Compare commits

...
Author SHA1 Message Date
MickLesk 232086d7da AudioMuse-AI: replace the venv on update without asking
uv venv on an existing .venv asks before replacing it and refuses outright
without a terminal, so updates through update-apps.sh failed and left the
services stopped (#17734). --clear replaces it the way the interactive prompt
did.
2026-10-07 07:35:18 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 48706f41d5 Update CHANGELOG.md (#17730)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 15:39:40 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 017691457a Update CHANGELOG.md (#17729)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:29:29 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 17f5ac84e5 Update CHANGELOG.md (#17728)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:27:31 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 0b0ad2e9bd Update CHANGELOG.md (#17727)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:27:19 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 78a4d809c7 Update CHANGELOG.md (#17726)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:26:51 +00:00
CanbiZ (MickLesk) 36078aa896 Webtrees: stop serving data/ and the source folders directly (#17724)
Caddy served all of /opt/webtrees through file_server, so media under
data/media could be fetched by URL without passing webtrees' privacy rules.
webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the
folders webtrees' own nginx guide keeps private, plus dotfiles.

update_script adds the rule to existing Caddyfiles on every update, not only
when a new release is out, and keeps the old file if the result fails
caddy validate.
2026-10-06 16:26:21 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 69bbf389f3 Update CHANGELOG.md (#17725)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:23:09 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 1da0c463ca Update CHANGELOG.md (#17723)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:54:15 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 745f88d484 Update CHANGELOG.md (#17722)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:53:39 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 0fba89af41 Update CHANGELOG.md (#17720)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:31:19 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 2fa0128614 Update CHANGELOG.md (#17719)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:24:53 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] efd8a86c2a Update CHANGELOG.md (#17718)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 13:23:14 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] c7257f3f9d Update CHANGELOG.md (#17717)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:40:22 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 15263edeaf Update CHANGELOG.md (#17716)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:32:56 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 463d9828d9 Update CHANGELOG.md (#17715)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:32:35 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 405d2fa578 Update CHANGELOG.md (#17714)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 11:10:46 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 185ae4fde2 Update CHANGELOG.md (#17712)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 08:49:06 +00:00
push-app-to-main[bot] bf3fad3984 Add pricebuddy (ct) (#17708)
Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
2026-10-06 10:48:36 +02:00
6 changed files with 320 additions and 1 deletions

No files matched your search

+28
View File
@@ -559,6 +559,34 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-10-06
### 🆕 New Scripts
- Pricebuddy ([#17708](https://github.com/community-scripts/ProxmoxVE/pull/17708))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Webtrees: stop serving data/ and the source folders directly [@MickLesk](https://github.com/MickLesk) ([#17724](https://github.com/community-scripts/ProxmoxVE/pull/17724))
### 💾 Core
- Incus: check the architecture on Incus hosts too [@MickLesk](https://github.com/MickLesk) ([core#113](https://github.com/community-scripts/core/pull/113))
- Incus: Pass the app's var_* settings into Incus containers [@MickLesk](https://github.com/MickLesk) ([core#112](https://github.com/community-scripts/core/pull/112))
- Incus: stub storage_content_check on Incus [@MickLesk](https://github.com/MickLesk) ([core#104](https://github.com/community-scripts/core/pull/104))
- Incus: map Proxmox template versions to Incus image names [@MickLesk](https://github.com/MickLesk) ([core#111](https://github.com/community-scripts/core/pull/111))
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
- Incus: show the spinner inside containers again [@MickLesk](https://github.com/MickLesk) ([core#109](https://github.com/community-scripts/core/pull/109))
- Incus: set the hostname with sh, so it works before bash is installed [@MickLesk](https://github.com/MickLesk) ([core#102](https://github.com/community-scripts/core/pull/102))
- Incus: reserve a plain address on Incus, leave the gateway to the network [@MickLesk](https://github.com/MickLesk) ([core#101](https://github.com/community-scripts/core/pull/101))
- Incus: Wait for the network on Alpine OS too [@MickLesk](https://github.com/MickLesk) ([core#105](https://github.com/community-scripts/core/pull/105))
- Incus: do not fail the build when hostname -I is missing [@MickLesk](https://github.com/MickLesk) ([core#103](https://github.com/community-scripts/core/pull/103))
- Incus: Fuse always in unprivileged Containers, attach TUN only when container lacks it [@MickLesk](https://github.com/MickLesk) ([core#108](https://github.com/community-scripts/core/pull/108))
- Incus: accept mode=generated [@MickLesk](https://github.com/MickLesk) ([core#106](https://github.com/community-scripts/core/pull/106))
- Incus: pass the full install environment into Incus containers (quoted) [@MickLesk](https://github.com/MickLesk) ([core#107](https://github.com/community-scripts/core/pull/107))
## 2026-10-05
### 🚀 Updated Scripts
+1 -1
View File
@@ -58,7 +58,7 @@ function update_script() {
msg_info "Updating Python Environment (${AUDIOMUSE_BACKEND})"
cd /opt/audiomuse-ai
$STD uv venv --seed --python "$PY_VERSION" /opt/audiomuse-ai/.venv
$STD uv venv --clear --seed --python "$PY_VERSION" /opt/audiomuse-ai/.venv
$STD uv pip install --python /opt/audiomuse-ai/.venv \
-r "/opt/audiomuse-ai/requirements/${REQ_COMMON}" \
-r "/opt/audiomuse-ai/requirements/${REQ_ACCEL}"
+106
View File
@@ -0,0 +1,106 @@
#!/usr/bin/env bash
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/jez500/pricebuddy
APP="PriceBuddy"
var_tags="${var_tags:-shopping;price-tracker}"
var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-3072}"
var_disk="${var_disk:-10}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-no}" # the bundled scraper runs Google Chrome, which is amd64-only
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -d /opt/pricebuddy ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "pricebuddy" "jez500/pricebuddy"; then
msg_info "Stopping PriceBuddy Worker"
systemctl stop pricebuddy-worker
msg_ok "Stopped PriceBuddy Worker"
setup_composer
NODE_VERSION="22" setup_nodejs
create_backup /opt/pricebuddy/.env /opt/pricebuddy/storage
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "pricebuddy" "jez500/pricebuddy" "tarball"
restore_backup
msg_info "Updating PriceBuddy"
cd /opt/pricebuddy
sed -i "s/^APP_VERSION=.*/APP_VERSION=$(cat ~/.pricebuddy)/" .env
$STD composer install --no-dev --optimize-autoloader --no-interaction
$STD npm install
$STD npm run build
$STD php artisan storage:link
$STD php artisan migrate --force
$STD php artisan optimize
$STD php artisan icons:cache
$STD php artisan buddy:regenerate-price-cache
chown -R www-data:www-data /opt/pricebuddy
msg_ok "Updated PriceBuddy"
msg_info "Starting PriceBuddy Worker"
systemctl start pricebuddy-worker
msg_ok "Started PriceBuddy Worker"
msg_ok "Updated successfully!"
fi
if check_for_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper"; then
msg_info "Stopping SeleniumBase Scrapper"
systemctl stop seleniumbase-scrapper
msg_ok "Stopped SeleniumBase Scrapper"
msg_info "Updating Google Chrome"
apt_update_safe
upgrade_packages_with_retry google-chrome-stable
msg_ok "Updated Google Chrome"
PYTHON_VERSION="3.12" setup_uv
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper" "tarball"
msg_info "Updating SeleniumBase Scrapper"
$STD uv venv --python 3.12 /opt/seleniumbase-scrapper/.venv
$STD uv pip install --python /opt/seleniumbase-scrapper/.venv/bin/python \
"seleniumbase==$(sed -n 's/^ARG SELENIUMBASE_VERSION=v//p' /opt/seleniumbase-scrapper/Dockerfile)" \
flask \
beautifulsoup4
$STD /opt/seleniumbase-scrapper/.venv/bin/seleniumbase get chromedriver
msg_ok "Updated SeleniumBase Scrapper"
msg_info "Starting SeleniumBase Scrapper"
systemctl start seleniumbase-scrapper
msg_ok "Started SeleniumBase Scrapper"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}${CL}"
echo -e "${INFO}${YW}Log in as admin@example.com - the password is APP_USER_PASSWORD in /opt/pricebuddy/.env${CL}"
+14
View File
@@ -31,6 +31,20 @@ function update_script() {
exit
fi
if ! grep -q "@private" /etc/caddy/Caddyfile; then
msg_info "Blocking direct access to webtrees data"
cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak
sed -i '\|root \* /opt/webtrees|a\ @private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*\n respond @private 403' /etc/caddy/Caddyfile
if grep -q "@private" /etc/caddy/Caddyfile && caddy validate --config /etc/caddy/Caddyfile &>/dev/null; then
rm -f /etc/caddy/Caddyfile.bak
systemctl reload-or-restart caddy
msg_ok "Blocked direct access to webtrees data"
else
mv /etc/caddy/Caddyfile.bak /etc/caddy/Caddyfile
msg_warn "Could not patch /etc/caddy/Caddyfile - deny /data/ there by hand"
fi
fi
if check_for_gh_release "webtrees" "fisharebest/webtrees"; then
msg_info "Stopping Service"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')
+168
View File
@@ -0,0 +1,168 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/jez500/pricebuddy
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y \
nginx \
cron \
xvfb
msg_ok "Installed Dependencies"
PHP_VERSION="8.4" PHP_FPM="YES" PHP_MEMORY_LIMIT="2048M" setup_php
setup_composer
NODE_VERSION="22" setup_nodejs
setup_mariadb
MARIADB_DB_NAME="pricebuddy" MARIADB_DB_USER="pricebuddy" setup_mariadb_db
PYTHON_VERSION="3.12" setup_uv
msg_info "Installing Google Chrome"
setup_deb822_repo \
"google-chrome" \
"https://dl.google.com/linux/linux_signing_key.pub" \
"https://dl.google.com/linux/chrome/deb/" \
"stable"
$STD apt install -y google-chrome-stable
# the package adds its own .list for the same repo, which apt rejects next to the deb822 source
rm -f /etc/apt/sources.list.d/google-chrome.list
msg_ok "Installed Google Chrome"
fetch_and_deploy_gh_release "seleniumbase-scrapper" "jez500/seleniumbase-scrapper" "tarball"
msg_info "Setting up SeleniumBase Scrapper"
$STD uv venv --python 3.12 /opt/seleniumbase-scrapper/.venv
# the SeleniumBase release upstream builds and tests its image against
$STD uv pip install --python /opt/seleniumbase-scrapper/.venv/bin/python \
"seleniumbase==$(sed -n 's/^ARG SELENIUMBASE_VERSION=v//p' /opt/seleniumbase-scrapper/Dockerfile)" \
flask \
beautifulsoup4
$STD /opt/seleniumbase-scrapper/.venv/bin/seleniumbase get chromedriver
msg_ok "Set up SeleniumBase Scrapper"
fetch_and_deploy_gh_release "pricebuddy" "jez500/pricebuddy" "tarball"
msg_info "Setting up PriceBuddy"
cd /opt/pricebuddy
cat <<EOF >/opt/pricebuddy/.env
APP_NAME=PriceBuddy
APP_ENV=production
APP_KEY=base64:$(openssl rand -base64 32)
APP_DEBUG=false
APP_URL=http://${LOCAL_IP}
APP_VERSION=$(cat ~/.pricebuddy)
DB_CONNECTION=mariadb
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=pricebuddy
DB_USERNAME=pricebuddy
DB_PASSWORD=${MARIADB_DB_PASS}
SCRAPER_BASE_URL=http://127.0.0.1:3000
APP_USER_EMAIL=admin@example.com
APP_USER_PASSWORD=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c16)
EOF
$STD composer install --no-dev --optimize-autoloader --no-interaction
$STD npm install
$STD npm run build
$STD php artisan storage:link
# reads APP_USER_* for the admin via env(), so it has to run before optimize caches the config
$STD php artisan buddy:init-db
$STD php artisan optimize
$STD php artisan icons:cache
chown -R www-data:www-data /opt/pricebuddy
chmod 600 /opt/pricebuddy/.env
msg_ok "Set up PriceBuddy"
msg_info "Configuring Nginx"
PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/nginx/sites-available/pricebuddy
server {
listen 80;
server_name _;
root /opt/pricebuddy/public;
index index.php;
charset utf-8;
location / {
try_files \$uri \$uri/ /index.php?\$query_string;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
error_page 404 /index.php;
location ~ \.php\$ {
fastcgi_pass unix:${PHP_SOCK};
fastcgi_param SCRIPT_FILENAME \$realpath_root\$fastcgi_script_name;
include fastcgi_params;
fastcgi_read_timeout 300;
}
location ~ /\.(?!well-known).* {
deny all;
}
}
EOF
nginx_enable_site "pricebuddy"
msg_ok "Configured Nginx"
msg_info "Creating Services"
cat <<EOF >/etc/systemd/system/seleniumbase-scrapper.service
[Unit]
Description=SeleniumBase Scrapper for PriceBuddy
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/seleniumbase-scrapper/api
Environment=API_HOST=127.0.0.1
Environment=API_PORT=3000
ExecStart=/opt/seleniumbase-scrapper/.venv/bin/python /opt/seleniumbase-scrapper/api/server.py
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/systemd/system/pricebuddy-worker.service
[Unit]
Description=PriceBuddy Queue Worker
After=network.target mariadb.service
[Service]
Type=simple
User=www-data
Group=www-data
WorkingDirectory=/opt/pricebuddy
ExecStart=/usr/bin/php /opt/pricebuddy/artisan queue:work
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
cat <<EOF >/etc/cron.d/pricebuddy
* * * * * www-data cd /opt/pricebuddy && php artisan schedule:run >/dev/null 2>&1
EOF
systemctl enable -q --now seleniumbase-scrapper pricebuddy-worker
msg_ok "Created Services"
motd_ssh
customize
cleanup_lxc
+3
View File
@@ -36,6 +36,9 @@ PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile
:80 {
root * /opt/webtrees
# Caddy ignores data/.htaccess; media must go through webtrees so its privacy rules apply.
@private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*
respond @private 403
php_fastcgi unix/${PHP_SOCK}
file_server
encode gzip