mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-07-05 21:52:14 +02:00
Compare commits
2 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e39e813436 | |||
| cf9632c1ee |
@@ -501,10 +501,6 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
|
||||
|
||||
## 2026-07-05
|
||||
|
||||
### 🆕 New Scripts
|
||||
|
||||
- excalidash ([#15604](https://github.com/community-scripts/ProxmoxVE/pull/15604))
|
||||
|
||||
## 2026-07-04
|
||||
|
||||
### 🚀 Updated Scripts
|
||||
|
||||
@@ -1,79 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/build.func)
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/ZimengXiong/ExcaliDash
|
||||
|
||||
APP="ExcaliDash"
|
||||
var_tags="${var_tags:-documents;drawing;collaboration}"
|
||||
var_cpu="${var_cpu:-2}"
|
||||
var_ram="${var_ram:-2048}"
|
||||
var_disk="${var_disk:-8}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-no}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
|
||||
if [[ ! -d /opt/excalidash ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
|
||||
if check_for_gh_release "excalidash" "ZimengXiong/ExcaliDash"; then
|
||||
msg_info "Stopping Service"
|
||||
systemctl stop excalidash
|
||||
msg_ok "Stopped Service"
|
||||
|
||||
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "excalidash" "ZimengXiong/ExcaliDash" "tarball"
|
||||
ln -sf /opt/excalidash_data/.env /opt/excalidash/backend/.env
|
||||
set -a && source /opt/excalidash_data/.env && set +a
|
||||
|
||||
msg_info "Configuring Database Provider (${DATABASE_PROVIDER:-sqlite})"
|
||||
cd /opt/excalidash/backend
|
||||
sed -i '/datasource db {/,/}/ s/provider = env("[^"]*")/provider = "'"${DATABASE_PROVIDER:-sqlite}"'"/' prisma/schema.prisma
|
||||
mv prisma/migrations/"${DATABASE_PROVIDER:-sqlite}"/* prisma/migrations/
|
||||
rm -rf prisma/migrations/postgresql prisma/migrations/sqlite
|
||||
msg_ok "Configured Database Provider"
|
||||
|
||||
msg_info "Rebuilding Application"
|
||||
$STD npm ci
|
||||
$STD npx prisma generate
|
||||
$STD npx tsc
|
||||
cd /opt/excalidash/frontend
|
||||
$STD npm ci
|
||||
$STD npm run build
|
||||
cp -r /opt/excalidash/frontend/dist/. /var/www/excalidash/
|
||||
msg_ok "Rebuilt Application"
|
||||
|
||||
msg_info "Running Migrations"
|
||||
cd /opt/excalidash/backend
|
||||
$STD npx prisma migrate deploy
|
||||
msg_ok "Ran Migrations"
|
||||
|
||||
msg_info "Starting Service"
|
||||
systemctl start excalidash
|
||||
msg_ok "Started Service"
|
||||
msg_ok "Updated successfully!"
|
||||
fi
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed Successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW} Access it using the following URL:${CL}"
|
||||
echo -e "${TAB}${GATEWAY}${BGN}http://${IP}:6767${CL}"
|
||||
@@ -1,6 +0,0 @@
|
||||
______ ___ ____ __
|
||||
/ ____/ ___________ _/ (_) __ \____ ______/ /_
|
||||
/ __/ | |/_/ ___/ __ `/ / / / / / __ `/ ___/ __ \
|
||||
/ /____> </ /__/ /_/ / / / /_/ / /_/ (__ ) / / /
|
||||
/_____/_/|_|\___/\__,_/_/_/_____/\__,_/____/_/ /_/
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
_____ _ __
|
||||
/ ___/____ ___ __(_)___/ /
|
||||
\__ \/ __ `/ / / / / __ /
|
||||
___/ / /_/ / /_/ / / /_/ /
|
||||
/____/\__, /\__,_/_/\__,_/
|
||||
/_/
|
||||
+55
@@ -0,0 +1,55 @@
|
||||
#!/usr/bin/env bash
|
||||
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/build.func)
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: 007hacky007
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://www.squid-cache.org/
|
||||
|
||||
APP="Squid"
|
||||
var_tags="${var_tags:-proxy}"
|
||||
var_cpu="${var_cpu:-1}"
|
||||
var_ram="${var_ram:-512}"
|
||||
var_disk="${var_disk:-4}"
|
||||
var_os="${var_os:-debian}"
|
||||
var_version="${var_version:-13}"
|
||||
var_arm64="${var_arm64:-yes}"
|
||||
var_unprivileged="${var_unprivileged:-1}"
|
||||
|
||||
header_info "$APP"
|
||||
variables
|
||||
color
|
||||
catch_errors
|
||||
|
||||
function update_script() {
|
||||
header_info
|
||||
check_container_storage
|
||||
check_container_resources
|
||||
if [[ ! -f /etc/squid/squid.conf ]]; then
|
||||
msg_error "No ${APP} Installation Found!"
|
||||
exit
|
||||
fi
|
||||
msg_info "Updating Squid"
|
||||
$STD apt update
|
||||
$STD apt upgrade -y
|
||||
msg_ok "Updated Squid"
|
||||
|
||||
msg_info "Validating Squid Configuration"
|
||||
$STD squid -k parse
|
||||
msg_ok "Validated Squid Configuration"
|
||||
|
||||
msg_info "Restarting Squid"
|
||||
systemctl restart squid
|
||||
msg_ok "Restarted Squid"
|
||||
exit
|
||||
}
|
||||
|
||||
start
|
||||
build_container
|
||||
description
|
||||
|
||||
msg_ok "Completed successfully!\n"
|
||||
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
|
||||
echo -e "${INFO}${YW} Proxy endpoint:${CL}"
|
||||
echo -e "${TAB}${GATEWAY}${BGN}${IP}:3128${CL}"
|
||||
echo -e "${INFO}${YW} Add a proxy user inside the container with:${CL}"
|
||||
echo -e "${TAB}${BGN}htpasswd /etc/squid/passwords <username>${CL}"
|
||||
@@ -1,139 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: MickLesk (CanbiZ)
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://github.com/ZimengXiong/ExcaliDash
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
build-essential \
|
||||
nginx
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
NODE_VERSION="20" setup_nodejs
|
||||
PG_VERSION="18" setup_postgresql
|
||||
PG_DB_NAME="excalidash" PG_DB_USER="excalidash" setup_postgresql_db
|
||||
|
||||
fetch_and_deploy_gh_release "excalidash" "ZimengXiong/ExcaliDash" "tarball"
|
||||
|
||||
msg_info "Configuring Database Provider"
|
||||
cd /opt/excalidash/backend
|
||||
sed -i '/datasource db {/,/}/ s/provider = env("[^"]*")/provider = "postgresql"/' prisma/schema.prisma
|
||||
sed -i '/datasource db {/,/}/ s/provider = "[^"]*"/provider = "postgresql"/' prisma/schema.prisma
|
||||
mv prisma/migrations/postgresql/* prisma/migrations/
|
||||
rm -rf prisma/migrations/sqlite prisma/migrations/postgresql
|
||||
msg_ok "Configured Database Provider"
|
||||
|
||||
msg_info "Building Backend"
|
||||
cd /opt/excalidash/backend
|
||||
$STD npm ci
|
||||
$STD npx prisma generate
|
||||
$STD npx tsc
|
||||
msg_ok "Built Backend"
|
||||
|
||||
msg_info "Building Frontend"
|
||||
cd /opt/excalidash/frontend
|
||||
$STD npm ci
|
||||
$STD npm run build
|
||||
msg_ok "Built Frontend"
|
||||
|
||||
msg_info "Configuring Application"
|
||||
mkdir -p /opt/excalidash_data
|
||||
mkdir -p /var/www/excalidash
|
||||
cp -r /opt/excalidash/frontend/dist/. /var/www/excalidash/
|
||||
cat <<EOF >/opt/excalidash_data/.env
|
||||
DATABASE_PROVIDER=postgresql
|
||||
DATABASE_URL=postgresql://${PG_DB_USER}:${PG_DB_PASS}@localhost:5432/${PG_DB_NAME}
|
||||
PORT=8000
|
||||
NODE_ENV=production
|
||||
FRONTEND_URL=http://${LOCAL_IP}:6767
|
||||
AUTH_MODE=local
|
||||
TRUST_PROXY=false
|
||||
RUN_MIGRATIONS=false
|
||||
JWT_SECRET=$(openssl rand -hex 32)
|
||||
CSRF_SECRET=$(openssl rand -base64 32)
|
||||
EOF
|
||||
ln -sf /opt/excalidash_data/.env /opt/excalidash/backend/.env
|
||||
cd /opt/excalidash/backend
|
||||
set -a && source /opt/excalidash_data/.env && set +a
|
||||
$STD npx prisma migrate deploy
|
||||
msg_ok "Configured Application"
|
||||
|
||||
msg_info "Configuring Nginx"
|
||||
cat <<EOF >/etc/nginx/sites-available/excalidash
|
||||
server {
|
||||
listen 6767;
|
||||
server_name _;
|
||||
root /var/www/excalidash;
|
||||
index index.html;
|
||||
client_max_body_size 50M;
|
||||
|
||||
location /api/ {
|
||||
proxy_pass http://127.0.0.1:8000/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade \$http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
proxy_read_timeout 300s;
|
||||
proxy_send_timeout 300s;
|
||||
}
|
||||
|
||||
location /socket.io/ {
|
||||
proxy_pass http://127.0.0.1:8000/socket.io/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade \$http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host \$host;
|
||||
proxy_set_header X-Real-IP \$remote_addr;
|
||||
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto \$scheme;
|
||||
proxy_read_timeout 3600s;
|
||||
proxy_send_timeout 3600s;
|
||||
}
|
||||
|
||||
location / {
|
||||
try_files \$uri \$uri/ /index.html;
|
||||
}
|
||||
}
|
||||
EOF
|
||||
ln -sf /etc/nginx/sites-available/excalidash /etc/nginx/sites-enabled/excalidash
|
||||
rm -f /etc/nginx/sites-enabled/default
|
||||
systemctl reload nginx
|
||||
msg_ok "Configured Nginx"
|
||||
|
||||
msg_info "Creating Service"
|
||||
cat <<EOF >/etc/systemd/system/excalidash.service
|
||||
[Unit]
|
||||
Description=ExcaliDash Service
|
||||
After=network.target postgresql.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/excalidash/backend
|
||||
EnvironmentFile=/opt/excalidash/backend/.env
|
||||
ExecStart=/usr/bin/node dist/index.js
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
systemctl enable -q --now excalidash
|
||||
msg_ok "Created Service"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
@@ -0,0 +1,88 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# Copyright (c) 2021-2026 community-scripts ORG
|
||||
# Author: 007hacky007
|
||||
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
|
||||
# Source: https://www.squid-cache.org/
|
||||
|
||||
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
|
||||
color
|
||||
verb_ip6
|
||||
catch_errors
|
||||
setting_up_container
|
||||
network_check
|
||||
update_os
|
||||
|
||||
msg_info "Configuring Squid"
|
||||
mkdir -p /etc/squid
|
||||
cat <<EOF >/etc/squid/squid.conf
|
||||
acl localnet src 0.0.0.1-0.255.255.255
|
||||
acl localnet src 10.0.0.0/8
|
||||
acl localnet src 100.64.0.0/10
|
||||
acl localnet src 169.254.0.0/16
|
||||
acl localnet src 172.16.0.0/12
|
||||
acl localnet src 192.168.0.0/16
|
||||
acl localnet src fc00::/7
|
||||
acl localnet src fe80::/10
|
||||
|
||||
acl SSL_ports port 443
|
||||
acl Safe_ports port 80
|
||||
acl Safe_ports port 21
|
||||
acl Safe_ports port 443
|
||||
acl Safe_ports port 70
|
||||
acl Safe_ports port 210
|
||||
acl Safe_ports port 1025-65535
|
||||
acl Safe_ports port 280
|
||||
acl Safe_ports port 488
|
||||
acl Safe_ports port 591
|
||||
acl Safe_ports port 777
|
||||
acl CONNECT method CONNECT
|
||||
|
||||
http_access deny !Safe_ports
|
||||
http_access deny CONNECT !SSL_ports
|
||||
http_access allow localhost manager
|
||||
http_access deny manager
|
||||
|
||||
auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/passwords
|
||||
auth_param basic realm proxy
|
||||
acl authenticated proxy_auth REQUIRED
|
||||
http_access allow authenticated
|
||||
http_access deny all
|
||||
|
||||
http_port 3128
|
||||
|
||||
coredump_dir /var/spool/squid
|
||||
|
||||
refresh_pattern ^ftp: 1440 20% 10080
|
||||
refresh_pattern ^gopher: 1440 0% 1440
|
||||
refresh_pattern -i (/cgi-bin/|\\?) 0 0% 0
|
||||
refresh_pattern . 0 20% 4320
|
||||
|
||||
# Privacy / hardening
|
||||
httpd_suppress_version_string on
|
||||
visible_hostname $(hostname)
|
||||
forwarded_for delete
|
||||
request_header_access X-Forwarded-For deny all
|
||||
EOF
|
||||
msg_ok "Configured Squid"
|
||||
|
||||
msg_info "Installing Dependencies"
|
||||
$STD apt install -y \
|
||||
squid \
|
||||
apache2-utils
|
||||
msg_ok "Installed Dependencies"
|
||||
|
||||
msg_info "Configuring Squid Authentication"
|
||||
touch /etc/squid/passwords
|
||||
chown proxy:proxy /etc/squid/passwords
|
||||
chmod 640 /etc/squid/passwords
|
||||
$STD squid -k parse
|
||||
msg_ok "Configured Squid Authentication"
|
||||
|
||||
msg_info "Starting Service"
|
||||
systemctl enable -q --now squid
|
||||
msg_ok "Started Service"
|
||||
|
||||
motd_ssh
|
||||
customize
|
||||
cleanup_lxc
|
||||
Reference in New Issue
Block a user