Compare commits

..

1 Commits

Author SHA1 Message Date
renovate[bot]
958265f12e chore(deps): update traefik docker tag to v3.7.11 2026-08-21 08:03:09 +00:00
12 changed files with 16 additions and 77 deletions

View File

@@ -10,24 +10,24 @@ INSECURE=true
## Features ##
# The following variable is a convenience variable to enable or disable features of this compose project.
# Example: if you want to use traefik and letsencrypt, you can set the variable to
#COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:traefik/opencloud.yml
#COMPOSE_FILE=docker-compose.yml:traefik/opencloud.yml
# This enables you to just run `docker compose up -d` and the compose files will be added to the stack.
# As alternative approach you can run `docker compose -f docker-compose.yml -f docker-compose.traefik.yml up -d`
# Default: OpenCloud and Collabora with traefik and letsencypt
# This needs DNS entries for the domain names used in the .env file.
#COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml
# If you want to use the external proxy, you can use the following combination.
# DNS entries and certificates need to be managed by the external environment.
# The domain names need to be entered into the .env file.
#COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:external-proxy/opencloud.yml:external-proxy/collabora.yml
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:external-proxy/opencloud.yml:external-proxy/collabora.yml
# Keycloak Shared User Directory
#COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml
# External IDP
#COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
# Euro Office with traefik and letsencrypt
#COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
# Euro Office with external proxy (Nginx, Caddy, etc.)
#COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
## Traefik Settings ##
# Note: Traefik is always enabled and can't be disabled.
@@ -383,23 +383,9 @@ KC_DB_PASSWORD=
# - ./config/ldap/ldif/30_demo_users.ldif:/ldifs/30_demo_users.ldif
# - ./config/ldap/ldif/40_demo_groups.ldif:/ldifs/40_demo_groups.ldif
#
# Then add it to: COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml:custom/ldap-keycloak-demo-users.yml
# Then add it to: COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml:custom/ldap-keycloak-demo-users.yml
# WARNING: Do not use in production.
### Yjs Settings ###
# The yjs server relays updates between users editing the same file.
# It is enabled by default via yjs/yjs.yml in the COMPOSE_FILE variable.
# The browser reaches it under https://{OC_DOMAIN}/yjs, the OpenCloud proxy forwards it.
# Docker image to use for the yjs container.
#YJS_DOCKER_IMAGE=opencloudeu/yjs
# Docker tag to pull for the yjs container.
#YJS_DOCKER_TAG=
# URL the yjs server uses to reach OpenCloud. Defaults to "http://opencloud:9200".
#YJS_OPENCLOUD_URL=
# Grace period in milliseconds for a graceful shutdown. Defaults to "15000".
# Keep it below the stop_grace_period set in yjs/yjs.yml.
#YJS_SHUTDOWN_GRACE_PERIOD_MS=
### Radicale Setting ###
# Radicale is a small open-source CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
# When enabled OpenCloud is configured as a reverse proxy for Radicale, providing all authenticated

View File

@@ -195,22 +195,6 @@ By default, OpenCloud Compose uses `apache/tika:latest` which provides:
The base variant is recommended for most use cases. If you need advanced features like specialized OCR processing or specific image format support, you can override the image by setting `TIKA_IMAGE=apache/tika:latest-full` in your `.env` file.
### With the Yjs Server
The yjs server enables collaborative editing of files. The browser connects to `wss://{OC_DOMAIN}/yjs`. The OpenCloud proxy forwards this route to the yjs container, so no extra DNS entry or port is needed.
Using `-f` flags:
```bash
docker compose -f docker-compose.yml -f yjs/yjs.yml -f traefik/opencloud.yml up -d
```
Or by setting in `.env`:
```
COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:traefik/opencloud.yml
```
The service keeps documents in memory only. All users of one file must reach the same instance, so run a single instance.
### With Radicale
Enable CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
@@ -482,7 +466,6 @@ This repository uses a modular approach with multiple compose files:
- `traefik/` - Traefik reverse proxy configurations
- `external-proxy/` - Configuration for external reverse proxies
- `radicale/` - Radicale configuration
- `yjs/` - Yjs server configuration (collaborative editing)
- `config/` - Configuration files for OpenCloud, Keycloak, and LDAP
## Advanced Usage

View File

@@ -49,7 +49,6 @@ directives:
style-src:
- '''self'''
- '''unsafe-inline'''
- 'blob:'
worker-src:
- "'self'"
- 'blob:'

View File

@@ -1,13 +1,9 @@
# This adds additional routes to the proxy. Forwarding
# This adds four additional routes to the proxy. Forwarding
# request on '/carddav/', '/caldav/' and the respective '/.well-knwown'
# endpoints to the radicale container and setting the required headers.
# '/yjs' is forwarded to the yjs container.
additional_policies:
- name: default
routes:
- endpoint: /yjs
backend: http://yjs:1234
unprotected: true
- endpoint: /caldav/
backend: http://radicale:5232
remote_user_header: X-Remote-User

View File

@@ -2,7 +2,7 @@
services:
opencloud:
# renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-8.1.0}
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.4.0}
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
user: ${OC_CONTAINER_UID_GID:-1000:1000}

View File

@@ -78,7 +78,7 @@ services:
restart: always
keycloak:
image: quay.io/keycloak/keycloak:26.8.0
image: quay.io/keycloak/keycloak:26.7.1
networks:
opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -33,8 +33,7 @@
"customType": "regex",
"managerFilePatterns": [
"/^docker-compose\\.yml$/",
"/^weboffice\\/collabora\\.yml$/",
"/^yjs\\/yjs\\.yml$/"
"/^weboffice\\/collabora\\.yml$/"
],
"matchStrings": [
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"

View File

@@ -15,7 +15,7 @@ services:
restart: always
keycloak:
image: quay.io/keycloak/keycloak:26.8.0
image: quay.io/keycloak/keycloak:26.7.1
networks:
opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -16,7 +16,7 @@ services:
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
traefik:
image: traefik:v3.7.13
image: traefik:v3.7.11
# release notes: https://github.com/traefik/traefik/releases
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
networks:

View File

@@ -29,7 +29,7 @@ services:
# To rotate the key, remove the volume and start again:
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
collabora-proof-key:
image: alpine/openssl:3.5.9
image: alpine/openssl:3.5.7
entrypoint: ["/bin/sh"]
command:
- -ec
@@ -50,7 +50,7 @@ services:
restart: "no"
collabora:
image: collabora/code:26.04.4.2.1
image: collabora/code:26.04.3.1.1
# release notes: https://www.collaboraonline.com/release-notes/
networks:
opencloud-net:

View File

@@ -32,7 +32,6 @@ services:
WOPI_ENABLED: "true"
# self-signed certificates
USE_UNAUTHORIZED_STORAGE: "${INSECURE:-false}"
JWT_SECRET: "${EURO_OFFICE_JWT_SECRET}"
volumes:
# Mount local TrueType fonts so the container can use system fonts
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).

View File

@@ -1,23 +0,0 @@
---
services:
opencloud:
environment:
WEB_OPTION_YJS_SERVER_URL: wss://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/yjs
volumes:
# the /yjs route is configured in the proxy
- ./config/opencloud/proxy.yaml:/etc/opencloud/proxy.yaml
yjs:
# renovate: depName=opencloudeu/yjs
image: ${YJS_DOCKER_IMAGE:-opencloudeu/yjs}:${YJS_DOCKER_TAG:-1.1.0}
user: ${OC_CONTAINER_UID_GID:-1000:1000}
networks:
opencloud-net:
environment:
PORT: '1234'
# internal address, no TLS between the containers
OPENCLOUD_URL: ${YJS_OPENCLOUD_URL:-http://opencloud:9200}
SHUTDOWN_GRACE_PERIOD_MS: '${YJS_SHUTDOWN_GRACE_PERIOD_MS:-15000}'
logging:
driver: ${LOG_DRIVER:-local}
restart: always
stop_grace_period: 20s