mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-06-08 20:20:04 +08:00
Compare commits
176 Commits
enable-ocm
...
270374d9e1
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
270374d9e1 | ||
|
|
459b5ba9ff | ||
|
|
17012ada58 | ||
|
|
0ddef8a7f1 | ||
|
|
12f855c9ce | ||
|
|
c3caf7e65b | ||
|
|
5998ffbc96 | ||
|
|
29749588de | ||
|
|
781ae4c8b4 | ||
|
|
f62678fc9b | ||
|
|
372bc44e63 | ||
|
|
f0b1565edb | ||
|
|
892839eace | ||
|
|
86f1d6fb7e | ||
|
|
212f87a89c | ||
|
|
68ddb4eb79 | ||
|
|
6da37f5ba5 | ||
|
|
b6bde225d4 | ||
|
|
4f1ff44446 | ||
|
|
8ac4a770a6 | ||
|
|
6008e82a84 | ||
|
|
c600ac4988 | ||
|
|
1f5991578b | ||
|
|
376f06c4e3 | ||
|
|
6ab45a8594 | ||
|
|
938faf9a53 | ||
|
|
1e23a63910 | ||
|
|
39a3bcd45d | ||
|
|
932e794fd2 | ||
|
|
279b2cde68 | ||
|
|
4cbeb8ea38 | ||
|
|
1c94d436e4 | ||
|
|
2b1476950b | ||
|
|
8a30076bc0 | ||
|
|
bfd87b4bc0 | ||
|
|
060f8d09ca | ||
|
|
ec431ee2f8 | ||
|
|
2075573ac5 | ||
|
|
c5f235a54e | ||
|
|
daabcb9515 | ||
|
|
b3c2b06b5f | ||
|
|
a5c06c10cc | ||
|
|
61e128d975 | ||
|
|
958b21d80a | ||
|
|
93fa72b3a8 | ||
|
|
94db919f1d | ||
|
|
33c3861012 | ||
|
|
bc2b6b4a90 | ||
|
|
d146f60855 | ||
|
|
85e2c4aa35 | ||
|
|
70fa25573f | ||
|
|
55035e0a81 | ||
|
|
8f09fd66fd | ||
|
|
1dbce867e1 | ||
|
|
d0a9e71a89 | ||
|
|
634c95d5ed | ||
|
|
820ce2747f | ||
|
|
1eeabd5bcb | ||
|
|
69b1555af9 | ||
|
|
f480b7d6ed | ||
|
|
25af2c9f6f | ||
|
|
41b721b42b | ||
|
|
5ededbd4c9 | ||
|
|
98294c2dee | ||
|
|
1a4f302855 | ||
|
|
de88ca037b | ||
|
|
1b4cfb5759 | ||
|
|
1a231fa807 | ||
|
|
a79de3c5ee | ||
|
|
4e8f66ac5f | ||
|
|
8ce6895188 | ||
|
|
a0d5196dfa | ||
|
|
e19f6ba593 | ||
|
|
d9300db50e | ||
|
|
634cd89b0f | ||
|
|
59f5f1702d | ||
|
|
81888ebe66 | ||
|
|
c3471649f8 | ||
|
|
5fa7ab2d40 | ||
|
|
a738092592 | ||
|
|
3bddb65c8b | ||
|
|
6ecf59f078 | ||
|
|
adf5c3a388 | ||
|
|
4bfa819979 | ||
|
|
0ee8acafe3 | ||
|
|
a2f8a01119 | ||
|
|
d3c0c80250 | ||
|
|
a2411f8cec | ||
|
|
e897106b58 | ||
|
|
7386b21d7c | ||
|
|
f3ea0ee978 | ||
|
|
2f1f0d3149 | ||
|
|
537de1a843 | ||
|
|
497f09669c | ||
|
|
a650026624 | ||
|
|
171235f0b8 | ||
|
|
50254df2ab | ||
|
|
95c03733d7 | ||
|
|
79782cdd5f | ||
|
|
afe6399374 | ||
|
|
8d8b8dfc73 | ||
|
|
eca5b1117e | ||
|
|
cfd356a155 | ||
|
|
4e4fe65a97 | ||
|
|
dede740c0e | ||
|
|
0d389800b5 | ||
|
|
df7dfc0a02 | ||
|
|
0e35e4d6b9 | ||
|
|
c1a9d82702 | ||
|
|
7b2bd36f30 | ||
|
|
13e076b305 | ||
|
|
cfe3f0f612 | ||
|
|
6a5950da36 | ||
|
|
8c96301523 | ||
|
|
39412c7297 | ||
|
|
5873484022 | ||
|
|
6b3a1e36e1 | ||
|
|
fc67954f76 | ||
|
|
c392985614 | ||
|
|
900a05c2c0 | ||
|
|
ba14b78f58 | ||
|
|
4d2ad78f6d | ||
|
|
df985a5304 | ||
|
|
fddd76a560 | ||
|
|
74d359b85c | ||
|
|
73fdc8a96a | ||
|
|
6e40d2d96e | ||
|
|
f24923f95e | ||
|
|
4f79e9ab7b | ||
|
|
cd5d97cda9 | ||
|
|
b501311d0f | ||
|
|
85deada0d2 | ||
|
|
522ced8c96 | ||
|
|
0622cf6e60 | ||
|
|
69b40132c0 | ||
|
|
f466650a97 | ||
|
|
a27c40c4dc | ||
|
|
94c8075b36 | ||
|
|
7543aa2eec | ||
|
|
d51d43825a | ||
|
|
723fb73fb4 | ||
|
|
16dd321bf2 | ||
|
|
6d0454d7a2 | ||
|
|
6f71feff30 | ||
|
|
f5df55fedc | ||
|
|
df98c14b80 | ||
|
|
53ec7140da | ||
|
|
d3f0044fe3 | ||
|
|
9cb8196122 | ||
|
|
bdd2638f3f | ||
|
|
3558f9c2e1 | ||
|
|
bc338d7ff4 | ||
|
|
4fc30f0330 | ||
|
|
93b8186eb6 | ||
|
|
85e3098e1c | ||
|
|
fed9c09ae5 | ||
|
|
c689b26275 | ||
|
|
c1dcf1d1d9 | ||
|
|
25b0de4525 | ||
|
|
67743a8e19 | ||
|
|
f253158ae7 | ||
|
|
219899adfc | ||
|
|
6be2c824ea | ||
|
|
3d82f1b60b | ||
|
|
c55b36b559 | ||
|
|
ce65001eba | ||
|
|
b88b80539b | ||
|
|
6502f1fee7 | ||
|
|
ef64eb6b92 | ||
|
|
07183c14fc | ||
|
|
409d775471 | ||
|
|
ad89914a81 | ||
|
|
5c26c75080 | ||
|
|
27aa8f40f1 | ||
|
|
f3c5f8f591 | ||
|
|
fc560119f4 |
101
.env.example
101
.env.example
@@ -22,6 +22,8 @@ INSECURE=true
|
|||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:external-proxy/opencloud.yml:external-proxy/collabora.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:external-proxy/opencloud.yml:external-proxy/collabora.yml
|
||||||
# Keycloak Shared User Directory
|
# Keycloak Shared User Directory
|
||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml
|
||||||
|
# External IDP
|
||||||
|
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
|
||||||
|
|
||||||
## Traefik Settings ##
|
## Traefik Settings ##
|
||||||
# Note: Traefik is always enabled and can't be disabled.
|
# Note: Traefik is always enabled and can't be disabled.
|
||||||
@@ -59,14 +61,22 @@ TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
|
|||||||
# stores:
|
# stores:
|
||||||
# - default
|
# - default
|
||||||
#
|
#
|
||||||
# The certificates need to copied into ./certs/, the absolute path inside the container is /certs/.
|
# The certificates need to be copied into ./certs/, the absolute path inside the container is /certs/.
|
||||||
# You can also use TRAEFIK_CERTS_DIR=/path/on/host to set the path to the certificates directory.
|
# You can also use TRAEFIK_CERTS_DIR=/path/on/host to set the path to the certificates directory.
|
||||||
|
#TRAEFIK_CERTS_DIR=./certs
|
||||||
# Enable the access log for Traefik by setting the following variable to true.
|
# Enable the access log for Traefik by setting the following variable to true.
|
||||||
TRAEFIK_ACCESS_LOG=
|
TRAEFIK_ACCESS_LOG=
|
||||||
# Configure the log level for Traefik.
|
# Configure the log level for Traefik.
|
||||||
# Possible values are "TRACE", "DEBUG", "INFO", "WARN", "ERROR", "FATAL" and "PANIC". Default is "ERROR".
|
# Possible values are "TRACE", "DEBUG", "INFO", "WARN", "ERROR", "FATAL" and "PANIC". Default is "ERROR".
|
||||||
TRAEFIK_LOG_LEVEL=
|
TRAEFIK_LOG_LEVEL=
|
||||||
|
# The default for traefik is to run in privileged mode.
|
||||||
|
# If you want to run traefik non-privileged, use the following variable and the format [UID]:[GID] to set user and group of your choice.
|
||||||
|
# Ensure that the user has access to docker.sock and traefik volumes defined in traefik/opencloud.yml
|
||||||
|
#TRAEFIK_CONTAINER_UID_GID="1000:1000"
|
||||||
|
# Configure ports for HTTP and HTTPS when necessary, defaults are 80 and 443
|
||||||
|
# Don't use ports in the range of 8000-9999 and 5232 as those ports are used internally and therefore might create conflicts.
|
||||||
|
#TRAEFIK_PORT_HTTP=4080
|
||||||
|
#TRAEFIK_PORT_HTTPS=4443
|
||||||
|
|
||||||
## OpenCloud Settings ##
|
## OpenCloud Settings ##
|
||||||
# The opencloud container image.
|
# The opencloud container image.
|
||||||
@@ -75,8 +85,13 @@ TRAEFIK_LOG_LEVEL=
|
|||||||
# Defaults to production if not set otherwise
|
# Defaults to production if not set otherwise
|
||||||
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling
|
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling
|
||||||
# The openCloud container version.
|
# The openCloud container version.
|
||||||
# Defaults to "latest" and points to the latest stable tag.
|
# Defaults to the latest version-tag. Use git pull to update.
|
||||||
OC_DOCKER_TAG=
|
OC_DOCKER_TAG=
|
||||||
|
# The default id used in opencloud containers is 1000 for user and group.
|
||||||
|
# If you want to change the default, use the following variable and the format [UID]:[GID].
|
||||||
|
# The change affects all containers with access to data volumes.
|
||||||
|
# Ensure that the user has access to all volumes defined in docker-compose.yml
|
||||||
|
#OC_CONTAINER_UID_GID="1000:1000"
|
||||||
# Domain of openCloud, where you can find the frontend.
|
# Domain of openCloud, where you can find the frontend.
|
||||||
# Defaults to "cloud.opencloud.test"
|
# Defaults to "cloud.opencloud.test"
|
||||||
OC_DOMAIN=
|
OC_DOMAIN=
|
||||||
@@ -93,30 +108,39 @@ DEMO_USERS=
|
|||||||
# After the first initialization, the admin password can only be changed via the OpenCloud User Settings UI or by using the OpenCloud CLI.
|
# After the first initialization, the admin password can only be changed via the OpenCloud User Settings UI or by using the OpenCloud CLI.
|
||||||
# Documentation: https://docs.opencloud.eu/docs/admin/resources/common-issues#-change-admin-password-set-in-env
|
# Documentation: https://docs.opencloud.eu/docs/admin/resources/common-issues#-change-admin-password-set-in-env
|
||||||
INITIAL_ADMIN_PASSWORD=
|
INITIAL_ADMIN_PASSWORD=
|
||||||
|
# Whether clients should check for updates.
|
||||||
|
# Defaults to "true".
|
||||||
|
CHECK_FOR_UPDATES=
|
||||||
# Define the openCloud loglevel used.
|
# Define the openCloud loglevel used.
|
||||||
#
|
#
|
||||||
LOG_LEVEL=
|
LOG_LEVEL=
|
||||||
# Define the kind of logging.
|
# Define the kind of logging.
|
||||||
# The default log can be read by machines.
|
# The default log can be read by machines.
|
||||||
# Set this to true to make the log human readable.
|
# Set this to true to make the log human readable.
|
||||||
# LOG_PRETTY=true
|
#LOG_PRETTY=true
|
||||||
#
|
#
|
||||||
# Define the openCloud storage location. Set the paths for config and data to a local path.
|
# Define the openCloud storage location. Set the paths for config and data to a local path.
|
||||||
# Ensure that the configuration and data directories are owned by the user and group with ID 1000:1000.
|
# Ensure that the configuration and data directories are owned by the user and group with ID 1000:1000.
|
||||||
# This matches the default user inside the container and avoids permission issues when accessing files.
|
# This matches the default user inside the container and avoids permission issues when accessing files.
|
||||||
# Note that especially the data directory can grow big.
|
# Note that especially the data directory can grow big.
|
||||||
# Leaving it default stores data in docker internal volumes.
|
# Leaving it default stores data in docker internal volumes.
|
||||||
# OC_CONFIG_DIR=/your/local/opencloud/config
|
OC_CONFIG_DIR=
|
||||||
# OC_DATA_DIR=/your/local/opencloud/data
|
OC_DATA_DIR=
|
||||||
# OpenCloud Web can load extensions from a local directory.
|
# OpenCloud Web can load extensions from a local directory.
|
||||||
# The default uses the bind mount to the config/opencloud/apps directory.
|
# The default uses the bind mount to the config/opencloud/apps directory.
|
||||||
# Example: curl -L https://github.com/opencloud-eu/web-extensions/releases/download/unzip-v1.0.2/unzip-1.0.2.zip | tar -xz -C config/opencloud/apps
|
# Example: curl -L https://github.com/opencloud-eu/web-extensions/releases/download/unzip-v1.0.2/unzip-1.0.2.zip -o config/opencloud/apps/unzip-1.0.2.zip && unzip config/opencloud/apps/unzip-1.0.2.zip -d config/opencloud/apps && rm config/opencloud/apps/unzip-1.0.2.zip
|
||||||
# NOTE: you need to restart the openCloud container to load the new extensions.
|
# NOTE: you need to restart the openCloud container to load the new extensions.
|
||||||
# OC_APPS_DIR=/your/local/opencloud/apps
|
#OC_APPS_DIR=/your/local/opencloud/apps
|
||||||
|
#
|
||||||
|
# The default language used by services and the WebUI.
|
||||||
|
# Uses ISO 639-1 language codes (e.g. "en", "de", "fr").
|
||||||
|
# Defaults to English if not set.
|
||||||
|
DEFAULT_LANGUAGE=
|
||||||
|
|
||||||
# Define the ldap-server storage location. Set the paths for config and data to a local path.
|
# Define the ldap-server storage location. Set the paths for config and data to a local path.
|
||||||
# LDAP_CERTS_DIR=
|
# Leaving it default stores data in docker internal volumes.
|
||||||
# LDAP_DATA_DIR=
|
LDAP_CERTS_DIR=
|
||||||
|
LDAP_DATA_DIR=
|
||||||
|
|
||||||
# S3 Storage configuration - optional
|
# S3 Storage configuration - optional
|
||||||
# OpenCloud supports S3 storage as primary storage.
|
# OpenCloud supports S3 storage as primary storage.
|
||||||
@@ -137,6 +161,8 @@ DECOMPOSEDS3_BUCKET=
|
|||||||
|
|
||||||
|
|
||||||
# Define SMTP settings if you would like to send OpenCloud email notifications.
|
# Define SMTP settings if you would like to send OpenCloud email notifications.
|
||||||
|
# To actually send notifications, you also need to enable the 'notifications' service
|
||||||
|
# by adding it to the START_ADDITIONAL_SERVICES variable below.
|
||||||
#
|
#
|
||||||
# NOTE: when configuring Inbucket, these settings have no effect, see inbucket.yml for details.
|
# NOTE: when configuring Inbucket, these settings have no effect, see inbucket.yml for details.
|
||||||
# SMTP host to connect to.
|
# SMTP host to connect to.
|
||||||
@@ -157,12 +183,11 @@ SMTP_TRANSPORT_ENCRYPTION=
|
|||||||
# Allow insecure connections to the SMTP server. Defaults to false.
|
# Allow insecure connections to the SMTP server. Defaults to false.
|
||||||
SMTP_INSECURE=
|
SMTP_INSECURE=
|
||||||
|
|
||||||
# Addititional services to be started on opencloud startup
|
# Additional services to be started on opencloud startup
|
||||||
# The following list of services is not startet automatically and must be
|
# The following list of services is not started automatically and must be
|
||||||
# manually defined for startup:
|
# manually defined for startup:
|
||||||
# IMPORTANT: The notification service is MANDATORY, do not delete!
|
|
||||||
# IMPORTANT: Add any services to the startup list comma separated like "notifications,antivirus" etc.
|
# IMPORTANT: Add any services to the startup list comma separated like "notifications,antivirus" etc.
|
||||||
START_ADDITIONAL_SERVICES="notifications"
|
START_ADDITIONAL_SERVICES=""
|
||||||
|
|
||||||
|
|
||||||
## Default Enabled Services ##
|
## Default Enabled Services ##
|
||||||
@@ -174,7 +199,11 @@ START_ADDITIONAL_SERVICES="notifications"
|
|||||||
# search/tika.yml or by using the following command:
|
# search/tika.yml or by using the following command:
|
||||||
# docker compose -f docker-compose.yml -f search/tika.yml up -d
|
# docker compose -f docker-compose.yml -f search/tika.yml up -d
|
||||||
# Set the desired docker image tag or digest.
|
# Set the desired docker image tag or digest.
|
||||||
# Defaults to "apache/tika:latest-full"
|
# Defaults to "apache/tika:latest"
|
||||||
|
# The slim variant is recommended for most use cases as it provides core text extraction
|
||||||
|
# functionality with a smaller image size and faster startup time.
|
||||||
|
# Only use the full variant (apache/tika:latest-full) if you need specialized features
|
||||||
|
# like advanced OCR or specific image processing capabilities.
|
||||||
TIKA_IMAGE=
|
TIKA_IMAGE=
|
||||||
|
|
||||||
### IMPORTANT Note for Online Office Apps ###
|
### IMPORTANT Note for Online Office Apps ###
|
||||||
@@ -203,12 +232,18 @@ COLLABORA_SSL_ENABLE=false
|
|||||||
# If you're on an internet-facing server, enable SSL verification for Collabora Online.
|
# If you're on an internet-facing server, enable SSL verification for Collabora Online.
|
||||||
# Please comment out the following line:
|
# Please comment out the following line:
|
||||||
COLLABORA_SSL_VERIFICATION=false
|
COLLABORA_SSL_VERIFICATION=false
|
||||||
|
# Enable home mode in Collabore Online.
|
||||||
|
# Home users can enable this setting, which in turn disables welcome screen and user feedback popups,
|
||||||
|
# but also limits concurrent open connections to 20 and concurrent open documents to 10.
|
||||||
|
# Default is false if not specified.
|
||||||
|
COLLABORA_HOME_MODE=
|
||||||
|
|
||||||
|
|
||||||
### Virusscanner Settings ###
|
### Virusscanner Settings ###
|
||||||
# IMPORTANT: If you enable antivirus, you also MUST configure the START_ADDITIONAL_SERVICES
|
# IMPORTANT: If you enable antivirus, you also MUST configure the START_ADDITIONAL_SERVICES
|
||||||
# envvar in the OpenCloud Settings above by adding 'antivirus' to the list.
|
# envvar in the OpenCloud Settings above by adding 'antivirus' to the list.
|
||||||
# The maximum scan size the virus scanner can handle, needs adjustment in the scanner config as well.
|
# The maximum scan size the virus scanner can handle, needs adjustment in the scanner config as well:
|
||||||
|
# For ClamAV, set CLAMD_CONF_StreamMaxLength in antivirus/clamav.yml to the same or a higher value.
|
||||||
# Usable common abbreviations: [KB, KiB, MB, MiB, GB, GiB, TB, TiB, PB, PiB, EB, EiB], example: 2GB.
|
# Usable common abbreviations: [KB, KiB, MB, MiB, GB, GiB, TB, TiB, PB, PiB, EB, EiB], example: 2GB.
|
||||||
# Defaults to "100MB"
|
# Defaults to "100MB"
|
||||||
#ANTIVIRUS_MAX_SCAN_SIZE=
|
#ANTIVIRUS_MAX_SCAN_SIZE=
|
||||||
@@ -216,7 +251,7 @@ COLLABORA_SSL_VERIFICATION=false
|
|||||||
# Defaults to "partial"
|
# Defaults to "partial"
|
||||||
#ANTIVIRUS_MAX_SCAN_SIZE_MODE=
|
#ANTIVIRUS_MAX_SCAN_SIZE_MODE=
|
||||||
# Image version of the ClamAV container.
|
# Image version of the ClamAV container.
|
||||||
# Defaults to "latest"y
|
# Defaults to "latest"
|
||||||
CLAMAV_DOCKER_TAG=
|
CLAMAV_DOCKER_TAG=
|
||||||
|
|
||||||
|
|
||||||
@@ -278,6 +313,23 @@ IDP_DOMAIN=
|
|||||||
IDP_ISSUER_URL=
|
IDP_ISSUER_URL=
|
||||||
# Url of the account edit page from your Identity Provider.
|
# Url of the account edit page from your Identity Provider.
|
||||||
IDP_ACCOUNT_URL=
|
IDP_ACCOUNT_URL=
|
||||||
|
# Global Client ID: You can override this by specifying a custom client ID, or leave it blank to use the OC defaults, as described in the documentation
|
||||||
|
#OC_OIDC_CLIENT_ID=
|
||||||
|
# Declares which property should be used for the oidc claim
|
||||||
|
# Example: "roles"
|
||||||
|
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM=
|
||||||
|
# Defines the OIDC client scope
|
||||||
|
# Example: "openid profile email roles"
|
||||||
|
OC_OIDC_CLIENT_SCOPES=
|
||||||
|
# Client specific environment vars
|
||||||
|
#WEBFINGER_WEB_OIDC_CLIENT_ID=
|
||||||
|
#WEBFINGER_WEB_OIDC_CLIENT_SCOPES=
|
||||||
|
#WEBFINGER_IOS_OIDC_CLIENT_ID=
|
||||||
|
#WEBFINGER_IOS_OIDC_CLIENT_SCOPES=
|
||||||
|
#WEBFINGER_ANDROID_OIDC_CLIENT_ID=
|
||||||
|
#WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES=
|
||||||
|
#WEBFINGER_DESKTOP_OIDC_CLIENT_ID=
|
||||||
|
#WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES=
|
||||||
|
|
||||||
## Shared User Directory Mode ##
|
## Shared User Directory Mode ##
|
||||||
# Use together with idm/ldap-keycloak.yml and traefik/ldap-keycloak.yml
|
# Use together with idm/ldap-keycloak.yml and traefik/ldap-keycloak.yml
|
||||||
@@ -287,11 +339,26 @@ KEYCLOAK_DOMAIN=
|
|||||||
KEYCLOAK_ADMIN=
|
KEYCLOAK_ADMIN=
|
||||||
# Admin user login password. Defaults to "admin".
|
# Admin user login password. Defaults to "admin".
|
||||||
KEYCLOAK_ADMIN_PASSWORD=
|
KEYCLOAK_ADMIN_PASSWORD=
|
||||||
|
# Configure the log level for Keycloak.
|
||||||
|
# Possible values are "TRACE", "DEBUG", "INFO", "WARN", "ERROR", "FATAL" and "OFF". Default is "INFO".
|
||||||
|
KC_LOG_LEVEL=
|
||||||
# Keycloak Database username. Defaults to "keycloak".
|
# Keycloak Database username. Defaults to "keycloak".
|
||||||
KC_DB_USERNAME=
|
KC_DB_USERNAME=
|
||||||
# Keycloak Database password. Defaults to "keycloak".
|
# Keycloak Database password. Defaults to "keycloak".
|
||||||
KC_DB_PASSWORD=
|
KC_DB_PASSWORD=
|
||||||
|
|
||||||
|
## Demo Users ##
|
||||||
|
# Enable demo users and groups in the shared LDAP directory.
|
||||||
|
# To enable, create custom/ldap-keycloak-demo-users.yml with:
|
||||||
|
# services:
|
||||||
|
# ldap-server:
|
||||||
|
# volumes:
|
||||||
|
# - ./config/ldap/ldif/30_demo_users.ldif:/ldifs/30_demo_users.ldif
|
||||||
|
# - ./config/ldap/ldif/40_demo_groups.ldif:/ldifs/40_demo_groups.ldif
|
||||||
|
#
|
||||||
|
# Then add it to: COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml:custom/ldap-keycloak-demo-users.yml
|
||||||
|
# WARNING: Do not use in production.
|
||||||
|
|
||||||
### Radicale Setting ###
|
### Radicale Setting ###
|
||||||
# Radicale is a small open-source CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
|
# Radicale is a small open-source CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
|
||||||
# When enabled OpenCloud is configured as a reverse proxy for Radicale, providing all authenticated
|
# When enabled OpenCloud is configured as a reverse proxy for Radicale, providing all authenticated
|
||||||
|
|||||||
1
.gitignore
vendored
1
.gitignore
vendored
@@ -5,6 +5,7 @@
|
|||||||
# exclude the apps folder
|
# exclude the apps folder
|
||||||
/config/opencloud/apps/*
|
/config/opencloud/apps/*
|
||||||
!/config/opencloud/apps/.gitkeep
|
!/config/opencloud/apps/.gitkeep
|
||||||
|
!/config/opencloud/apps/maps
|
||||||
|
|
||||||
# exclude custom compose files
|
# exclude custom compose files
|
||||||
/custom
|
/custom
|
||||||
|
|||||||
66
README.md
66
README.md
@@ -2,6 +2,9 @@
|
|||||||
|
|
||||||
This repository provides Docker Compose configurations for deploying OpenCloud in various environments.
|
This repository provides Docker Compose configurations for deploying OpenCloud in various environments.
|
||||||
|
|
||||||
|
> [!IMPORTANT]
|
||||||
|
> Please use the [official docs](https://docs.opencloud.eu/docs/admin/getting-started/container/docker-compose/docker-compose-base) for a **Production Deployment**.
|
||||||
|
|
||||||
## Overview
|
## Overview
|
||||||
|
|
||||||
OpenCloud Compose offers a modular approach to deploying OpenCloud with several configuration options:
|
OpenCloud Compose offers a modular approach to deploying OpenCloud with several configuration options:
|
||||||
@@ -13,6 +16,7 @@ OpenCloud Compose offers a modular approach to deploying OpenCloud with several
|
|||||||
- **Full text search** with Apache Tika for content extraction and metadata analysis
|
- **Full text search** with Apache Tika for content extraction and metadata analysis
|
||||||
- **Monitoring** with metrics endpoints for observability and performance monitoring
|
- **Monitoring** with metrics endpoints for observability and performance monitoring
|
||||||
- **Radicale** integration for Calendar and Contacts
|
- **Radicale** integration for Calendar and Contacts
|
||||||
|
- **ClamAV** antivirus scanning with ClamAV
|
||||||
|
|
||||||
## Quick Start Guide
|
## Quick Start Guide
|
||||||
|
|
||||||
@@ -42,8 +46,9 @@ OpenCloud Compose offers a modular approach to deploying OpenCloud with several
|
|||||||
|
|
||||||
3. **Set admin password**:
|
3. **Set admin password**:
|
||||||
set `INITIAL_ADMIN_PASSWORD=your_secure_password` environment variable in your `.env` file
|
set `INITIAL_ADMIN_PASSWORD=your_secure_password` environment variable in your `.env` file
|
||||||
|
4. **Domain**:
|
||||||
4. **Configure deployment options**:
|
optionally, set `OC_DOMAIN=your-domain.com` to overwrite the default `cloud.opencloud.test`
|
||||||
|
5. **Configure deployment options**:
|
||||||
|
|
||||||
You can deploy using explicit `-f` flags:
|
You can deploy using explicit `-f` flags:
|
||||||
```bash
|
```bash
|
||||||
@@ -60,38 +65,18 @@ OpenCloud Compose offers a modular approach to deploying OpenCloud with several
|
|||||||
docker compose up -d
|
docker compose up -d
|
||||||
```
|
```
|
||||||
|
|
||||||
5. **Add local domains to `/etc/hosts`** (for local development only):
|
6. **Add local domains to `/etc/hosts`** (for local development only):
|
||||||
```
|
```
|
||||||
127.0.0.1 cloud.opencloud.test
|
127.0.0.1 cloud.opencloud.test
|
||||||
127.0.0.1 traefik.opencloud.test
|
127.0.0.1 traefik.opencloud.test
|
||||||
127.0.0.1 keycloak.opencloud.test
|
127.0.0.1 keycloak.opencloud.test
|
||||||
```
|
```
|
||||||
|
|
||||||
6. **Access OpenCloud**:
|
7. **Access OpenCloud**:
|
||||||
- URL: https://cloud.opencloud.test
|
- URL: https://cloud.opencloud.test
|
||||||
- Username: `admin`
|
- Username: `admin`
|
||||||
- Password: value of your `INITIAL_ADMIN_PASSWORD`
|
- Password: value of your `INITIAL_ADMIN_PASSWORD`
|
||||||
|
|
||||||
### Production Deployment
|
|
||||||
|
|
||||||
> **DNS Requirements**: For production deployments, you need real DNS entries pointing to your server for all required subdomains. You can either create individual DNS A/AAAA records for each subdomain (e.g., `cloud.example.com`, `collabora.example.com`, `keycloak.example.com`) or use a wildcard DNS entry (`*.example.com`) that covers all subdomains.
|
|
||||||
|
|
||||||
1. **Edit the `.env` file** and configure:
|
|
||||||
- Domain names (replace `.opencloud.test` domains with your real domains)
|
|
||||||
- Admin password
|
|
||||||
- SSL certificate email
|
|
||||||
- Storage paths
|
|
||||||
|
|
||||||
2. **Configure deployment options** in `.env`:
|
|
||||||
```
|
|
||||||
COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml
|
|
||||||
```
|
|
||||||
|
|
||||||
3. **Start OpenCloud**:
|
|
||||||
```bash
|
|
||||||
docker compose up -d
|
|
||||||
```
|
|
||||||
|
|
||||||
## Deployment Options
|
## Deployment Options
|
||||||
|
|
||||||
### With Keycloak and LDAP using a Shared User Directory
|
### With Keycloak and LDAP using a Shared User Directory
|
||||||
@@ -163,6 +148,14 @@ This setup includes:
|
|||||||
- Full text search functionality in the OpenCloud interface
|
- Full text search functionality in the OpenCloud interface
|
||||||
- Support for documents, PDFs, images, and other file types
|
- Support for documents, PDFs, images, and other file types
|
||||||
|
|
||||||
|
**Tika Image Variant:**
|
||||||
|
By default, OpenCloud Compose uses `apache/tika:latest` which provides:
|
||||||
|
- Smaller image size (~300MB vs ~1.2GB for the full variant)
|
||||||
|
- Faster container startup and deployment
|
||||||
|
- Core text extraction functionality for common document formats (PDF, Office docs, text files, etc.)
|
||||||
|
|
||||||
|
The base variant is recommended for most use cases. If you need advanced features like specialized OCR processing or specific image format support, you can override the image by setting `TIKA_IMAGE=apache/tika:latest-full` in your `.env` file.
|
||||||
|
|
||||||
### With Radicale
|
### With Radicale
|
||||||
|
|
||||||
Enable CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
|
Enable CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
|
||||||
@@ -239,6 +232,25 @@ This exposes the necessary ports:
|
|||||||
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
|
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
|
||||||
Otherwise, the desktop app authentication will return **error 403 Forbidden**.
|
Otherwise, the desktop app authentication will return **error 403 Forbidden**.
|
||||||
|
|
||||||
|
### ClamAV anti-virus
|
||||||
|
|
||||||
|
Enable anti-virus scans for uploaded files.
|
||||||
|
|
||||||
|
Using `-f` flags:
|
||||||
|
```bash
|
||||||
|
docker compose -f docker-compose.yml -f antivirus/clamav.yml -f traefik/opencloud.yml up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
Or by setting in `.env`:
|
||||||
|
```
|
||||||
|
COMPOSE_FILE=docker-compose.yml:antivirus/clamav.yml:traefik/opencloud.yml
|
||||||
|
```
|
||||||
|
|
||||||
|
**Important:** adjust the variable in `.env` to start the antivirus service. Add additional services separated by comma, e.g. `notifications,antivirus`:
|
||||||
|
```
|
||||||
|
START_ADDITIONAL_SERVICES="antivirus"
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
## SSL Certificate Support
|
## SSL Certificate Support
|
||||||
|
|
||||||
@@ -273,10 +285,6 @@ OpenCloud Compose supports adding SSL certificates for public domains and develo
|
|||||||
keyFile: /certs/opencloud.test.key
|
keyFile: /certs/opencloud.test.key
|
||||||
stores:
|
stores:
|
||||||
- default
|
- default
|
||||||
- certFile: /certs/wildcard.example.com.crt
|
|
||||||
keyFile: /certs/wildcard.example.com.key
|
|
||||||
stores:
|
|
||||||
- default
|
|
||||||
```
|
```
|
||||||
|
|
||||||
3. **Configure environment variables**:
|
3. **Configure environment variables**:
|
||||||
@@ -334,7 +342,7 @@ Key variables:
|
|||||||
| `INSECURE` | Skip certificate validation | true |
|
| `INSECURE` | Skip certificate validation | true |
|
||||||
| `COLLABORA_DOMAIN` | Collabora domain | collabora.opencloud.test |
|
| `COLLABORA_DOMAIN` | Collabora domain | collabora.opencloud.test |
|
||||||
| `WOPISERVER_DOMAIN` | WOPI server domain | wopiserver.opencloud.test |
|
| `WOPISERVER_DOMAIN` | WOPI server domain | wopiserver.opencloud.test |
|
||||||
| `TIKA_IMAGE` | Apache Tika image tag | apache/tika:latest-full |
|
| `TIKA_IMAGE` | Apache Tika image tag | apache/tika:slim |
|
||||||
| `KEYCLOAK_DOMAIN` | Keycloak domain | keycloak.opencloud.test |
|
| `KEYCLOAK_DOMAIN` | Keycloak domain | keycloak.opencloud.test |
|
||||||
| `KEYCLOAK_ADMIN` | Keycloak admin username | kcadmin |
|
| `KEYCLOAK_ADMIN` | Keycloak admin username | kcadmin |
|
||||||
| `KEYCLOAK_ADMIN_PASSWORD` | Keycloak admin password | admin |
|
| `KEYCLOAK_ADMIN_PASSWORD` | Keycloak admin password | admin |
|
||||||
|
|||||||
31
antivirus/clamav.yml
Normal file
31
antivirus/clamav.yml
Normal file
@@ -0,0 +1,31 @@
|
|||||||
|
---
|
||||||
|
services:
|
||||||
|
opencloud:
|
||||||
|
environment:
|
||||||
|
POSTPROCESSING_STEPS: "virusscan"
|
||||||
|
STORAGE_USERS_DATA_GATEWAY_URL: "http://opencloud:9200/data"
|
||||||
|
ANTIVIRUS_MAX_SCAN_SIZE: ${ANTIVIRUS_MAX_SCAN_SIZE:-100MB}
|
||||||
|
ANTIVIRUS_INFECTED_FILE_HANDLING: abort
|
||||||
|
ANTIVIRUS_MAX_SCAN_SIZE_MODE: ${ANTIVIRUS_MAX_SCAN_SIZE_MODE:-partial}
|
||||||
|
ANTIVIRUS_WORKERS: 1
|
||||||
|
ANTIVIRUS_CLAMAV_SOCKET: /var/run/clamav/clamd.sock
|
||||||
|
ANTIVIRUS_SCANNER_TYPE: clamav
|
||||||
|
volumes:
|
||||||
|
- clamav-socket:/var/run/clamav
|
||||||
|
clamav:
|
||||||
|
image: clamav/clamav:${CLAMAV_DOCKER_TAG:-latest}
|
||||||
|
environment:
|
||||||
|
# Accepts a number with optional K, M or G suffix. Must be greater or equal to ANTIVIRUS_MAX_SCAN_SIZE above.
|
||||||
|
# K = KiB (1024), M = MiB (1024 * 1024), G = GiB (1024 * 1024 * 1024)
|
||||||
|
CLAMD_CONF_StreamMaxLength: 100M
|
||||||
|
networks:
|
||||||
|
opencloud-net:
|
||||||
|
volumes:
|
||||||
|
- clamav-socket:/tmp
|
||||||
|
- clamav-db:/var/lib/clamav
|
||||||
|
logging:
|
||||||
|
driver: ${LOG_DRIVER:-local}
|
||||||
|
restart: always
|
||||||
|
volumes:
|
||||||
|
clamav-db:
|
||||||
|
clamav-socket:
|
||||||
@@ -1,5 +1,8 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
printenv
|
# print env variables for trace/debug log levels
|
||||||
|
log_level=$(printf '%s' "$KC_LOG_LEVEL" | tr '[:upper:]' '[:lower:]')
|
||||||
|
case "$log_level" in trace|debug) printenv ;; *) ;; esac
|
||||||
|
|
||||||
# replace openCloud domain and LDAP password in keycloak realm import
|
# replace openCloud domain and LDAP password in keycloak realm import
|
||||||
mkdir /opt/keycloak/data/import
|
mkdir /opt/keycloak/data/import
|
||||||
sed -e "s/cloud.opencloud.test/${OC_DOMAIN}/g" -e "s/ldap-admin-password/${LDAP_ADMIN_PASSWORD:-admin}/g" /opt/keycloak/data/import-dist/openCloud-realm.json > /opt/keycloak/data/import/openCloud-realm.json
|
sed -e "s/cloud.opencloud.test/${OC_DOMAIN}/g" -e "s/ldap-admin-password/${LDAP_ADMIN_PASSWORD:-admin}/g" /opt/keycloak/data/import-dist/openCloud-realm.json > /opt/keycloak/data/import/openCloud-realm.json
|
||||||
|
|||||||
@@ -676,6 +676,7 @@
|
|||||||
"profile",
|
"profile",
|
||||||
"roles",
|
"roles",
|
||||||
"groups",
|
"groups",
|
||||||
|
"OpenCloudUnique_ID",
|
||||||
"basic",
|
"basic",
|
||||||
"email"
|
"email"
|
||||||
],
|
],
|
||||||
@@ -2336,7 +2337,7 @@
|
|||||||
"always"
|
"always"
|
||||||
],
|
],
|
||||||
"usePasswordModifyExtendedOp": [
|
"usePasswordModifyExtendedOp": [
|
||||||
"false"
|
"true"
|
||||||
],
|
],
|
||||||
"trustEmail": [
|
"trustEmail": [
|
||||||
"false"
|
"false"
|
||||||
|
|||||||
11
config/ldap/init-ldap-acls.sh
Executable file
11
config/ldap/init-ldap-acls.sh
Executable file
@@ -0,0 +1,11 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
# apply acls
|
||||||
|
echo -n "Applying acls... "
|
||||||
|
slapmodify -F /opt/bitnami/openldap/etc/slapd.d -b cn=config -l /opt/bitnami/openldap/etc/schema/50_acls.ldif
|
||||||
|
if [ $? -eq 0 ]; then
|
||||||
|
echo "done."
|
||||||
|
else
|
||||||
|
echo "failed."
|
||||||
|
fi
|
||||||
9
config/ldap/ldif/50_acls.ldif
Normal file
9
config/ldap/ldif/50_acls.ldif
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
# OpenCloud ldap acl file which gets applied during the first db initialisation
|
||||||
|
dn: olcDatabase={2}mdb,cn=config
|
||||||
|
changetype: modify
|
||||||
|
replace: olcAccess
|
||||||
|
olcAccess: {0}to dn.subtree="dc=opencloud,dc=eu" attrs=entry,uid,objectClass,entryUUID
|
||||||
|
by * read
|
||||||
|
olcAccess: {1}to attrs=userPassword
|
||||||
|
by self write
|
||||||
|
by * auth
|
||||||
21
config/opencloud/apps/maps/js/maps-uKkx1qsf.js
Normal file
21
config/opencloud/apps/maps/js/maps-uKkx1qsf.js
Normal file
File diff suppressed because one or more lines are too long
3
config/opencloud/apps/maps/manifest.json
Normal file
3
config/opencloud/apps/maps/manifest.json
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
{
|
||||||
|
"entrypoint": "js/maps-uKkx1qsf.js"
|
||||||
|
}
|
||||||
@@ -4,10 +4,11 @@ directives:
|
|||||||
connect-src:
|
connect-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
- 'blob:'
|
- 'blob:'
|
||||||
- 'https://${COMPANION_DOMAIN|companion.opencloud.test}/'
|
- 'https://${COMPANION_DOMAIN|companion.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
- 'wss://${COMPANION_DOMAIN|companion.opencloud.test}/'
|
- 'wss://${COMPANION_DOMAIN|companion.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
- 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/'
|
- 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/'
|
||||||
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}/'
|
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
|
- 'https://update.opencloud.eu/'
|
||||||
default-src:
|
default-src:
|
||||||
- '''none'''
|
- '''none'''
|
||||||
font-src:
|
font-src:
|
||||||
@@ -19,7 +20,7 @@ directives:
|
|||||||
- 'blob:'
|
- 'blob:'
|
||||||
- 'https://embed.diagrams.net/'
|
- 'https://embed.diagrams.net/'
|
||||||
# In contrary to bash and docker the default is given after the | character
|
# In contrary to bash and docker the default is given after the | character
|
||||||
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}/'
|
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
# This is needed for the external-sites web extension when embedding sites
|
# This is needed for the external-sites web extension when embedding sites
|
||||||
- 'https://docs.opencloud.eu'
|
- 'https://docs.opencloud.eu'
|
||||||
img-src:
|
img-src:
|
||||||
@@ -27,8 +28,9 @@ directives:
|
|||||||
- 'data:'
|
- 'data:'
|
||||||
- 'blob:'
|
- 'blob:'
|
||||||
- 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/'
|
- 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/'
|
||||||
|
- 'https://tile.openstreetmap.org/'
|
||||||
# In contrary to bash and docker the default is given after the | character
|
# In contrary to bash and docker the default is given after the | character
|
||||||
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}/'
|
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
manifest-src:
|
manifest-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
media-src:
|
media-src:
|
||||||
@@ -39,7 +41,7 @@ directives:
|
|||||||
script-src:
|
script-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
- '''unsafe-inline'''
|
- '''unsafe-inline'''
|
||||||
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}/'
|
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
style-src:
|
style-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
- '''unsafe-inline'''
|
- '''unsafe-inline'''
|
||||||
|
|||||||
@@ -1,46 +0,0 @@
|
|||||||
[
|
|
||||||
{
|
|
||||||
"name": "host.docker.internal:9200",
|
|
||||||
"full_name": "host.docker.internal 9200",
|
|
||||||
"organization": "OpenCloud",
|
|
||||||
"domain": "host.docker.internal:9200",
|
|
||||||
"homepage": "https://opencloud.eu",
|
|
||||||
"services": [
|
|
||||||
{
|
|
||||||
"endpoint": {
|
|
||||||
"type": {
|
|
||||||
"name": "OCM",
|
|
||||||
"description": "OpenCloud Open Cloud Mesh API"
|
|
||||||
},
|
|
||||||
"name": "OpenCloud - OCM API",
|
|
||||||
"path": "https://host.docker.internal:9200/ocm/",
|
|
||||||
"is_monitored": true
|
|
||||||
},
|
|
||||||
"api_version": "0.0.1",
|
|
||||||
"host": "host.docker.internal:9200"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name": "cloud.opencloud.test",
|
|
||||||
"full_name": "cloud.opencloud.test",
|
|
||||||
"organization": "OpenCloud",
|
|
||||||
"domain": "cloud.opencloud.test",
|
|
||||||
"homepage": "https://opencloud.eu",
|
|
||||||
"services": [
|
|
||||||
{
|
|
||||||
"endpoint": {
|
|
||||||
"type": {
|
|
||||||
"name": "OCM",
|
|
||||||
"description": "OpenCloud Open Cloud Mesh API"
|
|
||||||
},
|
|
||||||
"name": "OpenCloud - OCM API",
|
|
||||||
"path": "https://cloud.opencloud.test/ocm/",
|
|
||||||
"is_monitored": true
|
|
||||||
},
|
|
||||||
"api_version": "0.0.1",
|
|
||||||
"host": "cloud.opencloud.test"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
]
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
# OpenCloud web configuration
|
|
||||||
web:
|
|
||||||
config:
|
|
||||||
apps:
|
|
||||||
- files
|
|
||||||
- search
|
|
||||||
- text-editor
|
|
||||||
- pdf-viewer
|
|
||||||
- external
|
|
||||||
- admin-settings
|
|
||||||
- epub-reader
|
|
||||||
- preview
|
|
||||||
- app-store
|
|
||||||
- ocm
|
|
||||||
@@ -14,10 +14,10 @@ add_arg "--log.level=${TRAEFIK_LOG_LEVEL:-ERROR}"
|
|||||||
# enable dashboard
|
# enable dashboard
|
||||||
add_arg "--api.dashboard=true"
|
add_arg "--api.dashboard=true"
|
||||||
# define entrypoints
|
# define entrypoints
|
||||||
add_arg "--entryPoints.http.address=:80"
|
add_arg "--entryPoints.http.address=:${TRAEFIK_PORT_HTTP:-80}"
|
||||||
add_arg "--entryPoints.http.http.redirections.entryPoint.to=https"
|
add_arg "--entryPoints.http.http.redirections.entryPoint.to=https"
|
||||||
add_arg "--entryPoints.http.http.redirections.entryPoint.scheme=https"
|
add_arg "--entryPoints.http.http.redirections.entryPoint.scheme=https"
|
||||||
add_arg "--entryPoints.https.address=:443"
|
add_arg "--entryPoints.https.address=:${TRAEFIK_PORT_HTTPS:-443}"
|
||||||
# change default timeouts for long-running requests
|
# change default timeouts for long-running requests
|
||||||
# this is needed for webdav clients that do not support the TUS protocol
|
# this is needed for webdav clients that do not support the TUS protocol
|
||||||
add_arg "--entryPoints.https.transport.respondingTimeouts.readTimeout=12h"
|
add_arg "--entryPoints.https.transport.respondingTimeouts.readTimeout=12h"
|
||||||
|
|||||||
@@ -1,9 +1,11 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
opencloud:
|
opencloud:
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-latest}
|
# renovate: depName=opencloudeu/opencloud-rolling
|
||||||
|
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.1.0}
|
||||||
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
||||||
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
||||||
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
entrypoint:
|
entrypoint:
|
||||||
@@ -15,7 +17,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
# enable services that are not started automatically
|
# enable services that are not started automatically
|
||||||
OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES}
|
OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES}
|
||||||
OC_URL: https://${OC_DOMAIN:-cloud.opencloud.test}
|
OC_URL: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
OC_LOG_LEVEL: ${LOG_LEVEL:-info}
|
OC_LOG_LEVEL: ${LOG_LEVEL:-info}
|
||||||
OC_LOG_COLOR: "${LOG_PRETTY:-false}"
|
OC_LOG_COLOR: "${LOG_PRETTY:-false}"
|
||||||
OC_LOG_PRETTY: "${LOG_PRETTY:-false}"
|
OC_LOG_PRETTY: "${LOG_PRETTY:-false}"
|
||||||
@@ -35,41 +37,32 @@ services:
|
|||||||
NOTIFICATIONS_SMTP_SENDER: "${SMTP_SENDER:-OpenCloud Notifications <notifications@cloud.opencloud.test>}"
|
NOTIFICATIONS_SMTP_SENDER: "${SMTP_SENDER:-OpenCloud Notifications <notifications@cloud.opencloud.test>}"
|
||||||
NOTIFICATIONS_SMTP_USERNAME: "${SMTP_USERNAME}"
|
NOTIFICATIONS_SMTP_USERNAME: "${SMTP_USERNAME}"
|
||||||
NOTIFICATIONS_SMTP_PASSWORD: "${SMTP_PASSWORD}"
|
NOTIFICATIONS_SMTP_PASSWORD: "${SMTP_PASSWORD}"
|
||||||
NOTIFICATIONS_SMTP_INSECURE: "${SMTP_INSECURE}"
|
NOTIFICATIONS_SMTP_INSECURE: "${SMTP_INSECURE:-false}"
|
||||||
NOTIFICATIONS_SMTP_AUTHENTICATION: "${SMTP_AUTHENTICATION}"
|
NOTIFICATIONS_SMTP_AUTHENTICATION: "${SMTP_AUTHENTICATION}"
|
||||||
NOTIFICATIONS_SMTP_ENCRYPTION: "${SMTP_TRANSPORT_ENCRYPTION:-none}"
|
NOTIFICATIONS_SMTP_ENCRYPTION: "${SMTP_TRANSPORT_ENCRYPTION:-none}"
|
||||||
FRONTEND_ARCHIVER_MAX_SIZE: "10000000000"
|
FRONTEND_ARCHIVER_MAX_SIZE: "10000000000"
|
||||||
|
FRONTEND_CHECK_FOR_UPDATES: "${CHECK_FOR_UPDATES:-true}"
|
||||||
PROXY_CSP_CONFIG_FILE_LOCATION: /etc/opencloud/csp.yaml
|
PROXY_CSP_CONFIG_FILE_LOCATION: /etc/opencloud/csp.yaml
|
||||||
# enable to allow using the banned passwords list
|
# enable to allow using the banned passwords list
|
||||||
OC_PASSWORD_POLICY_BANNED_PASSWORDS_LIST: banned-password-list.txt
|
OC_PASSWORD_POLICY_BANNED_PASSWORDS_LIST: banned-password-list.txt
|
||||||
# control the password enforcement and policy for public shares
|
# control the password enforcement and policy for public shares
|
||||||
OC_SHARING_PUBLIC_SHARE_MUST_HAVE_PASSWORD: "${OC_SHARING_PUBLIC_SHARE_MUST_HAVE_PASSWORD:-true}"
|
OC_SHARING_PUBLIC_SHARE_MUST_HAVE_PASSWORD: "${OC_SHARING_PUBLIC_SHARE_MUST_HAVE_PASSWORD:-true}"
|
||||||
OC_SHARING_PUBLIC_WRITEABLE_SHARE_MUST_HAVE_PASSWORD: "${OC_SHARING_PUBLIC_WRITEABLE_SHARE_MUST_HAVE_PASSWORD:-true}"
|
OC_SHARING_PUBLIC_WRITEABLE_SHARE_MUST_HAVE_PASSWORD: "${OC_SHARING_PUBLIC_WRITEABLE_SHARE_MUST_HAVE_PASSWORD:-false}"
|
||||||
OC_PASSWORD_POLICY_DISABLED: "${OC_PASSWORD_POLICY_DISABLED:-false}"
|
OC_PASSWORD_POLICY_DISABLED: "${OC_PASSWORD_POLICY_DISABLED:-false}"
|
||||||
OC_PASSWORD_POLICY_MIN_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_CHARACTERS:-8}"
|
OC_PASSWORD_POLICY_MIN_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_CHARACTERS:-8}"
|
||||||
OC_PASSWORD_POLICY_MIN_LOWERCASE_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_LOWERCASE_CHARACTERS:-1}"
|
OC_PASSWORD_POLICY_MIN_LOWERCASE_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_LOWERCASE_CHARACTERS:-1}"
|
||||||
OC_PASSWORD_POLICY_MIN_UPPERCASE_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_UPPERCASE_CHARACTERS:-1}"
|
OC_PASSWORD_POLICY_MIN_UPPERCASE_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_UPPERCASE_CHARACTERS:-1}"
|
||||||
OC_PASSWORD_POLICY_MIN_DIGITS: "${OC_PASSWORD_POLICY_MIN_DIGITS:-1}"
|
OC_PASSWORD_POLICY_MIN_DIGITS: "${OC_PASSWORD_POLICY_MIN_DIGITS:-1}"
|
||||||
OC_PASSWORD_POLICY_MIN_SPECIAL_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_SPECIAL_CHARACTERS:-1}"
|
OC_PASSWORD_POLICY_MIN_SPECIAL_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_SPECIAL_CHARACTERS:-1}"
|
||||||
|
# default language for services/WebUI; defaults to English, language code (ISO 639-1, e.g. de, en, fr)
|
||||||
# OCM
|
OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE}
|
||||||
OC_ENABLE_OCM: "true"
|
|
||||||
OCM_OCM_PROVIDER_AUTHORIZER_PROVIDERS_FILE: "/etc/opencloud/ocmproviders.json"
|
|
||||||
OCM_OCM_INVITE_MANAGER_INSECURE: "true"
|
|
||||||
OCM_OCM_SHARE_PROVIDER_INSECURE: "true"
|
|
||||||
OCM_OCM_STORAGE_PROVIDER_INSECURE: "true"
|
|
||||||
GRAPH_INCLUDE_OCM_SHAREES: "true"
|
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
|
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
|
||||||
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
|
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
|
||||||
- ./config/opencloud/opencloud.storage.ocmproviders.json:/etc/opencloud/ocmproviders.json
|
|
||||||
- ./config/opencloud/web.yaml:/etc/opencloud/web.yaml
|
|
||||||
# configure the .env file to use own paths instead of docker internal volumes
|
# configure the .env file to use own paths instead of docker internal volumes
|
||||||
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
||||||
- ${OC_DATA_DIR:-opencloud-data}:/var/lib/opencloud
|
- ${OC_DATA_DIR:-opencloud-data}:/var/lib/opencloud
|
||||||
- ${OC_APPS_DIR:-./config/opencloud/apps}:/var/lib/opencloud/web/assets/apps
|
- ${OC_APPS_DIR:-./config/opencloud/apps}:/var/lib/opencloud/web/assets/apps
|
||||||
|
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
restart: always
|
restart: always
|
||||||
|
|||||||
11
external-proxy/collabora-exposed.yml
Normal file
11
external-proxy/collabora-exposed.yml
Normal file
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
# only expose the ports when you know what you are doing!
|
||||||
|
services:
|
||||||
|
collaboration:
|
||||||
|
ports:
|
||||||
|
# expose the wopi server on all interfaces
|
||||||
|
- "0.0.0.0:9300:9300"
|
||||||
|
collabora:
|
||||||
|
ports:
|
||||||
|
# expose the collabora server on all interfaces
|
||||||
|
- "0.0.0.0:9980:9980"
|
||||||
@@ -2,9 +2,9 @@
|
|||||||
services:
|
services:
|
||||||
collaboration:
|
collaboration:
|
||||||
ports:
|
ports:
|
||||||
# expose the wopi server
|
# expose the wopi server on localhost
|
||||||
- "9300:9300"
|
- "127.0.0.1:9300:9300"
|
||||||
collabora:
|
collabora:
|
||||||
ports:
|
ports:
|
||||||
# expose the collabora server
|
# expose the collabora server on localhost
|
||||||
- "9980:9980"
|
- "127.0.0.1:9980:9980"
|
||||||
|
|||||||
8
external-proxy/keycloak-exposed.yml
Normal file
8
external-proxy/keycloak-exposed.yml
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
# only expose the ports when you know what you re doing!
|
||||||
|
services:
|
||||||
|
keycloak:
|
||||||
|
ports:
|
||||||
|
# expose the keycloak server on all interfaces
|
||||||
|
- "0.0.0.0:9000:9000"
|
||||||
|
- "0.0.0.0:8080:8080"
|
||||||
@@ -2,5 +2,6 @@
|
|||||||
services:
|
services:
|
||||||
keycloak:
|
keycloak:
|
||||||
ports:
|
ports:
|
||||||
- "9000:9000"
|
# expose the keycloak server on localhost
|
||||||
- "8080:8080"
|
- "127.0.0.1:9000:9000"
|
||||||
|
- "127.0.0.1:8080:8080"
|
||||||
|
|||||||
10
external-proxy/opencloud-exposed.yml
Normal file
10
external-proxy/opencloud-exposed.yml
Normal file
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
# only expose the ports when you know what you are doing!
|
||||||
|
services:
|
||||||
|
opencloud:
|
||||||
|
environment:
|
||||||
|
# bind to all interfaces
|
||||||
|
PROXY_HTTP_ADDR: "0.0.0.0:9200"
|
||||||
|
ports:
|
||||||
|
# expose the opencloud server on all interfaces
|
||||||
|
- "0.0.0.0:9200:9200"
|
||||||
@@ -5,5 +5,5 @@ services:
|
|||||||
# bind to all interfaces
|
# bind to all interfaces
|
||||||
PROXY_HTTP_ADDR: "0.0.0.0:9200"
|
PROXY_HTTP_ADDR: "0.0.0.0:9200"
|
||||||
ports:
|
ports:
|
||||||
# expose the opencloud server
|
# expose the opencloud server on localhost
|
||||||
- "9200:9200"
|
- "127.0.0.1:9200:9200"
|
||||||
|
|||||||
@@ -14,7 +14,17 @@ services:
|
|||||||
GRAPH_LDAP_REFINT_ENABLED: "true" # osixia has refint enabled.
|
GRAPH_LDAP_REFINT_ENABLED: "true" # osixia has refint enabled.
|
||||||
FRONTEND_READONLY_USER_ATTRIBUTES: "user.onPremisesSamAccountName,user.displayName,user.mail,user.passwordProfile,user.accountEnabled,user.appRoleAssignments"
|
FRONTEND_READONLY_USER_ATTRIBUTES: "user.onPremisesSamAccountName,user.displayName,user.mail,user.passwordProfile,user.accountEnabled,user.appRoleAssignments"
|
||||||
PROXY_OIDC_REWRITE_WELLKNOWN: "true"
|
PROXY_OIDC_REWRITE_WELLKNOWN: "true"
|
||||||
WEB_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID:-web}
|
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
|
||||||
|
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
|
||||||
|
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
|
||||||
|
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID}
|
||||||
|
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES}
|
||||||
|
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID}
|
||||||
|
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES}
|
||||||
|
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID}
|
||||||
|
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES}
|
||||||
|
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID}
|
||||||
|
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES}
|
||||||
PROXY_ROLE_ASSIGNMENT_DRIVER: "oidc"
|
PROXY_ROLE_ASSIGNMENT_DRIVER: "oidc"
|
||||||
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
||||||
# This specifies to start all services except idm and idp. These are replaced by external services.
|
# This specifies to start all services except idm and idp. These are replaced by external services.
|
||||||
@@ -44,7 +54,8 @@ services:
|
|||||||
# The openCloud users need to be able to edit their account in the externa IdP
|
# The openCloud users need to be able to edit their account in the externa IdP
|
||||||
WEB_OPTION_ACCOUNT_EDIT_LINK_HREF: ${IDP_ACCOUNT_URL}
|
WEB_OPTION_ACCOUNT_EDIT_LINK_HREF: ${IDP_ACCOUNT_URL}
|
||||||
ldap-server:
|
ldap-server:
|
||||||
image: bitnami/openldap:2.6
|
image: bitnamilegacy/openldap:2.6
|
||||||
|
# Bitnami images require GID 0 to write to internal socket and PID directories
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
entrypoint: [ "/bin/sh", "/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh", "/opt/bitnami/scripts/openldap/run.sh" ]
|
entrypoint: [ "/bin/sh", "/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh", "/opt/bitnami/scripts/openldap/run.sh" ]
|
||||||
@@ -57,9 +68,6 @@ services:
|
|||||||
LDAP_TLS_KEY_FILE: /opt/bitnami/openldap/share/openldap.key
|
LDAP_TLS_KEY_FILE: /opt/bitnami/openldap/share/openldap.key
|
||||||
LDAP_ROOT: "dc=opencloud,dc=eu"
|
LDAP_ROOT: "dc=opencloud,dc=eu"
|
||||||
LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin}
|
LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin}
|
||||||
ports:
|
|
||||||
- "127.0.0.1:389:1389"
|
|
||||||
- "127.0.0.1:636:1636"
|
|
||||||
volumes:
|
volumes:
|
||||||
# Only use the base ldif file to create the base structure
|
# Only use the base ldif file to create the base structure
|
||||||
- ./config/ldap/ldif/10_base.ldif:/ldifs/10_base.ldif
|
- ./config/ldap/ldif/10_base.ldif:/ldifs/10_base.ldif
|
||||||
@@ -68,6 +76,7 @@ services:
|
|||||||
- ./config/ldap/docker-entrypoint-override.sh:/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh
|
- ./config/ldap/docker-entrypoint-override.sh:/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh
|
||||||
- ${LDAP_CERTS_DIR:-ldap-certs}:/opt/bitnami/openldap/share
|
- ${LDAP_CERTS_DIR:-ldap-certs}:/opt/bitnami/openldap/share
|
||||||
- ${LDAP_DATA_DIR:-ldap-data}:/bitnami/openldap
|
- ${LDAP_DATA_DIR:-ldap-data}:/bitnami/openldap
|
||||||
|
restart: always
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
ldap-certs:
|
ldap-certs:
|
||||||
|
|||||||
@@ -23,19 +23,19 @@ services:
|
|||||||
# Keycloak IDP specific configuration
|
# Keycloak IDP specific configuration
|
||||||
PROXY_AUTOPROVISION_ACCOUNTS: "false"
|
PROXY_AUTOPROVISION_ACCOUNTS: "false"
|
||||||
PROXY_ROLE_ASSIGNMENT_DRIVER: "oidc"
|
PROXY_ROLE_ASSIGNMENT_DRIVER: "oidc"
|
||||||
OC_OIDC_ISSUER: https://${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}/realms/openCloud
|
OC_OIDC_ISSUER: https://${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/realms/openCloud
|
||||||
PROXY_OIDC_REWRITE_WELLKNOWN: "true"
|
PROXY_OIDC_REWRITE_WELLKNOWN: "true"
|
||||||
WEB_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID:-web}
|
WEB_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID:-web}
|
||||||
PROXY_USER_OIDC_CLAIM: "uuid"
|
PROXY_USER_OIDC_CLAIM: "uuid"
|
||||||
PROXY_USER_CS3_CLAIM: "userid"
|
PROXY_USER_CS3_CLAIM: "userid"
|
||||||
WEB_OPTION_ACCOUNT_EDIT_LINK_HREF: "https://${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}/realms/openCloud/account"
|
WEB_OPTION_ACCOUNT_EDIT_LINK_HREF: "https://${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/realms/openCloud/account"
|
||||||
# admin and demo accounts must be created in Keycloak
|
# admin and demo accounts must be created in Keycloak
|
||||||
OC_ADMIN_USER_ID: ""
|
OC_ADMIN_USER_ID: ""
|
||||||
SETTINGS_SETUP_DEFAULT_ASSIGNMENTS: "false"
|
SETTINGS_SETUP_DEFAULT_ASSIGNMENTS: "false"
|
||||||
GRAPH_ASSIGN_DEFAULT_USER_ROLE: "false"
|
GRAPH_ASSIGN_DEFAULT_USER_ROLE: "false"
|
||||||
GRAPH_USERNAME_MATCH: "none"
|
GRAPH_USERNAME_MATCH: "none"
|
||||||
# This is needed to set the correct CSP rules for OpenCloud
|
# This is needed to set the correct CSP rules for OpenCloud
|
||||||
IDP_DOMAIN: ${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}
|
IDP_DOMAIN: ${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
|
|
||||||
ldap-server:
|
ldap-server:
|
||||||
image: bitnamilegacy/openldap:2.6
|
image: bitnamilegacy/openldap:2.6
|
||||||
@@ -51,12 +51,11 @@ services:
|
|||||||
LDAP_TLS_KEY_FILE: /opt/bitnami/openldap/share/openldap.key
|
LDAP_TLS_KEY_FILE: /opt/bitnami/openldap/share/openldap.key
|
||||||
LDAP_ROOT: "dc=opencloud,dc=eu"
|
LDAP_ROOT: "dc=opencloud,dc=eu"
|
||||||
LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin}
|
LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin}
|
||||||
ports:
|
|
||||||
- "127.0.0.1:389:1389"
|
|
||||||
- "127.0.0.1:636:1636"
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./config/ldap/ldif/10_base.ldif:/ldifs/10_base.ldif
|
- ./config/ldap/ldif/10_base.ldif:/ldifs/10_base.ldif
|
||||||
- ./config/ldap/ldif/20_admin.ldif:/ldifs/20_admin.ldif
|
- ./config/ldap/ldif/20_admin.ldif:/ldifs/20_admin.ldif
|
||||||
|
- ./config/ldap/ldif/50_acls.ldif:/opt/bitnami/openldap/etc/schema/50_acls.ldif
|
||||||
|
- ./config/ldap/init-ldap-acls.sh:/docker-entrypoint-initdb.d/init-ldap-acls.sh
|
||||||
- ./config/ldap/docker-entrypoint-override.sh:/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh
|
- ./config/ldap/docker-entrypoint-override.sh:/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh
|
||||||
- ldap-certs:/opt/bitnami/openldap/share
|
- ldap-certs:/opt/bitnami/openldap/share
|
||||||
- ldap-data:/bitnami/openldap
|
- ldap-data:/bitnami/openldap
|
||||||
@@ -65,7 +64,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
postgres:
|
postgres:
|
||||||
image: postgres:alpine
|
image: postgres:17.9-alpine
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
volumes:
|
volumes:
|
||||||
@@ -79,7 +78,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.3.3
|
image: quay.io/keycloak/keycloak:26.6.1
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
@@ -90,13 +89,14 @@ services:
|
|||||||
- "./config/keycloak/themes/opencloud:/opt/keycloak/themes/opencloud"
|
- "./config/keycloak/themes/opencloud:/opt/keycloak/themes/opencloud"
|
||||||
environment:
|
environment:
|
||||||
LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin}
|
LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin}
|
||||||
OC_DOMAIN: ${OC_DOMAIN:-cloud.opencloud.test}
|
OC_DOMAIN: ${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
KC_HOSTNAME: ${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}
|
KC_HOSTNAME: ${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}
|
||||||
KC_DB: postgres
|
KC_DB: postgres
|
||||||
KC_DB_URL: "jdbc:postgresql://postgres:5432/keycloak"
|
KC_DB_URL: "jdbc:postgresql://postgres:5432/keycloak"
|
||||||
KC_DB_USERNAME: ${KC_DB_USERNAME:-keycloak}
|
KC_DB_USERNAME: ${KC_DB_USERNAME:-keycloak}
|
||||||
KC_DB_PASSWORD: ${KC_DB_PASSWORD:-keycloak}
|
KC_DB_PASSWORD: ${KC_DB_PASSWORD:-keycloak}
|
||||||
KC_FEATURES: impersonation
|
KC_FEATURES: impersonation
|
||||||
|
KC_LOG_LEVEL: ${KC_LOG_LEVEL:-INFO}
|
||||||
KC_PROXY_HEADERS: xforwarded
|
KC_PROXY_HEADERS: xforwarded
|
||||||
KC_HTTP_ENABLED: true
|
KC_HTTP_ENABLED: true
|
||||||
KEYCLOAK_ADMIN: ${KEYCLOAK_ADMIN:-kcadmin}
|
KEYCLOAK_ADMIN: ${KEYCLOAK_ADMIN:-kcadmin}
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ services:
|
|||||||
- ./config/opencloud/proxy.yaml:/etc/opencloud/proxy.yaml
|
- ./config/opencloud/proxy.yaml:/etc/opencloud/proxy.yaml
|
||||||
radicale:
|
radicale:
|
||||||
image: ${RADICALE_DOCKER_IMAGE:-opencloudeu/radicale}:${RADICALE_DOCKER_TAG:-latest}
|
image: ${RADICALE_DOCKER_IMAGE:-opencloudeu/radicale}:${RADICALE_DOCKER_TAG:-latest}
|
||||||
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
logging:
|
logging:
|
||||||
|
|||||||
43
renovate.json
Normal file
43
renovate.json
Normal file
@@ -0,0 +1,43 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||||
|
"platformAutomerge": true,
|
||||||
|
"enabledManagers": ["docker-compose", "custom.regex"],
|
||||||
|
"baseBranchPatterns": ["main", "stable-4.0"],
|
||||||
|
"packageRules": [
|
||||||
|
{
|
||||||
|
"matchManagers": ["docker-compose", "custom.regex"],
|
||||||
|
"labels": ["Type:Dependencies", "Bot:Renovate"]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"matchManagers": ["docker-compose"],
|
||||||
|
"matchUpdateTypes": ["patch"],
|
||||||
|
"automerge": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"matchBaseBranches": ["stable-4.0"],
|
||||||
|
"matchUpdateTypes": ["major", "minor"],
|
||||||
|
"enabled": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"matchPackageNames": ["postgres"],
|
||||||
|
"matchManagers": ["docker-compose"],
|
||||||
|
"allowedVersions": "/^17\\.\\d+-alpine$/"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"docker-compose": {
|
||||||
|
"managerFilePatterns": ["/.+\\.ya?ml$/"]
|
||||||
|
},
|
||||||
|
"customManagers": [
|
||||||
|
{
|
||||||
|
"customType": "regex",
|
||||||
|
"managerFilePatterns": [
|
||||||
|
"/^docker-compose\\.yml$/",
|
||||||
|
"/^weboffice\\/collabora\\.yml$/"
|
||||||
|
],
|
||||||
|
"matchStrings": [
|
||||||
|
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"
|
||||||
|
],
|
||||||
|
"datasourceTemplate": "docker"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -1,7 +1,10 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
tika:
|
tika:
|
||||||
image: ${TIKA_IMAGE:-apache/tika:latest-full}
|
image: ${TIKA_IMAGE:-apache/tika:latest}
|
||||||
|
# Using the base variant for smaller image size and faster startup
|
||||||
|
# The base variant includes core functionality for text extraction
|
||||||
|
# Full variant is only needed for specialized OCR/image processing
|
||||||
# release notes: https://tika.apache.org
|
# release notes: https://tika.apache.org
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
postgres:
|
postgres:
|
||||||
image: postgres:alpine
|
image: postgres:17.9-alpine
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
volumes:
|
volumes:
|
||||||
@@ -15,7 +15,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.3.3
|
image: quay.io/keycloak/keycloak:26.6.1
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
@@ -32,6 +32,7 @@ services:
|
|||||||
KC_DB_USERNAME: ${KC_DB_USERNAME:-keycloak}
|
KC_DB_USERNAME: ${KC_DB_USERNAME:-keycloak}
|
||||||
KC_DB_PASSWORD: ${KC_DB_PASSWORD:-keycloak}
|
KC_DB_PASSWORD: ${KC_DB_PASSWORD:-keycloak}
|
||||||
KC_FEATURES: impersonation
|
KC_FEATURES: impersonation
|
||||||
|
KC_LOG_LEVEL: ${KC_LOG_LEVEL:-INFO}
|
||||||
KC_PROXY_HEADERS: xforwarded
|
KC_PROXY_HEADERS: xforwarded
|
||||||
KC_HTTP_ENABLED: true
|
KC_HTTP_ENABLED: true
|
||||||
KEYCLOAK_ADMIN: ${KEYCLOAK_ADMIN:-kcadmin}
|
KEYCLOAK_ADMIN: ${KEYCLOAK_ADMIN:-kcadmin}
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ services:
|
|||||||
- "traefik.http.routers.collaboration.rule=Host(`${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}`)"
|
- "traefik.http.routers.collaboration.rule=Host(`${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}`)"
|
||||||
- "traefik.http.routers.collaboration.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
- "traefik.http.routers.collaboration.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
||||||
- "traefik.http.routers.collaboration.service=collaboration"
|
- "traefik.http.routers.collaboration.service=collaboration"
|
||||||
|
- "traefik.http.routers.collaboration.middlewares=hsts-header"
|
||||||
- "traefik.http.services.collaboration.loadbalancer.server.port=9300"
|
- "traefik.http.services.collaboration.loadbalancer.server.port=9300"
|
||||||
collabora:
|
collabora:
|
||||||
labels:
|
labels:
|
||||||
@@ -21,4 +22,5 @@ services:
|
|||||||
- "traefik.http.routers.collabora.rule=Host(`${COLLABORA_DOMAIN:-collabora.opencloud.test}`)"
|
- "traefik.http.routers.collabora.rule=Host(`${COLLABORA_DOMAIN:-collabora.opencloud.test}`)"
|
||||||
- "traefik.http.routers.collabora.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
- "traefik.http.routers.collabora.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
||||||
- "traefik.http.routers.collabora.service=collabora"
|
- "traefik.http.routers.collabora.service=collabora"
|
||||||
|
- "traefik.http.routers.collabora.middlewares=hsts-header"
|
||||||
- "traefik.http.services.collabora.loadbalancer.server.port=9980"
|
- "traefik.http.services.collabora.loadbalancer.server.port=9980"
|
||||||
|
|||||||
@@ -12,4 +12,5 @@ services:
|
|||||||
- "traefik.http.routers.keycloak.rule=Host(`${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}`)"
|
- "traefik.http.routers.keycloak.rule=Host(`${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}`)"
|
||||||
- "traefik.http.routers.keycloak.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
- "traefik.http.routers.keycloak.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
||||||
- "traefik.http.routers.keycloak.service=keycloak"
|
- "traefik.http.routers.keycloak.service=keycloak"
|
||||||
|
- "traefik.http.routers.keycloak.middlewares=hsts-header"
|
||||||
- "traefik.http.services.keycloak.loadbalancer.server.port=8080"
|
- "traefik.http.services.keycloak.loadbalancer.server.port=8080"
|
||||||
|
|||||||
@@ -3,14 +3,22 @@ services:
|
|||||||
opencloud:
|
opencloud:
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
|
# define middleware here, to make sure its loaded with the first defined container (opencloud)
|
||||||
|
# if defined in the traefik container with a disabled dashboard it won't be loaded fast enough
|
||||||
|
- "traefik.http.middlewares.hsts-header.headers.stsSeconds=31536000"
|
||||||
|
- "traefik.http.middlewares.hsts-header.headers.stsIncludeSubdomains=true"
|
||||||
|
- "traefik.http.middlewares.hsts-header.headers.stsPreload=true"
|
||||||
|
- "traefik.http.middlewares.hsts-header.headers.forceSTSHeader=true"
|
||||||
- "traefik.http.routers.opencloud.entrypoints=https"
|
- "traefik.http.routers.opencloud.entrypoints=https"
|
||||||
- "traefik.http.routers.opencloud.rule=Host(`${OC_DOMAIN:-cloud.opencloud.test}`)"
|
- "traefik.http.routers.opencloud.rule=Host(`${OC_DOMAIN:-cloud.opencloud.test}`)"
|
||||||
- "traefik.http.routers.opencloud.service=opencloud"
|
- "traefik.http.routers.opencloud.service=opencloud"
|
||||||
|
- "traefik.http.routers.opencloud.middlewares=hsts-header"
|
||||||
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
|
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
|
||||||
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
||||||
traefik:
|
traefik:
|
||||||
image: traefik:v3
|
image: traefik:v3.6.14
|
||||||
# release notes: https://github.com/traefik/traefik/releases
|
# release notes: https://github.com/traefik/traefik/releases
|
||||||
|
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
aliases:
|
aliases:
|
||||||
@@ -22,9 +30,11 @@ services:
|
|||||||
- "TRAEFIK_ACME_CASERVER=${TRAEFIK_ACME_CASERVER:-https://acme-v02.api.letsencrypt.org/directory}"
|
- "TRAEFIK_ACME_CASERVER=${TRAEFIK_ACME_CASERVER:-https://acme-v02.api.letsencrypt.org/directory}"
|
||||||
- "TRAEFIK_LOG_LEVEL=${TRAEFIK_LOG_LEVEL:-ERROR}"
|
- "TRAEFIK_LOG_LEVEL=${TRAEFIK_LOG_LEVEL:-ERROR}"
|
||||||
- "TRAEFIK_ACCESS_LOG=${TRAEFIK_ACCESS_LOG:-false}"
|
- "TRAEFIK_ACCESS_LOG=${TRAEFIK_ACCESS_LOG:-false}"
|
||||||
|
- "TRAEFIK_PORT_HTTP=${TRAEFIK_PORT_HTTP:-80}"
|
||||||
|
- "TRAEFIK_PORT_HTTPS=${TRAEFIK_PORT_HTTPS:-443}"
|
||||||
ports:
|
ports:
|
||||||
- "80:80"
|
- "${TRAEFIK_PORT_HTTP:-80}:${TRAEFIK_PORT_HTTP:-80}"
|
||||||
- "443:443"
|
- "${TRAEFIK_PORT_HTTPS:-443}:${TRAEFIK_PORT_HTTPS:-443}"
|
||||||
volumes:
|
volumes:
|
||||||
- "${DOCKER_SOCKET_PATH:-/var/run/docker.sock}:/var/run/docker.sock:ro"
|
- "${DOCKER_SOCKET_PATH:-/var/run/docker.sock}:/var/run/docker.sock:ro"
|
||||||
- "./config/traefik/docker-entrypoint-override.sh:/opt/traefik/bin/docker-entrypoint-override.sh"
|
- "./config/traefik/docker-entrypoint-override.sh:/opt/traefik/bin/docker-entrypoint-override.sh"
|
||||||
|
|||||||
@@ -5,15 +5,18 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
# this is needed for setting the correct CSP header
|
# this is needed for setting the correct CSP header
|
||||||
COLLABORA_DOMAIN: ${COLLABORA_DOMAIN:-collabora.opencloud.test}
|
COLLABORA_DOMAIN: ${COLLABORA_DOMAIN:-collabora.opencloud.test}
|
||||||
|
TRAEFIK_PORT_HTTPS: ${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
# expose nats and the reva gateway for the collaboration service
|
# expose nats and the reva gateway for the collaboration service
|
||||||
NATS_NATS_HOST: 0.0.0.0
|
NATS_NATS_HOST: 0.0.0.0
|
||||||
GATEWAY_GRPC_ADDR: 0.0.0.0:9142
|
GATEWAY_GRPC_ADDR: 0.0.0.0:9142
|
||||||
# make collabora the secure view app
|
# make collabora the secure view app
|
||||||
FRONTEND_APP_HANDLER_SECURE_VIEW_APP_ADDR: eu.opencloud.api.collaboration.CollaboraOnline
|
FRONTEND_APP_HANDLER_SECURE_VIEW_APP_ADDR: eu.opencloud.api.collaboration
|
||||||
GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6"
|
GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6"
|
||||||
|
|
||||||
collaboration:
|
collaboration:
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-latest}
|
# renovate: depName=opencloudeu/opencloud-rolling
|
||||||
|
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.1.0}
|
||||||
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
depends_on:
|
depends_on:
|
||||||
@@ -29,15 +32,15 @@ services:
|
|||||||
COLLABORATION_HTTP_ADDR: 0.0.0.0:9300
|
COLLABORATION_HTTP_ADDR: 0.0.0.0:9300
|
||||||
MICRO_REGISTRY: "nats-js-kv"
|
MICRO_REGISTRY: "nats-js-kv"
|
||||||
MICRO_REGISTRY_ADDRESS: "opencloud:9233"
|
MICRO_REGISTRY_ADDRESS: "opencloud:9233"
|
||||||
COLLABORATION_WOPI_SRC: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}
|
COLLABORATION_WOPI_SRC: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
COLLABORATION_APP_NAME: "CollaboraOnline"
|
COLLABORATION_APP_NAME: "CollaboraOnline"
|
||||||
COLLABORATION_APP_PRODUCT: "Collabora"
|
COLLABORATION_APP_PRODUCT: "Collabora"
|
||||||
COLLABORATION_APP_ADDR: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}
|
COLLABORATION_APP_ADDR: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
COLLABORATION_APP_ICON: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}/favicon.ico
|
COLLABORATION_APP_ICON: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/favicon.ico
|
||||||
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
||||||
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
||||||
COLLABORATION_LOG_LEVEL: ${LOG_LEVEL:-info}
|
COLLABORATION_LOG_LEVEL: ${LOG_LEVEL:-info}
|
||||||
OC_URL: https://${OC_DOMAIN:-cloud.opencloud.test}
|
OC_URL: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
volumes:
|
volumes:
|
||||||
# configure the .env file to use own paths instead of docker internal volumes
|
# configure the .env file to use own paths instead of docker internal volumes
|
||||||
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
||||||
@@ -46,28 +49,38 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
collabora:
|
collabora:
|
||||||
image: collabora/code:25.04.4.2.1
|
image: collabora/code:25.04.9.4.1
|
||||||
# release notes: https://www.collaboraonline.com/release-notes/
|
# release notes: https://www.collaboraonline.com/release-notes/
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
environment:
|
environment:
|
||||||
aliasgroup1: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}:443
|
aliasgroup1: https://${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
DONT_GEN_SSL_CERT: "YES"
|
DONT_GEN_SSL_CERT: "YES"
|
||||||
extra_params: |
|
extra_params: |
|
||||||
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \
|
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \
|
||||||
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \
|
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \
|
||||||
--o:ssl.termination=true \
|
--o:ssl.termination=true \
|
||||||
--o:welcome.enable=false \
|
--o:welcome.enable=false \
|
||||||
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}
|
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
||||||
|
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
||||||
|
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
||||||
username: ${COLLABORA_ADMIN_USER:-admin}
|
username: ${COLLABORA_ADMIN_USER:-admin}
|
||||||
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
||||||
cap_add:
|
cap_add:
|
||||||
- MKNOD
|
- SYS_ADMIN
|
||||||
|
security_opt:
|
||||||
|
- seccomp=unconfined
|
||||||
|
- apparmor:unconfined
|
||||||
|
volumes:
|
||||||
|
# Mount local TrueType fonts so the container can use system fonts
|
||||||
|
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
||||||
|
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
||||||
|
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
restart: always
|
restart: always
|
||||||
entrypoint: ['/bin/bash', '-c']
|
entrypoint: [ '/bin/bash', '-c' ]
|
||||||
command: ['coolconfig generate-proof-key && /start-collabora-online.sh']
|
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ]
|
test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ]
|
||||||
interval: 15s
|
interval: 15s
|
||||||
|
|||||||
Reference in New Issue
Block a user