Compare commits

..

30 Commits

Author SHA1 Message Date
community-scripts-pr-app[bot] 1b581bddea Update CHANGELOG.md (#17202)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 21:41:29 +00:00
push-app-to-main[bot] c1fc07d937 Lemonade-Server (#17190)
* Add lemonade-server (ct)

* Enable ARM64 support by default in script

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-09-11 23:40:58 +02:00
community-scripts-pr-app[bot] c98008cc16 Update CHANGELOG.md (#17201)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 18:12:50 +00:00
thieneret 8713dabc56 update authentik to 2026.8.2 (#17198) 2026-09-11 20:12:18 +02:00
community-scripts-pr-app[bot] 6b30d4462d Update .app files (#17194)
Co-authored-by: GitHub Actions <github-actions[bot]@users.noreply.github.com>
2026-09-11 10:18:07 +02:00
community-scripts-pr-app[bot] fc40e198b6 Update CHANGELOG.md (#17195)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 08:17:34 +00:00
push-app-to-main[bot] b875f780bb Dockhand (#17191)
* Add dockhand (addon)

* Revise copyright and license details in dockhand.sh

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: Tobias <96661824+CrazyWolf13@users.noreply.github.com>
2026-09-11 10:17:05 +02:00
MickLesk 10ab064f26 formatting fix issue report 2026-09-11 08:37:28 +02:00
community-scripts-pr-app[bot] db418a7a3b Update CHANGELOG.md (#17185)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:44:06 +00:00
community-scripts-pr-app[bot] f17a8df641 Update CHANGELOG.md (#17184)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:43:55 +00:00
community-scripts-pr-app[bot] 0fa0a912ac Update CHANGELOG.md (#17183)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:43:37 +00:00
push-app-to-main[bot] b9f7751590 OneTimeSecret (#17097) 2026-09-11 07:43:35 +02:00
community-scripts-pr-app[bot] 7c0283c73f Update CHANGELOG.md (#17182)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:43:29 +00:00
community-scripts-pr-app[bot] 5774100f05 Update CHANGELOG.md (#17181)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:43:11 +00:00
CanbiZ (MickLesk) 73a8c55c9d passwordpusher: restore data before running migrations (#17141) 2026-09-11 07:43:04 +02:00
community-scripts-pr-app[bot] 06115ca811 Update CHANGELOG.md (#17180)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:43:00 +00:00
community-scripts-pr-app[bot] e00429ea7e Update CHANGELOG.md (#17179)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:42:44 +00:00
CanbiZ (MickLesk) de9b2f7ff3 paperclip: install the rust toolchain needed by the runner build (#17142) 2026-09-11 07:42:37 +02:00
community-scripts-pr-app[bot] 2b541531f7 Update CHANGELOG.md (#17178)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:42:32 +00:00
CanbiZ (MickLesk) c001360b2d Rename lxc-delete.sh to guest-delete.sh (#17152) 2026-09-11 07:42:12 +02:00
community-scripts-pr-app[bot] b2f8add60f Update CHANGELOG.md (#17177)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:42:10 +00:00
community-scripts-pr-app[bot] fe26465c2c Update CHANGELOG.md (#17176)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:41:48 +00:00
CanbiZ (MickLesk) 785d33be40 core.func: fall back to a usable HOME when the shell has none (#17154) 2026-09-11 07:41:44 +02:00
community-scripts-pr-app[bot] 28b4ae0b07 Update CHANGELOG.md (#17175)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:41:29 +00:00
CanbiZ (MickLesk) e253713148 homepage: run next directly instead of through pnpm (#17155) 2026-09-11 07:41:21 +02:00
community-scripts-pr-app[bot] 5748b577c4 Update CHANGELOG.md (#17174)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:41:02 +00:00
CanbiZ (MickLesk) 7304dec635 update-apps: rewrite the retired Gitea base in every container before updating it (#17156) 2026-09-11 07:40:57 +02:00
CanbiZ (MickLesk) 28c18b735b issue template: add PVE release, execution context and phase; refresh distro list (#17160) 2026-09-11 07:40:36 +02:00
community-scripts-pr-app[bot] 46a3f05bfb Update CHANGELOG.md (#17173)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-11 05:39:47 +00:00
Tobias 433064a93f changedetection: fix: pin browserless (#17163) 2026-09-11 07:39:20 +02:00
23 changed files with 636 additions and 29 deletions
+72 -19
View File
@@ -5,15 +5,19 @@ body:
- type: markdown
attributes:
value: |
## ⚠️ **IMPORTANT - READ FIRST**
- 🔍 **Search first:** Before submitting, check if the issue has already been reported or resolved in [closed issues](https://github.com/community-scripts/ProxmoxVE/issues?q=is%3Aissue+is%3Aclosed). If found, comment on that issue instead of creating a new one.
Alternatively, check the **[Discussions](https://github.com/community-scripts/ProxmoxVE/discussions)** under the *"Announcement"* or *"Guide"* categories for relevant information.
- 🔎 If you encounter `[ERROR] in line 23: exit code *: while executing command "$@" > /dev/null 2>&1`, rerun the script with verbose mode before submitting the issue.
- 📜 **Read the script:** Familiarize yourself with the script's content and its purpose. This will help you understand the issue better and provide more relevant information
## ⚠️ **IMPORTANT - READ FIRST**
Thank you for taking the time to report an issue! Please provide as much detail as possible to help us address the problem efficiently.
**1. Reproduce the issue with verbose mode - this is mandatory.**
Set `var_verbose=yes` (or *Advanced Settings → Verbose Mode*) and run the script again.
Only a verbose log shows what actually failed - a bare `[ERROR] in line 23: exit code *` tells us nothing.
**Reports without a verbose log will most likely be closed.**
**2. Search before you post.**
Check the [closed issues](https://github.com/community-scripts/ProxmoxVE/issues?q=is%3Aissue+is%3Aclosed) and the [Discussions](https://github.com/community-scripts/ProxmoxVE/discussions) (*Announcement* / *Guide*). If it is already known, comment there instead of opening a new issue.
**3. Read the script.**
Knowing what it does makes it much easier to describe the problem - and often to solve it yourself.
- type: input
id: guidelines
attributes:
@@ -28,7 +32,6 @@ body:
label: 🔎 Did you run the script with verbose mode enabled?
description: "Required for debugging any script issue. A verbose log is mandatory."
options:
- ""
- "Yes, verbose mode was enabled and the output is included below"
- "No (this issue will likely be closed automatically)"
validations:
@@ -50,6 +53,32 @@ body:
validations:
required: true
- type: dropdown
id: issue_phase
attributes:
label: 🕒 When does the issue occur?
options:
- "Initial creation / installation"
- "Update of an existing container"
- "While the application is running"
validations:
required: true
- type: dropdown
id: execution_context
attributes:
label: 🖱️ Where did you run the command?
description: "The shell matters — the Proxmox web console starts without some environment variables that a normal login shell sets."
options:
- "Proxmox web UI → node → Shell"
- "Proxmox web UI → LXC → Console"
- "SSH into the Proxmox host"
- "SSH into the container"
- "pct enter from the host"
- "Other / not listed"
validations:
required: true
- type: checkboxes
validations:
required: true
@@ -64,18 +93,31 @@ body:
value: "💡 **Tip:** If you are using Advanced Settings, please test with Default Settings before submitting an issue."
- type: dropdown
id: linux_distribution
id: os_distribution
attributes:
label: 🖥️ Which Linux distribution are you using?
label: 🖥️ Which Linux distribution is the container running?
options:
-
- Debian
- Ubuntu
- Alpine
- Debian 11
- Debian 12
- Debian 13
- Ubuntu 22.04
- Ubuntu 24.04
- Ubuntu 24.10
- Devuan
- AlmaLinux
- Rocky Linux
- CentOS Stream
- Fedora
- openSUSE
- openEuler
- Gentoo
- Other / not listed
validations:
required: true
- type: input
id: os_version
attributes:
label: 🔢 Which version of that distribution?
description: "Run `cat /etc/os-release` inside the container if unsure."
placeholder: "e.g. 13 (Debian), 24.04 (Ubuntu), 3.22 (Alpine)"
validations:
required: true
@@ -85,16 +127,27 @@ body:
label: 🧱 Is this Proxmox host running arm64?
description: "Run `dpkg --print-architecture` on your Proxmox host if unsure."
options:
- ""
- "No"
- "Yes"
validations:
required: true
- type: dropdown
id: pve_major
attributes:
label: 📈 Which Proxmox VE release are you on?
options:
- "Proxmox VE 9"
- "Proxmox VE 8"
- "Proxmox VE 7 or older (end of life)"
validations:
required: true
- type: input
id: pve_version
attributes:
label: 📈 Which Proxmox version are you on?
label: 🔢 Exact Proxmox version and kernel
description: "Both matter — several issues turned out to be kernel-specific."
placeholder: "run pveversion in your PVE node console"
validations:
required: true
+3
View File
@@ -14,6 +14,9 @@ Fixes #
- [ ] **Tested thoroughly** Changes work as expected.
- [ ] **No security risks** No hardcoded secrets, unnecessary privilege escalations, or permission issues.
**Tested on:** <!-- e.g. PVE 9.2 / Debian 13 / fresh install + update. Write "not tested" if you could not run it. -->
---
## 🤖 AI Assistance (**X** in brackets)
+39
View File
@@ -540,6 +540,45 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-09-11
### 🆕 New Scripts
- Lemonade-Server ([#17190](https://github.com/community-scripts/ProxmoxVE/pull/17190))
- OneTimeSecret ([#17097](https://github.com/community-scripts/ProxmoxVE/pull/17097))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- update authentik to 2026.8.2 [@thieneret](https://github.com/thieneret) ([#17198](https://github.com/community-scripts/ProxmoxVE/pull/17198))
- passwordpusher: restore data before running migrations [@MickLesk](https://github.com/MickLesk) ([#17141](https://github.com/community-scripts/ProxmoxVE/pull/17141))
- paperclip: install the rust toolchain needed by the runner build [@MickLesk](https://github.com/MickLesk) ([#17142](https://github.com/community-scripts/ProxmoxVE/pull/17142))
- homepage: run next directly instead of through pnpm [@MickLesk](https://github.com/MickLesk) ([#17155](https://github.com/community-scripts/ProxmoxVE/pull/17155))
- changedetection: fix: pin browserless [@CrazyWolf13](https://github.com/CrazyWolf13) ([#17163](https://github.com/community-scripts/ProxmoxVE/pull/17163))
### 💾 Core
- #### 🐞 Bug Fixes
- core.func: fall back to a usable HOME when the shell has none [@MickLesk](https://github.com/MickLesk) ([#17154](https://github.com/community-scripts/ProxmoxVE/pull/17154))
### 🧰 Tools
- Dockhand ([#17191](https://github.com/community-scripts/ProxmoxVE/pull/17191))
- #### 🐞 Bug Fixes
- update-apps: rewrite the retired Gitea base in every container before updating it [@MickLesk](https://github.com/MickLesk) ([#17156](https://github.com/community-scripts/ProxmoxVE/pull/17156))
- #### 🔧 Refactor
- Rename lxc-delete.sh to guest-delete.sh [@MickLesk](https://github.com/MickLesk) ([#17152](https://github.com/community-scripts/ProxmoxVE/pull/17152))
### 📚 Documentation
- issue template: add PVE release, execution context and phase; refresh distro list / pve versions [@MickLesk](https://github.com/MickLesk) ([#17160](https://github.com/community-scripts/ProxmoxVE/pull/17160))
## 2026-09-10
### 🆕 New Scripts
+9 -5
View File
@@ -49,7 +49,7 @@ function update_script() {
RUST_PROFILE="minimal" RUST_TOOLCHAIN="stable" setup_rust
setup_yq
AUTHENTIK_VERSION="version/2026.8.1"
AUTHENTIK_VERSION="version/2026.8.2"
# Source: https://github.com/goauthentik/fips/blob/main/Makefile#L26
XMLSEC_VERSION="1.3.12"
@@ -184,8 +184,12 @@ EOF
msg_info "Updating services"
sed -i 's/authentik Go Server (API Gateway)/authentik Server/g' /etc/systemd/system/authentik-server.service
sed -i '/ExecStart=/i ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-server.service
sed -i '/ExecStart=/i ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-worker.service
if ! grep -qF -- 'ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-server.service; then
sed -i '/ExecStart=/i ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-server.service
fi
if ! grep -qF -- 'ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-worker.service; then
sed -i '/ExecStart=/i ExecStartPre=/usr/bin/mkdir -p "${TMPDIR}"' /etc/systemd/system/authentik-worker.service
fi
systemctl daemon-reload
msg_ok "Updated services"
@@ -224,8 +228,8 @@ for i in {1..10}; do
sleep 1
done
$STD pct exec "$CTID" -- bash -c "mkdir -p /opt/authentik-data/{certs,media,geoip,templates}; \
cp /opt/authentik/tests/GeoLite2-ASN-Test.mmdb /opt/authentik-data/geoip/GeoLite2-ASN.mmdb; \
cp /opt/authentik/tests/GeoLite2-City-Test.mmdb /opt/authentik-data/geoip/GeoLite2-City.mmdb; \
cp /opt/authentik/tests/geoip/GeoLite2-ASN-Test.mmdb /opt/authentik-data/geoip/GeoLite2-ASN.mmdb; \
cp /opt/authentik/tests/geoip/GeoLite2-City-Test.mmdb /opt/authentik-data/geoip/GeoLite2-City.mmdb; \
cp -r /opt/authentik/blueprints /opt/authentik-data/; \
rm -r /opt/authentik/blueprints; \
find /opt/authentik-data -path '*/lost+found' -prune -o -exec chown authentik:authentik {} +"
+1
View File
@@ -69,6 +69,7 @@ function update_script() {
$STD git -C /opt/browserless/ reset --hard origin/main
$STD npm update --prefix /opt/browserless
$STD npm ci --include=optional --include=dev --prefix /opt/browserless
$STD npm install --save-exact playwright-core@1.62.1 --prefix /opt/browserless
$STD /opt/browserless/node_modules/playwright-core/cli.js install --with-deps
# Update Chrome separately, as it has to be done with the force option. Otherwise the installation of other browsers will not be done if Chrome is already installed.
$STD /opt/browserless/node_modules/playwright-core/cli.js install --force chrome
+6
View File
@@ -0,0 +1,6 @@
__ __ _____
/ / ___ ____ ___ ____ ____ ____ _____/ /__ / ___/___ ______ _____ _____
/ / / _ \/ __ `__ \/ __ \/ __ \/ __ `/ __ / _ \______\__ \/ _ \/ ___/ | / / _ \/ ___/
/ /___/ __/ / / / / / /_/ / / / / /_/ / /_/ / __/_____/__/ / __/ / | |/ / __/ /
/_____/\___/_/ /_/ /_/\____/_/ /_/\__,_/\__,_/\___/ /____/\___/_/ |___/\___/_/
+6
View File
@@ -0,0 +1,6 @@
____ _______ _____ __
/ __ \____ ___/_ __(_)___ ___ ___ / ___/___ _____________ / /_
/ / / / __ \/ _ \/ / / / __ `__ \/ _ \\__ \/ _ \/ ___/ ___/ _ \/ __/
/ /_/ / / / / __/ / / / / / / / / __/__/ / __/ /__/ / / __/ /_
\____/_/ /_/\___/_/ /_/_/ /_/ /_/\___/____/\___/\___/_/ \___/\__/
+4
View File
@@ -83,6 +83,10 @@ EOF
sed -i '/^ExecStart=/i Environment=CI=true' /etc/systemd/system/homepage.service
systemctl daemon-reload
fi
if grep -q '^ExecStart=pnpm start' /etc/systemd/system/homepage.service; then
sed -i 's|^ExecStart=pnpm start$|ExecStart=/opt/homepage/node_modules/.bin/next start|' /etc/systemd/system/homepage.service
systemctl daemon-reload
fi
msg_ok "Updated Homepage"
msg_info "Starting service"
+57
View File
@@ -0,0 +1,57 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Jamie (jamiej)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/lemonade-sdk/lemonade
APP="Lemonade-Server"
var_tags="${var_tags:-ai}"
var_cpu="${var_cpu:-4}"
var_ram="${var_ram:-8192}"
var_disk="${var_disk:-80}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
var_gpu="${var_gpu:-yes}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if ! command -v lemonade &>/dev/null; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "lemonade-server" "lemonade-sdk/lemonade"; then
msg_info "Stopping Service"
systemctl stop lemond
msg_ok "Stopped Service"
fetch_and_deploy_gh_release "lemonade-server" "lemonade-sdk/lemonade" "binary" "latest" "/tmp" "lemonade-server_*-debian13_$(arch_resolve).deb"
msg_info "Starting Service"
systemctl start lemond
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:13305${CL}"
+101
View File
@@ -0,0 +1,101 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Hai Tran (epiHATR)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://onetimesecret.com/ | Github: https://github.com/onetimesecret/onetimesecret
APP="OneTimeSecret"
var_tags="${var_tags:-security;privacy;secrets}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-4096}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-no}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
SSL_VALUE="${OTS_SSL:-}"
if [[ -n "${SSL_VALUE}" ]]; then
case "${SSL_VALUE,,}" in
1 | true | yes | on) SSL_VALUE="true" ;;
0 | false | no | off) SSL_VALUE="false" ;;
*)
msg_error "Invalid OTS_SSL value '${OTS_SSL}' (use true/false)"
exit 1
;;
esac
fi
if [[ ! -d /opt/onetimesecret ]] || [[ ! -f /opt/onetimesecret/.env ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "onetimesecret" "onetimesecret/onetimesecret"; then
msg_info "Stopping Service"
systemctl stop onetimesecret
msg_ok "Stopped Service"
create_backup /opt/onetimesecret/.env
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "onetimesecret" "onetimesecret/onetimesecret" "tarball"
RUBY_VERSION=$(tr -d ' \n' </opt/onetimesecret/.ruby-version 2>/dev/null)
RUBY_VERSION="${RUBY_VERSION:-3.4.10}" setup_ruby
PNPM_VERSION=$(sed -n 's/.*"packageManager": "pnpm@\([^"]*\)".*/\1/p' /opt/onetimesecret/package.json)
NODE_VERSION=$(tr -d ' \n' </opt/onetimesecret/.nvmrc 2>/dev/null)
NODE_VERSION="${NODE_VERSION:-25}" NODE_MODULE="pnpm@${PNPM_VERSION:-11.1.2}" setup_nodejs
restore_backup
msg_info "Reconciling Application"
systemctl enable -q --now redis-server
cd /opt/onetimesecret
mkdir -p tmp/pids log
$STD bash bin/setup reconcile
msg_ok "Reconciled Application"
msg_info "Building Frontend"
cd /opt/onetimesecret
$STD pnpm run build
msg_ok "Built Frontend"
msg_info "Starting Service"
systemctl start onetimesecret
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
DISPLAY_HOST="${OTS_HOST:-$IP}"
case "${OTS_SSL:-false,,}" in
1 | true | yes | on)
DISPLAY_SCHEME="https"
;;
*)
DISPLAY_SCHEME="http"
;;
esac
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}${DISPLAY_SCHEME}://${DISPLAY_HOST}${CL}"
+2
View File
@@ -43,6 +43,8 @@ function update_script() {
restore_backup
setup_rust
msg_info "Rebuilding Paperclip"
cd /opt/paperclip-ai
export HUSKY=0
+3 -2
View File
@@ -40,6 +40,9 @@ function update_script() {
create_backup /opt/passwordpusher/storage /opt/passwordpusher/.env.production
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "passwordpusher" "pglombardo/PasswordPusher" "tarball"
restore_backup
RUBY_VERSION="$(cat /opt/passwordpusher/.ruby-version)" RUBY_INSTALL_RAILS="false" setup_ruby
msg_info "Installing Gem Dependencies"
@@ -62,8 +65,6 @@ function update_script() {
RAILS_ENV=production SECRET_KEY_BASE_DUMMY=1 $STD bundle exec rails assets:precompile
msg_ok "Precompiled Assets"
restore_backup
msg_info "Starting Service"
systemctl start passwordpusher
msg_ok "Started Service"
+1 -1
View File
@@ -58,7 +58,7 @@ PG_VERSION="17" setup_postgresql
PG_DB_NAME="authentik" PG_DB_USER="authentik" PG_DB_GRANT_SUPERUSER="true" setup_postgresql_db
XMLSEC_VERSION="1.3.12"
AUTHENTIK_VERSION="version/2026.8.1"
AUTHENTIK_VERSION="version/2026.8.2"
fetch_and_deploy_gh_release "xmlsec" "lsh123/xmlsec" "tarball" "${XMLSEC_VERSION}" "/opt/xmlsec"
fetch_and_deploy_gh_release "authentik" "goauthentik/authentik" "tarball" "${AUTHENTIK_VERSION}" "/opt/authentik"
GO_VERSION="$(grep -m1 '^go ' /opt/authentik/go.mod | awk '{print $2}')" setup_go
+1
View File
@@ -62,6 +62,7 @@ mkdir /opt/browserless
$STD /opt/changedetection/.venv/bin/python -m pip install playwright
$STD git clone https://github.com/browserless/chrome /opt/browserless
$STD npm ci --include=optional --include=dev --prefix /opt/browserless
$STD npm install --save-exact playwright-core@1.62.1 --prefix /opt/browserless
$STD /opt/browserless/node_modules/playwright-core/cli.js install --with-deps &>/dev/null
$STD /opt/browserless/node_modules/playwright-core/cli.js install --force chrome &>/dev/null
$STD /opt/browserless/node_modules/playwright-core/cli.js install chromium firefox webkit &>/dev/null
+1 -1
View File
@@ -64,7 +64,7 @@ RestartSec=1
User=root
WorkingDirectory=/opt/homepage/
Environment=CI=true
ExecStart=pnpm start
ExecStart=/opt/homepage/node_modules/.bin/next start
[Install]
WantedBy=multi-user.target
+47
View File
@@ -0,0 +1,47 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Jamie (jamiej)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/lemonade-sdk/lemonade
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
setup_deb822_repo \
"backports" \
"https://ftp-master.debian.org/keys/archive-key-13.asc" \
"http://deb.debian.org/debian" \
"trixie-backports" \
"main"
msg_info "Installing Lemonade Server dependencies"
$STD apt install -y \
fonts-katex \
libcpp-httplib0.41 \
libmbedcrypto16 \
libwebsockets19t64
msg_ok "Installed Lemonade Server dependencies"
setup_hwaccel
fetch_and_deploy_gh_release "lemonade-server" "lemonade-sdk/lemonade" "binary" "latest" "/tmp" "lemonade-server_*-debian13_$(arch_resolve).deb"
msg_info "Configuring Remote Access"
systemctl enable -q --now lemond
for _ in $(seq 1 60); do
lemonade status >/dev/null 2>&1 && break
sleep 2
done
$STD lemonade config set host=0.0.0.0
systemctl restart lemond
msg_ok "Configured Remote Access"
motd_ssh
customize
cleanup_lxc
+138
View File
@@ -0,0 +1,138 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Hai Tran (epiHATR)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://onetimesecret.com/ | Github: https://github.com/onetimesecret/onetimesecret
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
build-essential \
git \
libffi-dev \
libgmp-dev \
libpq-dev \
libreadline-dev \
libsodium23 \
libsqlite3-dev \
libssl-dev \
libxml2-dev \
libxslt1-dev \
libyaml-dev \
nginx \
pkg-config \
python3 \
redis-server \
zlib1g-dev
msg_ok "Installed Dependencies"
fetch_and_deploy_gh_release "onetimesecret" "onetimesecret/onetimesecret" "tarball"
RUBY_VERSION=$(tr -d ' \n' </opt/onetimesecret/.ruby-version 2>/dev/null)
RUBY_VERSION="${RUBY_VERSION:-3.4.10}" setup_ruby
PNPM_VERSION=$(sed -n 's/.*"packageManager": "pnpm@\([^"]*\)".*/\1/p' /opt/onetimesecret/package.json)
NODE_VERSION=$(tr -d ' \n' </opt/onetimesecret/.nvmrc 2>/dev/null)
NODE_VERSION="${NODE_VERSION:-25}" NODE_MODULE="pnpm@${PNPM_VERSION:-11.1.2}" setup_nodejs
HOST_VALUE="${OTS_HOST:-$LOCAL_IP}"
SSL_VALUE="${OTS_SSL:-false}"
case "${SSL_VALUE,,}" in
1 | true | yes | on) SSL_VALUE="true" ;;
0 | false | no | off | "") SSL_VALUE="false" ;;
*)
msg_error "Invalid OTS_SSL value '${OTS_SSL}' (use true/false)"
exit 1
;;
esac
msg_info "Configuring Application"
systemctl enable -q --now redis-server
cd /opt/onetimesecret
$STD bash bin/setup init
sed -i \
-e "s|^REDIS_URL=.*|REDIS_URL=redis://127.0.0.1:6379/0|" \
-e "s|^HOST=.*|HOST=${HOST_VALUE//&/\\&}|" \
-e "s|^SSL=.*|SSL=${SSL_VALUE}|" \
/opt/onetimesecret/.env
if grep -q '^RACK_ENV=' /opt/onetimesecret/.env; then
sed -i 's|^RACK_ENV=.*|RACK_ENV=production|' /opt/onetimesecret/.env
else
echo "RACK_ENV=production" >>/opt/onetimesecret/.env
fi
if grep -q '^AUTHENTICATION_MODE=' /opt/onetimesecret/.env; then
sed -i 's|^AUTHENTICATION_MODE=.*|AUTHENTICATION_MODE=simple|' /opt/onetimesecret/.env
else
echo "AUTHENTICATION_MODE=simple" >>/opt/onetimesecret/.env
fi
if ! grep -q '^PORT=' /opt/onetimesecret/.env; then
echo "PORT=3000" >>/opt/onetimesecret/.env
fi
chmod 600 /opt/onetimesecret/.env
mkdir -p /opt/onetimesecret/tmp/pids /opt/onetimesecret/log
msg_ok "Configured Application"
msg_info "Reconciling Application"
cd /opt/onetimesecret
$STD bash bin/setup reconcile
msg_ok "Reconciled Application"
msg_info "Building Frontend"
cd /opt/onetimesecret
$STD pnpm run build
msg_ok "Built Frontend"
msg_info "Creating Service"
cat <<'EOF' >/etc/systemd/system/onetimesecret.service
[Unit]
Description=Onetime Secret Service
After=network.target redis-server.service
Requires=redis-server.service
[Service]
Type=simple
User=root
WorkingDirectory=/opt/onetimesecret
Environment=HOME=/root
Environment=PATH=/root/.rbenv/shims:/root/.rbenv/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
EnvironmentFile=/opt/onetimesecret/.env
ExecStart=/root/.rbenv/shims/bundle exec puma -C etc/puma.rb
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now onetimesecret
msg_ok "Created Service"
msg_info "Configuring Nginx"
cat <<'EOF' >/etc/nginx/sites-available/onetimesecret
server {
listen 80 default_server;
server_name _;
location / {
proxy_pass http://127.0.0.1:3000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
EOF
nginx_enable_site onetimesecret
msg_ok "Configured Nginx"
motd_ssh
customize
cleanup_lxc
+1
View File
@@ -23,6 +23,7 @@ msg_ok "Installed Dependencies"
NODE_VERSION="24" NODE_MODULE="pnpm" setup_nodejs
PG_VERSION="17" setup_postgresql
PG_DB_NAME="paperclip" PG_DB_USER="paperclip" setup_postgresql_db
setup_rust
fetch_and_deploy_gh_release "paperclip-ai" "paperclipai/paperclip" "tarball"
+5
View File
@@ -15,6 +15,11 @@
[[ -n "${_CORE_FUNC_LOADED:-}" ]] && return
_CORE_FUNC_LOADED=1
if [[ -z "${HOME:-}" ]]; then
HOME="$(getent passwd "$(id -u)" 2>/dev/null | cut -d: -f6)"
export HOME="${HOME:-/root}"
fi
# ==============================================================================
# SECTION 1: INITIALIZATION & SETUP
# ==============================================================================
+111
View File
@@ -0,0 +1,111 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/Finsys/dockhand
if command -v curl >/dev/null 2>&1; then
source <(curl -fsSL ${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/core.func)
load_functions
elif command -v wget >/dev/null 2>&1; then
source <(wget -qO- ${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/core.func)
load_functions
fi
source <(curl -fsSL ${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/lib/tools.func)
color
catch_errors
APP="Dockhand"
APP_TYPE="addon"
INSTALL_PATH="/opt/dockhand"
COMPOSE_FILE="${INSTALL_PATH}/docker-compose.yaml"
DEFAULT_PORT=3000
header_info "$APP"
IP=$(_get_current_ip)
function check_docker() {
if ! command -v docker >/dev/null 2>&1; then
msg_error "Docker is not installed. This addon requires an existing Docker host/LXC. Exiting."
exit 1
fi
if ! docker compose version >/dev/null 2>&1; then
msg_error "Docker Compose plugin is not available. Install it before running this addon. Exiting."
exit 1
fi
msg_ok "Docker $(docker --version | cut -d' ' -f3 | tr -d ',') and Docker Compose are available"
}
function install_dockhand() {
local port="${1:-$DEFAULT_PORT}"
check_docker
msg_info "Creating Compose Project"
mkdir -p "$INSTALL_PATH"
cat <<EOF >"$COMPOSE_FILE"
services:
dockhand:
image: fnsys/dockhand:latest
container_name: dockhand
restart: unless-stopped
ports:
- ${port}:3000
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- dockhand_data:/app/data
volumes:
dockhand_data:
EOF
msg_ok "Created Compose Project"
msg_info "Starting ${APP}"
cd "$INSTALL_PATH"
$STD docker compose up -d
msg_ok "Started ${APP}"
msg_ok "${APP} is reachable at http://${IP}:${port}"
echo -e "${TAB}Open the URL and complete the first-run setup wizard to create the admin account."
}
function update_dockhand() {
msg_info "Pulling latest ${APP} image"
cd "$INSTALL_PATH"
$STD docker compose pull
msg_ok "Pulled latest image"
msg_info "Restarting ${APP}"
$STD docker compose up -d --remove-orphans
msg_ok "Restarted ${APP}"
msg_ok "${APP} updated successfully"
}
function uninstall_dockhand() {
msg_info "Removing ${APP}"
cd "$INSTALL_PATH"
$STD docker compose down --remove-orphans
cd /
rm -rf "$INSTALL_PATH"
msg_ok "${APP} uninstalled (the dockhand_data volume was kept; remove it with: docker volume rm dockhand_data)"
}
if [[ -f "$COMPOSE_FILE" ]]; then
read -r -p "Update (1), Uninstall (2), Cancel (3)? [1/2/3]: " action
action="${action//[[:space:]]/}"
case "$action" in
1) update_dockhand ;;
2) uninstall_dockhand ;;
3) msg_info "Cancelled" ;;
*) msg_error "Invalid input" ;;
esac
else
read -r -p "Enter port number (default: ${DEFAULT_PORT}): " PORT_INPUT
PORT="${PORT_INPUT:-$DEFAULT_PORT}"
read -r -p "Install ${APP}? (y/n): " answer
answer="${answer//[[:space:]]/}"
[[ "${answer,,}" =~ ^(y|yes)$ ]] && install_dockhand "$PORT" || msg_info "Installation skipped"
fi
+6
View File
@@ -0,0 +1,6 @@
____ __ __ __
/ __ \____ _____/ /__/ /_ ____ _____ ____/ /
/ / / / __ \/ ___/ //_/ __ \/ __ `/ __ \/ __ /
/ /_/ / /_/ / /__/ ,< / / / / /_/ / / / / /_/ /
/_____/\____/\___/_/|_/_/ /_/\__,_/_/ /_/\__,_/
@@ -40,7 +40,7 @@ CM="${TAB}✔️${TAB}${CL}"
# Telemetry
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/api.func) 2>/dev/null || true
declare -f init_tool_telemetry &>/dev/null && init_tool_telemetry "lxc-delete" "pve"
declare -f init_tool_telemetry &>/dev/null && init_tool_telemetry "guest-delete" "pve"
GUEST_LOG=$(mktemp)
trap 'rm -f "$GUEST_LOG"' EXIT
+21
View File
@@ -178,6 +178,24 @@ function resolve_service_script() {
return 1
}
# The retired Gitea mirror. The old entrypoint pulls ct/<app>.sh straight from
# it and never reaches the update helper that would repair itself, so rewrite it
# here. Only host and /raw/<kind>/ change; owner, repo and ref are kept.
function repair_update_url() {
local container="$1"
pct exec "$container" -- sh -c '
[ -f /usr/bin/update ] || exit 1
grep -q git.community-scripts.org /usr/bin/update || exit 1
sed -i \
-e "s|https://git[.]community-scripts[.]org/|https://raw.githubusercontent.com/|g" \
-e "s|/raw/branch/|/|g" -e "s|/raw/tag/|/|g" -e "s|/raw/commit/|/|g" \
/usr/bin/update
' >/dev/null 2>&1 || return 1
echo -e "${BL}[INFO]${CL} Repaired update URL (Gitea -> GitHub) in container $container"
log_write "Container $container: rewrote the retired Gitea base in /usr/bin/update"
}
function detect_service() {
local container="$1"
local tmpdir update_file
@@ -489,6 +507,9 @@ for container in $CHOICE; do
sleep 5
fi
#0.5) Rewrite a retired Gitea base before anything reads it.
repair_update_url "$container"
#1) Detect service using the service name in the update command
detect_service $container