Compare commits

...

5 Commits

Author SHA1 Message Date
CanbiZ (MickLesk) 6f5b4279da Clean up comments in budget-board.sh
Remove comments about engine sourcing and local core checkout.
2026-08-24 10:56:42 +02:00
push-app-to-main[bot] 1f7cc9ce25 Add budget-board (ct) 2026-08-24 08:54:14 +00:00
Michel Roegl-Brunner 19bfe87e0e Notify Helper-Scripts site when a breaking-change PR merges
On a merged PR labelled "breaking change", POST the PR number to the site's
/api/breaking-changes/ingest endpoint so it can show a temporary advisory on
the affected scripts. Uses pull_request_target (secrets available for fork
PRs) and never checks out PR code — it only forwards the number after merge.
The `labeled` trigger also covers labelling a PR after it has merged.

Requires repo secret BREAKING_CHANGE_INGEST_SECRET (matching the site) and an
optional SITE_URL variable (defaults to https://community-scripts.org).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TFBuZEp142Ei2PAfWqbMXT
2026-08-24 10:33:51 +02:00
community-scripts-pr-app[bot] c8c5b91ec4 Update CHANGELOG.md (#16705)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-24 05:45:16 +00:00
CanbiZ (MickLesk) 065f34aefe build.func: allow default.vars to raise var_cpu/var_ram/var_disk above app baseline (#16704) 2026-08-24 07:44:47 +02:00
6 changed files with 299 additions and 3 deletions
+58
View File
@@ -0,0 +1,58 @@
name: Notify breaking change
# When a PR labelled "breaking change" is merged, tell the Helper-Scripts site
# so it can show a temporary advisory on the affected scripts. The site pulls
# the PR itself and re-verifies it is merged + labelled, so this workflow only
# has to hand over the PR number.
#
# Requires one repo secret:
# BREAKING_CHANGE_INGEST_SECRET — must match the value the site runs with.
# Site URL is taken from the existing FRONTEND_URL secret, then an optional
# SITE_URL variable, then a hard default.
#
# pull_request_target (not pull_request) so the run has access to the secret
# even for fork PRs. It is safe here: the job never checks out or runs PR code —
# it only forwards the number after the PR has merged.
on:
pull_request_target:
# closed -> fires on the merge itself
# labeled -> fires if the label is added to an already-merged PR
types: [closed, labeled]
concurrency:
group: notify-breaking-change-${{ github.event.pull_request.number }}
cancel-in-progress: false
jobs:
notify:
if: >-
github.event.pull_request.merged == true &&
contains(github.event.pull_request.labels.*.name, 'breaking change')
runs-on: ubuntu-latest
steps:
- name: Notify site of breaking change
env:
INGEST_SECRET: ${{ secrets.BREAKING_CHANGE_INGEST_SECRET }}
SITE_URL: ${{ secrets.FRONTEND_URL || vars.SITE_URL || 'https://community-scripts.org' }}
PR: ${{ github.event.pull_request.number }}
run: |
set -euo pipefail
if [ -z "${INGEST_SECRET:-}" ]; then
echo "::error::BREAKING_CHANGE_INGEST_SECRET secret is not set."
exit 1
fi
url="${SITE_URL%/}/api/breaking-changes/ingest"
echo "Notifying $url for PR #${PR}"
status="$(curl -sS -o response.json -w '%{http_code}' \
-X POST "$url" \
-H "Authorization: Bearer ${INGEST_SECRET}" \
-H "Content-Type: application/json" \
-d "{\"pr\": ${PR}}")"
echo "HTTP $status"
cat response.json || true
echo
if [ "$status" != "200" ]; then
echo "::error::ingest endpoint returned HTTP $status"
exit 1
fi
+2
View File
@@ -527,6 +527,8 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-08-24
## 2026-08-23
### 🚀 Updated Scripts
+82
View File
@@ -0,0 +1,82 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Slaviša Arežina (tremor021)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/teelur/budget-board
APP="Budget-Board"
var_tags="${var_tags:-finance;budget;money}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
#var_arm64="${var_arm64:-no}" # unset = ask the user; set yes/no only when verified
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/budget-board ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "budget-board" "teelur/budget-board"; then
msg_info "Stopping Service"
systemctl stop budget-board
msg_ok "Stopped Service"
msg_info "Backing up Data"
cp -r /opt/budget-board/budget-board.env /opt/budget-board.env.bak
msg_ok "Backed up Data"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "budget-board" "teelur/budget-board" "tarball"
msg_info "Restoring Configuration"
cp -r /opt/budget-board.env.bak /opt/budget-board/budget-board.env
rm -f /opt/budget-board.env.bak
msg_ok "Restored Configuration"
msg_info "Rebuilding Backend"
cd /opt/budget-board/server
$STD dotnet restore "BudgetBoard.WebAPI/BudgetBoard.WebAPI.csproj"
export configuration=Release
$STD dotnet publish "BudgetBoard.WebAPI/BudgetBoard.WebAPI.csproj" -c $configuration -o /opt/budget-board/publish /p:UseAppHost=false --no-restore
msg_ok "Rebuilt Backend"
msg_info "Rebuilding Frontend"
cd /opt/budget-board/client
export COREPACK_ENABLE_DOWNLOAD_PROMPT=0
$STD yarn install
$STD yarn run build
cp -r dist/. /var/www/html/
msg_ok "Rebuilt Frontend"
msg_info "Starting Service"
systemctl start budget-board
systemctl reload nginx
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"
+6
View File
@@ -0,0 +1,6 @@
____ __ __ ____ __
/ __ )__ ______/ /___ ____ / /_ / __ )____ ____ __________/ /
/ __ / / / / __ / __ `/ _ \/ __/_____/ __ / __ \/ __ `/ ___/ __ /
/ /_/ / /_/ / /_/ / /_/ / __/ /_/_____/ /_/ / /_/ / /_/ / / / /_/ /
/_____/\__,_/\__,_/\__, /\___/\__/ /_____/\____/\__,_/_/ \__,_/
/____/
+129
View File
@@ -0,0 +1,129 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: Slaviša Arežina (tremor021)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/teelur/budget-board
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y nginx
setup_deb822_repo \
"microsoft" \
"https://packages.microsoft.com/keys/microsoft-2025.asc" \
"https://packages.microsoft.com/debian/13/prod/" \
"trixie"
$STD apt install -y dotnet-sdk-10.0
msg_ok "Installed Dependencies"
NODE_VERSION=25 setup_nodejs
PG_VERSION=16 setup_postgresql
PG_DB_NAME=budget_board_db PG_DB_USER=budget_board setup_postgresql_db
fetch_and_deploy_gh_release "budget-board" "teelur/budget-board" "tarball"
msg_info "Configuring Budget Board Backend"
cd /opt/budget-board/server
$STD dotnet restore "BudgetBoard.WebAPI/BudgetBoard.WebAPI.csproj"
export configuration=Release
$STD dotnet publish "BudgetBoard.WebAPI/BudgetBoard.WebAPI.csproj" -c $configuration -o /opt/budget-board/publish /p:UseAppHost=false --no-restore
cat <<EOF >/opt/budget-board/budget-board.env
Logging__LogLevel__Default=Information
CLIENT_ADDRESS=$LOCAL_IP
POSTGRES_HOST=localhost
POSTGRES_PORT=5432
POSTGRES_DATABASE=$PG_DB_NAME
POSTGRES_USER=$PG_DB_USER
POSTGRES_PASSWORD=$PG_DB_PASS
OIDC_ENABLED=false
OIDC_ISSUER=
OIDC_CLIENT_ID=
OIDC_CLIENT_SECRET=
EMAIL_SENDER=
EMAIL_SENDER_USERNAME=
EMAIL_SENDER_PASSWORD=
EMAIL_SMTP_HOST=
EMAIL_SMTP_PORT=587
DISABLE_NEW_USERS=false
DISABLE_LOCAL_AUTH=false
AUTO_UPDATE_DB=true
DISABLE_AUTO_SYNC=false
SYNC_INTERVAL_HOURS=8
TZ=UTC
ASPNETCORE_URLS=http://127.0.0.1:6253
PORT=6253
VITE_SERVER_ADDRESS=${LOCAL_IP}
VITE_OIDC_ENABLED=false
VITE_OIDC_PROVIDER=
VITE_OIDC_CLIENT_ID=
VITE_DISABLE_NEW_USERS=false
VITE_DISABLE_LOCAL_AUTH=false
EOF
msg_ok "Configured Budget Board Backend"
msg_info "Configuring Budget Board Frontend"
cd /opt/budget-board/client
export COREPACK_ENABLE_DOWNLOAD_PROMPT=0
$STD yarn config set --home enableTelemetry 0
$STD npm install --global corepack@latest
$STD corepack enable
$STD yarn install
$STD yarn run build
cp -r dist/. /var/www/html/
msg_ok "Configured Budget Board Frontend"
msg_info "Creating services"
cat <<EOF >/etc/systemd/system/budget-board.service
[Unit]
Description=Budget Board Service
After=network.target
[Service]
WorkingDirectory=/opt/budget-board/publish
ExecStart=dotnet BudgetBoard.WebAPI.dll
Restart=always
EnvironmentFile=/opt/budget-board/budget-board.env
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now budget-board
cat <<'EOF' >/etc/nginx/sites-available/budget-board.conf
server {
listen 80 default_server;
server_name _;
root /var/www/html;
index index.html;
location /api/ {
proxy_pass http://127.0.0.1:6253;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location / {
try_files $uri $uri/ /index.html;
}
}
EOF
ln -sf /etc/nginx/sites-available/budget-board.conf /etc/nginx/sites-enabled/budget-board.conf
rm -f /etc/nginx/sites-enabled/default
systemctl reload nginx
msg_ok "Created services"
motd_ssh
customize
cleanup_lxc
+22 -3
View File
@@ -1208,10 +1208,12 @@ base_settings() {
# - Used by default_var_settings and app defaults loading
# - Only loads whitelisted var_* keys
# - Optional force parameter to override existing values (for app defaults)
# - Optional protected list preserves genuinely user-exported var_* values
# ------------------------------------------------------------------------------
load_vars_file() {
local file="$1"
local force="${2:-no}" # If "yes", override existing variables
local force="${2:-no}" # If "yes", override existing variables
local protected="${3:-}" # space-separated var_* keys the user genuinely exported before this file loaded; never overwritten
[ -f "$file" ] || return 0
msg_info "Loading defaults from ${file}"
@@ -1231,6 +1233,13 @@ load_vars_file() {
return 1
}
# Protected check helper (genuinely user-exported vars, see $protected above)
_is_protected() {
local k="$1" p
for p in $protected; do [ "$k" = "$p" ] && return 0; done
return 1
}
local line key val
while IFS= read -r line || [ -n "$line" ]; do
line="${line#"${line%%[![:space:]]*}"}"
@@ -1435,9 +1444,19 @@ load_vars_file() {
esac
fi
# Set variable: force mode overrides existing, otherwise only set if empty
# Set variable: force mode overrides existing, otherwise only set if empty.
# Exception: var_cpu/var_ram/var_disk are always applied here (unless the
# user genuinely exported them beforehand, per $protected) even though the
# app script already declared its own baseline for them - base_settings()
# reconciles the final floor against APP_DEFAULT_* afterward, so this file
# must be allowed to raise them instead of being silently blocked by the
# app's own pre-set value.
if [[ "$force" == "yes" ]]; then
export "${var_key}=${var_val}"
elif _is_protected "$var_key"; then
:
elif [[ "$var_key" == "var_cpu" || "$var_key" == "var_ram" || "$var_key" == "var_disk" ]]; then
export "${var_key}=${var_val}"
else
[[ -z "${!var_key+x}" ]] && export "${var_key}=${var_val}"
fi
@@ -1597,7 +1616,7 @@ EOF
msg_error "default.vars not found after ensure step"
return 252
}
load_vars_file "$dv"
load_vars_file "$dv" "no" "${!_HARD_ENV[*]}"
# 3) Map var_verbose → VERBOSE
if [[ -n "${var_verbose:-}" ]]; then