Compare commits

...

9 Commits

Author SHA1 Message Date
Ralf Haferkamp
f0277501f0 Merge pull request #318 from opencloud-eu/issue/263
fix: README contains wrong variable name
2026-06-25 13:27:21 +02:00
Ralf Haferkamp
76e41a4848 fix: README contains wrong variable name
It's TRAEFIK_ACME_MAIL not TRAEFIK_LETSENCRYPT_EMAIL

Closes: #263
2026-06-25 12:08:17 +02:00
Michael Barz
9cac2bd525 Merge pull request #275 from dschmidt/feat/opensearch-module
feat: add opensearch search backend module
2026-06-25 09:45:21 +02:00
Michael Barz
d965660599 Merge pull request #300 from jgoclawski/add_tika_healthcheck
Ensure OpenCloud doesn't start until Tika is ready.
2026-06-25 09:31:55 +02:00
Michael Barz
f3f0ece32a Merge pull request #292 from chippey5/main
Add IDP_DOMAIN to the frame-src section in csp.yaml
2026-06-25 09:29:36 +02:00
Jakub Gocławski
cc49b063c0 Ensure OpenCloud doesn't start until Tika is ready. 2026-06-05 17:45:47 +02:00
Simon
7cf59a62a9 Add IDP_DOMAIN to the frame-src section in csp.yaml
When using an external IDP, not having the IDP FQDN in frame-src causes silent refreshes to get blocked.
2026-05-20 14:32:37 +02:00
Dominik Schmidt
32b328218f Update search/opensearch.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-04-22 00:53:50 +02:00
Dominik Schmidt
c814f08cd5 feat: add opensearch search backend module
Adds search/opensearch.yml — a single-node OpenSearch deployment wired up
as the opencloud search engine backend via SEARCH_ENGINE_TYPE=open-search.

The security plugin is disabled because the service is only reachable on
the internal opencloud-net bridge (no published port). Do not publish or
proxy this without enabling the security plugin first.

The disk-based shard allocation watermarks are disabled so the index
does not flip to read-only on modest disks, which otherwise silently
turns bulk upserts into no-ops.
2026-04-22 00:43:41 +02:00
4 changed files with 78 additions and 3 deletions

View File

@@ -319,12 +319,12 @@ OpenCloud Compose supports adding SSL certificates for public domains and develo
### Use Let's Encrypt with ACME Challenge
1. **Enable Let's Encrypt**:
- Set `TRAEFIK_LETSENCRYPT_EMAIL` to your email address for the ACME challenge
- Set `TRAEFIK_ACME_MAIL` to your email address for the ACME challenge
- Set `TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"` to use Let's Encrypt (default value)
```bash
# In your .env file
TRAEFIK_LETSENCRYPT_EMAIL=devops@your-domain.tld
TRAEFIK_ACME_MAIL=devops@your-domain.tld
TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
```
@@ -412,7 +412,7 @@ Key variables:
| `LDAP_BIND_PASSWORD` | LDAP password for the bind user | admin |
| `KC_DB_USERNAME` | Database user for keycloak | keycloak |
| `KC_DB_PASSWORD` | Database password for keycloak | keycloak |
| `TRAEFIK_LETSENCRYPT_EMAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
| `TRAEFIK_ACME_MAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
| `TRAEFIK_SERVICES_TLS_CONFIG` | Tell traefik and the services which TLS config to use | tls.certresolver=letsencrypt |
| `TRAEFIK_CERTS_DIR` | Directory for custom certificates. | ./certs |

View File

@@ -25,6 +25,7 @@ directives:
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
# This is needed for the external-sites web extension when embedding sites
- 'https://docs.opencloud.eu'
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
img-src:
- '''self'''
- 'data:'

59
search/opensearch.yml Normal file
View File

@@ -0,0 +1,59 @@
---
services:
opencloud:
environment:
# Point the search service at OpenSearch instead of the embedded bleve index.
SEARCH_ENGINE_TYPE: open-search
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_ADDRESSES: http://opensearch:9200
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_INSECURE: "true"
SEARCH_ENGINE_OPEN_SEARCH_RESOURCE_INDEX_NAME: ${OPENSEARCH_RESOURCE_INDEX:-opencloud-resources}
depends_on:
opensearch:
condition: service_healthy
opensearch:
image: ${OPENSEARCH_DOCKER_IMAGE:-opensearchproject/opensearch}:${OPENSEARCH_DOCKER_TAG:-2.19.5}
environment:
discovery.type: single-node
bootstrap.memory_lock: "true"
OPENSEARCH_JAVA_OPTS: ${OPENSEARCH_JAVA_OPTS:--Xms512m -Xmx512m}
# Security plugin is disabled: OpenSearch is only reachable on the
# internal opencloud-net bridge and no port is published to the host.
# Do NOT enable a published port or expose this via the reverse proxy
# without first enabling and configuring the security plugin.
DISABLE_SECURITY_PLUGIN: "true"
DISABLE_INSTALL_DEMO_CONFIG: "true"
# Disable the disk-based shard allocation watermarks. By default OpenSearch
# marks indices read-only when the host disk is <5% free, which silently
# turns bulk upserts into no-ops. Fine to disable on a single-node dev box.
cluster.routing.allocation.disk.threshold_enabled: "false"
ulimits:
memlock:
soft: -1
hard: -1
nofile:
soft: 65536
hard: 65536
networks:
opencloud-net:
volumes:
- ${OPENSEARCH_DATA_DIR:-opensearch-data}:/usr/share/opensearch/data
healthcheck:
# Single-node clusters can't go green (replicas have nowhere to land), so
# yellow is the healthy state. Still gates opencloud until opensearch accepts
# requests.
test:
[
"CMD-SHELL",
"curl -sf 'http://localhost:9200/_cluster/health?wait_for_status=yellow&timeout=5s' > /dev/null || exit 1"
]
interval: 5s
timeout: 10s
retries: 24
start_period: 60s
logging:
driver: ${LOG_DRIVER:-local}
restart: always
volumes:
opensearch-data:

View File

@@ -11,6 +11,18 @@ services:
restart: always
logging:
driver: ${LOG_DRIVER:-local}
healthcheck:
test:
[
"CMD",
"bash",
"-c",
"exec 3<>/dev/tcp/127.0.0.1/9998 && printf 'GET /tika HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && grep '200 OK' <&3",
]
interval: 5s
timeout: 5s
retries: 10
start_period: 5s
opencloud:
environment:
@@ -18,3 +30,6 @@ services:
SEARCH_EXTRACTOR_TYPE: tika
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
depends_on:
tika:
condition: service_healthy