Compare commits

..

47 Commits

Author SHA1 Message Date
Michael Barz
f0b1565edb Merge pull request #273 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.1 (main)
2026-04-16 18:01:27 +02:00
renovate[bot]
892839eace chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.1 2026-04-16 10:53:05 +00:00
Michael Barz
6da37f5ba5 Merge pull request #265 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.6.13 (main)
2026-04-08 15:49:34 +02:00
renovate[bot]
b6bde225d4 chore(deps): update traefik docker tag to v3.6.13 2026-04-08 13:45:08 +00:00
Michael Barz
4f1ff44446 Merge pull request #268 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.0 (main)
2026-04-08 15:44:41 +02:00
renovate[bot]
8ac4a770a6 chore(deps): update quay.io/keycloak/keycloak docker tag to v26.6.0 2026-04-08 13:37:20 +00:00
Michael Barz
6008e82a84 Merge pull request #255 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.6.12 (main)
2026-04-07 11:16:51 +02:00
renovate[bot]
c600ac4988 chore(deps): update traefik docker tag to v3.6.12 2026-04-07 08:58:16 +00:00
Michael Barz
1f5991578b Merge pull request #261 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.5.7 (main)
2026-04-07 10:57:02 +02:00
renovate[bot]
376f06c4e3 chore(deps): update quay.io/keycloak/keycloak docker tag to v26.5.7 2026-04-02 17:08:08 +00:00
Thomas Schweiger
6ab45a8594 Merge pull request #259 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-6.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v6 (main)
2026-04-02 10:03:00 +02:00
renovate[bot]
938faf9a53 chore(deps): update opencloudeu/opencloud-rolling docker tag to v6 2026-03-31 14:17:33 +00:00
Michael Barz
1e23a63910 Merge pull request #252 from opencloud-eu/renovate/main-collabora-code-25.x
chore(deps): update collabora/code docker tag to v25.04.9.4.1 (main)
2026-03-25 09:29:41 +01:00
renovate[bot]
39a3bcd45d chore(deps): update collabora/code docker tag to v25.04.9.4.1 2026-03-25 08:29:24 +00:00
Michael Barz
932e794fd2 Merge pull request #249 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.5.6 (main)
2026-03-25 09:29:08 +01:00
renovate[bot]
279b2cde68 chore(deps): update quay.io/keycloak/keycloak docker tag to v26.5.6 2026-03-25 08:28:42 +00:00
Michael Barz
4cbeb8ea38 Merge pull request #250 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.6.11 (main)
2026-03-25 09:28:02 +01:00
renovate[bot]
1c94d436e4 chore(deps): update traefik docker tag to v3.6.11 2026-03-19 21:51:02 +00:00
Michael Barz
2b1476950b Merge pull request #247 from opencloud-eu/renovate/main-collabora-code-25.x
chore(deps): update collabora/code docker tag to v25.04.9.3.1 (main)
2026-03-17 08:48:36 +01:00
renovate[bot]
8a30076bc0 chore(deps): update collabora/code docker tag to v25.04.9.3.1 2026-03-16 17:30:11 +00:00
Viktor Scharf
bfd87b4bc0 Merge pull request #245 from opencloud-eu/demo-users-for-keycloak-ldap-setup
add optional demo users for ldap-keycloak setup
2026-03-12 08:15:50 +01:00
Viktor Scharf
060f8d09ca add optional demo users for ldap-keycloak setup 2026-03-11 14:16:34 +01:00
Michael Flemming
ec431ee2f8 Merge pull request #244 from opencloud-eu/flimmy-patch-2
Update OC_DOCKER_TAG comment in .env.example
2026-03-10 11:19:10 +01:00
Michael Flemming
2075573ac5 Update OC_DOCKER_TAG comment in .env.example
Updated comment for OC_DOCKER_TAG as it does not default to "latest".
2026-03-10 11:17:07 +01:00
Michael Flemming
c5f235a54e Merge pull request #242 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-5.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v5.2.0 (main)
2026-03-10 11:12:50 +01:00
renovate[bot]
daabcb9515 chore(deps): update opencloudeu/opencloud-rolling docker tag to v5.2.0 2026-03-09 17:12:28 +00:00
Michael Barz
b3c2b06b5f Merge pull request #240 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.6.10 (main)
2026-03-07 08:01:49 +01:00
renovate[bot]
a5c06c10cc chore(deps): update traefik docker tag to v3.6.10 2026-03-06 21:45:32 +00:00
Michael Barz
61e128d975 Merge pull request #239 from opencloud-eu/renovate/main-quay.io-keycloak-keycloak-26.x
chore(deps): update quay.io/keycloak/keycloak docker tag to v26.5.5 (main)
2026-03-05 19:44:04 +01:00
renovate[bot]
958b21d80a chore(deps): update quay.io/keycloak/keycloak docker tag to v26.5.5 2026-03-05 18:32:46 +00:00
Michael Barz
93fa72b3a8 Merge pull request #228 from opencloud-eu/add-hsts
feat: add hsts
2026-03-04 11:31:39 +01:00
Michael Barz
94db919f1d Merge pull request #236 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-5.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v5.1.0 (main)
2026-03-04 11:30:16 +01:00
renovate[bot]
33c3861012 chore(deps): update opencloudeu/opencloud-rolling docker tag to v5.1.0 2026-03-04 10:28:57 +00:00
Michael Barz
bc2b6b4a90 fix: regex match string
fix: regex match string

fix: regex match string

fix: plaform merge

fix: labels

fix: labels 2
2026-03-04 11:28:31 +01:00
Michael Barz
d146f60855 feat: pin version, add renovate 2026-03-04 11:28:29 +01:00
Michael 'Flimmy' Flemming
85e2c4aa35 fix middleware race condition with disabled dashboard 2026-03-04 10:56:57 +01:00
Michael Barz
70fa25573f Merge pull request #230 from opencloud-eu/renovate/main-traefik-3.x
chore(deps): update traefik docker tag to v3.6.9 (main)
2026-03-03 21:59:30 +01:00
renovate[bot]
55035e0a81 chore(deps): update traefik docker tag to v3.6.9 2026-03-03 20:58:46 +00:00
Michael Barz
8f09fd66fd fix: automerge config 2026-03-03 21:56:16 +01:00
Michael Barz
1dbce867e1 fix: pin postgres version 2026-03-03 21:48:32 +01:00
Michael Barz
d0a9e71a89 Merge pull request #229 from opencloud-eu/renovate/main-collabora-code-25.x
chore(deps): update collabora/code docker tag to v25.04.9.2.1 (main)
2026-03-03 17:18:37 +01:00
renovate[bot]
634c95d5ed chore(deps): update collabora/code docker tag to v25.04.9.2.1 2026-03-03 16:15:38 +00:00
Michael Barz
820ce2747f chore: add renovate config 2026-03-03 17:12:08 +01:00
Michael Barz
1eeabd5bcb feat: add hsts 2026-03-03 16:14:36 +01:00
Viktor Scharf
69b1555af9 Merge pull request #227 from opencloud-eu/update-keycloak
chore: update keycloak to 26.5.4
2026-03-02 11:40:35 +01:00
Michael Barz
f480b7d6ed chore: update keycloak to 26.5.4 2026-03-02 11:34:25 +01:00
Ralf Haferkamp
25af2c9f6f Merge pull request #223 from opencloud-eu/fix-slow-jailkit
fix: slow kit jail error server audit in collabora (next try)
2026-02-17 16:50:18 +01:00
9 changed files with 76 additions and 9 deletions

View File

@@ -85,7 +85,7 @@ TRAEFIK_LOG_LEVEL=
# Defaults to production if not set otherwise # Defaults to production if not set otherwise
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling
# The openCloud container version. # The openCloud container version.
# Defaults to "latest" and points to the latest stable tag. # Defaults to the latest version-tag. Use git pull to update.
OC_DOCKER_TAG= OC_DOCKER_TAG=
# The default id used in opencloud containers is 1000 for user and group. # The default id used in opencloud containers is 1000 for user and group.
# If you want to change the default, use the following variable and the format [UID]:[GID]. # If you want to change the default, use the following variable and the format [UID]:[GID].
@@ -330,6 +330,18 @@ KC_DB_USERNAME=
# Keycloak Database password. Defaults to "keycloak". # Keycloak Database password. Defaults to "keycloak".
KC_DB_PASSWORD= KC_DB_PASSWORD=
## Demo Users ##
# Enable demo users and groups in the shared LDAP directory.
# To enable, create custom/ldap-keycloak-demo-users.yml with:
# services:
# ldap-server:
# volumes:
# - ./config/ldap/ldif/30_demo_users.ldif:/ldifs/30_demo_users.ldif
# - ./config/ldap/ldif/40_demo_groups.ldif:/ldifs/40_demo_groups.ldif
#
# Then add it to: COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml:custom/ldap-keycloak-demo-users.yml
# WARNING: Do not use in production.
### Radicale Setting ### ### Radicale Setting ###
# Radicale is a small open-source CalDAV (calendars, to-do lists) and CardDAV (contacts) server. # Radicale is a small open-source CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
# When enabled OpenCloud is configured as a reverse proxy for Radicale, providing all authenticated # When enabled OpenCloud is configured as a reverse proxy for Radicale, providing all authenticated

View File

@@ -1,7 +1,8 @@
--- ---
services: services:
opencloud: opencloud:
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-latest} # renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.0.0}
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog # changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html # release notes: https://docs.opencloud.eu/opencloud_release_notes.html
user: ${OC_CONTAINER_UID_GID:-1000:1000} user: ${OC_CONTAINER_UID_GID:-1000:1000}

View File

@@ -64,7 +64,7 @@ services:
restart: always restart: always
postgres: postgres:
image: postgres:17-alpine image: postgres:17.9-alpine
networks: networks:
opencloud-net: opencloud-net:
volumes: volumes:
@@ -78,7 +78,7 @@ services:
restart: always restart: always
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.3.3 image: quay.io/keycloak/keycloak:26.6.1
networks: networks:
opencloud-net: opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ] command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

43
renovate.json Normal file
View File

@@ -0,0 +1,43 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"platformAutomerge": true,
"enabledManagers": ["docker-compose", "custom.regex"],
"baseBranchPatterns": ["main", "stable-4.0"],
"packageRules": [
{
"matchManagers": ["docker-compose", "custom.regex"],
"labels": ["Type:Dependencies", "Bot:Renovate"]
},
{
"matchManagers": ["docker-compose"],
"matchUpdateTypes": ["patch"],
"automerge": true
},
{
"matchBaseBranches": ["stable-4.0"],
"matchUpdateTypes": ["major", "minor"],
"enabled": false
},
{
"matchPackageNames": ["postgres"],
"matchManagers": ["docker-compose"],
"allowedVersions": "/^17\\.\\d+-alpine$/"
}
],
"docker-compose": {
"managerFilePatterns": ["/.+\\.ya?ml$/"]
},
"customManagers": [
{
"customType": "regex",
"managerFilePatterns": [
"/^docker-compose\\.yml$/",
"/^weboffice\\/collabora\\.yml$/"
],
"matchStrings": [
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"
],
"datasourceTemplate": "docker"
}
]
}

View File

@@ -1,7 +1,7 @@
--- ---
services: services:
postgres: postgres:
image: postgres:17-alpine image: postgres:17.9-alpine
networks: networks:
opencloud-net: opencloud-net:
volumes: volumes:
@@ -15,7 +15,7 @@ services:
restart: always restart: always
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.3.3 image: quay.io/keycloak/keycloak:26.6.1
networks: networks:
opencloud-net: opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ] command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -13,6 +13,7 @@ services:
- "traefik.http.routers.collaboration.rule=Host(`${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}`)" - "traefik.http.routers.collaboration.rule=Host(`${WOPISERVER_DOMAIN:-wopiserver.opencloud.test}`)"
- "traefik.http.routers.collaboration.${TRAEFIK_SERVICES_TLS_CONFIG}" - "traefik.http.routers.collaboration.${TRAEFIK_SERVICES_TLS_CONFIG}"
- "traefik.http.routers.collaboration.service=collaboration" - "traefik.http.routers.collaboration.service=collaboration"
- "traefik.http.routers.collaboration.middlewares=hsts-header"
- "traefik.http.services.collaboration.loadbalancer.server.port=9300" - "traefik.http.services.collaboration.loadbalancer.server.port=9300"
collabora: collabora:
labels: labels:
@@ -21,4 +22,5 @@ services:
- "traefik.http.routers.collabora.rule=Host(`${COLLABORA_DOMAIN:-collabora.opencloud.test}`)" - "traefik.http.routers.collabora.rule=Host(`${COLLABORA_DOMAIN:-collabora.opencloud.test}`)"
- "traefik.http.routers.collabora.${TRAEFIK_SERVICES_TLS_CONFIG}" - "traefik.http.routers.collabora.${TRAEFIK_SERVICES_TLS_CONFIG}"
- "traefik.http.routers.collabora.service=collabora" - "traefik.http.routers.collabora.service=collabora"
- "traefik.http.routers.collabora.middlewares=hsts-header"
- "traefik.http.services.collabora.loadbalancer.server.port=9980" - "traefik.http.services.collabora.loadbalancer.server.port=9980"

View File

@@ -12,4 +12,5 @@ services:
- "traefik.http.routers.keycloak.rule=Host(`${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}`)" - "traefik.http.routers.keycloak.rule=Host(`${KEYCLOAK_DOMAIN:-keycloak.opencloud.test}`)"
- "traefik.http.routers.keycloak.${TRAEFIK_SERVICES_TLS_CONFIG}" - "traefik.http.routers.keycloak.${TRAEFIK_SERVICES_TLS_CONFIG}"
- "traefik.http.routers.keycloak.service=keycloak" - "traefik.http.routers.keycloak.service=keycloak"
- "traefik.http.routers.keycloak.middlewares=hsts-header"
- "traefik.http.services.keycloak.loadbalancer.server.port=8080" - "traefik.http.services.keycloak.loadbalancer.server.port=8080"

View File

@@ -3,13 +3,20 @@ services:
opencloud: opencloud:
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
# define middleware here, to make sure its loaded with the first defined container (opencloud)
# if defined in the traefik container with a disabled dashboard it won't be loaded fast enough
- "traefik.http.middlewares.hsts-header.headers.stsSeconds=31536000"
- "traefik.http.middlewares.hsts-header.headers.stsIncludeSubdomains=true"
- "traefik.http.middlewares.hsts-header.headers.stsPreload=true"
- "traefik.http.middlewares.hsts-header.headers.forceSTSHeader=true"
- "traefik.http.routers.opencloud.entrypoints=https" - "traefik.http.routers.opencloud.entrypoints=https"
- "traefik.http.routers.opencloud.rule=Host(`${OC_DOMAIN:-cloud.opencloud.test}`)" - "traefik.http.routers.opencloud.rule=Host(`${OC_DOMAIN:-cloud.opencloud.test}`)"
- "traefik.http.routers.opencloud.service=opencloud" - "traefik.http.routers.opencloud.service=opencloud"
- "traefik.http.routers.opencloud.middlewares=hsts-header"
- "traefik.http.services.opencloud.loadbalancer.server.port=9200" - "traefik.http.services.opencloud.loadbalancer.server.port=9200"
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}" - "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
traefik: traefik:
image: traefik:v3.6.7 image: traefik:v3.6.13
# release notes: https://github.com/traefik/traefik/releases # release notes: https://github.com/traefik/traefik/releases
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0} user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
networks: networks:

View File

@@ -14,7 +14,8 @@ services:
GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6" GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6"
collaboration: collaboration:
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-latest} # renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.0.0}
user: ${OC_CONTAINER_UID_GID:-1000:1000} user: ${OC_CONTAINER_UID_GID:-1000:1000}
networks: networks:
opencloud-net: opencloud-net:
@@ -48,7 +49,7 @@ services:
restart: always restart: always
collabora: collabora:
image: collabora/code:25.04.9.1.1 image: collabora/code:25.04.9.4.1
# release notes: https://www.collaboraonline.com/release-notes/ # release notes: https://www.collaboraonline.com/release-notes/
networks: networks:
opencloud-net: opencloud-net: