mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-10-07 11:28:15 +08:00
Compare commits
31 Commits
radicale-c
...
6725f45749
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6725f45749 | ||
|
|
c213706dfa | ||
|
|
848fd1f628 | ||
|
|
3509a0abc0 | ||
|
|
cc03dce3b2 | ||
|
|
4f6d691f16 | ||
|
|
8efca76bdb | ||
|
|
b5baab2b00 | ||
|
|
21467e4f1a | ||
|
|
a930989ec7 | ||
|
|
6ff4fb4417 | ||
|
|
68a2f53ef2 | ||
|
|
fffb04bac2 | ||
|
|
c72832dc8a | ||
|
|
32d9e5fb50 | ||
|
|
e6256ebadb | ||
|
|
8b271811a6 | ||
|
|
40882d6f8f | ||
|
|
2ec04b4466 | ||
|
|
2c72369d24 | ||
|
|
6d3a1f8c49 | ||
|
|
cc1471e467 | ||
|
|
300fc4779b | ||
|
|
12efcc9e91 | ||
|
|
cd22ba6f6e | ||
|
|
23f4b6eefe | ||
|
|
225740f7d4 | ||
|
|
f74c434267 | ||
|
|
e2c680ea6b | ||
|
|
b0fdcec0a3 | ||
|
|
a0f9ffbc6f |
@@ -25,9 +25,9 @@ INSECURE=true
|
|||||||
# External IDP
|
# External IDP
|
||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
|
||||||
# Euro Office with traefik and letsencrypt
|
# Euro Office with traefik and letsencrypt
|
||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:traefik/opencloud.yml:traefik/euroffice.yml
|
||||||
# Euro Office with external proxy (Nginx, Caddy, etc.)
|
# Euro Office with external proxy (Nginx, Caddy, etc.)
|
||||||
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
|
#COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:external-proxy/opencloud.yml:external-proxy/euroffice.yml
|
||||||
|
|
||||||
## Traefik Settings ##
|
## Traefik Settings ##
|
||||||
# Note: Traefik is always enabled and can't be disabled.
|
# Note: Traefik is always enabled and can't be disabled.
|
||||||
@@ -87,7 +87,7 @@ TRAEFIK_LOG_LEVEL=
|
|||||||
# For production releases: "opencloudeu/opencloud"
|
# For production releases: "opencloudeu/opencloud"
|
||||||
# For rolling releases: "opencloudeu/opencloud-rolling"
|
# For rolling releases: "opencloudeu/opencloud-rolling"
|
||||||
# Defaults to production if not set otherwise
|
# Defaults to production if not set otherwise
|
||||||
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling
|
OC_DOCKER_IMAGE=opencloudeu/opencloud
|
||||||
# The openCloud container version.
|
# The openCloud container version.
|
||||||
# Defaults to the latest version-tag. Use git pull to update.
|
# Defaults to the latest version-tag. Use git pull to update.
|
||||||
OC_DOCKER_TAG=
|
OC_DOCKER_TAG=
|
||||||
|
|||||||
21
README.md
21
README.md
@@ -147,12 +147,12 @@ Include Euro Office for document editing using either method:
|
|||||||
|
|
||||||
Using `-f` flags:
|
Using `-f` flags:
|
||||||
```bash
|
```bash
|
||||||
docker compose -f docker-compose.yml -f weboffice/euro-office.yml -f traefik/opencloud.yml -f traefik/euro-office.yml up -d
|
docker compose -f docker-compose.yml -f weboffice/euroffice.yml -f traefik/opencloud.yml -f traefik/euroffice.yml up -d
|
||||||
```
|
```
|
||||||
|
|
||||||
Or by setting in `.env`:
|
Or by setting in `.env`:
|
||||||
```
|
```
|
||||||
COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
|
COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:traefik/opencloud.yml:traefik/euroffice.yml
|
||||||
```
|
```
|
||||||
|
|
||||||
> **For local development only**: Add to `/etc/hosts`:
|
> **For local development only**: Add to `/etc/hosts`:
|
||||||
@@ -215,11 +215,6 @@ This setup includes:
|
|||||||
- Radicale as a CalDAV (calendars, to-do lists) and CardDAV (contacts) server
|
- Radicale as a CalDAV (calendars, to-do lists) and CardDAV (contacts) server
|
||||||
- Users access to a Personal Calendar and Addressbook
|
- Users access to a Personal Calendar and Addressbook
|
||||||
|
|
||||||
Clients connect to `https://<your-domain>/caldav/` (calendar) and
|
|
||||||
`https://<your-domain>/carddav/` (contacts) — note the required trailing
|
|
||||||
slash — using an App Token as password. See [radicale/README.md](radicale/README.md)
|
|
||||||
for client setup (GNOME Online Accounts, Thunderbird) and troubleshooting.
|
|
||||||
|
|
||||||
### With Monitoring
|
### With Monitoring
|
||||||
|
|
||||||
Enable monitoring capabilities with metrics endpoints using either method:
|
Enable monitoring capabilities with metrics endpoints using either method:
|
||||||
@@ -276,12 +271,12 @@ The WOPI server runs inside the OpenCloud process and is served on the OpenCloud
|
|||||||
To use Euro Office instead of Collabora behind an external proxy, swap the web office compose files:
|
To use Euro Office instead of Collabora behind an external proxy, swap the web office compose files:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker compose -f docker-compose.yml -f weboffice/euro-office.yml -f external-proxy/opencloud.yml -f external-proxy/euro-office.yml up -d
|
docker compose -f docker-compose.yml -f weboffice/euroffice.yml -f external-proxy/opencloud.yml -f external-proxy/euroffice.yml up -d
|
||||||
```
|
```
|
||||||
|
|
||||||
Or by setting in `.env`:
|
Or by setting in `.env`:
|
||||||
```
|
```
|
||||||
COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
|
COMPOSE_FILE=docker-compose.yml:weboffice/euroffice.yml:external-proxy/opencloud.yml:external-proxy/euroffice.yml
|
||||||
```
|
```
|
||||||
|
|
||||||
This exposes the necessary ports:
|
This exposes the necessary ports:
|
||||||
@@ -291,7 +286,7 @@ This exposes the necessary ports:
|
|||||||
As with Collabora, the WOPI server is served on the OpenCloud port (9200) under the `/wopi` and `/collaboration` paths and needs no separate port.
|
As with Collabora, the WOPI server is served on the OpenCloud port (9200) under the `/wopi` and `/collaboration` paths and needs no separate port.
|
||||||
|
|
||||||
> [!WARNING]
|
> [!WARNING]
|
||||||
> `external-proxy/euro-office.yml` binds the exposed ports to `127.0.0.1` only. If your external proxy runs on a different host, use `external-proxy/euro-office-exposed.yml`, which binds to all interfaces (`0.0.0.0`). Only expose these ports when you know what you are doing.
|
> `external-proxy/euroffice.yml` binds the exposed ports to `127.0.0.1` only. If your external proxy runs on a different host, use `external-proxy/euroffice-exposed.yml`, which binds to all interfaces (`0.0.0.0`). Only expose these ports when you know what you are doing.
|
||||||
|
|
||||||
**Please note:**
|
**Please note:**
|
||||||
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
|
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
|
||||||
@@ -324,12 +319,12 @@ OpenCloud Compose supports adding SSL certificates for public domains and develo
|
|||||||
### Use Let's Encrypt with ACME Challenge
|
### Use Let's Encrypt with ACME Challenge
|
||||||
|
|
||||||
1. **Enable Let's Encrypt**:
|
1. **Enable Let's Encrypt**:
|
||||||
- Set `TRAEFIK_ACME_MAIL` to your email address for the ACME challenge
|
- Set `TRAEFIK_LETSENCRYPT_EMAIL` to your email address for the ACME challenge
|
||||||
- Set `TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"` to use Let's Encrypt (default value)
|
- Set `TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"` to use Let's Encrypt (default value)
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# In your .env file
|
# In your .env file
|
||||||
TRAEFIK_ACME_MAIL=devops@your-domain.tld
|
TRAEFIK_LETSENCRYPT_EMAIL=devops@your-domain.tld
|
||||||
TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
|
TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -417,7 +412,7 @@ Key variables:
|
|||||||
| `LDAP_BIND_PASSWORD` | LDAP password for the bind user | admin |
|
| `LDAP_BIND_PASSWORD` | LDAP password for the bind user | admin |
|
||||||
| `KC_DB_USERNAME` | Database user for keycloak | keycloak |
|
| `KC_DB_USERNAME` | Database user for keycloak | keycloak |
|
||||||
| `KC_DB_PASSWORD` | Database password for keycloak | keycloak |
|
| `KC_DB_PASSWORD` | Database password for keycloak | keycloak |
|
||||||
| `TRAEFIK_ACME_MAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
|
| `TRAEFIK_LETSENCRYPT_EMAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
|
||||||
| `TRAEFIK_SERVICES_TLS_CONFIG` | Tell traefik and the services which TLS config to use | tls.certresolver=letsencrypt |
|
| `TRAEFIK_SERVICES_TLS_CONFIG` | Tell traefik and the services which TLS config to use | tls.certresolver=letsencrypt |
|
||||||
| `TRAEFIK_CERTS_DIR` | Directory for custom certificates. | ./certs |
|
| `TRAEFIK_CERTS_DIR` | Directory for custom certificates. | ./certs |
|
||||||
|
|
||||||
|
|||||||
@@ -1,51 +1,38 @@
|
|||||||
:root {
|
:root {
|
||||||
--pf-v5-global--primary-color--100: #e2baff;
|
--pf-global--primary-color--100: #e2baff;
|
||||||
--pf-v5-global--primary-color--200: #e2baff;
|
--pf-global--primary-color--200: #e2baff;
|
||||||
--pf-v5-global--primary-color--dark-100: #e2baff;
|
--pf-global--primary-color--dark-100: #e2baff;
|
||||||
--pf-v5-c-button--m-secondary--Color: #e2baff;
|
--pf-global--Color--light-100: #20434f;
|
||||||
--pf-v5-global--Color--light-100: #20434f;
|
|
||||||
--pf-v5-global--FontFamily--text: "Inter", "RedHatText", helvetica, arial, sans-serif;
|
|
||||||
--pf-v5-global--FontFamily--heading: "Inter", "RedHatDisplay", helvetica, arial, sans-serif;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
@font-face {
|
@font-face {
|
||||||
font-family: Inter;
|
font-family: OpenCloud;
|
||||||
src: url('../fonts/Inter-Variable.woff2') format('woff2');
|
src: url('../fonts/OpenCloud500-Regular.woff2') format('woff2');
|
||||||
font-weight: 100 900;
|
font-weight: normal;
|
||||||
|
font-style: normal;
|
||||||
|
}
|
||||||
|
|
||||||
|
@font-face {
|
||||||
|
font-family: OpenCloud;
|
||||||
|
src: url('../fonts/OpenCloud750-Bold.woff2') format('woff2');
|
||||||
|
font-weight: bold;
|
||||||
font-style: normal;
|
font-style: normal;
|
||||||
}
|
}
|
||||||
|
|
||||||
body {
|
body {
|
||||||
background: url(../img/background.png) no-repeat center fixed !important;
|
font-family: "OpenCloud", "Open Sans", Helvetica, Arial, sans-serif;
|
||||||
|
background: url(../img/background.png) no-repeat center !important;
|
||||||
background-size: cover !important;
|
background-size: cover !important;
|
||||||
}
|
}
|
||||||
|
|
||||||
.kc-logo-text {
|
.kc-logo-text {
|
||||||
display: block;
|
background-image: url(../img/logo.svg) !important;
|
||||||
width: 300px;
|
|
||||||
height: 63px;
|
|
||||||
background: url('../img/logo.svg') no-repeat center;
|
|
||||||
background-size: contain;
|
background-size: contain;
|
||||||
|
width: 400px;
|
||||||
|
margin: 0 !important;
|
||||||
}
|
}
|
||||||
|
|
||||||
.kc-logo-text span {
|
#kc-header-wrapper{
|
||||||
display: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
#kc-header-wrapper {
|
|
||||||
display: flex;
|
display: flex;
|
||||||
justify-content: center;
|
justify-content: center;
|
||||||
}
|
}
|
||||||
|
|
||||||
.pf-v5-c-login__main-header {
|
|
||||||
border-top: 4px solid var(--pf-v5-global--primary-color--100);
|
|
||||||
}
|
|
||||||
|
|
||||||
@media (min-width: 1200px) {
|
|
||||||
.pf-v5-c-login__container {
|
|
||||||
grid-template-columns: 34rem;
|
|
||||||
grid-template-areas:
|
|
||||||
"header"
|
|
||||||
"main";
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -1,4 +1,4 @@
|
|||||||
parent=keycloak.v2
|
parent=keycloak
|
||||||
import=common/keycloak
|
import=common/keycloak
|
||||||
|
|
||||||
styles=css/login.css css/theme.css
|
styles=css/login.css css/theme.css
|
||||||
|
|||||||
@@ -1,3 +0,0 @@
|
|||||||
maps:
|
|
||||||
config:
|
|
||||||
folderViewEnabled: false
|
|
||||||
File diff suppressed because one or more lines are too long
2
config/opencloud/apps/maps/assets/src-D755RU42.css
Normal file
2
config/opencloud/apps/maps/assets/src-D755RU42.css
Normal file
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -1 +0,0 @@
|
|||||||
import{t as e}from"./preload-helper-DYl5dUZ5.mjs";await(await e(()=>import(`./remoteEntry-BXGAhFe2.mjs`),[],import.meta.url)).init();
|
|
||||||
1
config/opencloud/apps/maps/js/hostInit-E45YfNWJ.mjs
Normal file
1
config/opencloud/apps/maps/js/hostInit-E45YfNWJ.mjs
Normal file
@@ -0,0 +1 @@
|
|||||||
|
import{t as e}from"./preload-helper-DafEc2pQ.mjs";await(await e(()=>import(`./remoteEntry-lxWu31Tr.mjs`),[],import.meta.url)).init();
|
||||||
@@ -1 +0,0 @@
|
|||||||
import"./dist-CXnzN4cY.mjs";var e={"@opencloud-eu/web-client":{name:`@opencloud-eu/web-client`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/graph":{name:`@opencloud-eu/web-client/graph`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/graph' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/graph/generated":{name:`@opencloud-eu/web-client/graph/generated`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/graph/generated' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/ocs":{name:`@opencloud-eu/web-client/ocs`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/ocs' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/ox":{name:`@opencloud-eu/web-client/ox`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/ox' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/sse":{name:`@opencloud-eu/web-client/sse`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/sse' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/webdav":{name:`@opencloud-eu/web-client/webdav`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/webdav' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-pkg":{name:`@opencloud-eu/web-pkg`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-pkg' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-pkg/editor":{name:`@opencloud-eu/web-pkg/editor`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-pkg/editor' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},luxon:{name:`luxon`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module 'luxon' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},pinia:{name:`pinia`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module 'pinia' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},vue:{name:`vue`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module 'vue' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"vue3-gettext":{name:`vue3-gettext`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module 'vue3-gettext' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}}},t=[];export{t as usedRemotes,e as usedShared};
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
import"./dist-r7AkbZvS.mjs";var e={"@opencloud-eu/web-client":{name:`@opencloud-eu/web-client`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/graph":{name:`@opencloud-eu/web-client/graph`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/graph' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/graph/generated":{name:`@opencloud-eu/web-client/graph/generated`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/graph/generated' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/ocs":{name:`@opencloud-eu/web-client/ocs`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/ocs' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/sse":{name:`@opencloud-eu/web-client/sse`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/sse' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-client/webdav":{name:`@opencloud-eu/web-client/webdav`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-client/webdav' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"@opencloud-eu/web-pkg":{name:`@opencloud-eu/web-pkg`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module '@opencloud-eu/web-pkg' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},luxon:{name:`luxon`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module 'luxon' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},pinia:{name:`pinia`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module 'pinia' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},vue:{name:`vue`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module 'vue' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}},"vue3-gettext":{name:`vue3-gettext`,version:void 0,scope:[`default`],loaded:!1,from:`maps`,async get(){throw Error(`[Module Federation] Shared module 'vue3-gettext' must be provided by host`)},shareConfig:{singleton:!0,requiredVersion:`*`,import:!1}}},t=[];export{t as usedRemotes,e as usedShared};
|
||||||
1
config/opencloud/apps/maps/js/maps-BAf8IhJ5.mjs
Normal file
1
config/opencloud/apps/maps/js/maps-BAf8IhJ5.mjs
Normal file
@@ -0,0 +1 @@
|
|||||||
|
import{t as e}from"./src-CIfRBuLG.mjs";export{e as default};
|
||||||
@@ -1 +0,0 @@
|
|||||||
import{t as e}from"./src-Bjkk5jHv.mjs";export{e as default};
|
|
||||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -1 +0,0 @@
|
|||||||
var e=function(e,t){return new URL(e,t).href},t={},n=function(n,r,i){let a=Promise.resolve();if(r&&r.length>0){let n=document.getElementsByTagName(`link`),o=document.querySelector(`meta[property=csp-nonce]`),s=o?.nonce||o?.getAttribute(`nonce`);function c(e){return Promise.all(e.map(e=>Promise.resolve(e).then(e=>({status:`fulfilled`,value:e}),e=>({status:`rejected`,reason:e}))))}function l(e){return import.meta.resolve?import.meta.resolve(e):new URL(e,new URL(`../../../src/node/plugins/importAnalysisBuild.ts`,import.meta.url)).href}a=c(r.map(r=>{if(r=e(r,i),r=l(r),r in t)return;t[r]=!0;let a=r.endsWith(`.css`);for(let e=n.length-1;e>=0;e--){let t=n[e];if(t.href===r&&(!a||t.rel===`stylesheet`))return}let o=document.createElement(`link`);if(o.rel=a?`stylesheet`:`modulepreload`,a||(o.as=`script`),o.crossOrigin=``,o.href=r,s&&o.setAttribute(`nonce`,s),document.head.appendChild(o),a)return new Promise((e,t)=>{o.addEventListener(`load`,e),o.addEventListener(`error`,()=>t(Error(`Unable to preload CSS for ${r}`)))})}))}function o(e){let t=new Event(`vite:preloadError`,{cancelable:!0});if(t.payload=e,window.dispatchEvent(t),!t.defaultPrevented)throw e}return a.then(e=>{for(let t of e||[])t.status===`rejected`&&o(t.reason);return n().catch(o)})};export{n as t};
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
var e=`modulepreload`,t=function(e,t){return new URL(e,t).href},n={},r=function(r,i,a){let o=Promise.resolve();if(i&&i.length>0){let r=document.getElementsByTagName(`link`),s=document.querySelector(`meta[property=csp-nonce]`),c=s?.nonce||s?.getAttribute(`nonce`);function l(e){return Promise.all(e.map(e=>Promise.resolve(e).then(e=>({status:`fulfilled`,value:e}),e=>({status:`rejected`,reason:e}))))}o=l(i.map(i=>{if(i=t(i,a),i in n)return;n[i]=!0;let o=i.endsWith(`.css`),s=o?`[rel="stylesheet"]`:``;if(a)for(let e=r.length-1;e>=0;e--){let t=r[e];if(t.href===i&&(!o||t.rel===`stylesheet`))return}else if(document.querySelector(`link[href="${i}"]${s}`))return;let l=document.createElement(`link`);if(l.rel=o?`stylesheet`:e,o||(l.as=`script`),l.crossOrigin=``,l.href=i,c&&l.setAttribute(`nonce`,c),document.head.appendChild(l),o)return new Promise((e,t)=>{l.addEventListener(`load`,e),l.addEventListener(`error`,()=>t(Error(`Unable to preload CSS for ${i}`)))})}))}function s(e){let t=new Event(`vite:preloadError`,{cancelable:!0});if(t.payload=e,window.dispatchEvent(t),!t.defaultPrevented)throw e}return o.then(e=>{for(let t of e||[])t.status===`rejected`&&s(t.reason);return r().catch(s)})};export{r as t};
|
||||||
@@ -1,2 +1,2 @@
|
|||||||
const __vite__mapDeps=(i,m=__vite__mapDeps,d=(m.f||(m.f=["./localSharedImportMap-BrxIqYlq.mjs","./dist-CXnzN4cY.mjs","./preload-helper-DYl5dUZ5.mjs","./virtualExposes-BsjVAkf0.mjs"])))=>i.map(i=>d[i]);
|
const __vite__mapDeps=(i,m=__vite__mapDeps,d=(m.f||(m.f=["./localSharedImportMap-CALnqYrs.mjs","./dist-r7AkbZvS.mjs","./preload-helper-DafEc2pQ.mjs","./virtualExposes-CZMUMkHF.mjs"])))=>i.map(i=>d[i]);
|
||||||
import{t as e}from"./dist-CXnzN4cY.mjs";import{t}from"./preload-helper-DYl5dUZ5.mjs";typeof __VUE_HMR_RUNTIME__>`u`&&(globalThis.__VUE_HMR_RUNTIME__={createRecord(){},rerender(){},reload(){}});var n=`__mf_init____mf__virtual/maps__mf_v__runtimeInit__mf_v__.js__`,r=globalThis[n];if(!r){let e,t,i=new Promise((n,r)=>{e=n,t=r});r=globalThis[n]={initPromise:i,initResolve:e,initReject:t},typeof window>`u`&&e({loadRemote:function(){return Promise.resolve(void 0)},loadShare:function(){return Promise.resolve(void 0)}})}var i=r.initResolve,a={},o=`default`,s=`maps`,c,l;async function u(){return c??=t(()=>import(`./localSharedImportMap-BrxIqYlq.mjs`),__vite__mapDeps([0,1,2]),import.meta.url),c}async function d(){return l??=t(()=>import(`./virtualExposes-BsjVAkf0.mjs`).then(e=>e.default??e),__vite__mapDeps([3,2]),import.meta.url),l}async function f(t={},n=[]){let{usedShared:r,usedRemotes:c}=await u(),l=e({name:s,remotes:c,shared:r,plugins:[],shareStrategy:`version-first`});var d=a[o];if(d||=a[o]={from:s},!(n.indexOf(d)>=0)){n.push(d),l.initShareScopeMap(`default`,t),i(l);try{await Promise.all(await l.initializeSharing(`default`,{strategy:`version-first`,from:`build`,initScope:n}))}catch(e){console.error(`[Module Federation]`,e)}return l}}async function p(e){let t=await d();if(!(e in t))throw Error(`[Module Federation] Module ${e} does not exist in container.`);return t[e]().then(e=>()=>e)}export{p as get,f as init};
|
import{t as e}from"./dist-r7AkbZvS.mjs";import{t}from"./preload-helper-DafEc2pQ.mjs";typeof __VUE_HMR_RUNTIME__>`u`&&(globalThis.__VUE_HMR_RUNTIME__={createRecord(){},rerender(){},reload(){}});var n=`__mf_init____mf__virtual/maps__mf_v__runtimeInit__mf_v__.js__`,r=globalThis[n];if(!r){let e,t,i=new Promise((n,r)=>{e=n,t=r});r=globalThis[n]={initPromise:i,initResolve:e,initReject:t},typeof window>`u`&&e({loadRemote:function(){return Promise.resolve(void 0)},loadShare:function(){return Promise.resolve(void 0)}})}var i=r.initResolve,a={},o=`default`,s=`maps`,c,l;async function u(){return c??=t(()=>import(`./localSharedImportMap-CALnqYrs.mjs`),__vite__mapDeps([0,1,2]),import.meta.url),c}async function d(){return l??=t(()=>import(`./virtualExposes-CZMUMkHF.mjs`).then(e=>e.default??e),__vite__mapDeps([3,2]),import.meta.url),l}async function f(t={},n=[]){let{usedShared:r,usedRemotes:c}=await u(),l=e({name:s,remotes:c,shared:r,plugins:[],shareStrategy:`version-first`});var d=a[o];if(d||=a[o]={from:s},!(n.indexOf(d)>=0)){n.push(d),l.initShareScopeMap(`default`,t),i(l);try{await Promise.all(await l.initializeSharing(`default`,{strategy:`version-first`,from:`build`,initScope:n}))}catch(e){console.error(`[Module Federation]`,e)}return l}}async function p(e){let t=await d();if(!(e in t))throw Error(`[Module Federation] Module ${e} does not exist in container.`);return t[e]().then(e=>()=>e)}export{p as get,f as init};
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
var e=Object.create,t=Object.defineProperty,n=Object.getOwnPropertyDescriptor,r=Object.getOwnPropertyNames,i=Object.getPrototypeOf,a=Object.prototype.hasOwnProperty,o=(e,t)=>()=>(t||e((t={exports:{}}).exports,t),t.exports),s=(e,i,o,s)=>{if(i&&typeof i==`object`||typeof i==`function`)for(var c=r(i),l=0,u=c.length,d;l<u;l++)d=c[l],!a.call(e,d)&&d!==o&&t(e,d,{get:(e=>i[e]).bind(null,d),enumerable:!(s=n(i,d))||s.enumerable});return e},c=(n,r,a)=>(a=n==null?{}:e(i(n)),s(r||!n||!n.__esModule?t(a,`default`,{value:n,enumerable:!0}):a,n));export{c as n,o as t};
|
||||||
File diff suppressed because one or more lines are too long
808
config/opencloud/apps/maps/js/src-CIfRBuLG.mjs
Normal file
808
config/opencloud/apps/maps/js/src-CIfRBuLG.mjs
Normal file
File diff suppressed because one or more lines are too long
1
config/opencloud/apps/maps/js/src-D0iZetHT.mjs
Normal file
1
config/opencloud/apps/maps/js/src-D0iZetHT.mjs
Normal file
@@ -0,0 +1 @@
|
|||||||
|
import{t as e}from"./src-CIfRBuLG.mjs";export{e as default};
|
||||||
@@ -1 +0,0 @@
|
|||||||
import{t as e}from"./src-Bjkk5jHv.mjs";export{e as default};
|
|
||||||
@@ -1,2 +1,2 @@
|
|||||||
const __vite__mapDeps=(i,m=__vite__mapDeps,d=(m.f||(m.f=["../assets/src-CNZX96BL.css"])))=>i.map(i=>d[i]);
|
const __vite__mapDeps=(i,m=__vite__mapDeps,d=(m.f||(m.f=["../assets/src-D755RU42.css"])))=>i.map(i=>d[i]);
|
||||||
import{t as e}from"./preload-helper-DYl5dUZ5.mjs";var t={},n=new Set;async function r(e){if(typeof document>`u`)return;let r=t[e]||[];await Promise.all(r.map(e=>{let t=new URL(e,import.meta.url).href;return n.has(t)||(n.add(t),document.querySelector(`link[rel="stylesheet"][data-mf-href="${t}"]`))?Promise.resolve():new Promise((e,n)=>{let r=document.createElement(`link`);r.rel=`stylesheet`,r.href=t,r.setAttribute(`data-mf-href`,t),r.onload=()=>e(),r.onerror=()=>n(Error(`[Module Federation] Failed to load CSS asset: ${t}`)),document.head.appendChild(r)})}))}var i={".":async()=>{await r(`.`);let t=await e(()=>import(`./maps-z34tTD6Z.mjs`),__vite__mapDeps([0]),import.meta.url),n={};return Object.assign(n,t),Object.defineProperty(n,"__esModule",{value:!0,enumerable:!1}),n}};export{i as default};
|
import{t as e}from"./preload-helper-DafEc2pQ.mjs";var t={},n=new Set;async function r(e){if(typeof document>`u`)return;let r=t[e]||[];await Promise.all(r.map(e=>{let t=new URL(e,import.meta.url).href;return n.has(t)||(n.add(t),document.querySelector(`link[rel="stylesheet"][data-mf-href="${t}"]`))?Promise.resolve():new Promise((e,n)=>{let r=document.createElement(`link`);r.rel=`stylesheet`,r.href=t,r.setAttribute(`data-mf-href`,t),r.onload=()=>e(),r.onerror=()=>n(Error(`[Module Federation] Failed to load CSS asset: ${t}`)),document.head.appendChild(r)})}))}var i={".":async()=>{await r(`.`);let t=await e(()=>import(`./maps-BAf8IhJ5.mjs`),__vite__mapDeps([0]),import.meta.url),n={};return Object.assign(n,t),Object.defineProperty(n,`__esModule`,{value:!0,enumerable:!1}),n}};export{i as default};
|
||||||
@@ -1,7 +1,3 @@
|
|||||||
{
|
{
|
||||||
"name": "web-app-maps",
|
"entrypoint": "js/remoteEntry-lxWu31Tr.mjs"
|
||||||
"version": "3.1.0",
|
|
||||||
"description": "OpenCloud Web Maps",
|
|
||||||
"license": "AGPL-3.0",
|
|
||||||
"entrypoint": "js/remoteEntry-BXGAhFe2.mjs"
|
|
||||||
}
|
}
|
||||||
@@ -25,7 +25,6 @@ directives:
|
|||||||
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
# This is needed for the external-sites web extension when embedding sites
|
# This is needed for the external-sites web extension when embedding sites
|
||||||
- 'https://docs.opencloud.eu'
|
- 'https://docs.opencloud.eu'
|
||||||
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
|
||||||
img-src:
|
img-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
- 'data:'
|
- 'data:'
|
||||||
@@ -49,7 +48,6 @@ directives:
|
|||||||
style-src:
|
style-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
- '''unsafe-inline'''
|
- '''unsafe-inline'''
|
||||||
- 'blob:'
|
|
||||||
worker-src:
|
worker-src:
|
||||||
- "'self'"
|
- "'self'"
|
||||||
- 'blob:'
|
- 'blob:'
|
||||||
|
|||||||
@@ -1,10 +1,6 @@
|
|||||||
# This adds four additional routes to the proxy, forwarding requests
|
# This adds four additional routes to the proxy. Forwarding
|
||||||
# on '/caldav/', '/carddav/' and the respective '/.well-known'
|
# request on '/carddav/', '/caldav/' and the respective '/.well-knwown'
|
||||||
# endpoints to the radicale container and setting the required headers.
|
# endpoints to the radicale container and setting the required headers.
|
||||||
#
|
|
||||||
# Client URLs (trailing slash required, see radicale/README.md):
|
|
||||||
# CalDAV: https://<your-domain>/caldav/
|
|
||||||
# CardDAV: https://<your-domain>/carddav/
|
|
||||||
additional_policies:
|
additional_policies:
|
||||||
- name: default
|
- name: default
|
||||||
routes:
|
routes:
|
||||||
@@ -14,15 +10,10 @@ additional_policies:
|
|||||||
skip_x_access_token: true
|
skip_x_access_token: true
|
||||||
additional_headers:
|
additional_headers:
|
||||||
- X-Script-Name: /caldav
|
- X-Script-Name: /caldav
|
||||||
# The '.well-known' endpoints are 'unprotected' so that DAV clients
|
|
||||||
# can discover the CalDAV/CardDAV URLs (RFC 6764) before they
|
|
||||||
# authenticate. Radicale only ever answers these paths with a 301
|
|
||||||
# redirect to '/caldav/' or '/carddav/' and serves no data here
|
|
||||||
# (deeper paths return 404), so no authentication is required.
|
|
||||||
- endpoint: /.well-known/caldav
|
- endpoint: /.well-known/caldav
|
||||||
backend: http://radicale:5232
|
backend: http://radicale:5232
|
||||||
|
remote_user_header: X-Remote-User
|
||||||
skip_x_access_token: true
|
skip_x_access_token: true
|
||||||
unprotected: true
|
|
||||||
additional_headers:
|
additional_headers:
|
||||||
- X-Script-Name: /caldav
|
- X-Script-Name: /caldav
|
||||||
- endpoint: /carddav/
|
- endpoint: /carddav/
|
||||||
@@ -33,8 +24,8 @@ additional_policies:
|
|||||||
- X-Script-Name: /carddav
|
- X-Script-Name: /carddav
|
||||||
- endpoint: /.well-known/carddav
|
- endpoint: /.well-known/carddav
|
||||||
backend: http://radicale:5232
|
backend: http://radicale:5232
|
||||||
|
remote_user_header: X-Remote-User
|
||||||
skip_x_access_token: true
|
skip_x_access_token: true
|
||||||
unprotected: true
|
|
||||||
additional_headers:
|
additional_headers:
|
||||||
- X-Script-Name: /carddav
|
- X-Script-Name: /carddav
|
||||||
# To enable the radicale web UI add this rule.
|
# To enable the radicale web UI add this rule.
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
opencloud:
|
opencloud:
|
||||||
# renovate: depName=opencloudeu/opencloud-rolling
|
# renovate: depName=opencloudeu/opencloud
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.5.0}
|
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud}:${OC_DOCKER_TAG:-7.2.4}
|
||||||
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
||||||
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
||||||
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
@@ -58,7 +58,6 @@ services:
|
|||||||
OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE}
|
OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE}
|
||||||
volumes:
|
volumes:
|
||||||
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
|
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
|
||||||
- ./config/opencloud/apps.yaml:/etc/opencloud/apps.yaml
|
|
||||||
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
|
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
|
||||||
# configure the .env file to use own paths instead of docker internal volumes
|
# configure the .env file to use own paths instead of docker internal volumes
|
||||||
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
|
||||||
|
|||||||
@@ -64,7 +64,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
postgres:
|
postgres:
|
||||||
image: postgres:17.11-alpine
|
image: postgres:17.10-alpine
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
volumes:
|
volumes:
|
||||||
@@ -78,7 +78,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.7.3
|
image: quay.io/keycloak/keycloak:26.6.4
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -1,77 +0,0 @@
|
|||||||
# Radicale — CalDAV / CardDAV
|
|
||||||
|
|
||||||
This module adds [Radicale](https://radicale.org/) as a CalDAV (calendars,
|
|
||||||
to-do lists) and CardDAV (contacts) server behind the OpenCloud proxy. Every
|
|
||||||
user gets a personal calendar and address book on first access.
|
|
||||||
|
|
||||||
## Enabling
|
|
||||||
|
|
||||||
Add `radicale/radicale.yml` to your `COMPOSE_FILE`:
|
|
||||||
|
|
||||||
```
|
|
||||||
COMPOSE_FILE=docker-compose.yml:radicale/radicale.yml:traefik/opencloud.yml
|
|
||||||
```
|
|
||||||
|
|
||||||
The routes are defined in [`config/opencloud/proxy.yaml`](../config/opencloud/proxy.yaml),
|
|
||||||
which `radicale.yml` mounts into the opencloud container.
|
|
||||||
|
|
||||||
## Connecting clients
|
|
||||||
|
|
||||||
### URLs
|
|
||||||
|
|
||||||
| Service | URL |
|
|
||||||
|---|---|
|
|
||||||
| CalDAV (calendar) | `https://<your-domain>/caldav/` |
|
|
||||||
| CardDAV (contacts) | `https://<your-domain>/carddav/` |
|
|
||||||
|
|
||||||
**The trailing slash is required.** `https://<your-domain>/caldav` (without
|
|
||||||
the slash) is not routed to Radicale and returns the OpenCloud web UI instead.
|
|
||||||
|
|
||||||
Clients that implement DAV service discovery (RFC 6764) can also be pointed
|
|
||||||
at the bare domain `https://<your-domain>/` — the `/.well-known/caldav` and
|
|
||||||
`/.well-known/carddav` endpoints redirect them to the URLs above. Clients
|
|
||||||
that don't (or that get confused by the web UI at the base URL) need the full
|
|
||||||
URL including the suffix.
|
|
||||||
|
|
||||||
### Authentication: use an App Token
|
|
||||||
|
|
||||||
DAV clients authenticate with **username + App Token** — not your account
|
|
||||||
password. With the default configuration (`PROXY_ENABLE_BASIC_AUTH=false`)
|
|
||||||
the account password is rejected with `401 Unauthorized`; App Tokens work out
|
|
||||||
of the box.
|
|
||||||
|
|
||||||
Create a token either
|
|
||||||
|
|
||||||
- in the web UI under **Settings → App Tokens**, or
|
|
||||||
- on the CLI:
|
|
||||||
|
|
||||||
```bash
|
|
||||||
docker compose exec opencloud opencloud auth-app create --user-name=<user> --expiration=72h
|
|
||||||
```
|
|
||||||
|
|
||||||
### GNOME Online Accounts
|
|
||||||
|
|
||||||
GNOME expects a directly answering DAV endpoint per account, so calendars and
|
|
||||||
contacts are added as two separate accounts:
|
|
||||||
|
|
||||||
1. **Settings → Online Accounts → Add Account → Calendar (CalDAV)**
|
|
||||||
— URL `https://<your-domain>/caldav/`, your username, an App Token as
|
|
||||||
password.
|
|
||||||
2. **Settings → Online Accounts → Add Account → Contacts (CardDAV)**
|
|
||||||
— URL `https://<your-domain>/carddav/`, same credentials.
|
|
||||||
|
|
||||||
### Thunderbird
|
|
||||||
|
|
||||||
- Calendar: *New Calendar → On the Network*, URL `https://<your-domain>/caldav/`
|
|
||||||
- Address book: *New Address Book → Add CardDAV Address Book*, URL
|
|
||||||
`https://<your-domain>/carddav/`
|
|
||||||
|
|
||||||
Use an App Token as the password in both dialogs.
|
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
| Symptom | Cause |
|
|
||||||
|---|---|
|
|
||||||
| `401 Unauthorized` | Account password used instead of an App Token (or the token expired). |
|
|
||||||
| `405 Method Not Allowed` / HTML response | Trailing slash missing — the request landed on the web UI, not Radicale. |
|
|
||||||
| Client says "not a (Cal)DAV server" at the base URL | The client doesn't do RFC 6764 discovery. Use the full `/caldav/` / `/carddav/` URL. |
|
|
||||||
@@ -1,44 +0,0 @@
|
|||||||
{
|
|
||||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
|
||||||
"dependencyDashboard": true,
|
|
||||||
"platformAutomerge": true,
|
|
||||||
"enabledManagers": ["docker-compose", "custom.regex"],
|
|
||||||
"baseBranchPatterns": ["main", "stable-4.0", "stable-7.2"],
|
|
||||||
"packageRules": [
|
|
||||||
{
|
|
||||||
"matchManagers": ["docker-compose", "custom.regex"],
|
|
||||||
"labels": ["Type:Dependencies", "Bot:Renovate"]
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchManagers": ["docker-compose"],
|
|
||||||
"matchUpdateTypes": ["patch"],
|
|
||||||
"automerge": true
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchBaseBranches": ["stable-4.0", "stable-7.2"],
|
|
||||||
"matchUpdateTypes": ["major", "minor"],
|
|
||||||
"enabled": false
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"matchPackageNames": ["postgres"],
|
|
||||||
"matchManagers": ["docker-compose"],
|
|
||||||
"allowedVersions": "/^17\\.\\d+-alpine$/"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"docker-compose": {
|
|
||||||
"managerFilePatterns": ["/.+\\.ya?ml$/"]
|
|
||||||
},
|
|
||||||
"customManagers": [
|
|
||||||
{
|
|
||||||
"customType": "regex",
|
|
||||||
"managerFilePatterns": [
|
|
||||||
"/^docker-compose\\.yml$/",
|
|
||||||
"/^weboffice\\/collabora\\.yml$/"
|
|
||||||
],
|
|
||||||
"matchStrings": [
|
|
||||||
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"
|
|
||||||
],
|
|
||||||
"datasourceTemplate": "docker"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
@@ -1,59 +0,0 @@
|
|||||||
---
|
|
||||||
services:
|
|
||||||
opencloud:
|
|
||||||
environment:
|
|
||||||
# Point the search service at OpenSearch instead of the embedded bleve index.
|
|
||||||
SEARCH_ENGINE_TYPE: open-search
|
|
||||||
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_ADDRESSES: http://opensearch:9200
|
|
||||||
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_INSECURE: "true"
|
|
||||||
SEARCH_ENGINE_OPEN_SEARCH_RESOURCE_INDEX_NAME: ${OPENSEARCH_RESOURCE_INDEX:-opencloud-resources}
|
|
||||||
depends_on:
|
|
||||||
opensearch:
|
|
||||||
condition: service_healthy
|
|
||||||
|
|
||||||
opensearch:
|
|
||||||
image: ${OPENSEARCH_DOCKER_IMAGE:-opensearchproject/opensearch}:${OPENSEARCH_DOCKER_TAG:-2.19.5}
|
|
||||||
environment:
|
|
||||||
discovery.type: single-node
|
|
||||||
bootstrap.memory_lock: "true"
|
|
||||||
OPENSEARCH_JAVA_OPTS: ${OPENSEARCH_JAVA_OPTS:--Xms512m -Xmx512m}
|
|
||||||
# Security plugin is disabled: OpenSearch is only reachable on the
|
|
||||||
# internal opencloud-net bridge and no port is published to the host.
|
|
||||||
# Do NOT enable a published port or expose this via the reverse proxy
|
|
||||||
# without first enabling and configuring the security plugin.
|
|
||||||
DISABLE_SECURITY_PLUGIN: "true"
|
|
||||||
DISABLE_INSTALL_DEMO_CONFIG: "true"
|
|
||||||
# Disable the disk-based shard allocation watermarks. By default OpenSearch
|
|
||||||
# marks indices read-only when the host disk is <5% free, which silently
|
|
||||||
# turns bulk upserts into no-ops. Fine to disable on a single-node dev box.
|
|
||||||
cluster.routing.allocation.disk.threshold_enabled: "false"
|
|
||||||
ulimits:
|
|
||||||
memlock:
|
|
||||||
soft: -1
|
|
||||||
hard: -1
|
|
||||||
nofile:
|
|
||||||
soft: 65536
|
|
||||||
hard: 65536
|
|
||||||
networks:
|
|
||||||
opencloud-net:
|
|
||||||
volumes:
|
|
||||||
- ${OPENSEARCH_DATA_DIR:-opensearch-data}:/usr/share/opensearch/data
|
|
||||||
healthcheck:
|
|
||||||
# Single-node clusters can't go green (replicas have nowhere to land), so
|
|
||||||
# yellow is the healthy state. Still gates opencloud until opensearch accepts
|
|
||||||
# requests.
|
|
||||||
test:
|
|
||||||
[
|
|
||||||
"CMD-SHELL",
|
|
||||||
"curl -sf 'http://localhost:9200/_cluster/health?wait_for_status=yellow&timeout=5s' > /dev/null || exit 1"
|
|
||||||
]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 10s
|
|
||||||
retries: 24
|
|
||||||
start_period: 60s
|
|
||||||
logging:
|
|
||||||
driver: ${LOG_DRIVER:-local}
|
|
||||||
restart: always
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
opensearch-data:
|
|
||||||
@@ -11,18 +11,6 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
healthcheck:
|
|
||||||
test:
|
|
||||||
[
|
|
||||||
"CMD",
|
|
||||||
"bash",
|
|
||||||
"-c",
|
|
||||||
"exec 3<>/dev/tcp/127.0.0.1/9998 && printf 'GET /tika HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && grep '200 OK' <&3",
|
|
||||||
]
|
|
||||||
interval: 5s
|
|
||||||
timeout: 5s
|
|
||||||
retries: 10
|
|
||||||
start_period: 5s
|
|
||||||
|
|
||||||
opencloud:
|
opencloud:
|
||||||
environment:
|
environment:
|
||||||
@@ -30,6 +18,3 @@ services:
|
|||||||
SEARCH_EXTRACTOR_TYPE: tika
|
SEARCH_EXTRACTOR_TYPE: tika
|
||||||
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
|
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
|
||||||
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
|
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
|
||||||
depends_on:
|
|
||||||
tika:
|
|
||||||
condition: service_healthy
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
postgres:
|
postgres:
|
||||||
image: postgres:17.11-alpine
|
image: postgres:17.10-alpine
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
volumes:
|
volumes:
|
||||||
@@ -15,7 +15,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.7.3
|
image: quay.io/keycloak/keycloak:26.6.4
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ services:
|
|||||||
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
|
- "traefik.http.services.opencloud.loadbalancer.server.port=9200"
|
||||||
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
|
||||||
traefik:
|
traefik:
|
||||||
image: traefik:v3.7.12
|
image: traefik:v3.6.14
|
||||||
# release notes: https://github.com/traefik/traefik/releases
|
# release notes: https://github.com/traefik/traefik/releases
|
||||||
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
|
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
|
||||||
networks:
|
networks:
|
||||||
|
|||||||
@@ -32,7 +32,6 @@ services:
|
|||||||
WOPI_ENABLED: "true"
|
WOPI_ENABLED: "true"
|
||||||
# self-signed certificates
|
# self-signed certificates
|
||||||
USE_UNAUTHORIZED_STORAGE: "${INSECURE:-false}"
|
USE_UNAUTHORIZED_STORAGE: "${INSECURE:-false}"
|
||||||
JWT_SECRET: "${EURO_OFFICE_JWT_SECRET}"
|
|
||||||
volumes:
|
volumes:
|
||||||
# Mount local TrueType fonts so the container can use system fonts
|
# Mount local TrueType fonts so the container can use system fonts
|
||||||
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
||||||
Reference in New Issue
Block a user