mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-08-07 20:38:42 +08:00
Compare commits
1 Commits
46ad111b94
...
39e2ad94d5
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
39e2ad94d5 |
@@ -25,7 +25,6 @@ directives:
|
|||||||
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
# This is needed for the external-sites web extension when embedding sites
|
# This is needed for the external-sites web extension when embedding sites
|
||||||
- 'https://docs.opencloud.eu'
|
- 'https://docs.opencloud.eu'
|
||||||
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
|
||||||
img-src:
|
img-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
- 'data:'
|
- 'data:'
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
services:
|
services:
|
||||||
opencloud:
|
opencloud:
|
||||||
# renovate: depName=opencloudeu/opencloud-rolling
|
# renovate: depName=opencloudeu/opencloud-rolling
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.2.0}
|
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.1.0}
|
||||||
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
||||||
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
||||||
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
|
|||||||
@@ -17,14 +17,14 @@ services:
|
|||||||
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
|
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
|
||||||
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
|
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
|
||||||
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
|
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
|
||||||
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID:-web}
|
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID}
|
||||||
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES:-openid profile email}
|
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES}
|
||||||
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID:-OpenCloudAndroid}
|
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID}
|
||||||
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES}
|
||||||
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID:-OpenCloudIOS}
|
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID}
|
||||||
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES}
|
||||||
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID:-OpenCloudDesktop}
|
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID}
|
||||||
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES}
|
||||||
PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc}
|
PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc}
|
||||||
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
||||||
# This specifies to start all services except idm and idp. These are replaced by external services.
|
# This specifies to start all services except idm and idp. These are replaced by external services.
|
||||||
|
|||||||
@@ -1,59 +0,0 @@
|
|||||||
---
|
|
||||||
services:
|
|
||||||
opencloud:
|
|
||||||
environment:
|
|
||||||
# Point the search service at OpenSearch instead of the embedded bleve index.
|
|
||||||
SEARCH_ENGINE_TYPE: open-search
|
|
||||||
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_ADDRESSES: http://opensearch:9200
|
|
||||||
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_INSECURE: "true"
|
|
||||||
SEARCH_ENGINE_OPEN_SEARCH_RESOURCE_INDEX_NAME: ${OPENSEARCH_RESOURCE_INDEX:-opencloud-resources}
|
|
||||||
depends_on:
|
|
||||||
opensearch:
|
|
||||||
condition: service_healthy
|
|
||||||
|
|
||||||
opensearch:
|
|
||||||
image: ${OPENSEARCH_DOCKER_IMAGE:-opensearchproject/opensearch}:${OPENSEARCH_DOCKER_TAG:-2.19.5}
|
|
||||||
environment:
|
|
||||||
discovery.type: single-node
|
|
||||||
bootstrap.memory_lock: "true"
|
|
||||||
OPENSEARCH_JAVA_OPTS: ${OPENSEARCH_JAVA_OPTS:--Xms512m -Xmx512m}
|
|
||||||
# Security plugin is disabled: OpenSearch is only reachable on the
|
|
||||||
# internal opencloud-net bridge and no port is published to the host.
|
|
||||||
# Do NOT enable a published port or expose this via the reverse proxy
|
|
||||||
# without first enabling and configuring the security plugin.
|
|
||||||
DISABLE_SECURITY_PLUGIN: "true"
|
|
||||||
DISABLE_INSTALL_DEMO_CONFIG: "true"
|
|
||||||
# Disable the disk-based shard allocation watermarks. By default OpenSearch
|
|
||||||
# marks indices read-only when the host disk is <5% free, which silently
|
|
||||||
# turns bulk upserts into no-ops. Fine to disable on a single-node dev box.
|
|
||||||
cluster.routing.allocation.disk.threshold_enabled: "false"
|
|
||||||
ulimits:
|
|
||||||
memlock:
|
|
||||||
soft: -1
|
|
||||||
hard: -1
|
|
||||||
nofile:
|
|
||||||
soft: 65536
|
|
||||||
hard: 65536
|
|
||||||
networks:
|
|
||||||
opencloud-net:
|
|
||||||
volumes:
|
|
||||||
- ${OPENSEARCH_DATA_DIR:-opensearch-data}:/usr/share/opensearch/data
|
|
||||||
healthcheck:
|
|
||||||
# Single-node clusters can't go green (replicas have nowhere to land), so
|
|
||||||
# yellow is the healthy state. Still gates opencloud until opensearch accepts
|
|
||||||
# requests.
|
|
||||||
test:
|
|
||||||
[
|
|
||||||
"CMD-SHELL",
|
|
||||||
"curl -sf 'http://localhost:9200/_cluster/health?wait_for_status=yellow&timeout=5s' > /dev/null || exit 1"
|
|
||||||
]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 10s
|
|
||||||
retries: 24
|
|
||||||
start_period: 60s
|
|
||||||
logging:
|
|
||||||
driver: ${LOG_DRIVER:-local}
|
|
||||||
restart: always
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
opensearch-data:
|
|
||||||
@@ -11,18 +11,6 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
healthcheck:
|
|
||||||
test:
|
|
||||||
[
|
|
||||||
"CMD",
|
|
||||||
"bash",
|
|
||||||
"-c",
|
|
||||||
"exec 3<>/dev/tcp/127.0.0.1/9998 && printf 'GET /tika HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && grep '200 OK' <&3",
|
|
||||||
]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 5s
|
|
||||||
retries: 10
|
|
||||||
start_period: 5s
|
|
||||||
|
|
||||||
opencloud:
|
opencloud:
|
||||||
environment:
|
environment:
|
||||||
@@ -30,6 +18,3 @@ services:
|
|||||||
SEARCH_EXTRACTOR_TYPE: tika
|
SEARCH_EXTRACTOR_TYPE: tika
|
||||||
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
|
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
|
||||||
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
|
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
|
||||||
depends_on:
|
|
||||||
tika:
|
|
||||||
condition: service_healthy
|
|
||||||
|
|||||||
Reference in New Issue
Block a user