Compare commits

..

10 Commits

Author SHA1 Message Date
MickLesk af111bf419 Refactor nginx management to use helper
Replace direct nginx systemctl/ln calls with the `nginx_enable_site` helper function across multiple update scripts. Also use `get_php_fpm_socket` in paymenter.sh for dynamic PHP socket path instead of hardcoded version string.
2026-07-28 15:02:51 +02:00
MickLesk b7688ff97a Standardize nginx setup in install scripts
Refactors many install scripts to use the shared `nginx_enable_site` helper instead of manual symlink/default-site/reload sequences, making webserver setup more consistent and less error-prone. It also replaces hardcoded PHP-FPM socket paths with `get_php_fpm_socket` (including templated substitutions where needed) across nginx and caddy configs to improve compatibility with varying PHP versions and socket locations.
2026-07-28 14:57:58 +02:00
MickLesk f862ce0c13 Add nginx site helper and PHP socket resolver
Introduce `get_php_fpm_socket` to reliably resolve the active PHP-FPM Unix socket, preferring the configured PHP version and falling back to the highest running socket under `/run/php`. Add `nginx_enable_site` to safely enable a site by removing defaults, linking configs, testing `nginx -t`, enabling the service, and restarting through the existing safe restart path.
2026-07-28 14:55:52 +02:00
community-scripts-pr-app[bot] 57e02eee1b Update .app files (#16114)
Co-authored-by: GitHub Actions <github-actions[bot]@users.noreply.github.com>
2026-07-28 13:38:55 +02:00
community-scripts-pr-app[bot] 45053ea4c3 Update CHANGELOG.md (#16115)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-28 11:37:14 +00:00
Sam Heinz 1fa4c1fbf7 fix Node.js version drift (#16111)
* fix Node.js version drift

* add upgrade node for oxicloud,ps5,syncin
2026-07-28 13:36:40 +02:00
community-scripts-pr-app[bot] 0299e420e8 Update CHANGELOG.md (#16113)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-28 10:30:10 +00:00
push-app-to-main[bot] db18c72bd8 Add actual-budget-prometheus-exporter (addon) (#16109)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-07-28 12:29:40 +02:00
community-scripts-pr-app[bot] 4bf8a972bf Update CHANGELOG.md (#16112)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-28 09:44:49 +00:00
Sam Heinz 47b8fbf2fb fix keep-open for close invalid pr (#16105) 2026-07-28 11:44:26 +02:00
55 changed files with 408 additions and 169 deletions
+2 -2
View File
@@ -45,7 +45,7 @@ jobs:
} }
const labels = pr.labels.map((label) => label.name); const labels = pr.labels.map((label) => label.name);
const skipLabels = ["automated pr", "keep open"]; const skipLabels = ["automated pr", "keep-open"];
if (skipLabels.some((label) => labels.includes(label))) { if (skipLabels.some((label) => labels.includes(label))) {
core.info(`PR #${prNumber} has a skip label (${labels.join(", ")}) — skipping template validation.`); core.info(`PR #${prNumber} has a skip label (${labels.join(", ")}) — skipping template validation.`);
@@ -136,7 +136,7 @@ jobs:
``, ``,
`> Use the template sections, fill in the description, check all prerequisite boxes, and select at least one type of change.`, `> Use the template sections, fill in the description, check all prerequisite boxes, and select at least one type of change.`,
``, ``,
`Maintainers can add the \`keep open\` label to exempt a PR from this check.`, `Maintainers can add the \`keep-open\` label to exempt a PR from this check.`,
``, ``,
`Thank you for contributing! 🙏`, `Thank you for contributing! 🙏`,
].join("\n"); ].join("\n");
+7 -1
View File
@@ -514,13 +514,19 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
- #### 🐞 Bug Fixes - #### 🐞 Bug Fixes
- fix Node.js version drift [@asylumexp](https://github.com/asylumexp) ([#16111](https://github.com/community-scripts/ProxmoxVE/pull/16111))
- UmlautAdaptarr: use the Debian 13 Microsoft repo with its 2025 signing key [@angusmaul](https://github.com/angusmaul) ([#16077](https://github.com/community-scripts/ProxmoxVE/pull/16077)) - UmlautAdaptarr: use the Debian 13 Microsoft repo with its 2025 signing key [@angusmaul](https://github.com/angusmaul) ([#16077](https://github.com/community-scripts/ProxmoxVE/pull/16077))
- fix(bazarr): store data in /var/lib/bazarr instead of inside /opt/bazarr [@angusmaul](https://github.com/angusmaul) ([#16098](https://github.com/community-scripts/ProxmoxVE/pull/16098)) - fix(bazarr): store data in /var/lib/bazarr instead of inside /opt/bazarr [@angusmaul](https://github.com/angusmaul) ([#16098](https://github.com/community-scripts/ProxmoxVE/pull/16098))
- Cloudflare-DDNS: store API token in a 600 env file and build the binary at install time [@angusmaul](https://github.com/angusmaul) ([#16100](https://github.com/community-scripts/ProxmoxVE/pull/16100)) - Cloudflare-DDNS: store API token in a 600 env file and build the binary at install time [@angusmaul](https://github.com/angusmaul) ([#16100](https://github.com/community-scripts/ProxmoxVE/pull/16100))
### 🧰 Tools
- actual-budget-prometheus-exporter ([#16109](https://github.com/community-scripts/ProxmoxVE/pull/16109))
### 📂 Github ### 📂 Github
- Bump GitHub Actions across workflows [@MickLesk](https://github.com/MickLesk) ([#16091](https://github.com/community-scripts/ProxmoxVE/pull/16091)) - fix keep-open for close invalid pr [@asylumexp](https://github.com/asylumexp) ([#16105](https://github.com/community-scripts/ProxmoxVE/pull/16105))
- Bump GitHub Actions across workflows [@MickLesk](https://github.com/MickLesk) ([#16091](https://github.com/community-scripts/ProxmoxVE/pull/16091))
## 2026-07-27 ## 2026-07-27
+1 -1
View File
@@ -100,7 +100,7 @@ server {
} }
} }
EOF EOF
systemctl reload nginx nginx_enable_site dispatcharr.conf
msg_ok "Migrated Nginx Configuration" msg_ok "Migrated Nginx Configuration"
fi fi
+1 -3
View File
@@ -59,9 +59,7 @@ function update_script() {
envsubst </opt/feishin/settings.js.template >/etc/nginx/conf.d/settings.js envsubst </opt/feishin/settings.js.template >/etc/nginx/conf.d/settings.js
envsubst '${PUBLIC_PATH}' </opt/feishin/ng.conf.template >/etc/nginx/sites-available/feishin envsubst '${PUBLIC_PATH}' </opt/feishin/ng.conf.template >/etc/nginx/sites-available/feishin
ln -sf /etc/nginx/sites-available/feishin /etc/nginx/sites-enabled/feishin nginx_enable_site feishin
rm -f /etc/nginx/sites-enabled/default
systemctl restart nginx
msg_ok "Published Web Assets" msg_ok "Published Web Assets"
msg_ok "Updated successfully!" msg_ok "Updated successfully!"
+3 -2
View File
@@ -34,8 +34,9 @@ function update_script() {
if [[ "$CURRENT_PHP" != "8.3" ]]; then if [[ "$CURRENT_PHP" != "8.3" ]]; then
PHP_VERSION="8.3" PHP_FPM="YES" setup_php PHP_VERSION="8.3" PHP_FPM="YES" setup_php
setup_composer setup_composer
sed -i 's|php8\.2-fpm\.sock|php8.3-fpm.sock|g' /etc/nginx/sites-available/paymenter.conf PHP_SOCK=$(get_php_fpm_socket)
$STD systemctl reload nginx sed -i "s|fastcgi_pass unix:.*|fastcgi_pass unix:${PHP_SOCK};|" /etc/nginx/sites-available/paymenter.conf
nginx_enable_site paymenter.conf
fi fi
if check_for_gh_release "paymenter" "paymenter/paymenter"; then if check_for_gh_release "paymenter" "paymenter/paymenter"; then
+2 -2
View File
@@ -62,9 +62,9 @@ function update_script() {
msg_ok "Updated Configuration" msg_ok "Updated Configuration"
msg_info "Starting Services" msg_info "Starting Services"
$STD nginx -t
systemctl daemon-reload systemctl daemon-reload
systemctl start nginx rackula-api nginx_enable_site rackula
systemctl start rackula-api
msg_ok "Started Services" msg_ok "Started Services"
msg_ok "Updated successfully!" msg_ok "Updated successfully!"
fi fi
+1 -1
View File
@@ -75,7 +75,7 @@ function update_script() {
systemctl reload angie systemctl reload angie
elif [[ -f /etc/nginx/sites-available/romm ]]; then elif [[ -f /etc/nginx/sites-available/romm ]]; then
sed -i "s|alias .*/library/;|alias ${ROMM_BASE}/library/;|" /etc/nginx/sites-available/romm sed -i "s|alias .*/library/;|alias ${ROMM_BASE}/library/;|" /etc/nginx/sites-available/romm
systemctl reload nginx nginx_enable_site romm
fi fi
msg_ok "Updated ROMM" msg_ok "Updated ROMM"
+2 -1
View File
@@ -93,7 +93,8 @@ EOF
msg_ok "Refreshed SparkyFitness Service" msg_ok "Refreshed SparkyFitness Service"
msg_info "Starting Services" msg_info "Starting Services"
$STD systemctl start sparkyfitness-server nginx $STD systemctl start sparkyfitness-server
nginx_enable_site sparkyfitness
msg_ok "Started Services" msg_ok "Started Services"
msg_ok "Updated successfully!" msg_ok "Updated successfully!"
fi fi
+2 -1
View File
@@ -49,6 +49,7 @@ chmod -R 755 /opt/2fauth
msg_ok "Setup 2fauth" msg_ok "Setup 2fauth"
msg_info "Configure Service" msg_info "Configure Service"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/conf.d/2fauth.conf cat <<EOF >/etc/nginx/conf.d/2fauth.conf
server { server {
listen 80; listen 80;
@@ -67,7 +68,7 @@ server {
error_page 404 /index.php; error_page 404 /index.php;
location ~ \.php\$ { location ~ \.php\$ {
fastcgi_pass unix:/var/run/php/php${PHP_VERSION}-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name;
include fastcgi_params; include fastcgi_params;
} }
+1 -3
View File
@@ -207,9 +207,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/affine.conf /etc/nginx/sites-enabled/ nginx_enable_site affine.conf
rm -f /etc/nginx/sites-enabled/default
systemctl enable -q --now nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+1 -4
View File
@@ -89,10 +89,7 @@ server {
} }
EOF EOF
ln -sf /etc/nginx/sites-available/babybuddy /etc/nginx/sites-enabled/babybuddy nginx_enable_site babybuddy
rm /etc/nginx/sites-enabled/default
systemctl enable -q --now nginx
service nginx reload
msg_ok "Configured NGINX" msg_ok "Configured NGINX"
motd_ssh motd_ssh
+3 -4
View File
@@ -73,6 +73,7 @@ $STD npm run build
msg_ok "Installed Salt Rim" msg_ok "Installed Salt Rim"
msg_info "Creating Service" msg_info "Creating Service"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/barassistant.conf cat <<EOF >/etc/nginx/sites-available/barassistant.conf
server { server {
listen 80 default_server; listen 80 default_server;
@@ -126,7 +127,7 @@ server {
error_page 404 /index.php; error_page 404 /index.php;
location ~ ^/index\.php(/|$) { location ~ ^/index\.php(/|$) {
fastcgi_pass unix:/var/run/php/php$PHPVER-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name;
include fastcgi_params; include fastcgi_params;
fastcgi_hide_header X-Powered-By; fastcgi_hide_header X-Powered-By;
@@ -148,9 +149,7 @@ server {
} }
EOF EOF
ln -s /etc/nginx/sites-available/barassistant.conf /etc/nginx/sites-enabled/ nginx_enable_site barassistant.conf
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
msg_ok "Created Service" msg_ok "Created Service"
motd_ssh motd_ssh
+1 -3
View File
@@ -122,9 +122,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/checkmate /etc/nginx/sites-enabled/checkmate nginx_enable_site checkmate
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
msg_ok "Configured Nginx Reverse Proxy" msg_ok "Configured Nginx Reverse Proxy"
motd_ssh motd_ssh
+1 -5
View File
@@ -185,11 +185,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/databasus /etc/nginx/sites-enabled/databasus nginx_enable_site databasus
rm -f /etc/nginx/sites-enabled/default
$STD nginx -t
$STD systemctl enable -q --now nginx
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+1 -3
View File
@@ -174,9 +174,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/dawarich.conf /etc/nginx/sites-enabled/ nginx_enable_site dawarich.conf
rm -f /etc/nginx/sites-enabled/default
systemctl enable -q --now nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+1 -4
View File
@@ -207,10 +207,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/discourse /etc/nginx/sites-enabled/discourse nginx_enable_site discourse
rm -f /etc/nginx/sites-enabled/default
$STD systemctl enable --now nginx
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+1 -3
View File
@@ -139,9 +139,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/dispatcharr.conf /etc/nginx/sites-enabled/dispatcharr.conf nginx_enable_site dispatcharr.conf
rm -f /etc/nginx/sites-enabled/default
systemctl restart nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
msg_info "Creating Services" msg_info "Creating Services"
+1 -5
View File
@@ -46,11 +46,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/espconnect /etc/nginx/sites-enabled/espconnect nginx_enable_site espconnect
rm -f /etc/nginx/sites-enabled/default
$STD nginx -t
systemctl enable -q nginx
systemctl restart nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+1 -3
View File
@@ -108,9 +108,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/excalidash /etc/nginx/sites-enabled/excalidash nginx_enable_site excalidash
rm -f /etc/nginx/sites-enabled/default
systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
msg_info "Creating Service" msg_info "Creating Service"
+1 -4
View File
@@ -57,10 +57,7 @@ set +a
envsubst </opt/feishin/settings.js.template >/etc/nginx/conf.d/settings.js envsubst </opt/feishin/settings.js.template >/etc/nginx/conf.d/settings.js
envsubst '${PUBLIC_PATH}' </opt/feishin/ng.conf.template >/etc/nginx/sites-available/feishin envsubst '${PUBLIC_PATH}' </opt/feishin/ng.conf.template >/etc/nginx/sites-available/feishin
ln -sf /etc/nginx/sites-available/feishin /etc/nginx/sites-enabled/feishin nginx_enable_site feishin
rm -f /etc/nginx/sites-enabled/default
systemctl enable -q --now nginx
systemctl reload nginx
msg_ok "Published Web Assets" msg_ok "Published Web Assets"
motd_ssh motd_ssh
+1 -4
View File
@@ -178,10 +178,7 @@ server {
error_log /var/log/geopulse/nginx/error.log; error_log /var/log/geopulse/nginx/error.log;
} }
EOF EOF
ln -sf /etc/nginx/sites-available/geopulse.conf /etc/nginx/sites-enabled/ nginx_enable_site geopulse.conf
rm -f /etc/nginx/sites-enabled/default
systemctl enable -q --now nginx
systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
msg_info "Creating Admin Helper" msg_info "Creating Admin Helper"
+2 -7
View File
@@ -26,9 +26,7 @@ chown -R www-data:www-data /opt/grav
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;') PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')
PHP_FPM_SOCK=$(find /run/php -maxdepth 1 -name "php*-fpm.sock" -type s | sort -V | tail -1) PHP_FPM_SOCK=$(get_php_fpm_socket)
unlink /etc/nginx/sites-enabled/default
rm -f /etc/nginx/sites-available/default
cat <<EOF >/etc/nginx/sites-available/grav cat <<EOF >/etc/nginx/sites-available/grav
server { server {
listen 80; listen 80;
@@ -99,11 +97,8 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/grav /etc/nginx/sites-enabled/grav
systemctl enable -q --now php${PHP_VER}-fpm systemctl enable -q --now php${PHP_VER}-fpm
$STD nginx -t nginx_enable_site grav
systemctl enable -q --now nginx
$STD nginx -s reload
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+3 -4
View File
@@ -115,6 +115,7 @@ chmod -R 775 /opt/investbrain/bootstrap/cache
msg_ok "Installed Investbrain" msg_ok "Installed Investbrain"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/investbrain.conf cat <<EOF >/etc/nginx/sites-available/investbrain.conf
server { server {
listen 8000 default_server; listen 8000 default_server;
@@ -135,7 +136,7 @@ server {
} }
location ~ \.php\$ { location ~ \.php\$ {
fastcgi_pass unix:/var/run/php/php${PHP_VERSION}-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name;
include fastcgi_params; include fastcgi_params;
fastcgi_hide_header X-Powered-By; fastcgi_hide_header X-Powered-By;
@@ -150,9 +151,7 @@ server {
access_log /var/log/nginx/investbrain_access.log; access_log /var/log/nginx/investbrain_access.log;
} }
EOF EOF
ln -sf /etc/nginx/sites-available/investbrain.conf /etc/nginx/sites-enabled/ nginx_enable_site investbrain.conf
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
msg_info "Setting up Supervisor" msg_info "Setting up Supervisor"
+4 -4
View File
@@ -110,6 +110,7 @@ chown -R www-data:www-data /opt/invoiceninja
msg_ok "Set up Database" msg_ok "Set up Database"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<'EOF' >/etc/nginx/sites-available/invoiceninja cat <<'EOF' >/etc/nginx/sites-available/invoiceninja
server { server {
listen 8080; listen 8080;
@@ -130,7 +131,7 @@ server {
} }
location = /index.php { location = /index.php {
fastcgi_pass unix:/run/php/php8.4-fpm.sock; fastcgi_pass unix:__PHP_SOCK__;
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
include fastcgi_params; include fastcgi_params;
fastcgi_param HTTP_X_FORWARDED_HOST $http_host; fastcgi_param HTTP_X_FORWARDED_HOST $http_host;
@@ -151,9 +152,8 @@ server {
} }
EOF EOF
ln -sf /etc/nginx/sites-available/invoiceninja /etc/nginx/sites-enabled/ sed -i "s|__PHP_SOCK__|${PHP_SOCK}|" /etc/nginx/sites-available/invoiceninja
rm -f /etc/nginx/sites-enabled/default nginx_enable_site invoiceninja
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
msg_info "Setting up Queue Worker" msg_info "Setting up Queue Worker"
+2 -1
View File
@@ -56,10 +56,11 @@ msg_ok "Set up InvoiceShelf"
msg_info "Configuring Caddy" msg_info "Configuring Caddy"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;') PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile cat <<EOF >/etc/caddy/Caddyfile
:80 { :80 {
root * /opt/invoiceshelf/public root * /opt/invoiceshelf/public
php_fastcgi unix//run/php/php${PHP_VER}-fpm.sock php_fastcgi unix/${PHP_SOCK}
file_server file_server
encode gzip encode gzip
} }
+1 -4
View File
@@ -86,7 +86,6 @@ systemctl enable -q --now kitchenowl
msg_ok "Created and Started Service" msg_ok "Created and Started Service"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
rm -f /etc/nginx/sites-enabled/default
cat <<'EOF' >/etc/nginx/sites-available/kitchenowl.conf cat <<'EOF' >/etc/nginx/sites-available/kitchenowl.conf
server { server {
listen 80; listen 80;
@@ -134,9 +133,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/kitchenowl.conf /etc/nginx/sites-enabled/ nginx_enable_site kitchenowl.conf
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+4 -4
View File
@@ -129,6 +129,7 @@ $STD systemctl restart php8.4-fpm
msg_ok "Tuned PHP-FPM" msg_ok "Tuned PHP-FPM"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<'EOF' >/etc/nginx/sites-available/koel cat <<'EOF' >/etc/nginx/sites-available/koel
server { server {
listen 80; listen 80;
@@ -156,7 +157,7 @@ server {
location ~ \.php$ { location ~ \.php$ {
try_files $uri $uri/ /index.php?$args; try_files $uri $uri/ /index.php?$args;
fastcgi_pass unix:/run/php/php8.4-fpm.sock; fastcgi_pass unix:__PHP_SOCK__;
fastcgi_index index.php; fastcgi_index index.php;
fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_split_path_info ^(.+\.php)(/.+)$;
fastcgi_intercept_errors on; fastcgi_intercept_errors on;
@@ -171,9 +172,8 @@ server {
} }
} }
EOF EOF
rm -f /etc/nginx/sites-enabled/default sed -i "s|__PHP_SOCK__|${PHP_SOCK}|" /etc/nginx/sites-available/koel
ln -sf /etc/nginx/sites-available/koel /etc/nginx/sites-enabled/koel nginx_enable_site koel
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
msg_info "Setting up Cron Job" msg_info "Setting up Cron Job"
+2 -3
View File
@@ -80,7 +80,7 @@ sed -i "s/listen = \/run\/php\/php8.4-fpm.sock/listen = \/run\/php-fpm-librenms.
msg_ok "Configured PHP-FPM" msg_ok "Configured PHP-FPM"
msg_info "Configure Nginx" msg_info "Configure Nginx"
cat <<EOF >/etc/nginx/sites-enabled/librenms cat <<EOF >/etc/nginx/sites-available/librenms
server { server {
listen 80; listen 80;
server_name ${LOCAL_IP}; server_name ${LOCAL_IP};
@@ -103,8 +103,7 @@ server {
} }
} }
EOF EOF
rm /etc/nginx/sites-enabled/default nginx_enable_site librenms
$STD systemctl reload nginx
systemctl restart php8.4-fpm systemctl restart php8.4-fpm
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
+2 -4
View File
@@ -115,10 +115,8 @@ server {
} }
} }
EOF EOF
$STD rm -f /etc/nginx/sites-enabled/default systemctl enable -q --now linkding linkding-tasks
$STD ln -sf /etc/nginx/sites-available/linkding /etc/nginx/sites-enabled/linkding nginx_enable_site linkding
systemctl enable -q --now nginx linkding linkding-tasks
systemctl restart nginx
msg_ok "Created Services" msg_ok "Created Services"
motd_ssh motd_ssh
+2 -1
View File
@@ -56,10 +56,11 @@ chown -R www-data:www-data /opt/lychee
msg_info "Configuring Caddy" msg_info "Configuring Caddy"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;') PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile cat <<EOF >/etc/caddy/Caddyfile
:80 { :80 {
root * /opt/lychee/public root * /opt/lychee/public
php_fastcgi unix//run/php/php${PHP_VER}-fpm.sock php_fastcgi unix/${PHP_SOCK}
file_server file_server
encode gzip encode gzip
} }
+1 -3
View File
@@ -134,9 +134,7 @@ server {
} }
} }
EOF EOF
ln -s /etc/nginx/sites-available/manyfold.conf /etc/nginx/sites-enabled/ nginx_enable_site manyfold.conf
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
msg_ok "Created Services" msg_ok "Created Services"
motd_ssh motd_ssh
+1 -5
View File
@@ -262,12 +262,8 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/mastodon /etc/nginx/sites-enabled/mastodon
rm -f /etc/nginx/sites-enabled/default
$STD nginx -t
systemctl enable -q --now redis-server systemctl enable -q --now redis-server
systemctl enable -q --now nginx nginx_enable_site mastodon
systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+2 -1
View File
@@ -45,12 +45,13 @@ msg_ok "Set up Matomo"
msg_info "Configuring Caddy" msg_info "Configuring Caddy"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;') PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile cat <<EOF >/etc/caddy/Caddyfile
:80 { :80 {
root * /opt/matomo root * /opt/matomo
@blocked path /config /config/* /tmp /tmp/* /.* /.*/* @blocked path /config /config/* /tmp /tmp/* /.* /.*/*
respond @blocked 403 respond @blocked 403
php_fastcgi unix//run/php/php${PHP_VER}-fpm.sock php_fastcgi unix/${PHP_SOCK}
file_server file_server
encode gzip encode gzip
} }
+1 -3
View File
@@ -59,7 +59,6 @@ USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "netboot-xyz-multiarch-im
USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "netboot-xyz-checksums" "netbootxyz/netboot.xyz" "singlefile" "latest" "/var/www/html" "netboot.xyz-sha256-checksums.txt" USE_ORIGINAL_FILENAME=true fetch_and_deploy_gh_release "netboot-xyz-checksums" "netbootxyz/netboot.xyz" "singlefile" "latest" "/var/www/html" "netboot.xyz-sha256-checksums.txt"
msg_info "Configuring Webserver" msg_info "Configuring Webserver"
rm -f /etc/nginx/sites-enabled/default
cat <<'EOF' >/etc/nginx/sites-available/netboot-xyz cat <<'EOF' >/etc/nginx/sites-available/netboot-xyz
server { server {
listen 80 default_server; listen 80 default_server;
@@ -83,8 +82,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/netboot-xyz /etc/nginx/sites-enabled/netboot-xyz nginx_enable_site netboot-xyz
$STD systemctl reload nginx
msg_ok "Configured Webserver" msg_ok "Configured Webserver"
msg_info "Configuring TFTP Server" msg_info "Configuring TFTP Server"
+1 -5
View File
@@ -55,11 +55,7 @@ server {
} }
EOF EOF
ln -sf /etc/nginx/sites-available/omnitools /etc/nginx/sites-enabled/omnitools nginx_enable_site omnitools
rm -f /etc/nginx/sites-enabled/default
$STD nginx -t
systemctl enable -q --now nginx
systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+1 -3
View File
@@ -62,9 +62,7 @@ server {
} }
EOF EOF
ln -s /etc/nginx/sites-available/ots.conf /etc/nginx/sites-enabled/ nginx_enable_site ots.conf
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
msg_ok "Configured nginx" msg_ok "Configured nginx"
msg_info "Creating Services" msg_info "Creating Services"
+3 -4
View File
@@ -57,6 +57,7 @@ $STD php artisan app:user:create paymenter admin admin@paymenter.org paymenter 1
msg_ok "Created Admin User" msg_ok "Created Admin User"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/paymenter.conf cat <<EOF >/etc/nginx/sites-available/paymenter.conf
server { server {
listen 80; listen 80;
@@ -72,7 +73,7 @@ server {
location ~ \.php\$ { location ~ \.php\$ {
include snippets/fastcgi-php.conf; include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php8.3-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name;
include fastcgi_params; include fastcgi_params;
} }
@@ -82,9 +83,7 @@ server {
} }
} }
EOF EOF
ln -s /etc/nginx/sites-available/paymenter.conf /etc/nginx/sites-enabled/ nginx_enable_site paymenter.conf
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
chown -R www-data:www-data /opt/paymenter/* chown -R www-data:www-data /opt/paymenter/*
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
+1 -3
View File
@@ -376,9 +376,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/plane.conf /etc/nginx/sites-enabled/plane.conf nginx_enable_site plane.conf
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+1 -5
View File
@@ -236,11 +236,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/postiz /etc/nginx/sites-enabled/postiz nginx_enable_site postiz
rm -f /etc/nginx/sites-enabled/default
$STD nginx -t
systemctl enable -q nginx
systemctl reload -q nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+3 -6
View File
@@ -29,6 +29,7 @@ chown -R www-data:www-data /var/www/html
msg_ok "Deployed Poznote" msg_ok "Deployed Poznote"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/poznote cat <<EOF >/etc/nginx/sites-available/poznote
server { server {
listen 8040; listen 8040;
@@ -41,7 +42,7 @@ server {
location ~ \.php$ { location ~ \.php$ {
include fastcgi_params; include fastcgi_params;
fastcgi_pass unix:/run/php/php8.4-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name;
fastcgi_param DOCUMENT_ROOT \$document_root; fastcgi_param DOCUMENT_ROOT \$document_root;
} }
@@ -51,11 +52,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/poznote /etc/nginx/sites-enabled/poznote nginx_enable_site poznote
rm -f /etc/nginx/sites-enabled/default
$STD nginx -t
systemctl enable -q --now nginx
systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+3 -4
View File
@@ -37,6 +37,7 @@ systemctl restart php8.2-fpm
msg_ok "Configured PHP" msg_ok "Configured PHP"
msg_info "Configuring Universal Nginx" msg_info "Configuring Universal Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/privatebin.conf cat <<EOF >/etc/nginx/sites-available/privatebin.conf
server { server {
listen 80 default_server; listen 80 default_server;
@@ -60,7 +61,7 @@ server {
location ~ \.php\$ { location ~ \.php\$ {
include snippets/fastcgi-php.conf; include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php8.2-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name;
include fastcgi_params; include fastcgi_params;
} }
@@ -75,9 +76,7 @@ server {
add_header X-XSS-Protection "1; mode=block"; add_header X-XSS-Protection "1; mode=block";
} }
EOF EOF
ln -s /etc/nginx/sites-available/privatebin.conf /etc/nginx/sites-enabled/ nginx_enable_site privatebin.conf
rm -f /etc/nginx/sites-enabled/default
systemctl reload nginx
msg_ok "Nginx Configured" msg_ok "Nginx Configured"
motd_ssh motd_ssh
+1 -3
View File
@@ -55,9 +55,7 @@ msg_ok "Set up Rackula"
msg_info "Configuring nginx" msg_info "Configuring nginx"
cp /opt/rackula/config/nginx.conf /etc/nginx/sites-available/rackula cp /opt/rackula/config/nginx.conf /etc/nginx/sites-available/rackula
rm -f /etc/nginx/sites-enabled/default nginx_enable_site rackula
ln -sf /etc/nginx/sites-available/rackula /etc/nginx/sites-enabled/rackula
$STD nginx -t
msg_ok "Configured nginx" msg_ok "Configured nginx"
msg_info "Creating Services" msg_info "Creating Services"
+1 -4
View File
@@ -93,10 +93,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/shlink-web-client /etc/nginx/sites-enabled/shlink-web-client nginx_enable_site shlink-web-client
rm -f /etc/nginx/sites-enabled/default
systemctl enable -q nginx
$STD systemctl restart nginx
msg_ok "Set up Web Client" msg_ok "Set up Web Client"
fi fi
+2 -1
View File
@@ -40,6 +40,7 @@ $STD php artisan key:generate --force
msg_ok "Configured Snipe-IT" msg_ok "Configured Snipe-IT"
msg_info "Creating Service" msg_info "Creating Service"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/conf.d/snipeit.conf cat <<EOF >/etc/nginx/conf.d/snipeit.conf
server { server {
listen 80; listen 80;
@@ -55,7 +56,7 @@ server {
location ~ \.php\$ { location ~ \.php\$ {
include fastcgi.conf; include fastcgi.conf;
include snippets/fastcgi-php.conf; include snippets/fastcgi-php.conf;
fastcgi_pass unix:/run/php/php8.3-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_split_path_info ^(.+\.php)(/.+)\$; fastcgi_split_path_info ^(.+\.php)(/.+)\$;
fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name;
include fastcgi_params; include fastcgi_params;
+2 -1
View File
@@ -68,10 +68,11 @@ msg_ok "Set up SolidTime"
msg_info "Configuring Caddy" msg_info "Configuring Caddy"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;') PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile cat <<EOF >/etc/caddy/Caddyfile
:80 { :80 {
root * /opt/solidtime/public root * /opt/solidtime/public
php_fastcgi unix//run/php/php${PHP_VER}-fpm.sock php_fastcgi unix/${PHP_SOCK}
file_server file_server
encode gzip encode gzip
} }
+1 -5
View File
@@ -91,11 +91,7 @@ sed \
-e 's|root /usr/share/nginx/html;|root /var/www/sparkyfitness;|g' \ -e 's|root /usr/share/nginx/html;|root /var/www/sparkyfitness;|g' \
-e 's|server_name localhost;|server_name _;|g' \ -e 's|server_name localhost;|server_name _;|g' \
"/opt/sparkyfitness/docker/nginx.conf" >/etc/nginx/sites-available/sparkyfitness "/opt/sparkyfitness/docker/nginx.conf" >/etc/nginx/sites-available/sparkyfitness
ln -sf /etc/nginx/sites-available/sparkyfitness /etc/nginx/sites-enabled/sparkyfitness nginx_enable_site sparkyfitness
rm -f /etc/nginx/sites-enabled/default
$STD nginx -t
$STD systemctl enable -q --now nginx
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+3 -4
View File
@@ -120,6 +120,7 @@ EOF
msg_ok "Set up Scheduler" msg_ok "Set up Scheduler"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/speedtest-tracker cat <<EOF >/etc/nginx/sites-available/speedtest-tracker
server { server {
listen 80; listen 80;
@@ -143,7 +144,7 @@ server {
error_page 404 /index.php; error_page 404 /index.php;
location ~ \.php$ { location ~ \.php$ {
fastcgi_pass unix:/var/run/php/php8.4-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name;
include fastcgi_params; include fastcgi_params;
} }
@@ -154,9 +155,7 @@ server {
} }
EOF EOF
ln -sf /etc/nginx/sites-available/speedtest-tracker /etc/nginx/sites-enabled/ nginx_enable_site speedtest-tracker
rm -f /etc/nginx/sites-enabled/default
systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+4 -4
View File
@@ -93,6 +93,7 @@ chmod -R 755 /opt/wallabag/{var,web/assets}
msg_ok "Installed Wallabag" msg_ok "Installed Wallabag"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<'EOF' >/etc/nginx/sites-available/wallabag cat <<'EOF' >/etc/nginx/sites-available/wallabag
server { server {
listen 8000; listen 8000;
@@ -110,7 +111,7 @@ server {
} }
location ~ ^/app\.php(/|$) { location ~ ^/app\.php(/|$) {
fastcgi_pass unix:/run/php/php8.3-fpm.sock; fastcgi_pass unix:__PHP_SOCK__;
fastcgi_split_path_info ^(.+\.php)(/.*)$; fastcgi_split_path_info ^(.+\.php)(/.*)$;
include fastcgi_params; include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
@@ -131,9 +132,8 @@ server {
} }
EOF EOF
ln -sf /etc/nginx/sites-available/wallabag /etc/nginx/sites-enabled/ sed -i "s|__PHP_SOCK__|${PHP_SOCK}|" /etc/nginx/sites-available/wallabag
rm -f /etc/nginx/sites-enabled/default nginx_enable_site wallabag
$STD systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
msg_info "Enabling Services" msg_info "Enabling Services"
+1 -4
View File
@@ -69,10 +69,7 @@ sed -i \
-e "s|/var/www/html|/opt/warracker/frontend|g" \ -e "s|/var/www/html|/opt/warracker/frontend|g" \
-e "s/client_max_body_size __NGINX_MAX_BODY_SIZE_CONFIG_VALUE__/client_max_body_size 32M/" \ -e "s/client_max_body_size __NGINX_MAX_BODY_SIZE_CONFIG_VALUE__/client_max_body_size 32M/" \
/etc/nginx/sites-available/warracker.conf /etc/nginx/sites-available/warracker.conf
ln -s /etc/nginx/sites-available/warracker.conf /etc/nginx/sites-enabled/warracker.conf nginx_enable_site warracker.conf
rm /etc/nginx/sites-enabled/default
systemctl restart nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
msg_info "Creating systemd services" msg_info "Creating systemd services"
+2 -1
View File
@@ -32,10 +32,11 @@ msg_ok "Set up Webtrees"
msg_info "Configuring Caddy" msg_info "Configuring Caddy"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;') PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile cat <<EOF >/etc/caddy/Caddyfile
:80 { :80 {
root * /opt/webtrees root * /opt/webtrees
php_fastcgi unix//run/php/php${PHP_VER}-fpm.sock php_fastcgi unix/${PHP_SOCK}
file_server file_server
encode gzip encode gzip
} }
+3 -6
View File
@@ -48,6 +48,7 @@ chown -R www-data:www-data /opt/yourls
msg_ok "Configured YOURLS" msg_ok "Configured YOURLS"
msg_info "Configuring Nginx" msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/yourls cat <<EOF >/etc/nginx/sites-available/yourls
server { server {
listen 80 default_server; listen 80 default_server;
@@ -62,7 +63,7 @@ server {
location ~ \.php\$ { location ~ \.php\$ {
try_files \$uri =404; try_files \$uri =404;
fastcgi_split_path_info ^(.+\.php)(/.+)\$; fastcgi_split_path_info ^(.+\.php)(/.+)\$;
fastcgi_pass unix:/run/php/php8.3-fpm.sock; fastcgi_pass unix:${PHP_SOCK};
fastcgi_index index.php; fastcgi_index index.php;
include fastcgi_params; include fastcgi_params;
fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name; fastcgi_param SCRIPT_FILENAME \$document_root\$fastcgi_script_name;
@@ -79,11 +80,7 @@ server {
} }
} }
EOF EOF
ln -sf /etc/nginx/sites-available/yourls /etc/nginx/sites-enabled/yourls nginx_enable_site yourls
rm -f /etc/nginx/sites-enabled/default
$STD nginx -t
systemctl enable -q --now nginx
systemctl reload nginx
msg_ok "Configured Nginx" msg_ok "Configured Nginx"
motd_ssh motd_ssh
+1 -3
View File
@@ -65,9 +65,7 @@ msg_ok "Installed Zammad"
msg_info "Setup Services" msg_info "Setup Services"
cp /opt/zammad/contrib/nginx/zammad.conf /etc/nginx/sites-available/zammad.conf cp /opt/zammad/contrib/nginx/zammad.conf /etc/nginx/sites-available/zammad.conf
sed -i "s/server_name localhost;/server_name $LOCAL_IP;/g" /etc/nginx/sites-available/zammad.conf sed -i "s/server_name localhost;/server_name $LOCAL_IP;/g" /etc/nginx/sites-available/zammad.conf
ln -sf /etc/nginx/sites-available/zammad.conf /etc/nginx/sites-enabled/ nginx_enable_site zammad.conf
rm -f /etc/nginx/sites-enabled/default
$STD systemctl reload nginx
msg_ok "Created Service" msg_ok "Created Service"
motd_ssh motd_ssh
+82
View File
@@ -8173,6 +8173,88 @@ EOF
msg_ok "Setup PHP ${INSTALLED_VERSION}" msg_ok "Setup PHP ${INSTALLED_VERSION}"
} }
# ------------------------------------------------------------------------------
# Resolves the path of the active PHP-FPM unix socket.
#
# Description:
# - Prefers the socket of ${PHP_VERSION} when that variable is set, which is
# the deterministic case directly after setup_php ran
# - Falls back to the highest version found below /run/php
# - Webserver-agnostic: works for nginx (fastcgi_pass) and Caddy (php_fastcgi)
#
# Notes:
# - Prints the path to stdout, diagnostics go to stderr, so the result can be
# captured via command substitution
# - Deliberately avoids `head -n1`: it closes the pipe early and with
# `set -o pipefail` (see catch_errors) SIGPIPE would abort the install
# - php-fpm has to be running, the socket only exists after the service start
#
# Usage:
# PHP_SOCK=$(get_php_fpm_socket)
# echo "fastcgi_pass unix:${PHP_SOCK};"
# ------------------------------------------------------------------------------
get_php_fpm_socket() {
local sock
if [[ -n "${PHP_VERSION:-}" && -S "/run/php/php${PHP_VERSION}-fpm.sock" ]]; then
echo "/run/php/php${PHP_VERSION}-fpm.sock"
return 0
fi
sock=$(find /run/php -maxdepth 1 -name "php*-fpm.sock" -type s 2>/dev/null | sort -V | tail -1)
if [[ -z "$sock" ]]; then
msg_error "No active PHP-FPM socket found under /run/php"
return 1
fi
echo "$sock"
}
# ------------------------------------------------------------------------------
# Enables an nginx site, validates the configuration and reloads the service.
#
# Description:
# - Removes the packaged default vhost (idempotent, unlike `unlink`)
# - Links the site from sites-available into sites-enabled
# - Runs `nginx -t` and aborts before a broken config reaches a running service
# - Enables the unit so nginx survives a reboot, then restarts it via
# safe_service_restart so a failed start is actually reported
#
# Variables:
# $1 - site name, has to exist as /etc/nginx/sites-available/<name>
#
# Usage:
# cat <<EOF >/etc/nginx/sites-available/myapp
# ...
# EOF
# nginx_enable_site myapp
# ------------------------------------------------------------------------------
nginx_enable_site() {
local site="${1:-}"
if [[ -z "$site" ]]; then
msg_error "nginx_enable_site: no site name given"
return 1
fi
if [[ ! -f "/etc/nginx/sites-available/${site}" ]]; then
msg_error "nginx site config not found: /etc/nginx/sites-available/${site}"
return 1
fi
rm -f /etc/nginx/sites-enabled/default /etc/nginx/sites-available/default
ln -sf "/etc/nginx/sites-available/${site}" "/etc/nginx/sites-enabled/${site}"
if ! $STD nginx -t; then
msg_error "nginx configuration test failed for site '${site}'"
return 1
fi
$STD systemctl enable -q nginx
safe_service_restart nginx
}
# ------------------------------------------------------------------------------ # ------------------------------------------------------------------------------
# Installs or upgrades PostgreSQL and optional extensions/modules. # Installs or upgrades PostgreSQL and optional extensions/modules.
# #
@@ -0,0 +1,224 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: CrazyWolf13
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/sakowicz/actual-budget-prometheus-exporter
if ! command -v curl &>/dev/null; then
printf "\r\e[2K%b" '\033[93m Setup Source \033[m' >&2
apt-get update >/dev/null 2>&1
apt-get install -y curl >/dev/null 2>&1
fi
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/core.func)
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/tools.func)
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/error_handler.func)
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/api.func) 2>/dev/null || true
declare -f init_tool_telemetry &>/dev/null && init_tool_telemetry "actual-budget-prometheus-exporter" "addon"
# Enable error handling
set -Eeuo pipefail
trap 'error_handler' ERR
load_functions
# ==============================================================================
# CONFIGURATION
# ==============================================================================
VERBOSE=${var_verbose:-no}
APP="actual-budget-prometheus-exporter"
APP_TYPE="tools"
INSTALL_PATH="/opt/actual-budget-prometheus-exporter"
CONFIG_PATH="/opt/actual-budget-prometheus-exporter.env"
SERVICE_PATH="/etc/systemd/system/actual-budget-prometheus-exporter.service"
# ==============================================================================
# OS DETECTION
# ==============================================================================
if ! grep -qE 'ID=debian|ID=ubuntu' /etc/os-release 2>/dev/null; then
echo -e "${CROSS} Unsupported OS detected. This script only supports Debian and Ubuntu."
exit 238
fi
# ==============================================================================
# UNINSTALL
# ==============================================================================
function uninstall() {
msg_info "Uninstalling Actual-Budget-Prometheus-Exporter"
systemctl disable -q --now actual-budget-prometheus-exporter
rm -f "$SERVICE_PATH"
rm -rf "$INSTALL_PATH"
rm -f "$CONFIG_PATH"
rm -f "/usr/local/bin/update_actual-budget-prometheus-exporter"
rm -f "$HOME/.actual-budget-prometheus-exporter"
msg_ok "Actual-Budget-Prometheus-Exporter has been uninstalled"
}
# ==============================================================================
# UPDATE
# ==============================================================================
function update() {
if check_for_gh_release "actual-budget-prometheus-exporter" "sakowicz/actual-budget-prometheus-exporter"; then
msg_info "Stopping service"
systemctl stop actual-budget-prometheus-exporter
msg_ok "Stopped service"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "actual-budget-prometheus-exporter" "sakowicz/actual-budget-prometheus-exporter" "tarball" "latest"
NODE_VERSION="22" setup_nodejs
msg_info "Building Actual-Budget-Prometheus-Exporter"
cd "$INSTALL_PATH"
$STD npm ci
$STD npm run build
msg_ok "Built Actual-Budget-Prometheus-Exporter"
msg_info "Starting service"
systemctl start actual-budget-prometheus-exporter
msg_ok "Started service"
msg_ok "Updated successfully!"
exit
fi
}
# ==============================================================================
# INSTALL
# ==============================================================================
function install() {
read -erp "Enter URL of Actual Budget server, example: (http://127.0.0.1:5006): " ACTUAL_SERVER_URL
read -rsp "Enter Actual Budget server password: " ACTUAL_PASSWORD
printf "\n"
echo -e "${TAB}${INFO} Find the Sync ID in Actual under Settings > Advanced settings > Sync ID"
read -erp "Enter Budget Sync ID: " ACTUAL_BUDGET_ID_1
read -rsp "Enter E2E encryption password (leave empty if end-to-end encryption is disabled): " ACTUAL_E2E_PASSWORD_1
printf "\n"
read -erp "Enter metrics port (default: 3001): " PORT_INPUT
PORT="${PORT_INPUT:-3001}"
# build-essential and python3 are required to compile better-sqlite3
# (native dependency of @actual-app/api) when no prebuilt binary is available.
msg_info "Installing Dependencies"
$STD apt install -y build-essential python3
msg_ok "Installed Dependencies"
fetch_and_deploy_gh_release "actual-budget-prometheus-exporter" "sakowicz/actual-budget-prometheus-exporter" "tarball" "latest"
NODE_VERSION="22" setup_nodejs
msg_info "Building Actual-Budget-Prometheus-Exporter"
cd "$INSTALL_PATH"
$STD npm ci
$STD npm run build
msg_ok "Built Actual-Budget-Prometheus-Exporter"
msg_info "Creating configuration"
cat <<EOF >"$CONFIG_PATH"
# https://github.com/sakowicz/actual-budget-prometheus-exporter
ACTUAL_SERVER_URL="${ACTUAL_SERVER_URL}"
ACTUAL_PASSWORD="${ACTUAL_PASSWORD}"
ACTUAL_BUDGET_ID_1="${ACTUAL_BUDGET_ID_1}"
ACTUAL_E2E_PASSWORD_1="${ACTUAL_E2E_PASSWORD_1}"
PORT="${PORT}"
# Optional: friendly label for the budget shown in the exported metrics
# ACTUAL_BUDGET_NAME_1=""
# Optional: monitor additional budgets by incrementing the numeric suffix
# ACTUAL_BUDGET_ID_2=""
# ACTUAL_E2E_PASSWORD_2=""
# ACTUAL_BUDGET_NAME_2=""
# Optional: set to 0 to accept a self-signed TLS certificate on the Actual server
# NODE_TLS_REJECT_UNAUTHORIZED="0"
EOF
msg_ok "Created configuration"
msg_info "Creating service"
cat <<EOF >"$SERVICE_PATH"
[Unit]
Description=Actual Budget Prometheus Exporter
Wants=network-online.target
After=network-online.target
[Service]
User=root
WorkingDirectory=$INSTALL_PATH
EnvironmentFile=$CONFIG_PATH
ExecStart=/usr/bin/node $INSTALL_PATH/dist/app.js
Restart=always
RestartSec=10
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now actual-budget-prometheus-exporter
msg_ok "Created and started service"
# Create update script
msg_info "Creating update script"
ensure_usr_local_bin_persist
cat <<'UPDATEEOF' >/usr/local/bin/update_actual-budget-prometheus-exporter
#!/usr/bin/env bash
# actual-budget-prometheus-exporter Update Script
type=update bash -c "$(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/tools/addon/actual-budget-prometheus-exporter.sh)"
UPDATEEOF
chmod +x /usr/local/bin/update_actual-budget-prometheus-exporter
msg_ok "Created update script (/usr/local/bin/update_actual-budget-prometheus-exporter)"
echo ""
msg_ok "Actual-Budget-Prometheus-Exporter installed successfully"
msg_ok "Metrics: ${BL}http://${LOCAL_IP}:${PORT}/metrics${CL}"
msg_ok "Config: ${BL}${CONFIG_PATH}${CL}"
}
# ==============================================================================
# MAIN
# ==============================================================================
header_info
ensure_usr_local_bin_persist
get_lxc_ip
# Handle type=update (called from update script)
if [[ "${type:-}" == "update" ]]; then
if [[ -d "$INSTALL_PATH" && -f "$INSTALL_PATH/dist/app.js" ]]; then
update
else
msg_error "Actual-Budget-Prometheus-Exporter is not installed. Nothing to update."
exit 233
fi
exit 0
fi
# Check if already installed
if [[ -d "$INSTALL_PATH" && -f "$INSTALL_PATH/dist/app.js" ]]; then
msg_warn "Actual-Budget-Prometheus-Exporter is already installed."
echo ""
echo -n "${TAB}Uninstall Actual-Budget-Prometheus-Exporter? (y/N): "
read -r uninstall_prompt
if [[ "${uninstall_prompt,,}" =~ ^(y|yes)$ ]]; then
uninstall
exit 0
fi
echo -n "${TAB}Update Actual-Budget-Prometheus-Exporter? (y/N): "
read -r update_prompt
if [[ "${update_prompt,,}" =~ ^(y|yes)$ ]]; then
update
exit 0
fi
msg_warn "No action selected. Exiting."
exit 0
fi
# Fresh installation
msg_warn "Actual-Budget-Prometheus-Exporter is not installed."
echo ""
echo -e "${TAB}${INFO} This will install:"
echo -e "${TAB} - Actual Budget Prometheus Exporter (Node.js source build)"
echo -e "${TAB} - Systemd service"
echo ""
echo -n "${TAB}Install Actual-Budget-Prometheus-Exporter? (y/N): "
read -r install_prompt
if [[ "${install_prompt,,}" =~ ^(y|yes)$ ]]; then
install
else
msg_warn "Installation cancelled. Exiting."
exit 0
fi
@@ -0,0 +1,6 @@
__ __ __ __ __ __ __ __
____ ______/ /___ ______ _/ / / /_ __ ______/ /___ ____ / /_ ____ _________ ____ ___ ___ / /_/ /_ ___ __ _______ ___ _ ______ ____ _____/ /____ _____
/ __ `/ ___/ __/ / / / __ `/ /_____/ __ \/ / / / __ / __ `/ _ \/ __/_____/ __ \/ ___/ __ \/ __ `__ \/ _ \/ __/ __ \/ _ \/ / / / ___/_____/ _ \| |/_/ __ \/ __ \/ ___/ __/ _ \/ ___/
/ /_/ / /__/ /_/ /_/ / /_/ / /_____/ /_/ / /_/ / /_/ / /_/ / __/ /_/_____/ /_/ / / / /_/ / / / / / / __/ /_/ / / / __/ /_/ (__ )_____/ __/> </ /_/ / /_/ / / / /_/ __/ /
\__,_/\___/\__/\__,_/\__,_/_/ /_.___/\__,_/\__,_/\__, /\___/\__/ / .___/_/ \____/_/ /_/ /_/\___/\__/_/ /_/\___/\__,_/____/ \___/_/|_/ .___/\____/_/ \__/\___/_/
/____/ /_/ /_/