxmoxVE/pull/15834)) + - esphome: install libusb-1.0-0 for ESP-IDF native builds [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15838](https://github.com/community-scripts/ProxmoxVE/pull/15838)) + + - #### ✨ New Features + + - AFFiNE: Bump to 0.27.0 [@MickLesk](https://github.com/MickLesk) ([#15848](https://github.com/community-scripts/ProxmoxVE/pull/15848)) + - n8n: unpin / use latest release [@MickLesk](https://github.com/MickLesk) ([#15817](https://github.com/community-scripts/ProxmoxVE/pull/15817)) + - Pin Opencloud to v7.3.0 [@vhsdream](https://github.com/vhsdream) ([#15826](https://github.com/community-scripts/ProxmoxVE/pull/15826)) + + - #### 🔧 Refactor + + - SFTPGo: Update APT Repo & Re-Enable Script [@MickLesk](https://github.com/MickLesk) ([#15829](https://github.com/community-scripts/ProxmoxVE/pull/15829)) + +### 💾 Core + + - #### ✨ New Features + + - tools.func: enhance rbenv with profile updates / bundle in bashrc [@MickLesk](https://github.com/MickLesk) ([#15822](https://github.com/community-scripts/ProxmoxVE/pull/15822)) + - feat(build.func): notify users when already on a pinned script version [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15819](https://github.com/community-scripts/ProxmoxVE/pull/15819)) + + - #### 💥 Breaking Changes + + - MongoDB: Implement kernel version check and patch [@MickLesk](https://github.com/MickLesk) ([#15821](https://github.com/community-scripts/ProxmoxVE/pull/15821)) + +### 🧰 Tools + + - #### ✨ New Features + + - update-lxc: autoremove and autoclean after apt full-upgrade [@soupy-boy](https://github.com/soupy-boy) ([#15831](https://github.com/community-scripts/ProxmoxVE/pull/15831)) + +## 2026-07-16 + +### 🆕 New Scripts + + - Sync-In ([#15812](https://github.com/community-scripts/ProxmoxVE/pull/15812)) +- Beaverhabits ([#15813](https://github.com/community-scripts/ProxmoxVE/pull/15813)) +- Notediscovery ([#15811](https://github.com/community-scripts/ProxmoxVE/pull/15811)) + +### 🚀 Updated Scripts + + - #### 🐞 Bug Fixes + + - Pin Immich to v3.0.3 [@vhsdream](https://github.com/vhsdream) ([#15790](https://github.com/community-scripts/ProxmoxVE/pull/15790)) + +## 2026-07-15 + +### 🆕 New Scripts + + - Nexterm ([#15688](https://github.com/community-scripts/ProxmoxVE/pull/15688)) + +### 🚀 Updated Scripts + + - #### 🐞 Bug Fixes + + - 2fauth: minor fixes for 8.0.0 [@MickLesk](https://github.com/MickLesk) ([#15795](https://github.com/community-scripts/ProxmoxVE/pull/15795)) + - SnapOtter: refactor update process to prebuild [@MickLesk](https://github.com/MickLesk) ([#15797](https://github.com/community-scripts/ProxmoxVE/pull/15797)) + +### 💾 Core + + - #### 🔧 Refactor + + - tools.func: default Docker setup to official repo [@MickLesk](https://github.com/MickLesk) ([#15794](https://github.com/community-scripts/ProxmoxVE/pull/15794)) + +## 2026-07-14 + +### 🆕 New Scripts + + - Grav ([#15773](https://github.com/community-scripts/ProxmoxVE/pull/15773)) +- Yuvomi ([#15772](https://github.com/community-scripts/ProxmoxVE/pull/15772)) + +### 🚀 Updated Scripts + + - #### 🐞 Bug Fixes + + - Lychee: Preserve uploads and ownership during update [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15768](https://github.com/community-scripts/ProxmoxVE/pull/15768)) + - Wanderer: Clean deploy and install plugins for v0.20.0 update [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15759](https://github.com/community-scripts/ProxmoxVE/pull/15759)) + - FileFlows: Handle update API 401, force update, and Node install [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15766](https://github.com/community-scripts/ProxmoxVE/pull/15766)) + - BirdNET-Go: Match new upstream release asset naming [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15758](https://github.com/community-scripts/ProxmoxVE/pull/15758)) + - [Upstream Fix] Immich: Fix loader priority [@vhsdream](https://github.com/vhsdream) ([#15755](https://github.com/community-scripts/ProxmoxVE/pull/15755)) + + - #### ✨ New Features + + - Bump OpenCloud version to v7.2.2 [@MickLesk](https://github.com/MickLesk) ([#15769](https://github.com/community-scripts/ProxmoxVE/pull/15769)) + - Silverbullet: Add optional Runtime API install via Chromium [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15761](https://github.com/community-scripts/ProxmoxVE/pull/15761)) + + - #### 💥 Breaking Changes + + - Pangolin: Bump to 1.20.0 | BREAKING: Switch to PostgreSQL [@MickLesk](https://github.com/MickLesk) ([#15682](https://github.com/community-scripts/ProxmoxVE/pull/15682)) + + - #### 🔧 Refactor + + - AFFiNE: Pin to v0.26.3 [@MickLesk](https://github.com/MickLesk) ([#15782](https://github.com/community-scripts/ProxmoxVE/pull/15782)) + +## 2026-07-13 + +### 🆕 New Scripts + + - LeafWiki ([#15748](https://github.com/community-scripts/ProxmoxVE/pull/15748)) + +### 🚀 Updated Scripts + + - #### 🐞 Bug Fixes + + - fix(hyperion): keep service running after container reboot [@TowyTowy](https://github.com/TowyTowy) ([#15653](https://github.com/community-scripts/ProxmoxVE/pull/15653)) + - Change sign-in URL to admin URL in affine.sh [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15741](https://github.com/community-scripts/ProxmoxVE/pull/15741)) + - immich: use actual PostgreSQL version for VectorChord package lookup [@mnavon](https://github.com/mnavon) ([#15705](https://github.com/community-scripts/ProxmoxVE/pull/15705)) + - fix storyteller release selection for stable web tags [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15736](https://github.com/community-scripts/ProxmoxVE/pull/15736)) + - Docmost: Fix update procedure [@MickLesk](https://github.com/MickLesk) ([#15732](https://github.com/community-scripts/ProxmoxVE/pull/15732)) + - fix(shinobi): remove obsolete --unsafe-perm npm flag [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15730](https://github.com/community-scripts/ProxmoxVE/pull/15730)) + + - #### 💥 Breaking Changes + + - reitti: update to v5 [@CrazyWolf13](https://github.com/CrazyWolf13) ([#15635](https://github.com/community-scripts/ProxmoxVE/pull/15635)) + +### 💾 Core + + - #### 🐞 Bug Fixes + + - fix(build.func): parse script status without jq dependency [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15729](https://github.com/community-scripts/ProxmoxVE/pull/15729)) + + - #### 🔧 Refactor + + - tools.func: some improvements (sql injection / command injection / guard) [@MickLesk](https://github.com/MickLesk) ([#15661](https://github.com/community-scripts/ProxmoxVE/pull/15661)) + +## 2026-07-12 + +### 🆕 New Scripts + + - AFFiNE ([#15690](https://github.com/community-scripts/ProxmoxVE/pull/15690)) + +### 🚀 Updated Scripts + + - Immich: Bump version to 3.0.2 [@vhsdream](https://github.com/vhsdream) ([#15668](https://github.com/community-scripts/ProxmoxVE/pull/15668)) + +### ❔ Uncategorized + + - fix(immich): correct Python indentation error in ct/immich.sh heredoc patch [@Copilot](https://github.com/Copilot) ([#15723](https://github.com/community-scripts/ProxmoxVE/pull/15723)) + ## 2026-07-11 ### 🆕 New Scripts diff --git a/CHANGELOG.md b/CHANGELOG.md index ab484bb31..2b3332fdf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -77,6 +77,9 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit + + + @@ -90,7 +93,7 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
-

July (11 entries)

+

July (18 entries)

[View July 2026 Changelog](.github/changelogs/2026/07.md) @@ -502,6 +505,26 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
+## 2026-07-19 + +## 2026-07-18 + +### 💾 Core + + - #### ✨ New Features + + - core: add configurable host CA inheritance during bootstrap [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15840](https://github.com/community-scripts/ProxmoxVE/pull/15840)) + + - #### 🔧 Refactor + + - tools.func: Safe Delete Directorys & Update PYTHON_VERSION with setup_uv [@MickLesk](https://github.com/MickLesk) ([#15870](https://github.com/community-scripts/ProxmoxVE/pull/15870)) + +### 🧰 Tools + + - #### ✨ New Features + + - [tools.update-lxcs] feat: optional reporting success/failures to heathchecks.io (or others) [@sir106](https://github.com/sir106) ([#15701](https://github.com/community-scripts/ProxmoxVE/pull/15701)) + ## 2026-07-17 ### 🆕 New Scripts @@ -1135,128 +1158,4 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit - chore(ct): sync coredns defaults with PocketBase [@github-actions[bot]](https://github.com/github-actions[bot]) ([#15182](https://github.com/community-scripts/ProxmoxVE/pull/15182)) - chore(ct): sync gatus defaults with PocketBase [@github-actions[bot]](https://github.com/github-actions[bot]) ([#15184](https://github.com/community-scripts/ProxmoxVE/pull/15184)) -- chore(ct): sync bitmagnet defaults with PocketBase [@github-actions[bot]](https://github.com/github-actions[bot]) ([#15183](https://github.com/community-scripts/ProxmoxVE/pull/15183)) - -## 2026-06-18 - -### 🚀 Updated Scripts - - - #### 🐞 Bug Fixes - - - flowise: add deps / uv / python 3.11 [@MickLesk](https://github.com/MickLesk) ([#15177](https://github.com/community-scripts/ProxmoxVE/pull/15177)) - - - #### 💥 Breaking Changes - - - refactor: crafty-controller [@CrazyWolf13](https://github.com/CrazyWolf13) ([#15178](https://github.com/community-scripts/ProxmoxVE/pull/15178)) - -## 2026-06-17 - -### 🚀 Updated Scripts - - - #### 🐞 Bug Fixes - - - kasm: fix release detection [@CrazyWolf13](https://github.com/CrazyWolf13) ([#15151](https://github.com/community-scripts/ProxmoxVE/pull/15151)) - - - #### ✨ New Features - - - trek: update install and upgrade workflow for v3.1.0 [@MickLesk](https://github.com/MickLesk) ([#15165](https://github.com/community-scripts/ProxmoxVE/pull/15165)) - - - #### 💥 Breaking Changes - - - TREK: Pin version [@tremor021](https://github.com/tremor021) ([#15156](https://github.com/community-scripts/ProxmoxVE/pull/15156)) - - - #### 🔧 Refactor - - - chore(paperless-ngx): pin version to prevent v3 update [@tomfrenzel](https://github.com/tomfrenzel) ([#15171](https://github.com/community-scripts/ProxmoxVE/pull/15171)) - -### 🧰 Tools - - - #### 🐞 Bug Fixes - - - immich public proxy: replace npm install with npm ci for consistent dependency installation [@MickLesk](https://github.com/MickLesk) ([#15166](https://github.com/community-scripts/ProxmoxVE/pull/15166)) - -## 2026-06-16 - -### 🆕 New Scripts - - - Feishin ([#15130](https://github.com/community-scripts/ProxmoxVE/pull/15130)) -- Kiwix ([#15131](https://github.com/community-scripts/ProxmoxVE/pull/15131)) -- Add runtime status guard and deleted script stubs [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15125](https://github.com/community-scripts/ProxmoxVE/pull/15125)) - -### 🚀 Updated Scripts - - - #### 🐞 Bug Fixes - - - fix(degoog): use localhost for valkey url [@ethan-hgwr](https://github.com/ethan-hgwr) ([#15149](https://github.com/community-scripts/ProxmoxVE/pull/15149)) - - Fix InvoiceShelf install/update Yarn package manager mismatch [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15141](https://github.com/community-scripts/ProxmoxVE/pull/15141)) - - fix storyteller install failure with yarn 4 corepack [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15140](https://github.com/community-scripts/ProxmoxVE/pull/15140)) - - fix: generate policy-compliant OpenObserve root password [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15137](https://github.com/community-scripts/ProxmoxVE/pull/15137)) - -## 2026-06-15 - -### 🚀 Updated Scripts - - - #### 🐞 Bug Fixes - - - Watcharr: Clean install on update [@tremor021](https://github.com/tremor021) ([#15119](https://github.com/community-scripts/ProxmoxVE/pull/15119)) - - Vaultwarden: extend version check for VaultWarden update [@MickLesk](https://github.com/MickLesk) ([#15105](https://github.com/community-scripts/ProxmoxVE/pull/15105)) - - - #### ✨ New Features - - - degoog: add curl-impersonate to script [@MickLesk](https://github.com/MickLesk) ([#15117](https://github.com/community-scripts/ProxmoxVE/pull/15117)) - -### 💾 Core - - - #### ✨ New Features - - - tools.func: extend mesa-vulkan-drivers and vulkan-tools to installation for ARC GPU's [@MickLesk](https://github.com/MickLesk) ([#15106](https://github.com/community-scripts/ProxmoxVE/pull/15106)) - - - #### 🔧 Refactor - - - core: improve mirror selection and error handling [@MickLesk](https://github.com/MickLesk) ([#15108](https://github.com/community-scripts/ProxmoxVE/pull/15108)) - - core: implement gateway validation for DHCP and static networks [@MickLesk](https://github.com/MickLesk) ([#15107](https://github.com/community-scripts/ProxmoxVE/pull/15107)) - -## 2026-06-14 - -### 🚀 Updated Scripts - - - #### 🐞 Bug Fixes - - - Iinvoiceninja: fix nginx setup assets port [@MickLesk](https://github.com/MickLesk) ([#15090](https://github.com/community-scripts/ProxmoxVE/pull/15090)) - - CheckMK: remove stale backup site before creating new backup during update [@MickLesk](https://github.com/MickLesk) ([#15088](https://github.com/community-scripts/ProxmoxVE/pull/15088)) - - - #### 🔧 Refactor - - - Refactor: Implement backup functions for scripts C-D [@tremor021](https://github.com/tremor021) ([#15096](https://github.com/community-scripts/ProxmoxVE/pull/15096)) - -## 2026-06-13 - -### 🆕 New Scripts - - - BookOrbit ([#15080](https://github.com/community-scripts/ProxmoxVE/pull/15080)) - -### 🚀 Updated Scripts - - - Update authentik version to 2026.5.3 [@thieneret](https://github.com/thieneret) ([#15093](https://github.com/community-scripts/ProxmoxVE/pull/15093)) - - - #### 🐞 Bug Fixes - - - Immich: Update image-processing libraries [@vhsdream](https://github.com/vhsdream) ([#15082](https://github.com/community-scripts/ProxmoxVE/pull/15082)) - - HomeBox: Support v0.26.0 [@tomfrenzel](https://github.com/tomfrenzel) ([#15086](https://github.com/community-scripts/ProxmoxVE/pull/15086)) - - - #### 🔧 Refactor - - - Refactor: Implement backup functions for scripts A-B [@tremor021](https://github.com/tremor021) ([#15075](https://github.com/community-scripts/ProxmoxVE/pull/15075)) - -## 2026-06-12 - -### 🆕 New Scripts - - - Twenty ([#15047](https://github.com/community-scripts/ProxmoxVE/pull/15047)) -- Alpine-Cinny ([#15044](https://github.com/community-scripts/ProxmoxVE/pull/15044)) - -### 💾 Core - - - #### ✨ New Features - - - [core] Implement backup and restore functions [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#15067](https://github.com/community-scripts/ProxmoxVE/pull/15067)) \ No newline at end of file +- chore(ct): sync bitmagnet defaults with PocketBase [@github-actions[bot]](https://github.com/github-actions[bot]) ([#15183](https://github.com/community-scripts/ProxmoxVE/pull/15183)) \ No newline at end of file diff --git a/misc/build.func b/misc/build.func index 53509780f..f22692d42 100644 --- a/misc/build.func +++ b/misc/build.func @@ -1009,6 +1009,7 @@ base_settings() { APT_CACHER=${var_apt_cacher:-""} APT_CACHER_IP=${var_apt_cacher_ip:-""} + INHERIT_HOST_CA="${var_inherit_host_ca:-auto}" # Runtime check: Verify APT cacher is reachable if configured if [[ -n "$APT_CACHER_IP" && "$APT_CACHER" == "yes" ]]; then @@ -1088,7 +1089,7 @@ load_vars_file() { # Allowed var_* keys local VAR_WHITELIST=( - var_apt_cacher var_apt_cacher_ip var_brg var_cpu var_disk var_fuse var_github_token var_gpu var_http_no_proxy var_http_proxy var_keyctl + var_apt_cacher var_apt_cacher_ip var_brg var_cpu var_disk var_fuse var_github_token var_gpu var_http_no_proxy var_http_proxy var_inherit_host_ca var_keyctl var_gateway var_hostname var_ipv6_method var_mac var_mknod var_mount_fs var_mtu var_net var_nesting var_ns var_os var_protection var_pw var_ram var_tags var_timezone var_tun var_unprivileged var_verbose var_version var_vlan var_ssh var_ssh_authorized_key var_container_storage var_template_storage var_searchdomain @@ -1285,6 +1286,12 @@ load_vars_file() { continue fi ;; + var_inherit_host_ca) + if [[ "$var_val" != "yes" && "$var_val" != "no" && "$var_val" != "auto" ]]; then + msg_warn "Invalid host CA inheritance value '$var_val' in $file (must be yes/no/auto), ignoring" + continue + fi + ;; var_container_storage | var_template_storage) # Validate that the storage exists and is active on the current node local _storage_status @@ -1324,7 +1331,7 @@ default_var_settings() { # Allowed var_* keys (alphabetically sorted) # Note: Removed var_ctid (can only exist once), var_ipv6_static (static IPs are unique) local VAR_WHITELIST=( - var_apt_cacher var_apt_cacher_ip var_brg var_cpu var_disk var_fuse var_github_token var_gpu var_http_no_proxy var_http_proxy var_keyctl + var_apt_cacher var_apt_cacher_ip var_brg var_cpu var_disk var_fuse var_github_token var_gpu var_http_no_proxy var_http_proxy var_inherit_host_ca var_keyctl var_gateway var_hostname var_ipv6_method var_mac var_mknod var_mount_fs var_mtu var_net var_nesting var_ns var_os var_protection var_pw var_ram var_tags var_timezone var_tun var_unprivileged var_verbose var_version var_vlan var_ssh var_ssh_authorized_key var_container_storage var_template_storage @@ -1407,6 +1414,7 @@ var_ssh=no # HTTP/HTTPS proxy (optional - for networks requiring a proxy) # var_http_proxy=http://proxy.local:8080 # var_http_no_proxy=localhost,127.0.0.1,.local +# var_inherit_host_ca=auto # Features/Tags/verbosity var_fuse=no @@ -1507,7 +1515,7 @@ get_app_defaults_path() { if ! declare -p VAR_WHITELIST >/dev/null 2>&1; then # Note: Removed var_ctid (can only exist once), var_ipv6_static (static IPs are unique) declare -ag VAR_WHITELIST=( - var_apt_cacher var_apt_cacher_ip var_brg var_cpu var_disk var_fuse var_github_token var_gpu var_http_no_proxy var_http_proxy var_keyctl + var_apt_cacher var_apt_cacher_ip var_brg var_cpu var_disk var_fuse var_github_token var_gpu var_http_no_proxy var_http_proxy var_inherit_host_ca var_keyctl var_gateway var_hostname var_ipv6_method var_mac var_mknod var_mount_fs var_mtu var_net var_nesting var_ns var_os var_protection var_pw var_ram var_tags var_timezone var_tun var_unprivileged var_verbose var_version var_vlan var_ssh var_ssh_authorized_key var_container_storage var_template_storage var_searchdomain @@ -1657,6 +1665,7 @@ _build_current_app_vars_tmp() { _apt_cacher_ip="${APT_CACHER_IP:-}" _http_proxy="${HTTP_PROXY:-${var_http_proxy:-}}" _http_no_proxy="${HTTP_NO_PROXY:-${var_http_no_proxy:-}}" + _inherit_host_ca="${INHERIT_HOST_CA:-${var_inherit_host_ca:-auto}}" _fuse="${ENABLE_FUSE:-no}" _tun="${ENABLE_TUN:-no}" _gpu="${ENABLE_GPU:-no}" @@ -1710,6 +1719,7 @@ _build_current_app_vars_tmp() { [ -n "$_apt_cacher_ip" ] && echo "var_apt_cacher_ip=$(_sanitize_value "$_apt_cacher_ip")" [ -n "$_http_proxy" ] && echo "var_http_proxy=$(_sanitize_value "$_http_proxy")" [ -n "$_http_no_proxy" ] && echo "var_http_no_proxy=$(_sanitize_value "$_http_no_proxy")" + [ -n "$_inherit_host_ca" ] && echo "var_inherit_host_ca=$(_sanitize_value "$_inherit_host_ca")" [ -n "$_fuse" ] && echo "var_fuse=$(_sanitize_value "$_fuse")" [ -n "$_tun" ] && echo "var_tun=$(_sanitize_value "$_tun")" @@ -1874,7 +1884,7 @@ advanced_settings() { TAGS="community-script${var_tags:+;${var_tags}}" fi local STEP=1 - local MAX_STEP=30 + local MAX_STEP=31 # Store values for back navigation - inherit from var_* app defaults local _ct_type="${var_unprivileged:-1}" @@ -1896,6 +1906,7 @@ advanced_settings() { local _apt_cacher_ip="${var_apt_cacher_ip:-}" local _http_proxy="${var_http_proxy:-}" local _http_no_proxy="${var_http_no_proxy:-}" + local _inherit_host_ca="${var_inherit_host_ca:-auto}" local _mtu="${var_mtu:-}" local _sd="${var_searchdomain:-}" local _ns="${var_ns:-}" @@ -2725,9 +2736,47 @@ advanced_settings() { ;; # ═══════════════════════════════════════════════════════════════════════════ - # STEP 25: Container Timezone + # STEP 25: Host CA Inheritance # ═══════════════════════════════════════════════════════════════════════════ 25) + local host_ca_count=0 + local host_ca_dir="/usr/local/share/ca-certificates" + local cert + shopt -s nullglob + for cert in "$host_ca_dir"/*.crt; do + host_ca_count=$((host_ca_count + 1)) + done + shopt -u nullglob + + if [[ $host_ca_count -eq 0 ]]; then + _inherit_host_ca="auto" + ((STEP++)) + continue + fi + + local host_ca_default_flag="" + [[ "$_inherit_host_ca" == "no" ]] && host_ca_default_flag="--defaultno" + if whiptail --backtitle "Proxmox VE Helper Scripts [Step $STEP/$MAX_STEP]" \ + --title "HOST CA INHERITANCE" \ + --ok-button "Next" --cancel-button "Back" \ + $host_ca_default_flag \ + --yesno "\nInherit host CA certificates into this container?\n\nDetected on host: ${host_ca_count} certificate(s) in:\n${host_ca_dir}\n\nRecommended for private PKI / TLS-inspection environments.\n\n(App default: ${var_inherit_host_ca:-auto})" 16 72; then + _inherit_host_ca="yes" + else + if [ $? -eq 1 ]; then + _inherit_host_ca="no" + else + ((STEP--)) + continue + fi + fi + ((STEP++)) + ;; + + # ═══════════════════════════════════════════════════════════════════════════ + # STEP 26: Container Timezone + # ═══════════════════════════════════════════════════════════════════════════ + 26) local tz_hint="$_ct_timezone" [[ -z "$tz_hint" ]] && tz_hint="(empty - will use host timezone)" @@ -2750,9 +2799,9 @@ advanced_settings() { ;; # ═══════════════════════════════════════════════════════════════════════════ - # STEP 26: Container Protection + # STEP 27: Container Protection # ═══════════════════════════════════════════════════════════════════════════ - 26) + 27) local protect_default_flag="--defaultno" [[ "$_protect_ct" == "yes" || "$_protect_ct" == "1" ]] && protect_default_flag="" @@ -2904,6 +2953,7 @@ Leave empty to skip." local apt_display="${_apt_cacher:-no}" [[ "$_apt_cacher" == "yes" && -n "$_apt_cacher_ip" ]] && apt_display="$_apt_cacher_ip" local http_proxy_display="${_http_proxy:-(none)}" + local inherit_ca_display="${_inherit_host_ca:-auto}" local post_install_display="${_post_install:-(none)}" local post_install_warn="" @@ -2934,6 +2984,7 @@ Advanced: Timezone: $tz_display APT Cacher: $apt_display HTTP Proxy: $http_proxy_display + Inherit Host CAs: $inherit_ca_display Verbose: $_verbose Post-Install Script: ${post_install_display}${post_install_warn}" @@ -2979,6 +3030,7 @@ Advanced: APT_CACHER_IP="$_apt_cacher_ip" HTTP_PROXY="$_http_proxy" HTTP_NO_PROXY="$_http_no_proxy" + INHERIT_HOST_CA="$_inherit_host_ca" VERBOSE="$_verbose" var_post_install="$_post_install" @@ -2997,6 +3049,7 @@ Advanced: var_sdn_vnet="$_sdn_vnet" var_http_proxy="$_http_proxy" var_http_no_proxy="$_http_no_proxy" + var_inherit_host_ca="$_inherit_host_ca" # Format optional values [[ -n "$_mtu" ]] && MTU=",mtu=$_mtu" || MTU="" @@ -3945,6 +3998,81 @@ EOF msg_ok "Applied HTTP proxy in container" } +# ------------------------------------------------------------------------------ +# _apply_host_ca_certs_in_container() +# +# - Copies administrator-provided CA certificates from the Proxmox host into the +# container before base package bootstrap +# - Source: /usr/local/share/ca-certificates/*.crt (Debian convention) +# - Refreshes the container trust store when update-ca-certificates is available +# - No-op when no host certificates are present; failures are non-fatal +# ------------------------------------------------------------------------------ +_apply_host_ca_certs_in_container() { + local host_ca_dir="/usr/local/share/ca-certificates" + [[ -z "${CTID:-}" ]] && return 0 + local inherit_host_ca="${INHERIT_HOST_CA:-${var_inherit_host_ca:-auto}}" + + local -a host_certs=() + local cert + shopt -s nullglob + for cert in "$host_ca_dir"/*.crt; do + host_certs+=("$cert") + done + shopt -u nullglob + + [[ ${#host_certs[@]} -eq 0 ]] && return 0 + + case "${inherit_host_ca,,}" in + no | false | 0 | off) + msg_info "Skipping host CA inheritance by configuration" + return 0 + ;; + esac + + msg_info "Inheriting host CA certificates into container" + + local found=${#host_certs[@]} + local copied=0 + local skipped=0 + local cert_name + + pct exec "$CTID" -- mkdir -p /usr/local/share/ca-certificates >/dev/null 2>&1 || { + msg_warn "Failed to create CA certificate directory in container" + return 0 + } + + for cert in "${host_certs[@]}"; do + cert_name="$(basename "$cert")" + if [[ ! -r "$cert" || "$cert_name" != *.crt ]]; then + msg_warn "Skipping invalid or unreadable host CA certificate: ${cert_name}" + skipped=$((skipped + 1)) + continue + fi + + if pct push "$CTID" "$cert" "/usr/local/share/ca-certificates/${cert_name}" >/dev/null 2>&1; then + pct exec "$CTID" -- chmod 644 "/usr/local/share/ca-certificates/${cert_name}" >/dev/null 2>&1 || true + copied=$((copied + 1)) + else + msg_warn "Failed to push host CA certificate: ${cert_name}" + skipped=$((skipped + 1)) + fi + done + + if [[ $copied -eq 0 ]]; then + msg_warn "No host CA certificates were copied (${found} found, ${skipped} skipped)" + return 0 + fi + + local refresh_shell="bash" + [[ "$var_os" == "alpine" ]] && refresh_shell="ash" + + if pct exec "$CTID" -- "$refresh_shell" -c 'command -v update-ca-certificates >/dev/null 2>&1 && update-ca-certificates' >/dev/null 2>&1; then + msg_ok "Inherited ${copied} host CA certificate(s) and updated trust store (${skipped} skipped)" + else + msg_warn "Copied ${copied} host CA certificate(s), but trust store update failed or update-ca-certificates is unavailable (${skipped} skipped)" + fi +} + # ------------------------------------------------------------------------------ # build_container() # @@ -4565,6 +4693,7 @@ EOF local install_exit_code=0 _apply_http_proxy_in_container + _apply_host_ca_certs_in_container # Continue with standard container setup if [ "$var_os" == "alpine" ]; then diff --git a/tools/pve/cron-update-lxcs.sh b/tools/pve/cron-update-lxcs.sh index c97975c44..437c7e472 100644 --- a/tools/pve/cron-update-lxcs.sh +++ b/tools/pve/cron-update-lxcs.sh @@ -116,6 +116,9 @@ add() { # Add container IDs to exclude from updates (comma-separated): # EXCLUDE=100,101,102 EXCLUDE= + +# Healthchecks.io Ping URL (optional) +# PING_URL= CONF ok "Created config ${CONF_FILE}" fi @@ -235,9 +238,11 @@ view_cron_config() { fi if [[ -f "$CONF_FILE" ]]; then echo -e " \e[36mConfig file:\e[0m ${CONF_FILE}" - local excludes + local excludes ping_url excludes=$(grep -oP '^\s*EXCLUDE\s*=\s*\K.*' "$CONF_FILE" 2>/dev/null || true) + ping_url=$(grep -oP '^\s*PING_URL\s*=\s*\K.*' "$CONF_FILE" 2>/dev/null | tr -d '"' | tr -d "'" || true) echo -e " \e[36mExcluded:\e[0m ${excludes:-(none)}" + echo -e " \e[36mPing URL:\e[0m ${ping_url:-(none)}" echo "" echo -e " \e[90m--- ${CONF_FILE} ---\e[0m" cat "$CONF_FILE" @@ -284,9 +289,11 @@ show_status() { fi if [[ -f "$CONF_FILE" ]]; then - local excludes + local excludes ping_url excludes=$(grep -oP '^\s*EXCLUDE\s*=\s*\K.*' "$CONF_FILE" 2>/dev/null || echo "(none)") + ping_url=$(grep -oP '^\s*PING_URL\s*=\s*\K.*' "$CONF_FILE" 2>/dev/null | tr -d '"' | tr -d "'" || echo "(none)") echo -e " \e[36mExcluded:\e[0m ${excludes:-"(none)"}" + echo -e " \e[36mPing URL:\e[0m ${ping_url:-"(none)"}" fi if [[ -f "$LOG_FILE" ]]; then diff --git a/tools/pve/update-lxcs-cron.sh b/tools/pve/update-lxcs-cron.sh index d7abc4cae..0e021944a 100644 --- a/tools/pve/update-lxcs-cron.sh +++ b/tools/pve/update-lxcs-cron.sh @@ -11,14 +11,15 @@ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin CONF_FILE="/etc/update-lxcs.conf" - -echo -e "\n $(date)" +LOG_FILE="/var/log/update-lxcs-cron.log" +PING_URL="" # Collect excluded containers from arguments excluded_containers=("$@") -# Merge exclusions from config file if it exists +# Merge exclusions and healthchecks URL from config file if it exists if [[ -f "$CONF_FILE" ]]; then + PING_URL=$(grep -oP '^\s*PING_URL\s*=\s*\K.+' "$CONF_FILE" 2>/dev/null | tr -d '"' | tr -d "'" || true) conf_exclude=$(grep -oP '^\s*EXCLUDE\s*=\s*\K[0-9,]+' "$CONF_FILE" 2>/dev/null || true) IFS=',' read -ra conf_ids <<<"$conf_exclude" for id in "${conf_ids[@]}"; do @@ -27,6 +28,17 @@ if [[ -f "$CONF_FILE" ]]; then done fi +# Overwrite logfile on each run when healthchecks is used +if [[ -n "$PING_URL" ]]; then + true > "$LOG_FILE" +fi + +if [[ -n "$PING_URL" ]]; then + curl -fsS -m 10 --retry 5 "${PING_URL}/start" -o /dev/null 2>/dev/null || true +fi + +echo -e "\n $(date)" + function update_container() { local container=$1 local name @@ -38,12 +50,36 @@ function update_container() { alpine) pct exec "$container" -- ash -c "apk -U upgrade" ;; archlinux) pct exec "$container" -- bash -c "pacman -Syyu --noconfirm" ;; fedora | rocky | centos | alma) pct exec "$container" -- bash -c "dnf -y update && dnf -y upgrade" ;; - ubuntu | debian | devuan) pct exec "$container" -- bash -c "apt-get update && DEBIAN_FRONTEND=noninteractive apt-get -o Dpkg::Options::='--force-confold' dist-upgrade -y; rm -rf /usr/lib/python3.*/EXTERNALLY-MANAGED" ;; + ubuntu | debian | devuan) pct exec "$container" -- bash -c "apt-get update; DEBIAN_FRONTEND=noninteractive apt-get -o Dpkg::Options::='--force-confold' dist-upgrade -y; status=\$?; rm -rf /usr/lib/python3.*/EXTERNALLY-MANAGED || true; exit \$status" ;; opensuse) pct exec "$container" -- bash -c "zypper ref && zypper --non-interactive dup" ;; *) echo " [Warn] Unknown OS type '$os' for container $container, skipping" ;; esac } +update_status=0 + +# Define exit handler to send healthchecks.io status (with logfile on failure/success) +function exit_handler() { + local exit_code=$? + if [[ -n "$PING_URL" ]]; then + sync + if [[ $exit_code -ne 0 || $update_status -ne 0 ]]; then + if [[ -f "$LOG_FILE" ]]; then + curl -fsS -m 10 --retry 5 --data-binary @"$LOG_FILE" "${PING_URL}/fail" -o /dev/null 2>/dev/null || true + else + curl -fsS -m 10 --retry 5 "${PING_URL}/fail" -o /dev/null 2>/dev/null || true + fi + else + if [[ -f "$LOG_FILE" ]]; then + curl -fsS -m 10 --retry 5 --data-binary @"$LOG_FILE" "$PING_URL" -o /dev/null 2>/dev/null || true + else + curl -fsS -m 10 --retry 5 "$PING_URL" -o /dev/null 2>/dev/null || true + fi + fi + fi +} +trap exit_handler EXIT + for container in $(pct list | awk '{if(NR>1) print $1}'); do excluded=false for excluded_container in "${excluded_containers[@]}"; do @@ -65,7 +101,7 @@ for container in $(pct list | awk '{if(NR>1) print $1}'); do echo -e "[Info] Starting $container" pct start "$container" sleep 5 - update_container "$container" || echo " [Error] Update failed for $container" + update_container "$container" || { echo " [Error] Update failed for $container"; update_status=1; } # check if patchmon agent is present in container and run a report if found if pct exec "$container" -- [ -e "/usr/local/bin/patchmon-agent" ]; then echo -e "${BL}[Info]${GN} patchmon-agent found in ${BL} $container ${CL}, triggering report. \n" @@ -74,7 +110,7 @@ for container in $(pct list | awk '{if(NR>1) print $1}'); do echo -e "[Info] Shutting down $container" pct shutdown "$container" --timeout 60 & elif [ "$status" == "status: running" ]; then - update_container "$container" || echo " [Error] Update failed for $container" + update_container "$container" || { echo " [Error] Update failed for $container"; update_status=1; } # check if patchmon agent is present in container and run a report if found if pct exec "$container" -- [ -e "/usr/local/bin/patchmon-agent" ]; then echo -e "${BL}[Info]${GN} patchmon-agent found in ${BL} $container ${CL}, triggering report. \n"