mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-08-07 20:38:42 +08:00
Compare commits
50 Commits
8184701cde
...
stable-7.2
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8efca76bdb | ||
|
|
b5baab2b00 | ||
|
|
21467e4f1a | ||
|
|
a930989ec7 | ||
|
|
6ff4fb4417 | ||
|
|
68a2f53ef2 | ||
|
|
fffb04bac2 | ||
|
|
c72832dc8a | ||
|
|
32d9e5fb50 | ||
|
|
e6256ebadb | ||
|
|
8b271811a6 | ||
|
|
40882d6f8f | ||
|
|
2ec04b4466 | ||
|
|
2c72369d24 | ||
|
|
6d3a1f8c49 | ||
|
|
cc1471e467 | ||
|
|
300fc4779b | ||
|
|
12efcc9e91 | ||
|
|
cd22ba6f6e | ||
|
|
23f4b6eefe | ||
|
|
225740f7d4 | ||
|
|
f74c434267 | ||
|
|
e2c680ea6b | ||
|
|
b0fdcec0a3 | ||
|
|
a0f9ffbc6f | ||
|
|
3314522ef9 | ||
|
|
9cee17c253 | ||
|
|
5268ad506b | ||
|
|
913920dd33 | ||
|
|
792bcd336e | ||
|
|
73b02b77d8 | ||
|
|
4d3e787e2d | ||
|
|
cda4138e7d | ||
|
|
c5ab316d45 | ||
|
|
b3b820f32b | ||
|
|
0636b2c871 | ||
|
|
03ba22ed4e | ||
|
|
4531d137ef | ||
|
|
d853a59078 | ||
|
|
75941df428 | ||
|
|
38f4ea52a5 | ||
|
|
5a1d9d4b9b | ||
|
|
217099947f | ||
|
|
03a4587c90 | ||
|
|
539d514bbb | ||
|
|
8564cb046f | ||
|
|
3813131dfd | ||
|
|
b5eb7bb7ca | ||
|
|
f01a8969bf | ||
|
|
87cbdc05e3 |
35
.env.example
35
.env.example
@@ -24,6 +24,10 @@ INSECURE=true
|
|||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml
|
||||||
# External IDP
|
# External IDP
|
||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
|
||||||
|
# Euro Office with traefik and letsencrypt
|
||||||
|
#COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:traefik/opencloud.yml:traefik/euroffice.yml
|
||||||
|
# Euro Office with external proxy (Nginx, Caddy, etc.)
|
||||||
|
#COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:external-proxy/opencloud.yml:external-proxy/euroffice.yml
|
||||||
|
|
||||||
## Traefik Settings ##
|
## Traefik Settings ##
|
||||||
# Note: Traefik is always enabled and can't be disabled.
|
# Note: Traefik is always enabled and can't be disabled.
|
||||||
@@ -83,7 +87,7 @@ TRAEFIK_LOG_LEVEL=
|
|||||||
# For production releases: "opencloudeu/opencloud"
|
# For production releases: "opencloudeu/opencloud"
|
||||||
# For rolling releases: "opencloudeu/opencloud-rolling"
|
# For rolling releases: "opencloudeu/opencloud-rolling"
|
||||||
# Defaults to production if not set otherwise
|
# Defaults to production if not set otherwise
|
||||||
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling
|
OC_DOCKER_IMAGE=opencloudeu/opencloud
|
||||||
# The openCloud container version.
|
# The openCloud container version.
|
||||||
# Defaults to the latest version-tag. Use git pull to update.
|
# Defaults to the latest version-tag. Use git pull to update.
|
||||||
OC_DOCKER_TAG=
|
OC_DOCKER_TAG=
|
||||||
@@ -215,9 +219,9 @@ TIKA_IMAGE=
|
|||||||
# Domain of Collabora, where you can find the frontend.
|
# Domain of Collabora, where you can find the frontend.
|
||||||
# Defaults to "collabora.opencloud.test"
|
# Defaults to "collabora.opencloud.test"
|
||||||
COLLABORA_DOMAIN=
|
COLLABORA_DOMAIN=
|
||||||
# Domain of the wopiserver which handles Collabora.
|
# NOTE: The WOPI server runs inside the main OpenCloud process and is served by
|
||||||
# Defaults to "wopiserver.opencloud.test"
|
# the OpenCloud proxy on the main OpenCloud domain (OC_DOMAIN) under the /wopi and
|
||||||
WOPISERVER_DOMAIN=
|
# /collaboration paths. It no longer needs its own domain.
|
||||||
# Admin user for Collabora.
|
# Admin user for Collabora.
|
||||||
# Defaults to "admin".
|
# Defaults to "admin".
|
||||||
# Collabora Admin Panel URL:
|
# Collabora Admin Panel URL:
|
||||||
@@ -239,6 +243,21 @@ COLLABORA_SSL_VERIFICATION=false
|
|||||||
COLLABORA_HOME_MODE=
|
COLLABORA_HOME_MODE=
|
||||||
|
|
||||||
|
|
||||||
|
### Euro Office Settings ###
|
||||||
|
# Domain of Euro Office, where you can find the document server.
|
||||||
|
# Defaults to "euro-office.opencloud.test"
|
||||||
|
EURO_OFFICE_DOMAIN=
|
||||||
|
# JWT Secret for Euro Office. IMPORTANT: Change this for production!
|
||||||
|
# Defaults to "changeme"
|
||||||
|
EURO_OFFICE_JWT_SECRET=
|
||||||
|
# Euro Office Docker image.
|
||||||
|
# Defaults to "ghcr.io/euro-office/documentserver"
|
||||||
|
EURO_OFFICE_DOCKER_IMAGE=
|
||||||
|
# Euro Office Docker tag.
|
||||||
|
# Defaults to "latest"
|
||||||
|
EURO_OFFICE_DOCKER_TAG=
|
||||||
|
|
||||||
|
|
||||||
### Virusscanner Settings ###
|
### Virusscanner Settings ###
|
||||||
# IMPORTANT: If you enable antivirus, you also MUST configure the START_ADDITIONAL_SERVICES
|
# IMPORTANT: If you enable antivirus, you also MUST configure the START_ADDITIONAL_SERVICES
|
||||||
# envvar in the OpenCloud Settings above by adding 'antivirus' to the list.
|
# envvar in the OpenCloud Settings above by adding 'antivirus' to the list.
|
||||||
@@ -304,6 +323,14 @@ LDAP_BIND_PASSWORD=
|
|||||||
|
|
||||||
## Autoprovisioning Mode ##
|
## Autoprovisioning Mode ##
|
||||||
# Use together with idm/external-idp.yml
|
# Use together with idm/external-idp.yml
|
||||||
|
# Role assignment driver for the proxy. Defaults to "oidc".
|
||||||
|
# Possible values: "oidc", "default"
|
||||||
|
# When set to "oidc", roles are assigned based on OIDC claims.
|
||||||
|
# When set to "default", all users get the 'user' role assigned.
|
||||||
|
PROXY_ROLE_ASSIGNMENT_DRIVER=
|
||||||
|
# Assign the default 'user' role to new users. Defaults to "false".
|
||||||
|
# Set to "true" when using PROXY_ROLE_ASSIGNMENT_DRIVER=default
|
||||||
|
GRAPH_ASSIGN_DEFAULT_USER_ROLE=
|
||||||
# If you want to use a keycloak for local testing, you can use testing/external-keycloak.yml and testing/ldap-manager.yml
|
# If you want to use a keycloak for local testing, you can use testing/external-keycloak.yml and testing/ldap-manager.yml
|
||||||
# Domain of your Identity Provider.
|
# Domain of your Identity Provider.
|
||||||
IDP_DOMAIN=
|
IDP_DOMAIN=
|
||||||
|
|||||||
71
README.md
71
README.md
@@ -12,6 +12,7 @@ OpenCloud Compose offers a modular approach to deploying OpenCloud with several
|
|||||||
- **Standard deployment** with Traefik reverse proxy and Let's Encrypt certificates or certificates from files
|
- **Standard deployment** with Traefik reverse proxy and Let's Encrypt certificates or certificates from files
|
||||||
- **External proxy** support for environments with existing reverse proxies (like Nginx, Caddy, etc.)
|
- **External proxy** support for environments with existing reverse proxies (like Nginx, Caddy, etc.)
|
||||||
- **Collabora Online** integration for document editing
|
- **Collabora Online** integration for document editing
|
||||||
|
- **Euro Office** integration for document editing
|
||||||
- **Keycloak and LDAP** integration for centralized identity management
|
- **Keycloak and LDAP** integration for centralized identity management
|
||||||
- **Full text search** with Apache Tika for content extraction and metadata analysis
|
- **Full text search** with Apache Tika for content extraction and metadata analysis
|
||||||
- **Monitoring** with metrics endpoints for observability and performance monitoring
|
- **Monitoring** with metrics endpoints for observability and performance monitoring
|
||||||
@@ -107,9 +108,12 @@ This setup includes:
|
|||||||
|
|
||||||
### With Collabora Online
|
### With Collabora Online
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> Collabora Online and [Euro Office](#with-euro-office) are mutually exclusive web office backends — both use the same `collaboration` (WOPI) service, which runs inside the main OpenCloud process. Enable only one of them at a time.
|
||||||
|
|
||||||
Include Collabora for document editing using either method:
|
Include Collabora for document editing using either method:
|
||||||
|
|
||||||
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain, Collabora subdomain, and WOPI server subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `collabora.example.com`, `wopiserver.example.com`) or use a wildcard DNS entry (`*.example.com`).
|
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain and the Collabora subdomain. The WOPI server is served by OpenCloud on the main domain, so it does not need its own subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `collabora.example.com`) or use a wildcard DNS entry (`*.example.com`).
|
||||||
|
|
||||||
Using `-f` flags:
|
Using `-f` flags:
|
||||||
```bash
|
```bash
|
||||||
@@ -124,9 +128,44 @@ COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:tr
|
|||||||
> **For local development only**: Add to `/etc/hosts`:
|
> **For local development only**: Add to `/etc/hosts`:
|
||||||
> ```
|
> ```
|
||||||
> 127.0.0.1 collabora.opencloud.test
|
> 127.0.0.1 collabora.opencloud.test
|
||||||
> 127.0.0.1 wopiserver.opencloud.test
|
|
||||||
> ```
|
> ```
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> **Upgrading from a previous setup**: The `collaboration` (WOPI) service no longer runs as a separate container or on its own `wopiserver.*` domain — it now runs inside the main OpenCloud process and is served by the OpenCloud proxy on the main domain under the `/wopi` and `/collaboration` paths. When upgrading:
|
||||||
|
> - Pull the latest compose files and recreate the stack (`docker compose up -d`). The old `collaboration` container is removed automatically.
|
||||||
|
> - You can retire the `wopiserver.*` DNS entry (and its `/etc/hosts` line), its reverse-proxy/Traefik route, and the `WOPISERVER_DOMAIN` variable in `.env` — all are now unused.
|
||||||
|
> - If you run behind an external proxy, make sure it forwards `/wopi` and `/collaboration` on the OpenCloud domain to OpenCloud (port 9200). Forwarding the whole OpenCloud domain, as already configured, covers this.
|
||||||
|
|
||||||
|
### With Euro Office
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> Euro Office and [Collabora Online](#with-collabora-online) are mutually exclusive web office backends — both use the same `collaboration` (WOPI) service, which runs inside the main OpenCloud process. Enable only one of them at a time.
|
||||||
|
|
||||||
|
Include Euro Office for document editing using either method:
|
||||||
|
|
||||||
|
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain and the Euro Office subdomain. The WOPI server is served by OpenCloud on the main domain, so it does not need its own subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `euro-office.example.com`) or use a wildcard DNS entry (`*.example.com`).
|
||||||
|
|
||||||
|
Using `-f` flags:
|
||||||
|
```bash
|
||||||
|
docker compose -f docker-compose.yml -f weboffice/euroffice.yml -f traefik/opencloud.yml -f traefik/euroffice.yml up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
Or by setting in `.env`:
|
||||||
|
```
|
||||||
|
COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:traefik/opencloud.yml:traefik/euroffice.yml
|
||||||
|
```
|
||||||
|
|
||||||
|
> **For local development only**: Add to `/etc/hosts`:
|
||||||
|
> ```
|
||||||
|
> 127.0.0.1 euro-office.opencloud.test
|
||||||
|
> ```
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> Set a strong `EURO_OFFICE_JWT_SECRET` in your `.env` file for production. The default value (`changeme`) is intended for local development only.
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> Upgrading from a previous setup? See [Upgrading from a previous setup](#with-collabora-online) under Collabora Online — the WOPI server changes (no more separate container or `wopiserver.*` domain) apply to Euro Office as well.
|
||||||
|
|
||||||
### With Full Text Search
|
### With Full Text Search
|
||||||
|
|
||||||
Enable full text search capabilities with Apache Tika using either method:
|
Enable full text search capabilities with Apache Tika using either method:
|
||||||
@@ -226,7 +265,28 @@ COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:external-proxy/opencloud
|
|||||||
This exposes the necessary ports:
|
This exposes the necessary ports:
|
||||||
- OpenCloud: 9200
|
- OpenCloud: 9200
|
||||||
- Collabora: 9980
|
- Collabora: 9980
|
||||||
- WOPI server: 9300
|
|
||||||
|
The WOPI server runs inside the OpenCloud process and is served on the OpenCloud port (9200) under the `/wopi` and `/collaboration` paths, so no separate port needs to be exposed for it.
|
||||||
|
|
||||||
|
To use Euro Office instead of Collabora behind an external proxy, swap the web office compose files:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker compose -f docker-compose.yml -f weboffice/euroffice.yml -f external-proxy/opencloud.yml -f external-proxy/euroffice.yml up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
Or by setting in `.env`:
|
||||||
|
```
|
||||||
|
COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:external-proxy/opencloud.yml:external-proxy/euroffice.yml
|
||||||
|
```
|
||||||
|
|
||||||
|
This exposes the necessary ports:
|
||||||
|
- OpenCloud: 9200
|
||||||
|
- Euro Office: 9900
|
||||||
|
|
||||||
|
As with Collabora, the WOPI server is served on the OpenCloud port (9200) under the `/wopi` and `/collaboration` paths and needs no separate port.
|
||||||
|
|
||||||
|
> [!WARNING]
|
||||||
|
> `external-proxy/euroffice.yml` binds the exposed ports to `127.0.0.1` only. If your external proxy runs on a different host, use `external-proxy/euroffice-exposed.yml`, which binds to all interfaces (`0.0.0.0`). Only expose these ports when you know what you are doing.
|
||||||
|
|
||||||
**Please note:**
|
**Please note:**
|
||||||
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
|
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
|
||||||
@@ -341,7 +401,10 @@ Key variables:
|
|||||||
| `OC_DATA_DIR` | Data directory path | (Docker volume) |
|
| `OC_DATA_DIR` | Data directory path | (Docker volume) |
|
||||||
| `INSECURE` | Skip certificate validation | true |
|
| `INSECURE` | Skip certificate validation | true |
|
||||||
| `COLLABORA_DOMAIN` | Collabora domain | collabora.opencloud.test |
|
| `COLLABORA_DOMAIN` | Collabora domain | collabora.opencloud.test |
|
||||||
| `WOPISERVER_DOMAIN` | WOPI server domain | wopiserver.opencloud.test |
|
| `EURO_OFFICE_DOMAIN` | Euro Office document server domain | euro-office.opencloud.test |
|
||||||
|
| `EURO_OFFICE_JWT_SECRET` | JWT secret for Euro Office (change for production!) | changeme |
|
||||||
|
| `EURO_OFFICE_DOCKER_IMAGE` | Euro Office Docker image | ghcr.io/euro-office/documentserver |
|
||||||
|
| `EURO_OFFICE_DOCKER_TAG` | Euro Office Docker tag | latest |
|
||||||
| `TIKA_IMAGE` | Apache Tika image tag | apache/tika:slim |
|
| `TIKA_IMAGE` | Apache Tika image tag | apache/tika:slim |
|
||||||
| `KEYCLOAK_DOMAIN` | Keycloak domain | keycloak.opencloud.test |
|
| `KEYCLOAK_DOMAIN` | Keycloak domain | keycloak.opencloud.test |
|
||||||
| `KEYCLOAK_ADMIN` | Keycloak admin username | kcadmin |
|
| `KEYCLOAK_ADMIN` | Keycloak admin username | kcadmin |
|
||||||
|
|||||||
71
config/euro-office/app-registry.yaml
Normal file
71
config/euro-office/app-registry.yaml
Normal file
@@ -0,0 +1,71 @@
|
|||||||
|
app_registry:
|
||||||
|
mimetypes:
|
||||||
|
- mime_type: application/pdf
|
||||||
|
extension: pdf
|
||||||
|
name: PDF
|
||||||
|
description: PDF document
|
||||||
|
icon: ''
|
||||||
|
default_app: ''
|
||||||
|
allow_creation: false
|
||||||
|
- mime_type: application/vnd.oasis.opendocument.text
|
||||||
|
extension: odt
|
||||||
|
name: OpenDocument
|
||||||
|
description: OpenDocument text document
|
||||||
|
icon: ''
|
||||||
|
default_app: Collabora
|
||||||
|
allow_creation: true
|
||||||
|
- mime_type: application/vnd.oasis.opendocument.spreadsheet
|
||||||
|
extension: ods
|
||||||
|
name: OpenSpreadsheet
|
||||||
|
description: OpenDocument spreadsheet document
|
||||||
|
icon: ''
|
||||||
|
default_app: Collabora
|
||||||
|
allow_creation: true
|
||||||
|
- mime_type: application/vnd.oasis.opendocument.presentation
|
||||||
|
extension: odp
|
||||||
|
name: OpenPresentation
|
||||||
|
description: OpenDocument presentation document
|
||||||
|
icon: ''
|
||||||
|
default_app: Collabora
|
||||||
|
- mime_type: application/vnd.oasis.opendocument.graphics
|
||||||
|
extension: odg
|
||||||
|
name: OpenGraphics
|
||||||
|
description: OpenDocument graphics document
|
||||||
|
icon: ''
|
||||||
|
default_app: Collabora
|
||||||
|
allow_creation: true
|
||||||
|
- mime_type: application/vnd.openxmlformats-officedocument.wordprocessingml.document
|
||||||
|
extension: docx
|
||||||
|
name: Microsoft Word
|
||||||
|
description: Microsoft Word document
|
||||||
|
icon: ''
|
||||||
|
default_app: Euro-Office
|
||||||
|
allow_creation: true
|
||||||
|
- mime_type: application/vnd.openxmlformats-officedocument.wordprocessingml.form
|
||||||
|
extension: docxf
|
||||||
|
name: Form Document
|
||||||
|
description: Form Document
|
||||||
|
icon: ''
|
||||||
|
default_app: Euro-Office
|
||||||
|
allow_creation: true
|
||||||
|
- mime_type: application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
|
||||||
|
extension: xlsx
|
||||||
|
name: Microsoft Excel
|
||||||
|
description: Microsoft Excel document
|
||||||
|
icon: ''
|
||||||
|
default_app: Euro-Office
|
||||||
|
allow_creation: true
|
||||||
|
- mime_type: application/vnd.openxmlformats-officedocument.presentationml.presentation
|
||||||
|
extension: pptx
|
||||||
|
name: Microsoft PowerPoint
|
||||||
|
description: Microsoft PowerPoint document
|
||||||
|
icon: ''
|
||||||
|
default_app: Euro-Office
|
||||||
|
allow_creation: true
|
||||||
|
- mime_type: application/vnd.jupyter
|
||||||
|
extension: ipynb
|
||||||
|
name: Jupyter Notebook
|
||||||
|
description: Jupyter Notebook
|
||||||
|
icon: ''
|
||||||
|
default_app: ''
|
||||||
|
allow_creation: true
|
||||||
@@ -22,6 +22,7 @@ directives:
|
|||||||
- 'https://embed.diagrams.net/'
|
- 'https://embed.diagrams.net/'
|
||||||
# In contrary to bash and docker the default is given after the | character
|
# In contrary to bash and docker the default is given after the | character
|
||||||
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
|
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
# This is needed for the external-sites web extension when embedding sites
|
# This is needed for the external-sites web extension when embedding sites
|
||||||
- 'https://docs.opencloud.eu'
|
- 'https://docs.opencloud.eu'
|
||||||
img-src:
|
img-src:
|
||||||
@@ -32,7 +33,7 @@ directives:
|
|||||||
- 'https://tile.openstreetmap.org/'
|
- 'https://tile.openstreetmap.org/'
|
||||||
# In contrary to bash and docker the default is given after the | character
|
# In contrary to bash and docker the default is given after the | character
|
||||||
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
- 'https://tile.openstreetmap.org/'
|
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
manifest-src:
|
manifest-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
media-src:
|
media-src:
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
opencloud:
|
opencloud:
|
||||||
# renovate: depName=opencloudeu/opencloud-rolling
|
# renovate: depName=opencloudeu/opencloud
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.1.0}
|
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud}:${OC_DOCKER_TAG:-7.2.3}
|
||||||
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
||||||
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
||||||
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
|
|||||||
@@ -1,10 +1,6 @@
|
|||||||
---
|
---
|
||||||
# only expose the ports when you know what you are doing!
|
# only expose the ports when you know what you are doing!
|
||||||
services:
|
services:
|
||||||
collaboration:
|
|
||||||
ports:
|
|
||||||
# expose the wopi server on all interfaces
|
|
||||||
- "0.0.0.0:9300:9300"
|
|
||||||
collabora:
|
collabora:
|
||||||
ports:
|
ports:
|
||||||
# expose the collabora server on all interfaces
|
# expose the collabora server on all interfaces
|
||||||
|
|||||||
@@ -1,9 +1,5 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
collaboration:
|
|
||||||
ports:
|
|
||||||
# expose the wopi server on localhost
|
|
||||||
- "127.0.0.1:9300:9300"
|
|
||||||
collabora:
|
collabora:
|
||||||
ports:
|
ports:
|
||||||
# expose the collabora server on localhost
|
# expose the collabora server on localhost
|
||||||
|
|||||||
7
external-proxy/euroffice-exposed.yml
Normal file
7
external-proxy/euroffice-exposed.yml
Normal file
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
# only expose the ports when you know what you are doing!
|
||||||
|
services:
|
||||||
|
euro-office:
|
||||||
|
ports:
|
||||||
|
# expose the euro-office document server on all interfaces
|
||||||
|
- "0.0.0.0:9900:80"
|
||||||
6
external-proxy/euroffice.yml
Normal file
6
external-proxy/euroffice.yml
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
services:
|
||||||
|
euro-office:
|
||||||
|
ports:
|
||||||
|
# expose the euro-office document server on localhost
|
||||||
|
- "127.0.0.1:9900:80"
|
||||||
@@ -17,15 +17,15 @@ services:
|
|||||||
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
|
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
|
||||||
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
|
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
|
||||||
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
|
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
|
||||||
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID}
|
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID:-web}
|
||||||
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES}
|
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES:-openid profile email}
|
||||||
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID}
|
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID:-OpenCloudAndroid}
|
||||||
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES}
|
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||||
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID}
|
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID:-OpenCloudIOS}
|
||||||
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES}
|
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||||
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID}
|
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID:-OpenCloudDesktop}
|
||||||
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES}
|
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||||
PROXY_ROLE_ASSIGNMENT_DRIVER: "oidc"
|
PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc}
|
||||||
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
||||||
# This specifies to start all services except idm and idp. These are replaced by external services.
|
# This specifies to start all services except idm and idp. These are replaced by external services.
|
||||||
OC_EXCLUDE_RUN_SERVICES: idm,idp
|
OC_EXCLUDE_RUN_SERVICES: idm,idp
|
||||||
@@ -47,7 +47,7 @@ services:
|
|||||||
OC_LDAP_DISABLE_USER_MECHANISM: "attribute"
|
OC_LDAP_DISABLE_USER_MECHANISM: "attribute"
|
||||||
OC_ADMIN_USER_ID: ""
|
OC_ADMIN_USER_ID: ""
|
||||||
SETTINGS_SETUP_DEFAULT_ASSIGNMENTS: "false"
|
SETTINGS_SETUP_DEFAULT_ASSIGNMENTS: "false"
|
||||||
GRAPH_ASSIGN_DEFAULT_USER_ROLE: "false"
|
GRAPH_ASSIGN_DEFAULT_USER_ROLE: ${GRAPH_ASSIGN_DEFAULT_USER_ROLE:-false}
|
||||||
GRAPH_USERNAME_MATCH: "none"
|
GRAPH_USERNAME_MATCH: "none"
|
||||||
# We need to set the IDP_DOMAIN to allow the CSP rules to be set correctly
|
# We need to set the IDP_DOMAIN to allow the CSP rules to be set correctly
|
||||||
IDP_DOMAIN: ${IDP_DOMAIN:-keycloak.opencloud.test}
|
IDP_DOMAIN: ${IDP_DOMAIN:-keycloak.opencloud.test}
|
||||||
|
|||||||
@@ -78,7 +78,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.2
|
image: quay.io/keycloak/keycloak:26.6.4
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -1,43 +0,0 @@
|
|||||||
{
|
|
||||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
||||||
"platformAutomerge": true,
|
|
||||||
"enabledManagers": ["docker-compose", "custom.regex"],
|
|
||||||
"baseBranchPatterns": ["main", "stable-4.0"],
|
|
||||||
"packageRules": [
|
|
||||||
{
|
|
||||||
"matchManagers": ["docker-compose", "custom.regex"],
|
|
||||||
"labels": ["Type:Dependencies", "Bot:Renovate"]
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchManagers": ["docker-compose"],
|
|
||||||
"matchUpdateTypes": ["patch"],
|
|
||||||
"automerge": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchBaseBranches": ["stable-4.0"],
|
|
||||||
"matchUpdateTypes": ["major", "minor"],
|
|
||||||
"enabled": false
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchPackageNames": ["postgres"],
|
|
||||||
"matchManagers": ["docker-compose"],
|
|
||||||
"allowedVersions": "/^17\\.\\d+-alpine$/"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"docker-compose": {
|
|
||||||
"managerFilePatterns": ["/.+\\.ya?ml$/"]
|
|
||||||
},
|
|
||||||
"customManagers": [
|
|
||||||
{
|
|
||||||
"customType": "regex",
|
|
||||||
"managerFilePatterns": [
|
|
||||||
"/^docker-compose\\.yml$/",
|
|
||||||
"/^weboffice\\/collabora\\.yml$/"
|
|
||||||
],
|
|
||||||
"matchStrings": [
|
|
||||||
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"
|
|
||||||
],
|
|
||||||
"datasourceTemplate": "docker"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
@@ -15,7 +15,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.2
|
image: quay.io/keycloak/keycloak:26.6.4
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -5,16 +5,6 @@ services:
|
|||||||
opencloud-net:
|
opencloud-net:
|
||||||
aliases:
|
aliases:
|
||||||
- ${COLLABORA_DOMAIN:-collabora.opencloud.test}
|
- ${COLLABORA_DOMAIN:-collabora.opencloud.test}
|
||||||
- ${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}
|
|
||||||
collaboration:
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.routers.collaboration.entrypoints=https"
|
|
||||||
- "traefik.http.routers.collaboration.rule=Host(`${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}`)"
|
|
||||||
- "traefik.http.routers.collaboration.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
|
||||||
- "traefik.http.routers.collaboration.service=collaboration"
|
|
||||||
- "traefik.http.routers.collaboration.middlewares=hsts-header"
|
|
||||||
- "traefik.http.services.collaboration.loadbalancer.server.port=9300"
|
|
||||||
collabora:
|
collabora:
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
|||||||
18
traefik/euroffice.yml
Normal file
18
traefik/euroffice.yml
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
services:
|
||||||
|
traefik:
|
||||||
|
networks:
|
||||||
|
opencloud-net:
|
||||||
|
aliases:
|
||||||
|
- ${EURO_OFFICE_DOMAIN:-euro-office.opencloud.test}
|
||||||
|
euro-office:
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.routers.euro-office.entrypoints=https"
|
||||||
|
- "traefik.http.routers.euro-office.rule=Host(`${EURO_OFFICE_DOMAIN:-euro-office.opencloud.test}`)"
|
||||||
|
- "traefik.http.routers.euro-office.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
||||||
|
- "traefik.http.routers.euro-office.service=euro-office"
|
||||||
|
- "traefik.http.services.euro-office.loadbalancer.server.port=80"
|
||||||
|
# websockets can't be opened when this is omitted
|
||||||
|
- "traefik.http.middlewares.euro-office.headers.customrequestheaders.X-Forwarded-Proto=https"
|
||||||
|
- "traefik.http.routers.euro-office.middlewares=euro-office"
|
||||||
@@ -6,63 +6,67 @@ services:
|
|||||||
# this is needed for setting the correct CSP header
|
# this is needed for setting the correct CSP header
|
||||||
COLLABORA_DOMAIN: ${COLLABORA_DOMAIN:-collabora.opencloud.test}
|
COLLABORA_DOMAIN: ${COLLABORA_DOMAIN:-collabora.opencloud.test}
|
||||||
TRAEFIK_PORT_HTTPS: ${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
TRAEFIK_PORT_HTTPS: ${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
# expose nats and the reva gateway for the collaboration service
|
# run the collaboration (WOPI) service inside the main opencloud process,
|
||||||
NATS_NATS_HOST: 0.0.0.0
|
# appended to any user defined services in START_ADDITIONAL_SERVICES
|
||||||
GATEWAY_GRPC_ADDR: 0.0.0.0:9142
|
OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES:-}${START_ADDITIONAL_SERVICES:+,}collaboration
|
||||||
# make collabora the secure view app
|
# make collabora the secure view app
|
||||||
FRONTEND_APP_HANDLER_SECURE_VIEW_APP_ADDR: eu.opencloud.api.collaboration
|
FRONTEND_APP_HANDLER_SECURE_VIEW_APP_ADDR: eu.opencloud.api.collaboration
|
||||||
GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6"
|
GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6"
|
||||||
|
# collaboration service configuration; the WOPI endpoint is served by the
|
||||||
collaboration:
|
# opencloud proxy on the opencloud domain (/wopi and /collaboration routes),
|
||||||
# renovate: depName=opencloudeu/opencloud-rolling
|
# so no separate wopiserver domain, route or port is needed
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.1.0}
|
COLLABORATION_WOPI_SRC: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
|
||||||
networks:
|
|
||||||
opencloud-net:
|
|
||||||
depends_on:
|
|
||||||
opencloud:
|
|
||||||
condition: service_started
|
|
||||||
collabora:
|
|
||||||
condition: service_healthy
|
|
||||||
entrypoint:
|
|
||||||
- /bin/sh
|
|
||||||
command: [ "-c", "opencloud collaboration server" ]
|
|
||||||
environment:
|
|
||||||
COLLABORATION_GRPC_ADDR: 0.0.0.0:9301
|
|
||||||
COLLABORATION_HTTP_ADDR: 0.0.0.0:9300
|
|
||||||
MICRO_REGISTRY: "nats-js-kv"
|
|
||||||
MICRO_REGISTRY_ADDRESS: "opencloud:9233"
|
|
||||||
COLLABORATION_WOPI_SRC: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
|
||||||
COLLABORATION_APP_NAME: "CollaboraOnline"
|
COLLABORATION_APP_NAME: "CollaboraOnline"
|
||||||
COLLABORATION_APP_PRODUCT: "Collabora"
|
COLLABORATION_APP_PRODUCT: "Collabora"
|
||||||
COLLABORATION_APP_ADDR: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
COLLABORATION_APP_ADDR: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
COLLABORATION_APP_ICON: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/favicon.ico
|
COLLABORATION_APP_ICON: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/favicon.ico
|
||||||
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
||||||
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
||||||
COLLABORATION_LOG_LEVEL: ${LOG_LEVEL:-info}
|
|
||||||
OC_URL: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
# One-shot service that generates the WOPI proof key on first start and
|
||||||
|
# keeps it in a named volume, like the proofKeyGeneration feature of the
|
||||||
|
# collabora-online helm chart.
|
||||||
|
# To rotate the key, remove the volume and start again:
|
||||||
|
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
|
||||||
|
collabora-proof-key:
|
||||||
|
image: alpine/openssl:3.5.7
|
||||||
|
entrypoint: ["/bin/sh"]
|
||||||
|
command:
|
||||||
|
- -ec
|
||||||
|
- |
|
||||||
|
if [ ! -s /proof/proof_key ]; then
|
||||||
|
openssl genrsa -traditional -out /proof/proof_key.tmp 4096
|
||||||
|
chown 1001:1001 /proof/proof_key.tmp
|
||||||
|
chmod 400 /proof/proof_key.tmp
|
||||||
|
mv /proof/proof_key.tmp /proof/proof_key
|
||||||
|
echo "WOPI proof key generated"
|
||||||
|
else
|
||||||
|
echo "WOPI proof key already exists"
|
||||||
|
fi
|
||||||
volumes:
|
volumes:
|
||||||
# configure the .env file to use own paths instead of docker internal volumes
|
- collabora-proof-key:/proof
|
||||||
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
restart: always
|
restart: "no"
|
||||||
|
|
||||||
collabora:
|
collabora:
|
||||||
image: collabora/code:25.04.10.3.1
|
image: collabora/code:26.04.2.4.1
|
||||||
# release notes: https://www.collaboraonline.com/release-notes/
|
# release notes: https://www.collaboraonline.com/release-notes/
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
|
depends_on:
|
||||||
|
collabora-proof-key:
|
||||||
|
condition: service_completed_successfully
|
||||||
environment:
|
environment:
|
||||||
aliasgroup1: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
|
||||||
DONT_GEN_SSL_CERT: "YES"
|
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
extra_params: |
|
extra_params: >
|
||||||
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \
|
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true}
|
||||||
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \
|
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true}
|
||||||
--o:ssl.termination=true \
|
--o:ssl.termination=true
|
||||||
--o:welcome.enable=false \
|
--o:welcome.enable=false
|
||||||
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
||||||
username: ${COLLABORA_ADMIN_USER:-admin}
|
username: ${COLLABORA_ADMIN_USER:-admin}
|
||||||
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
||||||
@@ -76,13 +80,24 @@ services:
|
|||||||
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
||||||
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
||||||
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
||||||
|
# WOPI proof key generated by the collabora-proof-key service.
|
||||||
|
- type: volume
|
||||||
|
source: collabora-proof-key
|
||||||
|
target: /etc/coolwsd/proof_key
|
||||||
|
read_only: true
|
||||||
|
volume:
|
||||||
|
subpath: proof_key
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
restart: always
|
restart: always
|
||||||
entrypoint: [ '/bin/bash', '-c' ]
|
|
||||||
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
|
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ]
|
# --use-env-vars makes the probe read extra_params, so it probes with
|
||||||
|
# the same http/https scheme the server actually runs with; without it
|
||||||
|
# the probe falls back to coolwsd.xml where ssl.enable defaults to true
|
||||||
|
test: ["CMD", "/usr/bin/coolwsd", "--probe", "--use-env-vars"]
|
||||||
interval: 15s
|
interval: 15s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
collabora-proof-key:
|
||||||
|
|||||||
53
weboffice/euroffice.yml
Normal file
53
weboffice/euroffice.yml
Normal file
@@ -0,0 +1,53 @@
|
|||||||
|
---
|
||||||
|
services:
|
||||||
|
|
||||||
|
opencloud:
|
||||||
|
environment:
|
||||||
|
# this is needed for setting the correct CSP header
|
||||||
|
EURO_OFFICE_DOMAIN: ${EURO_OFFICE_DOMAIN:-euro-office.opencloud.test}
|
||||||
|
TRAEFIK_PORT_HTTPS: ${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
|
# run the collaboration (WOPI) service inside the main opencloud process,
|
||||||
|
# appended to any user defined services in START_ADDITIONAL_SERVICES
|
||||||
|
OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES:-}${START_ADDITIONAL_SERVICES:+,}collaboration
|
||||||
|
# collaboration service configuration; the WOPI endpoint is served by the
|
||||||
|
# opencloud proxy on the opencloud domain (/wopi and /collaboration routes),
|
||||||
|
# so no separate wopiserver domain, route or port is needed
|
||||||
|
COLLABORATION_WOPI_SRC: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
|
COLLABORATION_APP_NAME: "Euro-Office"
|
||||||
|
COLLABORATION_APP_PRODUCT: "OnlyOffice"
|
||||||
|
COLLABORATION_APP_ADDR: https://${EURO_OFFICE_DOMAIN:-euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
|
COLLABORATION_APP_ICON: https://${EURO_OFFICE_DOMAIN:-euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/web-apps/apps/documenteditor/main/resources/img/favicon.ico
|
||||||
|
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
||||||
|
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
||||||
|
COLLABORATION_APP_PROOF_DISABLE: "true"
|
||||||
|
volumes:
|
||||||
|
- ./config/euro-office/app-registry.yaml:/etc/opencloud/app-registry.yaml
|
||||||
|
|
||||||
|
euro-office:
|
||||||
|
image: ${EURO_OFFICE_DOCKER_IMAGE:-ghcr.io/euro-office/documentserver}:${EURO_OFFICE_DOCKER_TAG:-latest}
|
||||||
|
# changelog https://github.com/EURO-office/DocumentServer/releases
|
||||||
|
networks:
|
||||||
|
opencloud-net:
|
||||||
|
environment:
|
||||||
|
WOPI_ENABLED: "true"
|
||||||
|
# self-signed certificates
|
||||||
|
USE_UNAUTHORIZED_STORAGE: "${INSECURE:-false}"
|
||||||
|
volumes:
|
||||||
|
# Mount local TrueType fonts so the container can use system fonts
|
||||||
|
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
||||||
|
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
||||||
|
logging:
|
||||||
|
driver: ${LOG_DRIVER:-local}
|
||||||
|
restart: always
|
||||||
|
healthcheck:
|
||||||
|
test:
|
||||||
|
[
|
||||||
|
"CMD",
|
||||||
|
"bash",
|
||||||
|
"-c",
|
||||||
|
"exec 3<>/dev/tcp/127.0.0.1/80 && printf 'GET /hosting/discovery HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && cat <&3 | head -1 | grep -q '200 OK'"
|
||||||
|
]
|
||||||
|
interval: 30s
|
||||||
|
timeout: 10s
|
||||||
|
retries: 5
|
||||||
|
start_period: 120s
|
||||||
Reference in New Issue
Block a user