Commit Graph

3473 Commits

Author SHA1 Message Date
thieneret f884cb704b update authentik to 2026.8.0 (#16674) 2026-08-22 06:30:52 +02:00
push-app-to-main[bot] b99e7a3774 Add pve-ups (ct) (#16670)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-08-22 06:30:33 +02:00
CanbiZ (MickLesk) d59a673211 docuseal: use DocuSeal's patched PDFium build to fix service start (#16673)
DocuSeal switched to its own PDFium fork (upstream commit "adjust pdfium",
2026-08-15) and now attaches functions that only exist in that build, e.g.
FPDFPage_GetAnnotCountRaw from the added fpdf_annots_raw.h. The generic
bblanchon/pdfium-binaries library the script installed does not export them,
so lib/pdfium.rb raises FFI::NotFoundError while Rails eager-loads and both
docuseal.service and docuseal-sidekiq.service fail to start:

  Unable to load application: FFI::NotFoundError: Function
  'FPDFPage_GetAnnotCountRaw' not found in [libpdfium.so]

Install the library from docusealco/pdfium-binaries instead, matching the
upstream Dockerfile. It is only published as a musl build (DocuSeal's image is
Alpine based), so the musl runtime is installed and its library directory is
added to the loader search path - the shared object needs "libc.so" (musl) at
dlopen time. Verified on glibc: the library loads, resolves the raw annotation
functions and renders pages correctly.

The update path now refreshes PDFium too, so existing containers are repaired
by running "update" even when DocuSeal itself is already up to date.
2026-08-22 06:30:08 +02:00
Tobias 6a2dfe1421 fix: wallos (#16666) 2026-08-22 00:39:29 +02:00
Tobias a0f3f809e2 fix: barassistant compatibility with v6 (#16665) 2026-08-21 21:27:24 +02:00
CanbiZ (MickLesk) 288a40e96f immichframe: strip invalid UUID placeholders from default Settings.yml (#16660) 2026-08-21 10:37:12 +02:00
CanbiZ (MickLesk) 9d8b78daca openziti-controller: redirect stdin from /dev/null to skip postinst's interactive bootstrap prompt (#16650) 2026-08-21 08:08:33 +02:00
CanbiZ (MickLesk) d2fe695c49 immich: split jpegli into its own build step, resolve library revisions dynamically (#16656) 2026-08-21 07:55:32 +02:00
CanbiZ (MickLesk) a4542eacb3 tdarr: make unzip non-interactive to prevent hang on repeat/automated updates (#16648) 2026-08-21 07:24:22 +02:00
CanbiZ (MickLesk) a1761d4d6f immich: fix jpegli patch path after upstream base-images split jpegli from libjxl (#16647) 2026-08-21 13:59:15 +10:00
Tobias 888cc8b09f update: various script to debian 13 (#16525) 2026-08-20 14:32:42 +02:00
CanbiZ (MickLesk) 78d29a6de1 storyteller: fix build paths for upstream applications/web/ monorepo restructure (#16627) 2026-08-20 14:32:23 +02:00
Tobias 58e2fa46a6 tubearchivist: add bgutil POT provider and update yt-dlp to nightly (#16622) 2026-08-20 14:32:09 +02:00
CanbiZ (MickLesk) 8276f41ec9 networkoptimizer: preseed iperf3 debconf question to prevent hang install (#16626) 2026-08-20 14:31:54 +02:00
CanbiZ (MickLesk) 1bfcef0c80 scanopy: limit cargo build parallelism to prevent OOM kill (#16623) 2026-08-20 14:28:22 +02:00
CanbiZ (MickLesk) 7c1e07123a baikal: fall back to composer update when lock doesn't match (#16625) 2026-08-20 14:27:41 +02:00
push-app-to-main[bot] b93c3b9dae Umbraco (#16621)
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
Co-authored-by: Tobias <96661824+CrazyWolf13@users.noreply.github.com>
2026-08-20 14:27:23 +02:00
Brad Schroth e6ade07071 fix: clean yarn cache after mealie frontend build to prevent disk growth (#16609) 2026-08-19 21:42:34 +02:00
Tim Moore decda83256 VictoriaMetrics: use github_api_call for release lookups so GITHUB_TOKEN is honored (#16607)
The release-tag resolution used raw unauthenticated curl calls, which
ignore GITHUB_TOKEN and fail with curl exit 22 on the shared 60/hr
unauthenticated rate limit - after the container is already created.
Resolve via the existing github_api_call helper (auth + retries +
rate-limit diagnosis), matching proxmox-backup-server-install.sh.
Also collapses the two identical VictoriaLogs /releases/latest calls
into one.

Fixes community-scripts/ProxmoxVE#16606

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-19 21:41:41 +02:00
CanbiZ (MickLesk) 0e0ba4bfb3 romm: add missing /decode and /cache Angie locations for multi-file downloads (#16589) 2026-08-18 19:38:19 +02:00
CanbiZ (MickLesk) 78f381d8a9 odoo: use patched wkhtmltopdf build, apt's is missing --header-html/--footer-html support (#16590) 2026-08-18 23:55:34 +10:00
CanbiZ (MickLesk) 92e72e4137 Breaking Change: Migrate all "Alpine" Scripts to Normal CT's (#16587) 2026-08-18 12:38:22 +02:00
CanbiZ (MickLesk) e683dd92e7 patchmon: fetch only SCAP datastream XMLs (#16565)
* patchmon: fetch only SCAP datastream XMLs, not the full 2.1GB content archive

* Increase default disk size from 4GB to 8GB
2026-08-17 11:27:25 +02:00
CanbiZ (MickLesk) ee06ad86f1 teslamate: use precompiled Elixir (#16561) 2026-08-17 11:26:34 +02:00
CanbiZ (MickLesk) 7d7db6dd33 keycloak: remove invalid ExecStop, kc.sh has no stop subcommand (#16563) 2026-08-17 11:26:13 +02:00
CanbiZ (MickLesk) b559bcef39 Pin ownfoil release to version 2.3.0 (#16574) 2026-08-17 11:23:12 +02:00
CanbiZ (MickLesk) 4ec4bb26ed kometa: add git, needed by requirements.txt's git dependency (#16562) 2026-08-17 11:22:53 +02:00
Tim Moore 22e2a6d73e fix romm: deploy EmulatorJS and Ruffle after the frontend build (#16571) 2026-08-17 09:23:31 +02:00
Robbie Trencheny 05fdd15406 [FIX] Shelfmark: internal bypasser never starts under the gevent worker (#16495)
* Shelfmark: fix internal bypasser under the gevent worker

The internal captcha bypasser never worked on this install. Shelfmark is served
by gunicorn's GeventWebSocketWorker, and DOCKERMODE controls whether the bypass
browser runs in a helper process "isolated from gunicorn/gevent" (upstream's
_get_via_subprocess). With DOCKERMODE=false the SeleniumBase CDP browser starts
inside the monkey-patched loop, its asyncio websocket never connects, and every
bypass dies at "Pure CDP browser startup timed out after 45s" — searches then
burn their whole retry budget and surface as "mirrors are blocked".

Set DOCKERMODE=true for deployment type 1, and migrate existing installs on
update. The flag is misnamed upstream: it gates gevent isolation, not Docker.

Also drop chromium.service. Nothing in Shelfmark connects to port 9222 — the
bypasser launches its own browser on a random port — so it only consumed
~226MB. With DOCKERMODE enabled it is additionally killed by Shelfmark's
orphan-process reaper (pkill -f chromium) on every bypass and respawned by
systemd, since an LXC shares its PID namespace.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Ln3yVj3sWHG2c6T78W1we

* Shelfmark: address review — one check, drop comments

Collapse the chromium.service removal and the DOCKERMODE migration into the
single internal-bypasser check, as every affected install has both. Guard the
disable so a second update run does not fail on the removed unit, matching
esphome.sh. Drop the explanatory comments.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Ln3yVj3sWHG2c6T78W1we

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-16 20:43:14 +02:00
CanbiZ (MickLesk) fa8e6d5bb7 tracktor: build with pnpm using upstream's frozen lockfile (#16530) 2026-08-16 20:28:36 +02:00
CanbiZ (MickLesk) cb09223b37 networkoptimizer: also build uwnspeedtest binary for server arch (#16531) 2026-08-16 21:59:03 +10:00
CanbiZ (MickLesk) 1246048481 Remove: Jeedom (#16536) 2026-08-16 21:57:36 +10:00
CanbiZ (MickLesk) ab88c8decf Remove: Swizzin (#16535) 2026-08-16 12:24:27 +02:00
CanbiZ (MickLesk) 662adaa6d4 Remove: NocoDB (#16533) 2026-08-16 20:22:54 +10:00
push-app-to-main[bot] f4a36e9200 Securo (#16518)
* Add securo (ct)

* fix: src

* securo: enable nginx site via nginx_enable_site helper

Replaces the manual symlink + default removal + restart with the core
helper, which also runs nginx -t before restarting and enables the unit.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: Tobias <96661824+CrazyWolf13@users.noreply.github.com>
Co-authored-by: MickLesk <mickey.leskowitz@gmail.com>
2026-08-15 23:41:31 +02:00
push-app-to-main[bot] a06ca3cf59 ntopng (#16387) 2026-08-15 23:33:58 +02:00
CanbiZ (MickLesk) a566b6b129 adventurelog: remove pnpm build-allowlist override causing pnpm 10.33 conflict (#16478) 2026-08-15 13:36:49 +10:00
CanbiZ (MickLesk) 91dd24f38c PatchMon: add ssg-content (#16481)
* patchmon: fetch SCAP Security Guide content, bump disk default

* patchmon: simplify SCAP content fetch with &&/|| chaining

* patchmon: use fetch_and_deploy_gh_release for SCAP content

* Reintroduce fetch_and_deploy_gh_release for ssg-content
2026-08-15 13:36:27 +10:00
push-app-to-main[bot] cf6e9abfd0 RSS-Bridge (#16471) 2026-08-14 22:12:35 +02:00
CanbiZ (MickLesk) a1c38b514a powerdns: move poweradmin database outside the web root (#16476) 2026-08-14 22:12:12 +02:00
CanbiZ (MickLesk) f096c8b91f projectsend: rewrite for 2.0.0 (Laravel, nginx, MariaDB) (#16477) 2026-08-14 22:11:45 +02:00
CanbiZ (MickLesk) 70dfd66dff paperless-ngx: run services with uv --no-sync to avoid startup network dependency (#16479) 2026-08-14 22:10:54 +02:00
CanbiZ (MickLesk) 7317baddc1 calibre-web: install as package for 0.6.27's src-layout restructure (#16480) 2026-08-14 22:10:34 +02:00
Johann Grobe ade7cadf9b Wanderer: Refactor of Services / Installation / Paths (#16487) 2026-08-14 22:09:54 +02:00
CanbiZ (MickLesk) ca1f0181b2 pelican-panel: set APP_URL to container IP (#16488) 2026-08-14 22:09:22 +02:00
Chris b2997c15ed Homepage v2.0 (#16500) 2026-08-14 22:08:21 +02:00
push-app-to-main[bot] c9413b0ccf GoDoxy (#16470)
* Add godoxy (ct)

* Refactor fetch_and_deploy_gh_release call

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-08-14 16:07:15 +02:00
push-app-to-main[bot] 97c773a435 Mumble (#16474)
* Add mumble (ct)

* Update mumble.sh to source new build function

Removed local core checkout instructions and added new source for build.func.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-08-14 16:07:03 +02:00
push-app-to-main[bot] dd30b01b82 Fleet (#16472)
* Add fleet (ct)

* Clean up comments and source fallback in fleet.sh

Removed local core checkout comments and fallback source.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-08-14 16:03:28 +02:00
push-app-to-main[bot] ab9fb6279f Newt (#16473)
* Add newt (ct)

* Modify build function source and var_arm64 default

Updated source for build function and changed default value for var_arm64.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-08-14 15:57:31 +02:00