Compare commits

...

24 Commits

Author SHA1 Message Date
Michael Barz
8efca76bdb Merge pull request #356 from opencloud-eu/renovate/stable-7.2-opencloudeu-opencloud-7.x
chore(deps): update opencloudeu/opencloud docker tag to v7.2.3 (stable-7.2)
2026-08-06 19:12:29 +02:00
renovate[bot]
b5baab2b00 chore(deps): update opencloudeu/opencloud docker tag to v7.2.3 2026-08-06 16:59:01 +00:00
Michael Barz
21467e4f1a Merge pull request #345 from opencloud-eu/renovate/stable-7.2-collabora-code-26.x
chore(deps): update collabora/code docker tag to v26.04.2.4.1 (stable-7.2)
2026-07-29 15:52:23 +02:00
micbar
a930989ec7 feat: add proof key side car 2026-07-29 13:54:38 +02:00
kellergoech
6ff4fb4417 Adjust collavora to new distroless container 2026-07-29 13:54:18 +02:00
renovate[bot]
68a2f53ef2 chore(deps): update collabora/code docker tag to v26.04.2.4.1 2026-07-24 03:04:08 +00:00
Michael Barz
fffb04bac2 Merge pull request #342 from opencloud-eu/renovate/stable-7.2-collabora-code-26.x
chore(deps): update collabora/code docker tag to v26.04.2.2.1 (stable-7.2)
2026-07-19 18:29:22 +02:00
renovate[bot]
c72832dc8a chore(deps): update collabora/code docker tag to v26.04.2.2.1 2026-07-18 21:09:05 +00:00
Viktor Scharf
32d9e5fb50 Merge pull request #337 from opencloud-eu/renovate/stable-7.2-opencloudeu-opencloud-7.x
chore(deps): update opencloudeu/opencloud docker tag to v7.2.2 (stable-7.2)
2026-07-14 13:26:57 +02:00
renovate[bot]
e6256ebadb chore(deps): update opencloudeu/opencloud docker tag to v7.2.2 2026-07-14 11:25:15 +00:00
Viktor Scharf
8b271811a6 Merge pull request #336 from opencloud-eu/add-revovate-dependancy-to-stable
Add Renovate comment for opencloud dependency
2026-07-14 13:24:31 +02:00
Viktor Scharf
40882d6f8f Add Renovate comment for opencloud dependency 2026-07-14 11:27:13 +02:00
Viktor Scharf
2ec04b4466 Merge pull request #334 from opencloud-eu/fix/renovate-stable-7.2-use-production-image
fix: use docker image to production release on stable-7.2
2026-07-10 14:48:19 +02:00
Viktor Scharf
2c72369d24 Update docker-compose.yml 2026-07-10 10:03:01 +02:00
v.scharf
6d3a1f8c49 remove renovate from stable-7.2 2026-07-10 09:49:34 +02:00
v.scharf
cc1471e467 fix: use docker image to production release on stable-7.2 2026-07-10 09:43:07 +02:00
v.scharf
300fc4779b fix: use docker image to production release on stable-7.2 2026-07-10 09:39:48 +02:00
Michael Barz
12efcc9e91 Merge pull request #330 from opencloud-eu/renovate/stable-7.2-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.4 (stable-7.2)
2026-07-01 13:11:04 +02:00
renovate[bot]
cd22ba6f6e chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.4 2026-07-01 11:09:33 +00:00
Michael Barz
23f4b6eefe Merge pull request #329 from opencloud-eu/renovate/stable-7.2-collabora-code-26.x
chore(deps): update collabora/code docker tag to v26.04.2.1.1 (stable-7.2)
2026-07-01 13:08:42 +02:00
renovate[bot]
225740f7d4 chore(deps): update collabora/code docker tag to v26.04.2.1.1 2026-07-01 10:59:22 +00:00
Anja Barz
f74c434267 Merge pull request #316 from opencloud-eu/backport/313
Backport/313
2026-06-24 10:26:48 +02:00
Anja Barz
e2c680ea6b change the scopes for the clients 2026-06-24 10:23:27 +02:00
Anja Barz
b0fdcec0a3 add the default ids and scopes for the clients 2026-06-24 10:23:27 +02:00
7 changed files with 64 additions and 74 deletions

View File

@@ -87,7 +87,7 @@ TRAEFIK_LOG_LEVEL=
# For production releases: "opencloudeu/opencloud" # For production releases: "opencloudeu/opencloud"
# For rolling releases: "opencloudeu/opencloud-rolling" # For rolling releases: "opencloudeu/opencloud-rolling"
# Defaults to production if not set otherwise # Defaults to production if not set otherwise
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling OC_DOCKER_IMAGE=opencloudeu/opencloud
# The openCloud container version. # The openCloud container version.
# Defaults to the latest version-tag. Use git pull to update. # Defaults to the latest version-tag. Use git pull to update.
OC_DOCKER_TAG= OC_DOCKER_TAG=

View File

@@ -1,8 +1,8 @@
--- ---
services: services:
opencloud: opencloud:
# renovate: depName=opencloudeu/opencloud-rolling # renovate: depName=opencloudeu/opencloud
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.2.0} image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud}:${OC_DOCKER_TAG:-7.2.3}
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog # changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html # release notes: https://docs.opencloud.eu/opencloud_release_notes.html
user: ${OC_CONTAINER_UID_GID:-1000:1000} user: ${OC_CONTAINER_UID_GID:-1000:1000}

View File

@@ -17,14 +17,14 @@ services:
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID} OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES} OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles} PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID} WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID:-web}
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES} WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES:-openid profile email}
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID} WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID:-OpenCloudAndroid}
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES} WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID} WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID:-OpenCloudIOS}
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES} WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID} WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID:-OpenCloudDesktop}
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES} WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc} PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc}
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud} OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
# This specifies to start all services except idm and idp. These are replaced by external services. # This specifies to start all services except idm and idp. These are replaced by external services.

View File

@@ -78,7 +78,7 @@ services:
restart: always restart: always
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.6.3 image: quay.io/keycloak/keycloak:26.6.4
networks: networks:
opencloud-net: opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ] command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -1,43 +0,0 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"platformAutomerge": true,
"enabledManagers": ["docker-compose", "custom.regex"],
"baseBranchPatterns": ["main", "stable-4.0"],
"packageRules": [
{
"matchManagers": ["docker-compose", "custom.regex"],
"labels": ["Type:Dependencies", "Bot:Renovate"]
},
{
"matchManagers": ["docker-compose"],
"matchUpdateTypes": ["patch"],
"automerge": true
},
{
"matchBaseBranches": ["stable-4.0"],
"matchUpdateTypes": ["major", "minor"],
"enabled": false
},
{
"matchPackageNames": ["postgres"],
"matchManagers": ["docker-compose"],
"allowedVersions": "/^17\\.\\d+-alpine$/"
}
],
"docker-compose": {
"managerFilePatterns": ["/.+\\.ya?ml$/"]
},
"customManagers": [
{
"customType": "regex",
"managerFilePatterns": [
"/^docker-compose\\.yml$/",
"/^weboffice\\/collabora\\.yml$/"
],
"matchStrings": [
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"
],
"datasourceTemplate": "docker"
}
]
}

View File

@@ -15,7 +15,7 @@ services:
restart: always restart: always
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.6.3 image: quay.io/keycloak/keycloak:26.6.4
networks: networks:
opencloud-net: opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ] command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -23,22 +23,50 @@ services:
COLLABORATION_APP_INSECURE: "${INSECURE:-true}" COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}" COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
# One-shot service that generates the WOPI proof key on first start and
# keeps it in a named volume, like the proofKeyGeneration feature of the
# collabora-online helm chart.
# To rotate the key, remove the volume and start again:
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
collabora-proof-key:
image: alpine/openssl:3.5.7
entrypoint: ["/bin/sh"]
command:
- -ec
- |
if [ ! -s /proof/proof_key ]; then
openssl genrsa -traditional -out /proof/proof_key.tmp 4096
chown 1001:1001 /proof/proof_key.tmp
chmod 400 /proof/proof_key.tmp
mv /proof/proof_key.tmp /proof/proof_key
echo "WOPI proof key generated"
else
echo "WOPI proof key already exists"
fi
volumes:
- collabora-proof-key:/proof
logging:
driver: ${LOG_DRIVER:-local}
restart: "no"
collabora: collabora:
image: collabora/code:26.04.1.4.1 image: collabora/code:26.04.2.4.1
# release notes: https://www.collaboraonline.com/release-notes/ # release notes: https://www.collaboraonline.com/release-notes/
networks: networks:
opencloud-net: opencloud-net:
depends_on:
collabora-proof-key:
condition: service_completed_successfully
environment: environment:
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain # WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
DONT_GEN_SSL_CERT: "YES" extra_params: >
extra_params: | --o:ssl.enable=${COLLABORA_SSL_ENABLE:-true}
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \ --o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true}
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \ --o:ssl.termination=true
--o:ssl.termination=true \ --o:welcome.enable=false
--o:welcome.enable=false \ --o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \ --o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false} --o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
username: ${COLLABORA_ADMIN_USER:-admin} username: ${COLLABORA_ADMIN_USER:-admin}
password: ${COLLABORA_ADMIN_PASSWORD:-admin} password: ${COLLABORA_ADMIN_PASSWORD:-admin}
@@ -52,19 +80,24 @@ services:
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package). # (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro - /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro - /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
# WOPI proof key generated by the collabora-proof-key service.
- type: volume
source: collabora-proof-key
target: /etc/coolwsd/proof_key
read_only: true
volume:
subpath: proof_key
logging: logging:
driver: ${LOG_DRIVER:-local} driver: ${LOG_DRIVER:-local}
restart: always restart: always
entrypoint: [ '/bin/bash', '-c' ]
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
healthcheck: healthcheck:
test: # --use-env-vars makes the probe read extra_params, so it probes with
[ # the same http/https scheme the server actually runs with; without it
"CMD", # the probe falls back to coolwsd.xml where ssl.enable defaults to true
"bash", test: ["CMD", "/usr/bin/coolwsd", "--probe", "--use-env-vars"]
"-c",
"exec 3<>/dev/tcp/127.0.0.1/9980 && printf 'GET /hosting/discovery HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && cat <&3 | head -1 | grep -q '200 OK'"
]
interval: 15s interval: 15s
timeout: 10s timeout: 10s
retries: 5 retries: 5
volumes:
collabora-proof-key: