Compare commits

...

4 Commits

Author SHA1 Message Date
MickLesk
09a5860ea3 Warn when host CA inheritance is disabled
Changes the log level from info to warning when host CA inheritance is skipped by configuration, and includes the number of host certificates detected. This makes intentional skips more visible while still showing useful context.
2026-07-19 10:00:29 +02:00
MickLesk
043f1154e3 Add host CA inheritance for container builds
Introduces `var_inherit_host_ca` (default `auto`) across variable loading, validation, defaults, and persisted app vars. The advanced settings flow now includes a dedicated Host CA Inheritance step and surfaces the selection in the final summary.

Adds `_apply_host_ca_certs_in_container()` to copy host certificates from `/usr/local/share/ca-certificates/*.crt` into the container and refresh trust with `update-ca-certificates` when available. This runs during container setup after proxy configuration, with safe no-op behavior when no host certs exist or inheritance is disabled.
2026-07-19 09:57:17 +02:00
community-scripts-pr-app[bot]
8c7da1e036 Update CHANGELOG.md (#15887)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-19 07:42:15 +00:00
CanbiZ (MickLesk)
bbd5a3f522 Revert "add configurable host CA inheritance for LXC bootstrap (#15840)" (#15886)
This reverts commit eb5a5b2cb7.
2026-07-19 09:41:52 +02:00
2 changed files with 13 additions and 9 deletions

View File

@@ -507,6 +507,10 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
## 2026-07-19
### 💾 Core
- Revert "core: add configurable host CA inheritance during bootstrap" [@MickLesk](https://github.com/MickLesk) ([#15886](https://github.com/community-scripts/ProxmoxVE/pull/15886))
## 2026-07-18
### 💾 Core

View File

@@ -2823,9 +2823,9 @@ advanced_settings() {
;;
# ═══════════════════════════════════════════════════════════════════════════
# STEP 27: Device Node Creation (mknod)
# STEP 28: Device Node Creation (mknod)
# ═══════════════════════════════════════════════════════════════════════════
27)
28)
local mknod_default_flag="--defaultno"
[[ "$_enable_mknod" == "1" ]] && mknod_default_flag=""
@@ -2847,9 +2847,9 @@ advanced_settings() {
;;
# ═══════════════════════════════════════════════════════════════════════════
# STEP 28: Mount Filesystems
# STEP 29: Mount Filesystems
# ═══════════════════════════════════════════════════════════════════════════
28)
29)
local mount_hint=""
[[ -n "$_mount_fs" ]] && mount_hint="$_mount_fs" || mount_hint="(none)"
@@ -2870,9 +2870,9 @@ advanced_settings() {
;;
# ═══════════════════════════════════════════════════════════════════════════
# STEP 29: Optional host-side post-install hook (path on the Proxmox HOST)
# STEP 30: Optional host-side post-install hook (path on the Proxmox HOST)
# ═══════════════════════════════════════════════════════════════════════════
29)
30)
local _hook_prompt="Optional: absolute path to a *.sh file ON THE PROXMOX HOST.
It runs as root on the HOST (NOT in the LXC) after the container
@@ -2922,9 +2922,9 @@ Leave empty to skip."
;;
# ═══════════════════════════════════════════════════════════════════════════
# STEP 30: Verbose Mode & Confirmation
# STEP 31: Verbose Mode & Confirmation
# ═══════════════════════════════════════════════════════════════════════════
30)
31)
local verbose_default_flag="--defaultno"
[[ "$_verbose" == "yes" ]] && verbose_default_flag=""
@@ -4024,7 +4024,7 @@ _apply_host_ca_certs_in_container() {
case "${inherit_host_ca,,}" in
no | false | 0 | off)
msg_info "Skipping host CA inheritance by configuration"
msg_warn "Skipping host CA inheritance by configuration (${#host_certs[@]} host certificate(s) available)"
return 0
;;
esac