Compare commits

..

35 Commits

Author SHA1 Message Date
Michael Barz
db3ddbdf32 Merge pull request #355 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.1 (main)
2026-08-05 19:48:18 +02:00
renovate[bot]
1fbb2380cc chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.1 2026-08-05 17:43:39 +00:00
Michael Barz
34129ff018 Merge pull request #352 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.10 (main)
2026-08-05 19:42:49 +02:00
renovate[bot]
0f89106b89 chore(deps): update traefik docker tag to v3.7.10 2026-08-05 07:24:26 +00:00
Viktor Scharf
2b51cb53c0 Merge pull request #353 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-7.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.4.0 (main)
2026-08-05 09:23:29 +02:00
renovate[bot]
eab3b7e584 chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.4.0 2026-08-03 20:51:17 +00:00
Jannik Stehle
c4023ff553 Merge pull request #351 from opencloud-eu/feat/add-app-yaml-config-file
feat: add apps.yaml config
2026-07-31 16:16:25 +02:00
Jannik Stehle
aac9a1e2f5 feat: add apps.yaml config
Add a config for the maps map. Its purpose is not to change anything
but to guide and show users how to configure web apps. Now that the
apps.yaml file is mounted, it can easily be extended by more config
options
2026-07-31 11:20:17 +02:00
Tobias Baader
e6a0e8e2e6 Merge pull request #350 from opencloud-eu/feat(keycloak)-use-Inter-variable-font-in-login-theme
feat(keycloak): use Inter variable font in login theme
2026-07-31 09:33:05 +02:00
Alexander Ackermann
1ecdd0e32a use patternfly best practice 2026-07-30 19:16:30 +02:00
Alexander Ackermann
bcf59c86fd use patternfly best practice 2026-07-30 19:09:27 +02:00
Tobias Baader
7cd7c57bd9 feat(keycloak): use Inter variable font in login theme
Replace the bundled OpenCloud font with Inter in the Keycloak login
theme. Use the variable woff2 (weights 100-900) so a single self-hosted
file covers all weights, and drop the two static OpenCloud files.
follow up for
https://github.com/opencloud-eu/web/pull/2988
2026-07-30 18:27:52 +02:00
Jörn Friedrich Dreyer
213dde31c8 Merge pull request #347 from kellergoech/patch-1
Adjust collabora to new distroless container
2026-07-29 11:30:26 +02:00
Thomas Schweiger
dabd81377c chore: bump version to 6.04.2.4.1 2026-07-29 10:48:57 +02:00
Michael Barz
8d2d89f283 Merge pull request #348 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.9 (main)
2026-07-25 10:14:26 +02:00
renovate[bot]
189f17f6e0 chore(deps): update traefik docker tag to v3.7.9 2026-07-24 21:51:13 +00:00
micbar
27fd367113 feat: add proof key side car 2026-07-24 12:42:49 +02:00
kellergoech
fffcec12a8 Adjust collavora to new distroless container 2026-07-24 07:06:50 +02:00
Michael Barz
42b4343d6e Merge pull request #341 from opencloud-eu/renovate/main-collabora-code-26.x
chore(deps): update collabora/code docker tag to v26.04.2.2.1 (main)
2026-07-19 18:29:41 +02:00
renovate[bot]
5666410706 chore(deps): update collabora/code docker tag to v26.04.2.2.1 2026-07-18 21:09:00 +00:00
Michael Barz
62131f972b Merge pull request #339 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.8 (main)
2026-07-16 20:25:53 +02:00
renovate[bot]
274195c6ad chore(deps): update traefik docker tag to v3.7.8 2026-07-15 21:33:24 +00:00
Michael Barz
49ba000f6e Merge pull request #332 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.0 (main)
2026-07-15 14:41:16 +02:00
Michael Barz
d759e5a332 Merge pull request #331 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.7 (main)
2026-07-15 14:36:55 +02:00
renovate[bot]
d7fcd3da64 chore(deps): update traefik docker tag to v3.7.7 2026-07-15 04:55:36 +00:00
Michael Barz
325dce2f53 Merge pull request #338 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-7.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.3.0 (main)
2026-07-15 06:55:06 +02:00
renovate[bot]
0221cfd91b chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.3.0 2026-07-14 21:44:03 +00:00
renovate[bot]
c096f66dfd chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.0 2026-07-09 09:53:11 +00:00
Michael Barz
e6d987501e Merge pull request #328 from opencloud-eu/renovate/main-collabora-code-26.x
chore(deps): update collabora/code docker tag to v26.04.2.1.1 (main)
2026-07-01 13:09:05 +02:00
renovate[bot]
2f81c5f62c chore(deps): update collabora/code docker tag to v26.04.2.1.1 2026-07-01 11:08:45 +00:00
Michael Barz
670d978c1c Merge pull request #322 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.4 (main)
2026-07-01 13:08:22 +02:00
renovate[bot]
d952c2849b chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.4 2026-07-01 10:59:19 +00:00
Michael Barz
13b9489c52 chore: enable renovate for stable-7.2 2026-07-01 12:58:43 +02:00
Michael Barz
e8b8511477 Merge pull request #327 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.5 (main)
2026-07-01 09:08:57 +02:00
renovate[bot]
70e7679bc3 chore(deps): update traefik docker tag to v3.7.6 2026-07-01 00:54:25 +00:00
11 changed files with 66 additions and 35 deletions

View File

@@ -4,24 +4,18 @@
--pf-v5-global--primary-color--dark-100: #e2baff; --pf-v5-global--primary-color--dark-100: #e2baff;
--pf-v5-c-button--m-secondary--Color: #e2baff; --pf-v5-c-button--m-secondary--Color: #e2baff;
--pf-v5-global--Color--light-100: #20434f; --pf-v5-global--Color--light-100: #20434f;
--pf-v5-global--FontFamily--text: "Inter", "RedHatText", helvetica, arial, sans-serif;
--pf-v5-global--FontFamily--heading: "Inter", "RedHatDisplay", helvetica, arial, sans-serif;
} }
@font-face { @font-face {
font-family: OpenCloud; font-family: Inter;
src: url('../fonts/OpenCloud500-Regular.woff2') format('woff2'); src: url('../fonts/Inter-Variable.woff2') format('woff2');
font-weight: normal; font-weight: 100 900;
font-style: normal;
}
@font-face {
font-family: OpenCloud;
src: url('../fonts/OpenCloud750-Bold.woff2') format('woff2');
font-weight: bold;
font-style: normal; font-style: normal;
} }
body { body {
font-family: "OpenCloud", "Open Sans", Helvetica, Arial, sans-serif;
background: url(../img/background.png) no-repeat center fixed !important; background: url(../img/background.png) no-repeat center fixed !important;
background-size: cover !important; background-size: cover !important;
} }

View File

@@ -0,0 +1,3 @@
maps:
config:
folderViewEnabled: false

View File

@@ -2,7 +2,7 @@
services: services:
opencloud: opencloud:
# renovate: depName=opencloudeu/opencloud-rolling # renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.2.0} image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.4.0}
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog # changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html # release notes: https://docs.opencloud.eu/opencloud_release_notes.html
user: ${OC_CONTAINER_UID_GID:-1000:1000} user: ${OC_CONTAINER_UID_GID:-1000:1000}
@@ -58,6 +58,7 @@ services:
OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE} OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE}
volumes: volumes:
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml - ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
- ./config/opencloud/apps.yaml:/etc/opencloud/apps.yaml
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt - ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
# configure the .env file to use own paths instead of docker internal volumes # configure the .env file to use own paths instead of docker internal volumes
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud - ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud

View File

@@ -78,7 +78,7 @@ services:
restart: always restart: always
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.6.4 image: quay.io/keycloak/keycloak:26.7.1
networks: networks:
opencloud-net: opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ] command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -2,7 +2,7 @@
"$schema": "https://docs.renovatebot.com/renovate-schema.json", "$schema": "https://docs.renovatebot.com/renovate-schema.json",
"platformAutomerge": true, "platformAutomerge": true,
"enabledManagers": ["docker-compose", "custom.regex"], "enabledManagers": ["docker-compose", "custom.regex"],
"baseBranchPatterns": ["main", "stable-4.0"], "baseBranchPatterns": ["main", "stable-4.0", "stable-7.2"],
"packageRules": [ "packageRules": [
{ {
"matchManagers": ["docker-compose", "custom.regex"], "matchManagers": ["docker-compose", "custom.regex"],
@@ -14,7 +14,7 @@
"automerge": true "automerge": true
}, },
{ {
"matchBaseBranches": ["stable-4.0"], "matchBaseBranches": ["stable-4.0", "stable-7.2"],
"matchUpdateTypes": ["major", "minor"], "matchUpdateTypes": ["major", "minor"],
"enabled": false "enabled": false
}, },

View File

@@ -15,7 +15,7 @@ services:
restart: always restart: always
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.6.4 image: quay.io/keycloak/keycloak:26.7.1
networks: networks:
opencloud-net: opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ] command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -16,7 +16,7 @@ services:
- "traefik.http.services.opencloud.loadbalancer.server.port=9200" - "traefik.http.services.opencloud.loadbalancer.server.port=9200"
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}" - "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
traefik: traefik:
image: traefik:v3.6.14 image: traefik:v3.7.10
# release notes: https://github.com/traefik/traefik/releases # release notes: https://github.com/traefik/traefik/releases
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0} user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
networks: networks:

View File

@@ -23,22 +23,50 @@ services:
COLLABORATION_APP_INSECURE: "${INSECURE:-true}" COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}" COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
# One-shot service that generates the WOPI proof key on first start and
# keeps it in a named volume, like the proofKeyGeneration feature of the
# collabora-online helm chart.
# To rotate the key, remove the volume and start again:
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
collabora-proof-key:
image: alpine/openssl:3.5.7
entrypoint: ["/bin/sh"]
command:
- -ec
- |
if [ ! -s /proof/proof_key ]; then
openssl genrsa -traditional -out /proof/proof_key.tmp 4096
chown 1001:1001 /proof/proof_key.tmp
chmod 400 /proof/proof_key.tmp
mv /proof/proof_key.tmp /proof/proof_key
echo "WOPI proof key generated"
else
echo "WOPI proof key already exists"
fi
volumes:
- collabora-proof-key:/proof
logging:
driver: ${LOG_DRIVER:-local}
restart: "no"
collabora: collabora:
image: collabora/code:26.04.1.4.1 image: collabora/code:26.04.2.4.1
# release notes: https://www.collaboraonline.com/release-notes/ # release notes: https://www.collaboraonline.com/release-notes/
networks: networks:
opencloud-net: opencloud-net:
depends_on:
collabora-proof-key:
condition: service_completed_successfully
environment: environment:
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain # WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
DONT_GEN_SSL_CERT: "YES" extra_params: >
extra_params: | --o:ssl.enable=${COLLABORA_SSL_ENABLE:-true}
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \ --o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true}
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \ --o:ssl.termination=true
--o:ssl.termination=true \ --o:welcome.enable=false
--o:welcome.enable=false \ --o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \ --o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false} --o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
username: ${COLLABORA_ADMIN_USER:-admin} username: ${COLLABORA_ADMIN_USER:-admin}
password: ${COLLABORA_ADMIN_PASSWORD:-admin} password: ${COLLABORA_ADMIN_PASSWORD:-admin}
@@ -52,19 +80,24 @@ services:
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package). # (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro - /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro - /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
# WOPI proof key generated by the collabora-proof-key service.
- type: volume
source: collabora-proof-key
target: /etc/coolwsd/proof_key
read_only: true
volume:
subpath: proof_key
logging: logging:
driver: ${LOG_DRIVER:-local} driver: ${LOG_DRIVER:-local}
restart: always restart: always
entrypoint: [ '/bin/bash', '-c' ]
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
healthcheck: healthcheck:
test: # --use-env-vars makes the probe read extra_params, so it probes with
[ # the same http/https scheme the server actually runs with; without it
"CMD", # the probe falls back to coolwsd.xml where ssl.enable defaults to true
"bash", test: ["CMD", "/usr/bin/coolwsd", "--probe", "--use-env-vars"]
"-c",
"exec 3<>/dev/tcp/127.0.0.1/9980 && printf 'GET /hosting/discovery HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && cat <&3 | head -1 | grep -q '200 OK'"
]
interval: 15s interval: 15s
timeout: 10s timeout: 10s
retries: 5 retries: 5
volumes:
collabora-proof-key: