Compare commits

..

13 Commits

Author SHA1 Message Date
micbar
4f21b38d46 Radicale: document client setup, allow anonymous well-known discovery
Clients were left guessing the CalDAV/CardDAV URLs (issue #192): the
README documented how to deploy Radicale but not how to connect to it.

- Add radicale/README.md with client URLs (trailing slash required),
  the App-Token requirement (account passwords are rejected with the
  default PROXY_ENABLE_BASIC_AUTH=false), GNOME Online Accounts and
  Thunderbird walkthroughs, and troubleshooting.
- Mark the two '/.well-known/*' proxy routes as unprotected so DAV
  clients can run RFC 6764 service discovery before authenticating.
  Previously the proxy answered 401 where clients expect the 301
  redirect to /caldav/ or /carddav/. Radicale serves no data on these
  paths (deeper paths return 404, path traversal is normalized onto
  the protected routes), verified against opencloud 7.5.0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 10:32:42 +02:00
renovate[bot]
442017268a chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.3 (#374)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 16:22:03 +02:00
Madipodo
b31c3943fd Fix: EURO_OFFICE_JWT_SECRET was not passed to the container (#360)
* Fix: EURO_OFFICE_JWT_SECRET was not passed to the container

This issue has been open for a while and I ran into the same
problem, so I tried to fix it.

Fixes #340

* removed , what was added by auto formating

* Addes Line again, which was removed by auto formating
2026-08-31 16:21:30 +02:00
Michael Barz
cb23d6af18 Merge pull request #372 from opencloud-eu/renovate/main-alpine-openssl-3.x
chore(deps): update alpine/openssl docker tag to v3.5.8 (main)
2026-08-31 16:19:10 +02:00
renovate[bot]
8a1193f2d4 chore(deps): update alpine/openssl docker tag to v3.5.8 2026-08-31 14:18:57 +00:00
Michael Barz
18dc807be0 Merge pull request #363 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.2 (main)
2026-08-31 16:18:35 +02:00
Michael Barz
0fab6e73a0 Merge pull request #364 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.7.12 (main)
2026-08-31 16:18:06 +02:00
renovate[bot]
871b6ae4c8 chore(deps): update traefik docker tag to v3.7.12 2026-08-28 06:08:18 +00:00
renovate[bot]
f8b24d5200 chore(deps): update quay.io/keycloak/keycloak docker tag to v26.7.2 2026-08-28 06:08:14 +00:00
Benedikt Kulmann
8826153af8 Merge pull request #370 from opencloud-eu/extend-csp-yaml-epub-reader
feat: extend csp yaml for epub reader iframe sytle loading
2026-08-28 08:07:30 +02:00
Alexander Ackermann
6ed456d3df feat: extend csp yaml for epub reader iframe sytle loading 2026-08-27 17:54:03 +02:00
Michael Flemming
c092407fcd Merge pull request #369 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-7.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.5.0 (main)
2026-08-25 17:00:56 +02:00
renovate[bot]
8f79c17270 chore(deps): update opencloudeu/opencloud-rolling docker tag to v7.5.0 2026-08-25 14:50:10 +00:00
10 changed files with 102 additions and 9 deletions

View File

@@ -215,6 +215,11 @@ This setup includes:
- Radicale as a CalDAV (calendars, to-do lists) and CardDAV (contacts) server
- Users access to a Personal Calendar and Addressbook
Clients connect to `https://<your-domain>/caldav/` (calendar) and
`https://<your-domain>/carddav/` (contacts) — note the required trailing
slash — using an App Token as password. See [radicale/README.md](radicale/README.md)
for client setup (GNOME Online Accounts, Thunderbird) and troubleshooting.
### With Monitoring
Enable monitoring capabilities with metrics endpoints using either method:

View File

@@ -49,6 +49,7 @@ directives:
style-src:
- '''self'''
- '''unsafe-inline'''
- 'blob:'
worker-src:
- "'self'"
- 'blob:'

View File

@@ -1,6 +1,10 @@
# This adds four additional routes to the proxy. Forwarding
# request on '/carddav/', '/caldav/' and the respective '/.well-knwown'
# This adds four additional routes to the proxy, forwarding requests
# on '/caldav/', '/carddav/' and the respective '/.well-known'
# endpoints to the radicale container and setting the required headers.
#
# Client URLs (trailing slash required, see radicale/README.md):
# CalDAV: https://<your-domain>/caldav/
# CardDAV: https://<your-domain>/carddav/
additional_policies:
- name: default
routes:
@@ -10,10 +14,15 @@ additional_policies:
skip_x_access_token: true
additional_headers:
- X-Script-Name: /caldav
# The '.well-known' endpoints are 'unprotected' so that DAV clients
# can discover the CalDAV/CardDAV URLs (RFC 6764) before they
# authenticate. Radicale only ever answers these paths with a 301
# redirect to '/caldav/' or '/carddav/' and serves no data here
# (deeper paths return 404), so no authentication is required.
- endpoint: /.well-known/caldav
backend: http://radicale:5232
remote_user_header: X-Remote-User
skip_x_access_token: true
unprotected: true
additional_headers:
- X-Script-Name: /caldav
- endpoint: /carddav/
@@ -24,8 +33,8 @@ additional_policies:
- X-Script-Name: /carddav
- endpoint: /.well-known/carddav
backend: http://radicale:5232
remote_user_header: X-Remote-User
skip_x_access_token: true
unprotected: true
additional_headers:
- X-Script-Name: /carddav
# To enable the radicale web UI add this rule.

View File

@@ -2,7 +2,7 @@
services:
opencloud:
# renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.4.0}
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.5.0}
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
user: ${OC_CONTAINER_UID_GID:-1000:1000}

View File

@@ -78,7 +78,7 @@ services:
restart: always
keycloak:
image: quay.io/keycloak/keycloak:26.7.1
image: quay.io/keycloak/keycloak:26.7.3
networks:
opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

77
radicale/README.md Normal file
View File

@@ -0,0 +1,77 @@
# Radicale — CalDAV / CardDAV
This module adds [Radicale](https://radicale.org/) as a CalDAV (calendars,
to-do lists) and CardDAV (contacts) server behind the OpenCloud proxy. Every
user gets a personal calendar and address book on first access.
## Enabling
Add `radicale/radicale.yml` to your `COMPOSE_FILE`:
```
COMPOSE_FILE=docker-compose.yml:radicale/radicale.yml:traefik/opencloud.yml
```
The routes are defined in [`config/opencloud/proxy.yaml`](../config/opencloud/proxy.yaml),
which `radicale.yml` mounts into the opencloud container.
## Connecting clients
### URLs
| Service | URL |
|---|---|
| CalDAV (calendar) | `https://<your-domain>/caldav/` |
| CardDAV (contacts) | `https://<your-domain>/carddav/` |
**The trailing slash is required.** `https://<your-domain>/caldav` (without
the slash) is not routed to Radicale and returns the OpenCloud web UI instead.
Clients that implement DAV service discovery (RFC 6764) can also be pointed
at the bare domain `https://<your-domain>/` — the `/.well-known/caldav` and
`/.well-known/carddav` endpoints redirect them to the URLs above. Clients
that don't (or that get confused by the web UI at the base URL) need the full
URL including the suffix.
### Authentication: use an App Token
DAV clients authenticate with **username + App Token** — not your account
password. With the default configuration (`PROXY_ENABLE_BASIC_AUTH=false`)
the account password is rejected with `401 Unauthorized`; App Tokens work out
of the box.
Create a token either
- in the web UI under **Settings → App Tokens**, or
- on the CLI:
```bash
docker compose exec opencloud opencloud auth-app create --user-name=<user> --expiration=72h
```
### GNOME Online Accounts
GNOME expects a directly answering DAV endpoint per account, so calendars and
contacts are added as two separate accounts:
1. **Settings → Online Accounts → Add Account → Calendar (CalDAV)**
— URL `https://<your-domain>/caldav/`, your username, an App Token as
password.
2. **Settings → Online Accounts → Add Account → Contacts (CardDAV)**
— URL `https://<your-domain>/carddav/`, same credentials.
### Thunderbird
- Calendar: *New Calendar → On the Network*, URL `https://<your-domain>/caldav/`
- Address book: *New Address Book → Add CardDAV Address Book*, URL
`https://<your-domain>/carddav/`
Use an App Token as the password in both dialogs.
## Troubleshooting
| Symptom | Cause |
|---|---|
| `401 Unauthorized` | Account password used instead of an App Token (or the token expired). |
| `405 Method Not Allowed` / HTML response | Trailing slash missing — the request landed on the web UI, not Radicale. |
| Client says "not a (Cal)DAV server" at the base URL | The client doesn't do RFC 6764 discovery. Use the full `/caldav/` / `/carddav/` URL. |

View File

@@ -15,7 +15,7 @@ services:
restart: always
keycloak:
image: quay.io/keycloak/keycloak:26.7.1
image: quay.io/keycloak/keycloak:26.7.3
networks:
opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -16,7 +16,7 @@ services:
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
traefik:
image: traefik:v3.7.10
image: traefik:v3.7.12
# release notes: https://github.com/traefik/traefik/releases
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
networks:

View File

@@ -29,7 +29,7 @@ services:
# To rotate the key, remove the volume and start again:
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
collabora-proof-key:
image: alpine/openssl:3.5.7
image: alpine/openssl:3.5.8
entrypoint: ["/bin/sh"]
command:
- -ec

View File

@@ -32,6 +32,7 @@ services:
WOPI_ENABLED: "true"
# self-signed certificates
USE_UNAUTHORIZED_STORAGE: "${INSECURE:-false}"
JWT_SECRET: "${EURO_OFFICE_JWT_SECRET}"
volumes:
# Mount local TrueType fonts so the container can use system fonts
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).