mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-08-07 20:38:42 +08:00
Compare commits
37 Commits
6b4bb80fe5
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
db3ddbdf32 | ||
|
|
1fbb2380cc | ||
|
|
34129ff018 | ||
|
|
0f89106b89 | ||
|
|
2b51cb53c0 | ||
|
|
eab3b7e584 | ||
|
|
c4023ff553 | ||
|
|
aac9a1e2f5 | ||
|
|
e6a0e8e2e6 | ||
|
|
1ecdd0e32a | ||
|
|
bcf59c86fd | ||
|
|
7cd7c57bd9 | ||
|
|
213dde31c8 | ||
|
|
dabd81377c | ||
|
|
8d2d89f283 | ||
|
|
189f17f6e0 | ||
|
|
27fd367113 | ||
|
|
fffcec12a8 | ||
|
|
42b4343d6e | ||
|
|
5666410706 | ||
|
|
62131f972b | ||
|
|
274195c6ad | ||
|
|
49ba000f6e | ||
|
|
d759e5a332 | ||
|
|
d7fcd3da64 | ||
|
|
325dce2f53 | ||
|
|
0221cfd91b | ||
|
|
c096f66dfd | ||
|
|
e6d987501e | ||
|
|
2f81c5f62c | ||
|
|
670d978c1c | ||
|
|
d952c2849b | ||
|
|
13b9489c52 | ||
|
|
e8b8511477 | ||
|
|
70e7679bc3 | ||
|
|
0d62d41894 | ||
|
|
16bd598d4d |
@@ -25,9 +25,9 @@ INSECURE=true
|
|||||||
# External IDP
|
# External IDP
|
||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
|
||||||
# Euro Office with traefik and letsencrypt
|
# Euro Office with traefik and letsencrypt
|
||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:traefik/opencloud.yml:traefik/euroffice.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
|
||||||
# Euro Office with external proxy (Nginx, Caddy, etc.)
|
# Euro Office with external proxy (Nginx, Caddy, etc.)
|
||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:external-proxy/opencloud.yml:external-proxy/euroffice.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
|
||||||
|
|
||||||
## Traefik Settings ##
|
## Traefik Settings ##
|
||||||
# Note: Traefik is always enabled and can't be disabled.
|
# Note: Traefik is always enabled and can't be disabled.
|
||||||
|
|||||||
10
README.md
10
README.md
@@ -147,12 +147,12 @@ Include Euro Office for document editing using either method:
|
|||||||
|
|
||||||
Using `-f` flags:
|
Using `-f` flags:
|
||||||
```bash
|
```bash
|
||||||
docker compose -f docker-compose.yml -f weboffice/euroffice.yml -f traefik/opencloud.yml -f traefik/euroffice.yml up -d
|
docker compose -f docker-compose.yml -f weboffice/euro-office.yml -f traefik/opencloud.yml -f traefik/euro-office.yml up -d
|
||||||
```
|
```
|
||||||
|
|
||||||
Or by setting in `.env`:
|
Or by setting in `.env`:
|
||||||
```
|
```
|
||||||
COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:traefik/opencloud.yml:traefik/euroffice.yml
|
COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
|
||||||
```
|
```
|
||||||
|
|
||||||
> **For local development only**: Add to `/etc/hosts`:
|
> **For local development only**: Add to `/etc/hosts`:
|
||||||
@@ -271,12 +271,12 @@ The WOPI server runs inside the OpenCloud process and is served on the OpenCloud
|
|||||||
To use Euro Office instead of Collabora behind an external proxy, swap the web office compose files:
|
To use Euro Office instead of Collabora behind an external proxy, swap the web office compose files:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker compose -f docker-compose.yml -f weboffice/euroffice.yml -f external-proxy/opencloud.yml -f external-proxy/euroffice.yml up -d
|
docker compose -f docker-compose.yml -f weboffice/euro-office.yml -f external-proxy/opencloud.yml -f external-proxy/euro-office.yml up -d
|
||||||
```
|
```
|
||||||
|
|
||||||
Or by setting in `.env`:
|
Or by setting in `.env`:
|
||||||
```
|
```
|
||||||
COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:external-proxy/opencloud.yml:external-proxy/euroffice.yml
|
COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
|
||||||
```
|
```
|
||||||
|
|
||||||
This exposes the necessary ports:
|
This exposes the necessary ports:
|
||||||
@@ -286,7 +286,7 @@ This exposes the necessary ports:
|
|||||||
As with Collabora, the WOPI server is served on the OpenCloud port (9200) under the `/wopi` and `/collaboration` paths and needs no separate port.
|
As with Collabora, the WOPI server is served on the OpenCloud port (9200) under the `/wopi` and `/collaboration` paths and needs no separate port.
|
||||||
|
|
||||||
> [!WARNING]
|
> [!WARNING]
|
||||||
> `external-proxy/euroffice.yml` binds the exposed ports to `127.0.0.1` only. If your external proxy runs on a different host, use `external-proxy/euroffice-exposed.yml`, which binds to all interfaces (`0.0.0.0`). Only expose these ports when you know what you are doing.
|
> `external-proxy/euro-office.yml` binds the exposed ports to `127.0.0.1` only. If your external proxy runs on a different host, use `external-proxy/euro-office-exposed.yml`, which binds to all interfaces (`0.0.0.0`). Only expose these ports when you know what you are doing.
|
||||||
|
|
||||||
**Please note:**
|
**Please note:**
|
||||||
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
|
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
|
||||||
|
|||||||
@@ -4,24 +4,18 @@
|
|||||||
--pf-v5-global--primary-color--dark-100: #e2baff;
|
--pf-v5-global--primary-color--dark-100: #e2baff;
|
||||||
--pf-v5-c-button--m-secondary--Color: #e2baff;
|
--pf-v5-c-button--m-secondary--Color: #e2baff;
|
||||||
--pf-v5-global--Color--light-100: #20434f;
|
--pf-v5-global--Color--light-100: #20434f;
|
||||||
|
--pf-v5-global--FontFamily--text: "Inter", "RedHatText", helvetica, arial, sans-serif;
|
||||||
|
--pf-v5-global--FontFamily--heading: "Inter", "RedHatDisplay", helvetica, arial, sans-serif;
|
||||||
}
|
}
|
||||||
|
|
||||||
@font-face {
|
@font-face {
|
||||||
font-family: OpenCloud;
|
font-family: Inter;
|
||||||
src: url('../fonts/OpenCloud500-Regular.woff2') format('woff2');
|
src: url('../fonts/Inter-Variable.woff2') format('woff2');
|
||||||
font-weight: normal;
|
font-weight: 100 900;
|
||||||
font-style: normal;
|
|
||||||
}
|
|
||||||
|
|
||||||
@font-face {
|
|
||||||
font-family: OpenCloud;
|
|
||||||
src: url('../fonts/OpenCloud750-Bold.woff2') format('woff2');
|
|
||||||
font-weight: bold;
|
|
||||||
font-style: normal;
|
font-style: normal;
|
||||||
}
|
}
|
||||||
|
|
||||||
body {
|
body {
|
||||||
font-family: "OpenCloud", "Open Sans", Helvetica, Arial, sans-serif;
|
|
||||||
background: url(../img/background.png) no-repeat center fixed !important;
|
background: url(../img/background.png) no-repeat center fixed !important;
|
||||||
background-size: cover !important;
|
background-size: cover !important;
|
||||||
}
|
}
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
3
config/opencloud/apps.yaml
Normal file
3
config/opencloud/apps.yaml
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
maps:
|
||||||
|
config:
|
||||||
|
folderViewEnabled: false
|
||||||
@@ -2,7 +2,7 @@
|
|||||||
services:
|
services:
|
||||||
opencloud:
|
opencloud:
|
||||||
# renovate: depName=opencloudeu/opencloud-rolling
|
# renovate: depName=opencloudeu/opencloud-rolling
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.2.0}
|
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.4.0}
|
||||||
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
||||||
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
||||||
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
@@ -58,6 +58,7 @@ services:
|
|||||||
OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE}
|
OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE}
|
||||||
volumes:
|
volumes:
|
||||||
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
|
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
|
||||||
|
- ./config/opencloud/apps.yaml:/etc/opencloud/apps.yaml
|
||||||
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
|
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
|
||||||
# configure the .env file to use own paths instead of docker internal volumes
|
# configure the .env file to use own paths instead of docker internal volumes
|
||||||
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
||||||
|
|||||||
@@ -78,7 +78,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.4
|
image: quay.io/keycloak/keycloak:26.7.1
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||||
"platformAutomerge": true,
|
"platformAutomerge": true,
|
||||||
"enabledManagers": ["docker-compose", "custom.regex"],
|
"enabledManagers": ["docker-compose", "custom.regex"],
|
||||||
"baseBranchPatterns": ["main", "stable-4.0"],
|
"baseBranchPatterns": ["main", "stable-4.0", "stable-7.2"],
|
||||||
"packageRules": [
|
"packageRules": [
|
||||||
{
|
{
|
||||||
"matchManagers": ["docker-compose", "custom.regex"],
|
"matchManagers": ["docker-compose", "custom.regex"],
|
||||||
@@ -14,7 +14,7 @@
|
|||||||
"automerge": true
|
"automerge": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"matchBaseBranches": ["stable-4.0"],
|
"matchBaseBranches": ["stable-4.0", "stable-7.2"],
|
||||||
"matchUpdateTypes": ["major", "minor"],
|
"matchUpdateTypes": ["major", "minor"],
|
||||||
"enabled": false
|
"enabled": false
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.4
|
image: quay.io/keycloak/keycloak:26.7.1
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ services:
|
|||||||
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
|
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
|
||||||
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
||||||
traefik:
|
traefik:
|
||||||
image: traefik:v3.6.14
|
image: traefik:v3.7.10
|
||||||
# release notes: https://github.com/traefik/traefik/releases
|
# release notes: https://github.com/traefik/traefik/releases
|
||||||
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
|
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
|
||||||
networks:
|
networks:
|
||||||
|
|||||||
@@ -23,22 +23,50 @@ services:
|
|||||||
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
||||||
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
||||||
|
|
||||||
|
# One-shot service that generates the WOPI proof key on first start and
|
||||||
|
# keeps it in a named volume, like the proofKeyGeneration feature of the
|
||||||
|
# collabora-online helm chart.
|
||||||
|
# To rotate the key, remove the volume and start again:
|
||||||
|
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
|
||||||
|
collabora-proof-key:
|
||||||
|
image: alpine/openssl:3.5.7
|
||||||
|
entrypoint: ["/bin/sh"]
|
||||||
|
command:
|
||||||
|
- -ec
|
||||||
|
- |
|
||||||
|
if [ ! -s /proof/proof_key ]; then
|
||||||
|
openssl genrsa -traditional -out /proof/proof_key.tmp 4096
|
||||||
|
chown 1001:1001 /proof/proof_key.tmp
|
||||||
|
chmod 400 /proof/proof_key.tmp
|
||||||
|
mv /proof/proof_key.tmp /proof/proof_key
|
||||||
|
echo "WOPI proof key generated"
|
||||||
|
else
|
||||||
|
echo "WOPI proof key already exists"
|
||||||
|
fi
|
||||||
|
volumes:
|
||||||
|
- collabora-proof-key:/proof
|
||||||
|
logging:
|
||||||
|
driver: ${LOG_DRIVER:-local}
|
||||||
|
restart: "no"
|
||||||
|
|
||||||
collabora:
|
collabora:
|
||||||
image: collabora/code:26.04.1.4.1
|
image: collabora/code:26.04.2.4.1
|
||||||
# release notes: https://www.collaboraonline.com/release-notes/
|
# release notes: https://www.collaboraonline.com/release-notes/
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
|
depends_on:
|
||||||
|
collabora-proof-key:
|
||||||
|
condition: service_completed_successfully
|
||||||
environment:
|
environment:
|
||||||
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
|
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
|
||||||
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
DONT_GEN_SSL_CERT: "YES"
|
extra_params: >
|
||||||
extra_params: |
|
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true}
|
||||||
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \
|
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true}
|
||||||
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \
|
--o:ssl.termination=true
|
||||||
--o:ssl.termination=true \
|
--o:welcome.enable=false
|
||||||
--o:welcome.enable=false \
|
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
|
||||||
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
||||||
username: ${COLLABORA_ADMIN_USER:-admin}
|
username: ${COLLABORA_ADMIN_USER:-admin}
|
||||||
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
||||||
@@ -52,19 +80,24 @@ services:
|
|||||||
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
||||||
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
||||||
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
||||||
|
# WOPI proof key generated by the collabora-proof-key service.
|
||||||
|
- type: volume
|
||||||
|
source: collabora-proof-key
|
||||||
|
target: /etc/coolwsd/proof_key
|
||||||
|
read_only: true
|
||||||
|
volume:
|
||||||
|
subpath: proof_key
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
restart: always
|
restart: always
|
||||||
entrypoint: [ '/bin/bash', '-c' ]
|
|
||||||
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
|
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test:
|
# --use-env-vars makes the probe read extra_params, so it probes with
|
||||||
[
|
# the same http/https scheme the server actually runs with; without it
|
||||||
"CMD",
|
# the probe falls back to coolwsd.xml where ssl.enable defaults to true
|
||||||
"bash",
|
test: ["CMD", "/usr/bin/coolwsd", "--probe", "--use-env-vars"]
|
||||||
"-c",
|
|
||||||
"exec 3<>/dev/tcp/127.0.0.1/9980 && printf 'GET /hosting/discovery HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && cat <&3 | head -1 | grep -q '200 OK'"
|
|
||||||
]
|
|
||||||
interval: 15s
|
interval: 15s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
collabora-proof-key:
|
||||||
|
|||||||
Reference in New Issue
Block a user