mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-08-07 20:38:42 +08:00
Compare commits
25 Commits
46ad111b94
...
stable-7.2
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8efca76bdb | ||
|
|
b5baab2b00 | ||
|
|
21467e4f1a | ||
|
|
a930989ec7 | ||
|
|
6ff4fb4417 | ||
|
|
68a2f53ef2 | ||
|
|
fffb04bac2 | ||
|
|
c72832dc8a | ||
|
|
32d9e5fb50 | ||
|
|
e6256ebadb | ||
|
|
8b271811a6 | ||
|
|
40882d6f8f | ||
|
|
2ec04b4466 | ||
|
|
2c72369d24 | ||
|
|
6d3a1f8c49 | ||
|
|
cc1471e467 | ||
|
|
300fc4779b | ||
|
|
12efcc9e91 | ||
|
|
cd22ba6f6e | ||
|
|
23f4b6eefe | ||
|
|
225740f7d4 | ||
|
|
f74c434267 | ||
|
|
e2c680ea6b | ||
|
|
b0fdcec0a3 | ||
|
|
a0f9ffbc6f |
@@ -87,7 +87,7 @@ TRAEFIK_LOG_LEVEL=
|
|||||||
# For production releases: "opencloudeu/opencloud"
|
# For production releases: "opencloudeu/opencloud"
|
||||||
# For rolling releases: "opencloudeu/opencloud-rolling"
|
# For rolling releases: "opencloudeu/opencloud-rolling"
|
||||||
# Defaults to production if not set otherwise
|
# Defaults to production if not set otherwise
|
||||||
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling
|
OC_DOCKER_IMAGE=opencloudeu/opencloud
|
||||||
# The openCloud container version.
|
# The openCloud container version.
|
||||||
# Defaults to the latest version-tag. Use git pull to update.
|
# Defaults to the latest version-tag. Use git pull to update.
|
||||||
OC_DOCKER_TAG=
|
OC_DOCKER_TAG=
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
opencloud:
|
opencloud:
|
||||||
# renovate: depName=opencloudeu/opencloud-rolling
|
# renovate: depName=opencloudeu/opencloud
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.2.0}
|
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud}:${OC_DOCKER_TAG:-7.2.3}
|
||||||
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
||||||
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
||||||
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
|
|||||||
@@ -17,14 +17,14 @@ services:
|
|||||||
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
|
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
|
||||||
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
|
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
|
||||||
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
|
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
|
||||||
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID}
|
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID:-web}
|
||||||
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES}
|
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES:-openid profile email}
|
||||||
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID}
|
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID:-OpenCloudAndroid}
|
||||||
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES}
|
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||||
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID}
|
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID:-OpenCloudIOS}
|
||||||
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES}
|
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||||
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID}
|
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID:-OpenCloudDesktop}
|
||||||
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES}
|
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||||
PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc}
|
PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc}
|
||||||
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
||||||
# This specifies to start all services except idm and idp. These are replaced by external services.
|
# This specifies to start all services except idm and idp. These are replaced by external services.
|
||||||
|
|||||||
@@ -78,7 +78,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.3
|
image: quay.io/keycloak/keycloak:26.6.4
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -1,43 +0,0 @@
|
|||||||
{
|
|
||||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
||||||
"platformAutomerge": true,
|
|
||||||
"enabledManagers": ["docker-compose", "custom.regex"],
|
|
||||||
"baseBranchPatterns": ["main", "stable-4.0"],
|
|
||||||
"packageRules": [
|
|
||||||
{
|
|
||||||
"matchManagers": ["docker-compose", "custom.regex"],
|
|
||||||
"labels": ["Type:Dependencies", "Bot:Renovate"]
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchManagers": ["docker-compose"],
|
|
||||||
"matchUpdateTypes": ["patch"],
|
|
||||||
"automerge": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchBaseBranches": ["stable-4.0"],
|
|
||||||
"matchUpdateTypes": ["major", "minor"],
|
|
||||||
"enabled": false
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchPackageNames": ["postgres"],
|
|
||||||
"matchManagers": ["docker-compose"],
|
|
||||||
"allowedVersions": "/^17\\.\\d+-alpine$/"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"docker-compose": {
|
|
||||||
"managerFilePatterns": ["/.+\\.ya?ml$/"]
|
|
||||||
},
|
|
||||||
"customManagers": [
|
|
||||||
{
|
|
||||||
"customType": "regex",
|
|
||||||
"managerFilePatterns": [
|
|
||||||
"/^docker-compose\\.yml$/",
|
|
||||||
"/^weboffice\\/collabora\\.yml$/"
|
|
||||||
],
|
|
||||||
"matchStrings": [
|
|
||||||
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"
|
|
||||||
],
|
|
||||||
"datasourceTemplate": "docker"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
@@ -15,7 +15,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.3
|
image: quay.io/keycloak/keycloak:26.6.4
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -23,22 +23,50 @@ services:
|
|||||||
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
||||||
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
||||||
|
|
||||||
|
# One-shot service that generates the WOPI proof key on first start and
|
||||||
|
# keeps it in a named volume, like the proofKeyGeneration feature of the
|
||||||
|
# collabora-online helm chart.
|
||||||
|
# To rotate the key, remove the volume and start again:
|
||||||
|
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
|
||||||
|
collabora-proof-key:
|
||||||
|
image: alpine/openssl:3.5.7
|
||||||
|
entrypoint: ["/bin/sh"]
|
||||||
|
command:
|
||||||
|
- -ec
|
||||||
|
- |
|
||||||
|
if [ ! -s /proof/proof_key ]; then
|
||||||
|
openssl genrsa -traditional -out /proof/proof_key.tmp 4096
|
||||||
|
chown 1001:1001 /proof/proof_key.tmp
|
||||||
|
chmod 400 /proof/proof_key.tmp
|
||||||
|
mv /proof/proof_key.tmp /proof/proof_key
|
||||||
|
echo "WOPI proof key generated"
|
||||||
|
else
|
||||||
|
echo "WOPI proof key already exists"
|
||||||
|
fi
|
||||||
|
volumes:
|
||||||
|
- collabora-proof-key:/proof
|
||||||
|
logging:
|
||||||
|
driver: ${LOG_DRIVER:-local}
|
||||||
|
restart: "no"
|
||||||
|
|
||||||
collabora:
|
collabora:
|
||||||
image: collabora/code:26.04.1.4.1
|
image: collabora/code:26.04.2.4.1
|
||||||
# release notes: https://www.collaboraonline.com/release-notes/
|
# release notes: https://www.collaboraonline.com/release-notes/
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
|
depends_on:
|
||||||
|
collabora-proof-key:
|
||||||
|
condition: service_completed_successfully
|
||||||
environment:
|
environment:
|
||||||
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
|
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
|
||||||
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
DONT_GEN_SSL_CERT: "YES"
|
extra_params: >
|
||||||
extra_params: |
|
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true}
|
||||||
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \
|
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true}
|
||||||
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \
|
--o:ssl.termination=true
|
||||||
--o:ssl.termination=true \
|
--o:welcome.enable=false
|
||||||
--o:welcome.enable=false \
|
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
|
||||||
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
||||||
username: ${COLLABORA_ADMIN_USER:-admin}
|
username: ${COLLABORA_ADMIN_USER:-admin}
|
||||||
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
||||||
@@ -52,19 +80,24 @@ services:
|
|||||||
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
||||||
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
||||||
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
||||||
|
# WOPI proof key generated by the collabora-proof-key service.
|
||||||
|
- type: volume
|
||||||
|
source: collabora-proof-key
|
||||||
|
target: /etc/coolwsd/proof_key
|
||||||
|
read_only: true
|
||||||
|
volume:
|
||||||
|
subpath: proof_key
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
restart: always
|
restart: always
|
||||||
entrypoint: [ '/bin/bash', '-c' ]
|
|
||||||
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
|
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test:
|
# --use-env-vars makes the probe read extra_params, so it probes with
|
||||||
[
|
# the same http/https scheme the server actually runs with; without it
|
||||||
"CMD",
|
# the probe falls back to coolwsd.xml where ssl.enable defaults to true
|
||||||
"bash",
|
test: ["CMD", "/usr/bin/coolwsd", "--probe", "--use-env-vars"]
|
||||||
"-c",
|
|
||||||
"exec 3<>/dev/tcp/127.0.0.1/9980 && printf 'GET /hosting/discovery HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && cat <&3 | head -1 | grep -q '200 OK'"
|
|
||||||
]
|
|
||||||
interval: 15s
|
interval: 15s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
collabora-proof-key:
|
||||||
|
|||||||
Reference in New Issue
Block a user