Go to file
nexxo 5d25018cc6 Build the golden template so nobody has to remember how
All three Block A traps are CHECKED here rather than assumed, because each one
has already cost a paid order and none of them shows a symptom until it is too
late.

Trap 2 is checked before anything is built: virt-filesystems is asked whether
the image uses LVM and whether root is the last partition, and the section
refuses if either is wrong. Debian's cloud image satisfies both by construction,
which is exactly why it is the base — but "satisfies it by construction" is a
claim about an artefact somebody else builds, and it gets verified rather than
trusted.

Traps 1 and 3 are checked AFTER the image is customised, because virt-customize
reports success even when apt quietly did not install something. qemu-guest-agent
has to be in /usr/bin or every provisioning run hangs in WaitForGuestAgent until
it times out, and the compose file inside the image has to carry `user:
www-data` or every occ call fails — including the acceptance check that decides
whether a customer's instance is usable.

The template is verified by its ATTRIBUTE, not its existence. VerifyVmTemplate
checks only that 9000 is there, which a VM that merely happens to be numbered
9000 also passes; `template: 1` is passed only by a template.

Docker comes from Docker's own repository, not Debian's. docker.io ships no
compose plugin and Debian's docker-compose is the old Python one, which does not
read this file at all.

The compose file is deliberately customer-independent: no password, no name, no
domain. Everything variable arrives in /opt/nextcloud/.env, written into the
guest by cloud-init at clone time. Baking a password into an image copies it
onto every host and into every instance, and leaves it there long after the
customer has changed it.

OVERWRITEPROTOCOL, OVERWRITEHOST and TRUSTED_PROXIES are set because TLS ends at
Traefik on the host. Without them Nextcloud builds its own URLs with http://,
the login loops, and WebDAV clients get handed an address that does not exist.

Storage is discovered rather than named: local-zfs is what the PVE installer
creates on ZFS, local-lvm on ext4, and `local` frequently cannot hold disks at
all — an importdisk there fails only after the copy.

Verified without hardware: dash-clean; the compose file parses, carries `user:
www-data` on the app service, publishes 80, and every credential is a ${...}
reference rather than a literal. Step 2 unticked, and it is the one the plan is
most insistent about: the template must actually be cloned, started, and asked
`occ status` as www-data. Without that clone it is not proven.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-30 20:16:50 +02:00
.gitea/workflows feat(deploy): releases you can pin to, and a version that tells the truth 2026-07-26 15:21:38 +02:00
.npm chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
app Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
bin Make the private hostnames look like nothing is there, and close the way past the proxy 2026-07-27 11:26:48 +02:00
bootstrap Stop the 503 page appearing during an update 2026-07-29 17:50:15 +02:00
config Verify webhooks against the secret of the mode we are in 2026-07-30 12:13:55 +02:00
database Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
deploy Build the golden template so nobody has to remember how 2026-07-30 20:16:50 +02:00
docker Give the readiness probe long enough for a restart to finish 2026-07-27 14:46:47 +02:00
docs Build the golden template so nobody has to remember how 2026-07-30 20:16:50 +02:00
lang Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
public One wordmark, one typeface, and the address the server actually issues 2026-07-29 14:30:44 +02:00
resources Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
routes Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
storage chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
tests Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
.dockerignore chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.editorconfig chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.env.example Verify webhooks against the secret of the mode we are in 2026-07-30 12:13:55 +02:00
.gitattributes chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.gitignore Keep exported invoices out of the repository 2026-07-29 09:56:00 +02:00
.npmrc chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
CLAUDE.md R24: a modal is never taller than the screen 2026-07-29 23:33:57 +02:00
README.md chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
VERSION Release v1.3.62 2026-07-30 17:38:57 +02:00
artisan chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
composer.json Render an invoice, with the arithmetic held to integer cents 2026-07-29 01:41:46 +02:00
composer.lock Render an invoice, with the arithmetic held to integer cents 2026-07-29 01:41:46 +02:00
docker-compose.yml Stop root workers breaking every page, and let the panel be closed 2026-07-29 15:43:54 +02:00
package-lock.json Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
package.json Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
phpunit.xml Tell a read-only token apart from one that can write 2026-07-30 13:56:28 +02:00
postcss.config.js feat(portal): design foundation — Tailwind v3, tokens, self-hosted fonts 2026-07-25 00:43:01 +02:00
tailwind.config.js Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
vite.config.js feat(ops): update page, automatic 419 recovery, CI workflow 2026-07-26 00:58:27 +02:00

README.md

Laravel Logo

Build Status Total Downloads Latest Stable Version License

About Laravel

Laravel is a web application framework with expressive, elegant syntax. We believe development must be an enjoyable and creative experience to be truly fulfilling. Laravel takes the pain out of development by easing common tasks used in many web projects, such as:

Laravel is accessible, powerful, and provides tools required for large, robust applications.

Learning Laravel

Laravel has the most extensive and thorough documentation and video tutorial library of all modern web application frameworks, making it a breeze to get started with the framework.

In addition, Laracasts contains thousands of video tutorials on a range of topics including Laravel, modern PHP, unit testing, and JavaScript. Boost your skills by digging into our comprehensive video library.

You can also watch bite-sized lessons with real-world projects on Laravel Learn, where you will be guided through building a Laravel application from scratch while learning PHP fundamentals.

Agentic Development

Laravel's predictable structure and conventions make it ideal for AI coding agents like Claude Code, Cursor, and GitHub Copilot. Install Laravel Boost to supercharge your AI workflow:

composer require laravel/boost --dev

php artisan boost:install

Boost provides your agent 15+ tools and skills that help agents build Laravel applications while following best practices.

Contributing

Thank you for considering contributing to the Laravel framework! The contribution guide can be found in the Laravel documentation.

Code of Conduct

In order to ensure that the Laravel community is welcoming to all, please review and abide by the Code of Conduct.

Security Vulnerabilities

If you discover a security vulnerability within Laravel, please send an e-mail to Taylor Otwell via taylor@laravel.com. All security vulnerabilities will be promptly addressed.

License

The Laravel framework is open-sourced software licensed under the MIT license.