Added
- Docker Compose files in
docker-compose/:docker-compose.yml, used as is, reads every setting from.env(credentials, API keys,TZ,PUID/PGID,AIMM_PORT);.env.exampleis its template; anddocker-compose.traefik.yml, saved asdocker-compose.override.yml, serves aimm through Traefik. The Docker installation guide coversdocker runand Docker Compose, the first run, a reverse proxy, updates and troubleshooting, and explains what one UnitySVC key covers. - The Docker image reports its health:
GET /api/healthanswers without signing in, and the image'sHEALTHCHECKuses it, sodocker psand NAS app managers show the container ashealthyorunhealthy. - The image carries OCI labels (title, description, source, documentation, license), and
docs/icon.pngis a square app icon, for app stores such as Unraid, CasaOS, Umbrel and TrueNAS. AIMM_WEBUI_AUTHlets a reverse proxy sign users in to the web UI instead of aimm's Facebook username and password, and checks on every request and WebSocket that the proxy did:authentikandcloudflareverify the provider's signed token for aimm's application (audience and issuer) and end open connections when it expires;autheliarequires theRemote-Userheader;proxyrequires nothing.AIMM_WEBUI_PROXY_SECRET, sent by the proxy asX-Aimm-Proxy-Secret, protects the unsigned modes from requests that bypass the proxy. The default,password, is unchanged. See "Let the reverse proxy sign you in" in the Docker installation guide.
Changed
- The Docker image runs aimm as an unprivileged
aimmuser instead of root.PUIDandPGID(default1000) give that user your IDs so that files in the data folder stay yours; the container also runs as a fixed user (--user), withcap_drop: ALLplusSETUID/SETGID, and on shares that refusechownbut are writable (NFSroot_squash, SMB).docker exec aimm aimm ...runs as the same user.PUID/PGIDof 0 are refused. - The Docker data folder is
/data(newAIMM_HOMEvariable). A folder still mounted at/root/.ai-marketplace-monitorkeeps working, and the log asks you to mount it at/datainstead; on the first start the folder is given toPUID:PGID. - The web UI's Update button appears only when aimm can update its own installation (the image's own user); otherwise update by pulling the image.
- The Dockerfile moved to
docker/Dockerfile; build withdocker build -f docker/Dockerfile -t aimm .from the repository root. - The web UI's ⏸ now stops the monitor and ▶ starts it again: the config is reloaded and all items are searched right away, so changes saved while stopped take effect. ▶ refuses to start while the config on disk is invalid. Entering the CLI interactive session also stops the monitor, and leaving it restarts it. The browser, and so the Facebook login, is kept.
- The config file created on first run uses UnitySVC:
[ai.unitysvc]with thebalancedmodel rates listings, and[user.me]receives UnitySVC email with photos ([notification.unitysvc_email]) and UnitySVC phone/chat messages ([notification.unitysvc]), plus a daily digest at 08:00.[marketplace.facebook]logs in with theFACEBOOK_USERNAMEandFACEBOOK_PASSWORDenvironment variables, so with Docker onlyFACEBOOK_USERNAME,FACEBOOK_PASSWORDandUNITYSVC_API_KEYneed to be set.
Fixed
- The web UI read
username = "${FACEBOOK_USERNAME}"andpassword = "${FACEBOOK_PASSWORD}"as literal text: when exposed (as in Docker), its login was${FACEBOOK_USERNAME}/${FACEBOOK_PASSWORD}instead of your Facebook credentials, and the startup banner showeduser: ${FACEBOOK_USERNAME}. It now reads the variables, as the Facebook login does; an unset variable falls back toFACEBOOK_USERNAME/FACEBOOK_PASSWORD. - A user receiving more than one notification no longer logs "Overriding ... for user" warnings for channel defaults (retries, rate limits, message format) that have the same value.
- AI agents are replaced, not duplicated, when the config is reloaded.
Security
- In the Docker image, the VNC server listens on
127.0.0.1only; the browser view is reachable only through the signed-in web UI.