Compare commits

...

66 Commits

Author SHA1 Message Date
Michael Barz
db3ddbdf32 Merge pull request #355 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.1 (main)
2026-08-05 19:48:18 +02:00
renovate[bot]
1fbb2380cc chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.1 2026-08-05 17:43:39 +00:00
Michael Barz
34129ff018 Merge pull request #352 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.10 (main)
2026-08-05 19:42:49 +02:00
renovate[bot]
0f89106b89 chore(deps): update traefik docker tag to v3.7.10 2026-08-05 07:24:26 +00:00
Viktor Scharf
2b51cb53c0 Merge pull request #353 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-7.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.4.0 (main)
2026-08-05 09:23:29 +02:00
renovate[bot]
eab3b7e584 chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.4.0 2026-08-03 20:51:17 +00:00
Jannik Stehle
c4023ff553 Merge pull request #351 from opencloud-eu/feat/add-app-yaml-config-file
feat: add apps.yaml config
2026-07-31 16:16:25 +02:00
Jannik Stehle
aac9a1e2f5 feat: add apps.yaml config
Add a config for the maps map. Its purpose is not to change anything
but to guide and show users how to configure web apps. Now that the
apps.yaml file is mounted, it can easily be extended by more config
options
2026-07-31 11:20:17 +02:00
Tobias Baader
e6a0e8e2e6 Merge pull request #350 from opencloud-eu/feat(keycloak)-use-Inter-variable-font-in-login-theme
feat(keycloak): use Inter variable font in login theme
2026-07-31 09:33:05 +02:00
Alexander Ackermann
1ecdd0e32a use patternfly best practice 2026-07-30 19:16:30 +02:00
Alexander Ackermann
bcf59c86fd use patternfly best practice 2026-07-30 19:09:27 +02:00
Tobias Baader
7cd7c57bd9 feat(keycloak): use Inter variable font in login theme
Replace the bundled OpenCloud font with Inter in the Keycloak login
theme. Use the variable woff2 (weights 100-900) so a single self-hosted
file covers all weights, and drop the two static OpenCloud files.
follow up for
https://github.com/opencloud-eu/web/pull/2988
2026-07-30 18:27:52 +02:00
Jörn Friedrich Dreyer
213dde31c8 Merge pull request #347 from kellergoech/patch-1
Adjust collabora to new distroless container
2026-07-29 11:30:26 +02:00
Thomas Schweiger
dabd81377c chore: bump version to 6.04.2.4.1 2026-07-29 10:48:57 +02:00
Michael Barz
8d2d89f283 Merge pull request #348 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.9 (main)
2026-07-25 10:14:26 +02:00
renovate[bot]
189f17f6e0 chore(deps): update traefik docker tag to v3.7.9 2026-07-24 21:51:13 +00:00
micbar
27fd367113 feat: add proof key side car 2026-07-24 12:42:49 +02:00
kellergoech
fffcec12a8 Adjust collavora to new distroless container 2026-07-24 07:06:50 +02:00
Michael Barz
42b4343d6e Merge pull request #341 from opencloud-eu/renovate/main-collabora-code-26.x
chore(deps): update collabora/code docker tag to v26.04.2.2.1 (main)
2026-07-19 18:29:41 +02:00
renovate[bot]
5666410706 chore(deps): update collabora/code docker tag to v26.04.2.2.1 2026-07-18 21:09:00 +00:00
Michael Barz
62131f972b Merge pull request #339 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.8 (main)
2026-07-16 20:25:53 +02:00
renovate[bot]
274195c6ad chore(deps): update traefik docker tag to v3.7.8 2026-07-15 21:33:24 +00:00
Michael Barz
49ba000f6e Merge pull request #332 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.0 (main)
2026-07-15 14:41:16 +02:00
Michael Barz
d759e5a332 Merge pull request #331 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.7 (main)
2026-07-15 14:36:55 +02:00
renovate[bot]
d7fcd3da64 chore(deps): update traefik docker tag to v3.7.7 2026-07-15 04:55:36 +00:00
Michael Barz
325dce2f53 Merge pull request #338 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-7.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.3.0 (main)
2026-07-15 06:55:06 +02:00
renovate[bot]
0221cfd91b chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.3.0 2026-07-14 21:44:03 +00:00
renovate[bot]
c096f66dfd chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.0 2026-07-09 09:53:11 +00:00
Michael Barz
e6d987501e Merge pull request #328 from opencloud-eu/renovate/main-collabora-code-26.x
chore(deps): update collabora/code docker tag to v26.04.2.1.1 (main)
2026-07-01 13:09:05 +02:00
renovate[bot]
2f81c5f62c chore(deps): update collabora/code docker tag to v26.04.2.1.1 2026-07-01 11:08:45 +00:00
Michael Barz
670d978c1c Merge pull request #322 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.4 (main)
2026-07-01 13:08:22 +02:00
renovate[bot]
d952c2849b chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.4 2026-07-01 10:59:19 +00:00
Michael Barz
13b9489c52 chore: enable renovate for stable-7.2 2026-07-01 12:58:43 +02:00
Michael Barz
e8b8511477 Merge pull request #327 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.5 (main)
2026-07-01 09:08:57 +02:00
renovate[bot]
70e7679bc3 chore(deps): update traefik docker tag to v3.7.6 2026-07-01 00:54:25 +00:00
Michael Barz
0d62d41894 Merge pull request #325 from lbausch/rename-euroffice
Rename euroffice to euro-office
2026-06-28 08:24:33 +02:00
Lorenz Bausch
16bd598d4d Rename euroffice to euro-office 2026-06-27 22:20:15 +02:00
Michael Barz
bc0a74dd5a Merge pull request #323 from opencloud-eu/keycloak-theme-v2-followup
fix (keycloak): adjust opencloud theme background not using full heig…
2026-06-27 09:08:12 +02:00
Alexander Ackermann
b8a0a98a51 fix (keycloak): adjust opencloud theme background not using full height when scrollable 2026-06-27 00:28:27 +02:00
Jörn Friedrich Dreyer
b914288032 Merge pull request #321 from opencloud-eu/keycloak-theme-v2
chore (keycloak): migrate login theme to keycloak.v2
2026-06-26 15:03:21 +02:00
Alexander Ackermann
09e0d8f32a chore (keycloak): migrate login theme to keycloak.v2 2026-06-25 22:13:32 +02:00
Michael Barz
aab87f13a7 Merge pull request #294 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-7.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v7 (main)
2026-06-25 18:34:36 +02:00
Michael Barz
aebf5882f4 Merge pull request #319 from ralfbergs/patch-2
Update opencloud.yml: wrong indentation.
2026-06-25 18:25:59 +02:00
Ralf G. R. Bergs
f292460d32 Update opencloud.yml: wrong indentation. 2026-06-25 15:01:07 +02:00
Ralf Haferkamp
f0277501f0 Merge pull request #318 from opencloud-eu/issue/263
fix: README contains wrong variable name
2026-06-25 13:27:21 +02:00
Ralf Haferkamp
76e41a4848 fix: README contains wrong variable name
It's TRAEFIK_ACME_MAIL not TRAEFIK_LETSENCRYPT_EMAIL

Closes: #263
2026-06-25 12:08:17 +02:00
renovate[bot]
46ad111b94 chore(deps): update opencloudeu/opencloud-rolling docker tag to v7 2026-06-25 08:40:48 +00:00
Michael Barz
9cac2bd525 Merge pull request #275 from dschmidt/feat/opensearch-module
feat: add opensearch search backend module
2026-06-25 09:45:21 +02:00
Michael Barz
d965660599 Merge pull request #300 from jgoclawski/add_tika_healthcheck
Ensure OpenCloud doesn't start until Tika is ready.
2026-06-25 09:31:55 +02:00
Michael Barz
f3f0ece32a Merge pull request #292 from chippey5/main
Add IDP_DOMAIN to the frame-src section in csp.yaml
2026-06-25 09:29:36 +02:00
Anja Barz
b138f37c98 Merge pull request #313 from opencloud-eu/add-default-id-and-scopes
add the default ids and scopes for the clients
2026-06-24 10:14:43 +02:00
Viktor Scharf
3314522ef9 Merge pull request #314 from opencloud-eu/refactor-wopi
feat: move collaboration into the opencloud process
2026-06-22 15:25:30 +02:00
Michael Barz
9cee17c253 fix: remove collaboration from external proxy 2026-06-22 15:08:13 +02:00
Anja Barz
e92718ffa0 change the scopes for the clients 2026-06-22 10:09:32 +02:00
Michael Barz
5268ad506b feat: move collaboration into the opencloud process 2026-06-19 20:26:16 +02:00
Anja Barz
8c43842e7b add the default ids and scopes for the clients 2026-06-19 12:54:39 +02:00
Michael Barz
913920dd33 Merge pull request #312 from opencloud-eu/fix-collabora-healthcheck
fix: collabora healthcheck without curl
2026-06-19 12:19:36 +02:00
Michael Barz
792bcd336e Merge pull request #196 from maybenotconnor/feat/configurable-proxy-role-assignment-driver
make PROXY_ROLE_ASSIGNMENT_DRIVER configurable
2026-06-19 10:43:18 +02:00
Connor
73b02b77d8 feat: make role assignment settings configurable
Allow PROXY_ROLE_ASSIGNMENT_DRIVER and GRAPH_ASSIGN_DEFAULT_USER_ROLE
   to be set via environment variables in .env file.

   - PROXY_ROLE_ASSIGNMENT_DRIVER defaults to oidc
   - GRAPH_ASSIGN_DEFAULT_USER_ROLE defaults to false

   When using PROXY_ROLE_ASSIGNMENT_DRIVER=default, set
   GRAPH_ASSIGN_DEFAULT_USER_ROLE=true to assign the 'user' role
   to new users.
2026-06-19 10:42:34 +02:00
Michael Barz
4d3e787e2d fix: collabora healthcheck without curl 2026-06-19 09:36:25 +02:00
Benedikt Kulmann
cda4138e7d Merge pull request #310 from opencloud-eu/bump-code-to-26.04.1.4.1
chore: bump collabora to 26.04.1.4.1
2026-06-19 08:39:37 +02:00
Alexander Ackermann
d853a59078 chore: bump collabora to 26.04.1.4.1 2026-06-18 13:32:31 +02:00
Jakub Gocławski
cc49b063c0 Ensure OpenCloud doesn't start until Tika is ready. 2026-06-05 17:45:47 +02:00
Simon
7cf59a62a9 Add IDP_DOMAIN to the frame-src section in csp.yaml
When using an external IDP, not having the IDP FQDN in frame-src causes silent refreshes to get blocked.
2026-05-20 14:32:37 +02:00
Dominik Schmidt
32b328218f Update search/opensearch.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-04-22 00:53:50 +02:00
Dominik Schmidt
c814f08cd5 feat: add opensearch search backend module
Adds search/opensearch.yml — a single-node OpenSearch deployment wired up
as the opencloud search engine backend via SEARCH_ENGINE_TYPE=open-search.

The security plugin is disabled because the service is only reachable on
the internal opencloud-net bridge (no published port). Do not publish or
proxy this without enabling the security plugin first.

The disk-based shard allocation watermarks are disabled so the index
does not flip to read-only on modest disks, which otherwise silently
turns bulk upserts into no-ops.
2026-04-22 00:43:41 +02:00
27 changed files with 241 additions and 181 deletions

View File

@@ -25,9 +25,9 @@ INSECURE=true
# External IDP
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
# Euro Office with traefik and letsencrypt
#COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:traefik/opencloud.yml:traefik/euroffice.yml
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
# Euro Office with external proxy (Nginx, Caddy, etc.)
#COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:external-proxy/opencloud.yml:external-proxy/euroffice.yml
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
## Traefik Settings ##
# Note: Traefik is always enabled and can't be disabled.
@@ -219,9 +219,9 @@ TIKA_IMAGE=
# Domain of Collabora, where you can find the frontend.
# Defaults to "collabora.opencloud.test"
COLLABORA_DOMAIN=
# Domain of the wopiserver which handles Collabora.
# Defaults to "wopiserver.opencloud.test"
WOPISERVER_DOMAIN=
# NOTE: The WOPI server runs inside the main OpenCloud process and is served by
# the OpenCloud proxy on the main OpenCloud domain (OC_DOMAIN) under the /wopi and
# /collaboration paths. It no longer needs its own domain.
# Admin user for Collabora.
# Defaults to "admin".
# Collabora Admin Panel URL:
@@ -323,6 +323,14 @@ LDAP_BIND_PASSWORD=
## Autoprovisioning Mode ##
# Use together with idm/external-idp.yml
# Role assignment driver for the proxy. Defaults to "oidc".
# Possible values: "oidc", "default"
# When set to "oidc", roles are assigned based on OIDC claims.
# When set to "default", all users get the 'user' role assigned.
PROXY_ROLE_ASSIGNMENT_DRIVER=
# Assign the default 'user' role to new users. Defaults to "false".
# Set to "true" when using PROXY_ROLE_ASSIGNMENT_DRIVER=default
GRAPH_ASSIGN_DEFAULT_USER_ROLE=
# If you want to use a keycloak for local testing, you can use testing/external-keycloak.yml and testing/ldap-manager.yml
# Domain of your Identity Provider.
IDP_DOMAIN=

View File

@@ -109,11 +109,11 @@ This setup includes:
### With Collabora Online
> [!NOTE]
> Collabora Online and [Euro Office](#with-euro-office) are mutually exclusive web office backends — both use the same `collaboration` (WOPI) service. Enable only one of them at a time.
> Collabora Online and [Euro Office](#with-euro-office) are mutually exclusive web office backends — both use the same `collaboration` (WOPI) service, which runs inside the main OpenCloud process. Enable only one of them at a time.
Include Collabora for document editing using either method:
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain, Collabora subdomain, and WOPI server subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `collabora.example.com`, `wopiserver.example.com`) or use a wildcard DNS entry (`*.example.com`).
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain and the Collabora subdomain. The WOPI server is served by OpenCloud on the main domain, so it does not need its own subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `collabora.example.com`) or use a wildcard DNS entry (`*.example.com`).
Using `-f` flags:
```bash
@@ -128,37 +128,44 @@ COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:tr
> **For local development only**: Add to `/etc/hosts`:
> ```
> 127.0.0.1 collabora.opencloud.test
> 127.0.0.1 wopiserver.opencloud.test
> ```
> [!IMPORTANT]
> **Upgrading from a previous setup**: The `collaboration` (WOPI) service no longer runs as a separate container or on its own `wopiserver.*` domain — it now runs inside the main OpenCloud process and is served by the OpenCloud proxy on the main domain under the `/wopi` and `/collaboration` paths. When upgrading:
> - Pull the latest compose files and recreate the stack (`docker compose up -d`). The old `collaboration` container is removed automatically.
> - You can retire the `wopiserver.*` DNS entry (and its `/etc/hosts` line), its reverse-proxy/Traefik route, and the `WOPISERVER_DOMAIN` variable in `.env` — all are now unused.
> - If you run behind an external proxy, make sure it forwards `/wopi` and `/collaboration` on the OpenCloud domain to OpenCloud (port 9200). Forwarding the whole OpenCloud domain, as already configured, covers this.
### With Euro Office
> [!NOTE]
> Euro Office and [Collabora Online](#with-collabora-online) are mutually exclusive web office backends — both use the same `collaboration` (WOPI) service. Enable only one of them at a time.
> Euro Office and [Collabora Online](#with-collabora-online) are mutually exclusive web office backends — both use the same `collaboration` (WOPI) service, which runs inside the main OpenCloud process. Enable only one of them at a time.
Include Euro Office for document editing using either method:
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain, Euro Office subdomain, and WOPI server subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `euro-office.example.com`, `wopiserver.example.com`) or use a wildcard DNS entry (`*.example.com`).
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain and the Euro Office subdomain. The WOPI server is served by OpenCloud on the main domain, so it does not need its own subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `euro-office.example.com`) or use a wildcard DNS entry (`*.example.com`).
Using `-f` flags:
```bash
docker compose -f docker-compose.yml -f weboffice/euroffice.yml -f traefik/opencloud.yml -f traefik/euroffice.yml up -d
docker compose -f docker-compose.yml -f weboffice/euro-office.yml -f traefik/opencloud.yml -f traefik/euro-office.yml up -d
```
Or by setting in `.env`:
```
COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:traefik/opencloud.yml:traefik/euroffice.yml
COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
```
> **For local development only**: Add to `/etc/hosts`:
> ```
> 127.0.0.1 euro-office.opencloud.test
> 127.0.0.1 wopiserver.opencloud.test
> ```
> [!IMPORTANT]
> Set a strong `EURO_OFFICE_JWT_SECRET` in your `.env` file for production. The default value (`changeme`) is intended for local development only.
> [!NOTE]
> Upgrading from a previous setup? See [Upgrading from a previous setup](#with-collabora-online) under Collabora Online — the WOPI server changes (no more separate container or `wopiserver.*` domain) apply to Euro Office as well.
### With Full Text Search
Enable full text search capabilities with Apache Tika using either method:
@@ -258,26 +265,28 @@ COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:external-proxy/opencloud
This exposes the necessary ports:
- OpenCloud: 9200
- Collabora: 9980
- WOPI server: 9300
The WOPI server runs inside the OpenCloud process and is served on the OpenCloud port (9200) under the `/wopi` and `/collaboration` paths, so no separate port needs to be exposed for it.
To use Euro Office instead of Collabora behind an external proxy, swap the web office compose files:
```bash
docker compose -f docker-compose.yml -f weboffice/euroffice.yml -f external-proxy/opencloud.yml -f external-proxy/euroffice.yml up -d
docker compose -f docker-compose.yml -f weboffice/euro-office.yml -f external-proxy/opencloud.yml -f external-proxy/euro-office.yml up -d
```
Or by setting in `.env`:
```
COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:external-proxy/opencloud.yml:external-proxy/euroffice.yml
COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
```
This exposes the necessary ports:
- OpenCloud: 9200
- Euro Office: 9900
- WOPI server: 9300
As with Collabora, the WOPI server is served on the OpenCloud port (9200) under the `/wopi` and `/collaboration` paths and needs no separate port.
> [!WARNING]
> `external-proxy/euroffice.yml` binds the exposed ports to `127.0.0.1` only. If your external proxy runs on a different host, use `external-proxy/euroffice-exposed.yml`, which binds to all interfaces (`0.0.0.0`). Only expose these ports when you know what you are doing.
> `external-proxy/euro-office.yml` binds the exposed ports to `127.0.0.1` only. If your external proxy runs on a different host, use `external-proxy/euro-office-exposed.yml`, which binds to all interfaces (`0.0.0.0`). Only expose these ports when you know what you are doing.
**Please note:**
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
@@ -310,12 +319,12 @@ OpenCloud Compose supports adding SSL certificates for public domains and develo
### Use Let's Encrypt with ACME Challenge
1. **Enable Let's Encrypt**:
- Set `TRAEFIK_LETSENCRYPT_EMAIL` to your email address for the ACME challenge
- Set `TRAEFIK_ACME_MAIL` to your email address for the ACME challenge
- Set `TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"` to use Let's Encrypt (default value)
```bash
# In your .env file
TRAEFIK_LETSENCRYPT_EMAIL=devops@your-domain.tld
TRAEFIK_ACME_MAIL=devops@your-domain.tld
TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
```
@@ -392,7 +401,6 @@ Key variables:
| `OC_DATA_DIR` | Data directory path | (Docker volume) |
| `INSECURE` | Skip certificate validation | true |
| `COLLABORA_DOMAIN` | Collabora domain | collabora.opencloud.test |
| `WOPISERVER_DOMAIN` | WOPI server domain | wopiserver.opencloud.test |
| `EURO_OFFICE_DOMAIN` | Euro Office document server domain | euro-office.opencloud.test |
| `EURO_OFFICE_JWT_SECRET` | JWT secret for Euro Office (change for production!) | changeme |
| `EURO_OFFICE_DOCKER_IMAGE` | Euro Office Docker image | ghcr.io/euro-office/documentserver |
@@ -404,7 +412,7 @@ Key variables:
| `LDAP_BIND_PASSWORD` | LDAP password for the bind user | admin |
| `KC_DB_USERNAME` | Database user for keycloak | keycloak |
| `KC_DB_PASSWORD` | Database password for keycloak | keycloak |
| `TRAEFIK_LETSENCRYPT_EMAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
| `TRAEFIK_ACME_MAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
| `TRAEFIK_SERVICES_TLS_CONFIG` | Tell traefik and the services which TLS config to use | tls.certresolver=letsencrypt |
| `TRAEFIK_CERTS_DIR` | Directory for custom certificates. | ./certs |

View File

@@ -1,38 +1,51 @@
:root {
--pf-global--primary-color--100: #e2baff;
--pf-global--primary-color--200: #e2baff;
--pf-global--primary-color--dark-100: #e2baff;
--pf-global--Color--light-100: #20434f;
--pf-v5-global--primary-color--100: #e2baff;
--pf-v5-global--primary-color--200: #e2baff;
--pf-v5-global--primary-color--dark-100: #e2baff;
--pf-v5-c-button--m-secondary--Color: #e2baff;
--pf-v5-global--Color--light-100: #20434f;
--pf-v5-global--FontFamily--text: "Inter", "RedHatText", helvetica, arial, sans-serif;
--pf-v5-global--FontFamily--heading: "Inter", "RedHatDisplay", helvetica, arial, sans-serif;
}
@font-face {
font-family: OpenCloud;
src: url('../fonts/OpenCloud500-Regular.woff2') format('woff2');
font-weight: normal;
font-style: normal;
}
@font-face {
font-family: OpenCloud;
src: url('../fonts/OpenCloud750-Bold.woff2') format('woff2');
font-weight: bold;
font-family: Inter;
src: url('../fonts/Inter-Variable.woff2') format('woff2');
font-weight: 100 900;
font-style: normal;
}
body {
font-family: "OpenCloud", "Open Sans", Helvetica, Arial, sans-serif;
background: url(../img/background.png) no-repeat center !important;
background: url(../img/background.png) no-repeat center fixed !important;
background-size: cover !important;
}
.kc-logo-text {
background-image: url(../img/logo.svg) !important;
display: block;
width: 300px;
height: 63px;
background: url('../img/logo.svg') no-repeat center;
background-size: contain;
width: 400px;
margin: 0 !important;
}
#kc-header-wrapper{
.kc-logo-text span {
display: none;
}
#kc-header-wrapper {
display: flex;
justify-content: center;
}
.pf-v5-c-login__main-header {
border-top: 4px solid var(--pf-v5-global--primary-color--100);
}
@media (min-width: 1200px) {
.pf-v5-c-login__container {
grid-template-columns: 34rem;
grid-template-areas:
"header"
"main";
}
}

View File

@@ -1,4 +1,4 @@
parent=keycloak
parent=keycloak.v2
import=common/keycloak
styles=css/login.css css/theme.css

View File

@@ -0,0 +1,3 @@
maps:
config:
folderViewEnabled: false

View File

@@ -25,6 +25,7 @@ directives:
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
# This is needed for the external-sites web extension when embedding sites
- 'https://docs.opencloud.eu'
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
img-src:
- '''self'''
- 'data:'

View File

@@ -2,7 +2,7 @@
services:
opencloud:
# renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.2.0}
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.4.0}
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
user: ${OC_CONTAINER_UID_GID:-1000:1000}
@@ -58,6 +58,7 @@ services:
OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE}
volumes:
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
- ./config/opencloud/apps.yaml:/etc/opencloud/apps.yaml
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
# configure the .env file to use own paths instead of docker internal volumes
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud

View File

@@ -1,10 +1,6 @@
---
# only expose the ports when you know what you are doing!
services:
collaboration:
ports:
# expose the wopi server on all interfaces
- "0.0.0.0:9300:9300"
collabora:
ports:
# expose the collabora server on all interfaces

View File

@@ -1,9 +1,5 @@
---
services:
collaboration:
ports:
# expose the wopi server on localhost
- "127.0.0.1:9300:9300"
collabora:
ports:
# expose the collabora server on localhost

View File

@@ -1,10 +1,6 @@
---
# only expose the ports when you know what you are doing!
services:
collaboration:
ports:
# expose the wopi server on all interfaces
- "0.0.0.0:9300:9300"
euro-office:
ports:
# expose the euro-office document server on all interfaces

View File

@@ -1,9 +1,5 @@
---
services:
collaboration:
ports:
# expose the wopi server on localhost
- "127.0.0.1:9300:9300"
euro-office:
ports:
# expose the euro-office document server on localhost

View File

@@ -17,15 +17,15 @@ services:
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID}
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES}
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID}
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES}
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID}
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES}
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID}
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES}
PROXY_ROLE_ASSIGNMENT_DRIVER: "oidc"
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID:-web}
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES:-openid profile email}
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID:-OpenCloudAndroid}
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID:-OpenCloudIOS}
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID:-OpenCloudDesktop}
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc}
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
# This specifies to start all services except idm and idp. These are replaced by external services.
OC_EXCLUDE_RUN_SERVICES: idm,idp
@@ -47,7 +47,7 @@ services:
OC_LDAP_DISABLE_USER_MECHANISM: "attribute"
OC_ADMIN_USER_ID: ""
SETTINGS_SETUP_DEFAULT_ASSIGNMENTS: "false"
GRAPH_ASSIGN_DEFAULT_USER_ROLE: "false"
GRAPH_ASSIGN_DEFAULT_USER_ROLE: ${GRAPH_ASSIGN_DEFAULT_USER_ROLE:-false}
GRAPH_USERNAME_MATCH: "none"
# We need to set the IDP_DOMAIN to allow the CSP rules to be set correctly
IDP_DOMAIN: ${IDP_DOMAIN:-keycloak.opencloud.test}

View File

@@ -78,7 +78,7 @@ services:
restart: always
keycloak:
image: quay.io/keycloak/keycloak:26.6.3
image: quay.io/keycloak/keycloak:26.7.1
networks:
opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -2,7 +2,7 @@
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"platformAutomerge": true,
"enabledManagers": ["docker-compose", "custom.regex"],
"baseBranchPatterns": ["main", "stable-4.0"],
"baseBranchPatterns": ["main", "stable-4.0", "stable-7.2"],
"packageRules": [
{
"matchManagers": ["docker-compose", "custom.regex"],
@@ -14,7 +14,7 @@
"automerge": true
},
{
"matchBaseBranches": ["stable-4.0"],
"matchBaseBranches": ["stable-4.0", "stable-7.2"],
"matchUpdateTypes": ["major", "minor"],
"enabled": false
},

59
search/opensearch.yml Normal file
View File

@@ -0,0 +1,59 @@
---
services:
opencloud:
environment:
# Point the search service at OpenSearch instead of the embedded bleve index.
SEARCH_ENGINE_TYPE: open-search
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_ADDRESSES: http://opensearch:9200
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_INSECURE: "true"
SEARCH_ENGINE_OPEN_SEARCH_RESOURCE_INDEX_NAME: ${OPENSEARCH_RESOURCE_INDEX:-opencloud-resources}
depends_on:
opensearch:
condition: service_healthy
opensearch:
image: ${OPENSEARCH_DOCKER_IMAGE:-opensearchproject/opensearch}:${OPENSEARCH_DOCKER_TAG:-2.19.5}
environment:
discovery.type: single-node
bootstrap.memory_lock: "true"
OPENSEARCH_JAVA_OPTS: ${OPENSEARCH_JAVA_OPTS:--Xms512m -Xmx512m}
# Security plugin is disabled: OpenSearch is only reachable on the
# internal opencloud-net bridge and no port is published to the host.
# Do NOT enable a published port or expose this via the reverse proxy
# without first enabling and configuring the security plugin.
DISABLE_SECURITY_PLUGIN: "true"
DISABLE_INSTALL_DEMO_CONFIG: "true"
# Disable the disk-based shard allocation watermarks. By default OpenSearch
# marks indices read-only when the host disk is <5% free, which silently
# turns bulk upserts into no-ops. Fine to disable on a single-node dev box.
cluster.routing.allocation.disk.threshold_enabled: "false"
ulimits:
memlock:
soft: -1
hard: -1
nofile:
soft: 65536
hard: 65536
networks:
opencloud-net:
volumes:
- ${OPENSEARCH_DATA_DIR:-opensearch-data}:/usr/share/opensearch/data
healthcheck:
# Single-node clusters can't go green (replicas have nowhere to land), so
# yellow is the healthy state. Still gates opencloud until opensearch accepts
# requests.
test:
[
"CMD-SHELL",
"curl -sf 'http://localhost:9200/_cluster/health?wait_for_status=yellow&timeout=5s' > /dev/null || exit 1"
]
interval: 5s
timeout: 10s
retries: 24
start_period: 60s
logging:
driver: ${LOG_DRIVER:-local}
restart: always
volumes:
opensearch-data:

View File

@@ -11,6 +11,18 @@ services:
restart: always
logging:
driver: ${LOG_DRIVER:-local}
healthcheck:
test:
[
"CMD",
"bash",
"-c",
"exec 3<>/dev/tcp/127.0.0.1/9998 && printf 'GET /tika HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && grep '200 OK' <&3",
]
interval: 5s
timeout: 5s
retries: 10
start_period: 5s
opencloud:
environment:
@@ -18,3 +30,6 @@ services:
SEARCH_EXTRACTOR_TYPE: tika
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
depends_on:
tika:
condition: service_healthy

View File

@@ -15,7 +15,7 @@ services:
restart: always
keycloak:
image: quay.io/keycloak/keycloak:26.6.3
image: quay.io/keycloak/keycloak:26.7.1
networks:
opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -5,16 +5,6 @@ services:
opencloud-net:
aliases:
- ${COLLABORA_DOMAIN:-collabora.opencloud.test}
- ${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}
collaboration:
labels:
- "traefik.enable=true"
- "traefik.http.routers.collaboration.entrypoints=https"
- "traefik.http.routers.collaboration.rule=Host(`${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}`)"
- "traefik.http.routers.collaboration.${TRAEFIK_SERVICES_TLS_CONFIG}"
- "traefik.http.routers.collaboration.service=collaboration"
- "traefik.http.routers.collaboration.middlewares=hsts-header"
- "traefik.http.services.collaboration.loadbalancer.server.port=9300"
collabora:
labels:
- "traefik.enable=true"

View File

@@ -5,16 +5,6 @@ services:
opencloud-net:
aliases:
- ${EURO_OFFICE_DOMAIN:-euro-office.opencloud.test}
- ${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}
collaboration:
labels:
- "traefik.enable=true"
- "traefik.http.routers.collaboration.entrypoints=https"
- "traefik.http.routers.collaboration.rule=Host(`${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}`)"
- "traefik.http.routers.collaboration.${TRAEFIK_SERVICES_TLS_CONFIG}"
- "traefik.http.routers.collaboration.service=collaboration"
- "traefik.http.routers.collaboration.middlewares=hsts-header"
- "traefik.http.services.collaboration.loadbalancer.server.port=9300"
euro-office:
labels:
- "traefik.enable=true"

View File

@@ -16,7 +16,7 @@ services:
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
traefik:
image: traefik:v3.6.14
image: traefik:v3.7.10
# release notes: https://github.com/traefik/traefik/releases
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
networks:

View File

@@ -6,64 +6,67 @@ services:
# this is needed for setting the correct CSP header
COLLABORA_DOMAIN: ${COLLABORA_DOMAIN:-collabora.opencloud.test}
TRAEFIK_PORT_HTTPS: ${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
# expose nats and the reva gateway for the collaboration service
NATS_NATS_HOST: 0.0.0.0
GATEWAY_GRPC_ADDR: 0.0.0.0:9142
# run the collaboration (WOPI) service inside the main opencloud process,
# appended to any user defined services in START_ADDITIONAL_SERVICES
OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES:-}${START_ADDITIONAL_SERVICES:+,}collaboration
# make collabora the secure view app
FRONTEND_APP_HANDLER_SECURE_VIEW_APP_ADDR: eu.opencloud.api.collaboration
GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6"
collaboration:
# renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.2.0}
user: ${OC_CONTAINER_UID_GID:-1000:1000}
networks:
opencloud-net:
depends_on:
opencloud:
condition: service_started
collabora:
condition: service_healthy
entrypoint:
- /bin/sh
command: [ "-c", "opencloud collaboration server" ]
environment:
COLLABORATION_GRPC_ADDR: 0.0.0.0:9301
COLLABORATION_HTTP_ADDR: 0.0.0.0:9300
MICRO_REGISTRY: "nats-js-kv"
MICRO_REGISTRY_ADDRESS: "opencloud:9233"
COLLABORATION_WOPI_SRC: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
# collaboration service configuration; the WOPI endpoint is served by the
# opencloud proxy on the opencloud domain (/wopi and /collaboration routes),
# so no separate wopiserver domain, route or port is needed
COLLABORATION_WOPI_SRC: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
COLLABORATION_APP_NAME: "CollaboraOnline"
COLLABORATION_APP_PRODUCT: "Collabora"
COLLABORATION_APP_ADDR: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
COLLABORATION_APP_ICON: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/favicon.ico
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
COLLABORATION_LOG_LEVEL: ${LOG_LEVEL:-info}
OC_URL: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
OC_EVENTS_ENDPOINT: "opencloud:9233"
# One-shot service that generates the WOPI proof key on first start and
# keeps it in a named volume, like the proofKeyGeneration feature of the
# collabora-online helm chart.
# To rotate the key, remove the volume and start again:
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
collabora-proof-key:
image: alpine/openssl:3.5.7
entrypoint: ["/bin/sh"]
command:
- -ec
- |
if [ ! -s /proof/proof_key ]; then
openssl genrsa -traditional -out /proof/proof_key.tmp 4096
chown 1001:1001 /proof/proof_key.tmp
chmod 400 /proof/proof_key.tmp
mv /proof/proof_key.tmp /proof/proof_key
echo "WOPI proof key generated"
else
echo "WOPI proof key already exists"
fi
volumes:
# configure the .env file to use own paths instead of docker internal volumes
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
- collabora-proof-key:/proof
logging:
driver: ${LOG_DRIVER:-local}
restart: always
restart: "no"
collabora:
image: collabora/code:25.04.10.3.1
image: collabora/code:26.04.2.4.1
# release notes: https://www.collaboraonline.com/release-notes/
networks:
opencloud-net:
depends_on:
collabora-proof-key:
condition: service_completed_successfully
environment:
aliasgroup1: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
DONT_GEN_SSL_CERT: "YES"
extra_params: |
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \
--o:ssl.termination=true \
--o:welcome.enable=false \
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
extra_params: >
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true}
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true}
--o:ssl.termination=true
--o:welcome.enable=false
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
username: ${COLLABORA_ADMIN_USER:-admin}
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
@@ -77,13 +80,24 @@ services:
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
# WOPI proof key generated by the collabora-proof-key service.
- type: volume
source: collabora-proof-key
target: /etc/coolwsd/proof_key
read_only: true
volume:
subpath: proof_key
logging:
driver: ${LOG_DRIVER:-local}
restart: always
entrypoint: [ '/bin/bash', '-c' ]
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
healthcheck:
test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ]
# --use-env-vars makes the probe read extra_params, so it probes with
# the same http/https scheme the server actually runs with; without it
# the probe falls back to coolwsd.xml where ssl.enable defaults to true
test: ["CMD", "/usr/bin/coolwsd", "--probe", "--use-env-vars"]
interval: 15s
timeout: 10s
retries: 5
volumes:
collabora-proof-key:

View File

@@ -6,32 +6,13 @@ services:
# this is needed for setting the correct CSP header
EURO_OFFICE_DOMAIN: ${EURO_OFFICE_DOMAIN:-euro-office.opencloud.test}
TRAEFIK_PORT_HTTPS: ${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
# expose nats and the reva gateway for the collaboration service
NATS_NATS_HOST: 0.0.0.0
GATEWAY_GRPC_ADDR: 0.0.0.0:9142
volumes:
- ./config/euro-office/app-registry.yaml:/etc/opencloud/app-registry.yaml
collaboration:
# renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.2.0}
user: ${OC_CONTAINER_UID_GID:-1000:1000}
networks:
opencloud-net:
depends_on:
opencloud:
condition: service_started
euro-office:
condition: service_healthy
entrypoint:
- /bin/sh
command: [ "-c", "opencloud collaboration server" ]
environment:
COLLABORATION_GRPC_ADDR: 0.0.0.0:9301
COLLABORATION_HTTP_ADDR: 0.0.0.0:9300
MICRO_REGISTRY: "nats-js-kv"
MICRO_REGISTRY_ADDRESS: "opencloud:9233"
COLLABORATION_WOPI_SRC: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
# run the collaboration (WOPI) service inside the main opencloud process,
# appended to any user defined services in START_ADDITIONAL_SERVICES
OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES:-}${START_ADDITIONAL_SERVICES:+,}collaboration
# collaboration service configuration; the WOPI endpoint is served by the
# opencloud proxy on the opencloud domain (/wopi and /collaboration routes),
# so no separate wopiserver domain, route or port is needed
COLLABORATION_WOPI_SRC: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
COLLABORATION_APP_NAME: "Euro-Office"
COLLABORATION_APP_PRODUCT: "OnlyOffice"
COLLABORATION_APP_ADDR: https://${EURO_OFFICE_DOMAIN:-euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
@@ -39,15 +20,8 @@ services:
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
COLLABORATION_APP_PROOF_DISABLE: "true"
COLLABORATION_LOG_LEVEL: ${LOG_LEVEL:-info}
OC_URL: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
OC_EVENTS_ENDPOINT: "opencloud:9233"
volumes:
# configure the .env file to use own paths instead of docker internal volumes
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
logging:
driver: ${LOG_DRIVER:-local}
restart: always
- ./config/euro-office/app-registry.yaml:/etc/opencloud/app-registry.yaml
euro-office:
image: ${EURO_OFFICE_DOCKER_IMAGE:-ghcr.io/euro-office/documentserver}:${EURO_OFFICE_DOCKER_TAG:-latest}