Compare commits

...
Author SHA1 Message Date
MickLesk 4fdf136ffd Post a test command for vm/, tools/ and turnkey/ changes too
A fix to tools/addon/all-templates.sh got no comment because only ct/ and
install/ were recognised. Each script now also says where it runs, read from
what it calls: the Proxmox VE host, inside a guest, or PBS/PMG/PDM.
2026-09-29 14:12:06 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 36d6cb2c74 Update CHANGELOG.md (#17586)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 12:03:21 +00:00
Denislav DenevandMichel Roegl-Brunner 8a314a12be fix(romm): snapshot Redis hourly like the upstream image (#17562)
* fix(romm): snapshot Redis hourly like the upstream image

Redis' default save policy (3600 1 300 100 60 10000) rewrites the whole dump.rdb every 5 minutes on an idle RomM, because the RQ workers and scheduler change keys constantly. With the Switch TitleDB and PS2 serial caches the dump is ~50 MB, so an idle container writes ~14 GB/day. Upstream fixed this for the Docker image (rommapp/romm#3983, REDIS_SAVE_POLICY default "3600 1"), but that lives in docker/init_scripts/init, which the LXC install never runs. Apply the same policy on install and, for existing containers, on update unless a save policy is already set.

* Update ct/romm.sh

* Update install/romm-install.sh

---------

Co-authored-by: Michel Roegl-Brunner <73236783+michelroegl-brunner@users.noreply.github.com>
2026-09-29 14:02:51 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] d095b9020c Update CHANGELOG.md (#17584)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 11:49:13 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] f926f143cf Update CHANGELOG.md (#17580)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 11:13:56 +00:00
push-app-to-main[bot]andCanbiZ 098ce2dea0 Anki Sync Server (#17416)
* Add anki-sync-server (ct)

* Clean up comments in anki-sync-server.sh

Removed comments about local core checkout and credential storage.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-09-29 13:13:28 +02:00
7 changed files with 210 additions and 8 deletions
+63 -7
View File
@@ -2,7 +2,8 @@ name: PR test command
# Posts a ready-to-run test command for reviewers.
# It uses this PR’s script branch with the production engine, since both resolve
# independently. Only scripts using community-scripts/core are supported.
# independently. ct/ scripts need community-scripts/core; vm/, tools/ and
# turnkey/ scripts run straight from the branch.
#
# pull_request_target allows comments on fork PRs. No PR code is checked out or
# executed; API inputs are validated and the comment is assembled in JavaScript.
@@ -14,6 +15,9 @@ on:
paths:
- "ct/**"
- "install/**"
- "vm/**"
- "tools/**"
- "turnkey/**"
jobs:
comment:
@@ -50,14 +54,43 @@ jobs:
// ct/foo.sh and install/foo-install.sh are the same app. A removed
// file has nothing left to run.
const apps = new Map(); // slug -> {ct, install}
const others = [];
for (const f of files) {
if (f.status === 'removed') continue;
let m = f.filename.match(/^ct\/([a-z0-9][a-z0-9._-]*)\.sh$/);
if (m) { apps.set(m[1], { ...apps.get(m[1]), ct: true }); continue; }
m = f.filename.match(/^install\/([a-z0-9][a-z0-9._-]*)-install\.sh$/);
if (m) apps.set(m[1], { ...apps.get(m[1]), install: true });
if (m) { apps.set(m[1], { ...apps.get(m[1]), install: true }); continue; }
if (/^(vm|tools|turnkey)\/[A-Za-z0-9._\/-]+\.sh$/.test(f.filename)) others.push(f.filename);
}
if (apps.size === 0) return;
if (apps.size === 0 && others.length === 0) return;
others.sort();
// Where a tool runs is read from the script itself; it is never run.
const HOST = /(^|[\s;&|(`$])(pct|qm|pveam|pvesm|pvesh|pveversion)\s/m;
async function runsOn(path) {
if (path.startsWith('vm/')) return 'pve';
const appliance = (path.split('/').pop().match(/(?:^|-)(pbs|pmg|pdm)(?=[0-9-]|\.sh$)/) || [])[1];
if (path.startsWith('tools/pve/')) return appliance || 'pve';
let text = '';
try {
const res = await github.rest.repos.getContent({
owner: head.owner.login, repo: head.name, path, ref: pr.head.sha,
});
text = Buffer.from(res.data.content || '', 'base64').toString('utf8');
} catch (e) {}
if (HOST.test(text.replace(/^\s*#.*$/gm, '').replace(/command -v \S+/g, ''))) return 'pve';
if (appliance) return appliance;
return path.startsWith('tools/addon/') ? 'guest' : 'unknown';
}
const WHERE = {
pve: 'in the Proxmox VE shell',
guest: 'inside the LXC or VM that should get it',
pbs: 'in the Proxmox Backup Server shell',
pmg: 'in the Proxmox Mail Gateway shell',
pdm: 'in the Proxmox Datacenter Manager shell',
unknown: 'wherever the script is meant to run',
};
// Read the ct script at the PR head to see which engine it loads.
// Read only -- it is never sourced or run.
@@ -111,10 +144,9 @@ jobs:
);
}
lines.push(
'Both lines are needed. Each script pins `_CS_DEFAULT_URL` to `main`, and that',
'pin is what fills `COMMUNITY_SCRIPTS_URL` when the variable is unset — so',
'curling the branch URL on its own gives you the `ct/` script from this PR and',
'the `install/` script from `main`. Frequently the one you meant to test.',
'Both lines are needed. Without `COMMUNITY_SCRIPTS_URL` the engine falls back to',
'`main`, so curling the branch URL on its own gives you the `ct/` script from',
'this PR and the `install/` script from `main`. Frequently the one you meant to test.',
'',
'The same command works on an Incus host: the engine detects the platform and',
'loads the matching backend, while the scripts still come from this branch.',
@@ -133,6 +165,30 @@ jobs:
);
}
if (others.length > 0) {
const shown = others.slice(0, MAX_APPS);
lines.push(...(ready.length > 0 ? ['', '---', ''] : ['### Try this branch', '']));
for (const path of shown) {
lines.push(
`\`${path}\`, run ${WHERE[await runsOn(path)]}:`,
'```bash',
`bash -c "$(curl -fsSL "${base}/${path}")"`,
'```',
'',
);
}
if (others.length > shown.length) {
lines.push(
`${others.length - shown.length} more script(s) changed; same command, different path.`,
'',
);
}
lines.push(
'Only the script itself comes from this branch. Whatever it loads, the engine',
'or the `misc/` helpers, still comes from `main`.',
);
}
if (legacy.length > 0) {
lines.push(
'',
+7 -1
View File
@@ -551,15 +551,21 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
## 2026-09-29
### 🆕 New Scripts
- Anki Sync Server ([#17416](https://github.com/community-scripts/ProxmoxVE/pull/17416))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(romm): snapshot Redis hourly like the upstream image [@DenislavDenev](https://github.com/DenislavDenev) ([#17562](https://github.com/community-scripts/ProxmoxVE/pull/17562))
- checkmate: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17554](https://github.com/community-scripts/ProxmoxVE/pull/17554))
### 💾 Core
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#75](https://github.com/community-scripts/core/pull/75))
- Default the scripts base to ProxmoxVE [@MickLesk](https://github.com/MickLesk) ([core#76](https://github.com/community-scripts/core/pull/76))
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#75](https://github.com/community-scripts/core/pull/75))
## 2026-09-28
+66
View File
@@ -0,0 +1,66 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://docs.ankiweb.net/sync-server.html
APP="Anki-Sync-Server"
var_tags="${var_tags:-anki;flashcards;sync}"
var_cpu="${var_cpu:-1}"
var_ram="${var_ram:-512}"
var_disk="${var_disk:-4}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /opt/anki-sync-server/.env ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "anki-sync-server" "ankitects/anki"; then
msg_info "Stopping Service"
systemctl stop anki-sync-server
msg_ok "Stopped Service"
create_backup /opt/anki-sync-server/.env /opt/anki-sync-server/data
msg_info "Updating Anki Sync Server"
$STD uv pip install --python /opt/anki-sync-server/venv/bin/python "anki==$(get_latest_github_release "ankitects/anki")"
cat <<EOF >~/.anki-sync-server
$(get_latest_github_release "ankitects/anki")
EOF
msg_ok "Updated Anki Sync Server"
restore_backup
msg_info "Starting Service"
systemctl start anki-sync-server
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8080${CL}"
+6
View File
@@ -0,0 +1,6 @@
___ __ _ _____ _____
/ | ____ / /__(_) / ___/__ ______ _____ / ___/___ ______ _____ _____
/ /| | / __ \/ //_/ /_____\__ \/ / / / __ \/ ___/_____\__ \/ _ \/ ___/ | / / _ \/ ___/
/ ___ |/ / / / ,< / /_____/__/ / /_/ / / / / /__/_____/__/ / __/ / | |/ / __/ /
/_/ |_/_/ /_/_/|_/_/ /____/\__, /_/ /_/\___/ /____/\___/_/ |___/\___/_/
/____/
+7
View File
@@ -56,6 +56,13 @@ function update_script() {
msg_ok "Migrated RQ services"
fi
if ! grep -q '^save ' /etc/redis/redis.conf; then
msg_info "Reducing Redis snapshot frequency"
echo 'save 3600 1' >>/etc/redis/redis.conf
$STD redis-cli CONFIG SET save "3600 1"
msg_ok "Reduced Redis snapshot frequency"
fi
if check_for_gh_release "romm" "rommapp/romm"; then
msg_info "Stopping Services"
systemctl stop romm-backend romm-worker romm-scan-worker romm-scheduler romm-watcher
+60
View File
@@ -0,0 +1,60 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://docs.ankiweb.net/sync-server.html
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
UV_PYTHON="3.12" setup_uv
msg_info "Installing Anki Sync Server"
$STD uv venv --python 3.12 /opt/anki-sync-server/venv
$STD uv pip install --python /opt/anki-sync-server/venv/bin/python "anki==$(get_latest_github_release "ankitects/anki")"
cat <<EOF >~/.anki-sync-server
$(get_latest_github_release "ankitects/anki")
EOF
msg_ok "Installed Anki Sync Server"
msg_info "Configuring Anki Sync Server"
mkdir -p /opt/anki-sync-server/data
cat <<EOF >/opt/anki-sync-server/.env
SYNC_USER1=anki:$(tr -d '-' </proc/sys/kernel/random/uuid)
SYNC_BASE=/opt/anki-sync-server/data
SYNC_HOST=0.0.0.0
SYNC_PORT=8080
EOF
chmod 600 /opt/anki-sync-server/.env
msg_ok "Configured Anki Sync Server"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/anki-sync-server.service
[Unit]
Description=Anki Sync Server
After=network.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/anki-sync-server
EnvironmentFile=/opt/anki-sync-server/.env
ExecStart=/opt/anki-sync-server/venv/bin/python -m anki.syncserver
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now anki-sync-server
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc
+1
View File
@@ -167,6 +167,7 @@ echo "__version__ = \"$(cat ~/.romm)\"" >/opt/romm/backend/__version__.py
msg_info "Creating environment file"
sed -i 's/^supervised no/supervised systemd/' /etc/redis/redis.conf
echo 'save 3600 1' >>/etc/redis/redis.conf
systemctl restart redis-server
systemctl enable -q --now redis-server
AUTH_SECRET_KEY=$(openssl rand -hex 32)