Compare commits

..

15 Commits

Author SHA1 Message Date
Viktor Scharf
d6efecf176 Merge pull request #397 from opencloud-eu/renovate/main-opencloudeu-opencloud-rolling-8.x
chore(deps): update opencloudeu/opencloud-rolling docker tag to v8.1.0 (main)
2026-10-05 21:59:11 +02:00
renovate[bot]
05b2aefa97 chore(deps): update opencloudeu/opencloud-rolling docker tag to v8.1.0 2026-10-05 19:58:28 +00:00
Benedikt Kulmann
34555ec2db Merge pull request #396 from opencloud-eu/renovate/main-opencloudeu-yjs-1.x
chore(deps): update opencloudeu/yjs docker tag to v1.1.0 (main)
2026-10-05 16:35:34 +02:00
renovate[bot]
0cd92a3d59 chore(deps): update opencloudeu/yjs docker tag to v1.1.0 2026-10-05 14:19:12 +00:00
Benedikt Kulmann
2d423cca0c Merge pull request #395 from opencloud-eu/chore/yjs-version-default
chore: instruct renovate to bump the yjs server image
2026-10-05 16:18:20 +02:00
Jannik Stehle
a38dc348f4 chore: instruct renovate to bump the yjs server image 2026-10-05 16:08:52 +02:00
renovate[bot]
e6ae9deb4f chore(deps): update alpine/openssl docker tag to v3.5.9 (#393)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 10:52:19 +02:00
renovate[bot]
8f80c01d7e chore(deps): update collabora/code docker tag to v26.04.4.2.1 (#386)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 10:50:12 +02:00
renovate[bot]
55ee3523a0 chore(deps): update quay.io/keycloak/keycloak docker tag to v26.8.0 (#385)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 10:49:27 +02:00
renovate[bot]
53e3c0d95b chore(deps): update traefik docker tag to v3.7.13 (#378)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 10:45:15 +02:00
Viktor Scharf
87e3c61615 Merge pull request #384 from opencloud-eu/flimmy-patch-1
chore(deps): update opencloud-rolling docker tag to v8.0.1
2026-09-16 16:45:21 +02:00
Michael Flemming
2d992b77de chore(deps): update opencloud-rolling docker tag to v8.0.1
renovate is too slow, it uses a cached response from docker.io.
Image is available and tested.
2026-09-16 16:42:26 +02:00
renovate[bot]
81e347d300 chore(deps): update opencloudeu/opencloud-rolling docker tag to v8 (#381)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-15 15:31:30 +02:00
Jannik Stehle
fcfc216f16 feat: add yjs collaboration service (#380) 2026-09-15 15:29:49 +02:00
renovate[bot]
2b10bd8cb9 chore(deps): update collabora/code docker tag to v26.04.3.2.1 (#375)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-01 09:43:36 +02:00
11 changed files with 78 additions and 110 deletions

View File

@@ -10,24 +10,24 @@ INSECURE=true
## Features ## ## Features ##
# The following variable is a convenience variable to enable or disable features of this compose project. # The following variable is a convenience variable to enable or disable features of this compose project.
# Example: if you want to use traefik and letsencrypt, you can set the variable to # Example: if you want to use traefik and letsencrypt, you can set the variable to
#COMPOSE_FILE=docker-compose.yml:traefik/opencloud.yml #COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:traefik/opencloud.yml
# This enables you to just run `docker compose up -d` and the compose files will be added to the stack. # This enables you to just run `docker compose up -d` and the compose files will be added to the stack.
# As alternative approach you can run `docker compose -f docker-compose.yml -f docker-compose.traefik.yml up -d` # As alternative approach you can run `docker compose -f docker-compose.yml -f docker-compose.traefik.yml up -d`
# Default: OpenCloud and Collabora with traefik and letsencypt # Default: OpenCloud and Collabora with traefik and letsencypt
# This needs DNS entries for the domain names used in the .env file. # This needs DNS entries for the domain names used in the .env file.
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml #COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml
# If you want to use the external proxy, you can use the following combination. # If you want to use the external proxy, you can use the following combination.
# DNS entries and certificates need to be managed by the external environment. # DNS entries and certificates need to be managed by the external environment.
# The domain names need to be entered into the .env file. # The domain names need to be entered into the .env file.
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:external-proxy/opencloud.yml:external-proxy/collabora.yml #COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:external-proxy/opencloud.yml:external-proxy/collabora.yml
# Keycloak Shared User Directory # Keycloak Shared User Directory
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml #COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml
# External IDP # External IDP
#COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml #COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/external-idp.yml
# Euro Office with traefik and letsencrypt # Euro Office with traefik and letsencrypt
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml #COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/euro-office.yml:traefik/opencloud.yml:traefik/euro-office.yml
# Euro Office with external proxy (Nginx, Caddy, etc.) # Euro Office with external proxy (Nginx, Caddy, etc.)
#COMPOSE_FILE=docker-compose.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml #COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/euro-office.yml:external-proxy/opencloud.yml:external-proxy/euro-office.yml
## Traefik Settings ## ## Traefik Settings ##
# Note: Traefik is always enabled and can't be disabled. # Note: Traefik is always enabled and can't be disabled.
@@ -383,9 +383,23 @@ KC_DB_PASSWORD=
# - ./config/ldap/ldif/30_demo_users.ldif:/ldifs/30_demo_users.ldif # - ./config/ldap/ldif/30_demo_users.ldif:/ldifs/30_demo_users.ldif
# - ./config/ldap/ldif/40_demo_groups.ldif:/ldifs/40_demo_groups.ldif # - ./config/ldap/ldif/40_demo_groups.ldif:/ldifs/40_demo_groups.ldif
# #
# Then add it to: COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml:custom/ldap-keycloak-demo-users.yml # Then add it to: COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml:idm/ldap-keycloak.yml:traefik/ldap-keycloak.yml:custom/ldap-keycloak-demo-users.yml
# WARNING: Do not use in production. # WARNING: Do not use in production.
### Yjs Settings ###
# The yjs server relays updates between users editing the same file.
# It is enabled by default via yjs/yjs.yml in the COMPOSE_FILE variable.
# The browser reaches it under https://{OC_DOMAIN}/yjs, the OpenCloud proxy forwards it.
# Docker image to use for the yjs container.
#YJS_DOCKER_IMAGE=opencloudeu/yjs
# Docker tag to pull for the yjs container.
#YJS_DOCKER_TAG=
# URL the yjs server uses to reach OpenCloud. Defaults to "http://opencloud:9200".
#YJS_OPENCLOUD_URL=
# Grace period in milliseconds for a graceful shutdown. Defaults to "15000".
# Keep it below the stop_grace_period set in yjs/yjs.yml.
#YJS_SHUTDOWN_GRACE_PERIOD_MS=
### Radicale Setting ### ### Radicale Setting ###
# Radicale is a small open-source CalDAV (calendars, to-do lists) and CardDAV (contacts) server. # Radicale is a small open-source CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
# When enabled OpenCloud is configured as a reverse proxy for Radicale, providing all authenticated # When enabled OpenCloud is configured as a reverse proxy for Radicale, providing all authenticated

View File

@@ -195,6 +195,22 @@ By default, OpenCloud Compose uses `apache/tika:latest` which provides:
The base variant is recommended for most use cases. If you need advanced features like specialized OCR processing or specific image format support, you can override the image by setting `TIKA_IMAGE=apache/tika:latest-full` in your `.env` file. The base variant is recommended for most use cases. If you need advanced features like specialized OCR processing or specific image format support, you can override the image by setting `TIKA_IMAGE=apache/tika:latest-full` in your `.env` file.
### With the Yjs Server
The yjs server enables collaborative editing of files. The browser connects to `wss://{OC_DOMAIN}/yjs`. The OpenCloud proxy forwards this route to the yjs container, so no extra DNS entry or port is needed.
Using `-f` flags:
```bash
docker compose -f docker-compose.yml -f yjs/yjs.yml -f traefik/opencloud.yml up -d
```
Or by setting in `.env`:
```
COMPOSE_FILE=docker-compose.yml:yjs/yjs.yml:traefik/opencloud.yml
```
The service keeps documents in memory only. All users of one file must reach the same instance, so run a single instance.
### With Radicale ### With Radicale
Enable CalDAV (calendars, to-do lists) and CardDAV (contacts) server. Enable CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
@@ -215,11 +231,6 @@ This setup includes:
- Radicale as a CalDAV (calendars, to-do lists) and CardDAV (contacts) server - Radicale as a CalDAV (calendars, to-do lists) and CardDAV (contacts) server
- Users access to a Personal Calendar and Addressbook - Users access to a Personal Calendar and Addressbook
Clients connect to `https://<your-domain>/caldav/` (calendar) and
`https://<your-domain>/carddav/` (contacts) — note the required trailing
slash — using an App Token as password. See [radicale/README.md](radicale/README.md)
for client setup (GNOME Online Accounts, Thunderbird) and troubleshooting.
### With Monitoring ### With Monitoring
Enable monitoring capabilities with metrics endpoints using either method: Enable monitoring capabilities with metrics endpoints using either method:
@@ -471,6 +482,7 @@ This repository uses a modular approach with multiple compose files:
- `traefik/` - Traefik reverse proxy configurations - `traefik/` - Traefik reverse proxy configurations
- `external-proxy/` - Configuration for external reverse proxies - `external-proxy/` - Configuration for external reverse proxies
- `radicale/` - Radicale configuration - `radicale/` - Radicale configuration
- `yjs/` - Yjs server configuration (collaborative editing)
- `config/` - Configuration files for OpenCloud, Keycloak, and LDAP - `config/` - Configuration files for OpenCloud, Keycloak, and LDAP
## Advanced Usage ## Advanced Usage

View File

@@ -1,28 +1,23 @@
# This adds four additional routes to the proxy, forwarding requests # This adds additional routes to the proxy. Forwarding
# on '/caldav/', '/carddav/' and the respective '/.well-known' # request on '/carddav/', '/caldav/' and the respective '/.well-knwown'
# endpoints to the radicale container and setting the required headers. # endpoints to the radicale container and setting the required headers.
# # '/yjs' is forwarded to the yjs container.
# Client URLs (trailing slash required, see radicale/README.md):
# CalDAV: https://<your-domain>/caldav/
# CardDAV: https://<your-domain>/carddav/
additional_policies: additional_policies:
- name: default - name: default
routes: routes:
- endpoint: /yjs
backend: http://yjs:1234
unprotected: true
- endpoint: /caldav/ - endpoint: /caldav/
backend: http://radicale:5232 backend: http://radicale:5232
remote_user_header: X-Remote-User remote_user_header: X-Remote-User
skip_x_access_token: true skip_x_access_token: true
additional_headers: additional_headers:
- X-Script-Name: /caldav - X-Script-Name: /caldav
# The '.well-known' endpoints are 'unprotected' so that DAV clients
# can discover the CalDAV/CardDAV URLs (RFC 6764) before they
# authenticate. Radicale only ever answers these paths with a 301
# redirect to '/caldav/' or '/carddav/' and serves no data here
# (deeper paths return 404), so no authentication is required.
- endpoint: /.well-known/caldav - endpoint: /.well-known/caldav
backend: http://radicale:5232 backend: http://radicale:5232
remote_user_header: X-Remote-User
skip_x_access_token: true skip_x_access_token: true
unprotected: true
additional_headers: additional_headers:
- X-Script-Name: /caldav - X-Script-Name: /caldav
- endpoint: /carddav/ - endpoint: /carddav/
@@ -33,8 +28,8 @@ additional_policies:
- X-Script-Name: /carddav - X-Script-Name: /carddav
- endpoint: /.well-known/carddav - endpoint: /.well-known/carddav
backend: http://radicale:5232 backend: http://radicale:5232
remote_user_header: X-Remote-User
skip_x_access_token: true skip_x_access_token: true
unprotected: true
additional_headers: additional_headers:
- X-Script-Name: /carddav - X-Script-Name: /carddav
# To enable the radicale web UI add this rule. # To enable the radicale web UI add this rule.

View File

@@ -2,7 +2,7 @@
services: services:
opencloud: opencloud:
# renovate: depName=opencloudeu/opencloud-rolling # renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.5.0} image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-8.1.0}
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog # changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html # release notes: https://docs.opencloud.eu/opencloud_release_notes.html
user: ${OC_CONTAINER_UID_GID:-1000:1000} user: ${OC_CONTAINER_UID_GID:-1000:1000}

View File

@@ -78,7 +78,7 @@ services:
restart: always restart: always
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.7.3 image: quay.io/keycloak/keycloak:26.8.0
networks: networks:
opencloud-net: opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ] command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -1,77 +0,0 @@
# Radicale — CalDAV / CardDAV
This module adds [Radicale](https://radicale.org/) as a CalDAV (calendars,
to-do lists) and CardDAV (contacts) server behind the OpenCloud proxy. Every
user gets a personal calendar and address book on first access.
## Enabling
Add `radicale/radicale.yml` to your `COMPOSE_FILE`:
```
COMPOSE_FILE=docker-compose.yml:radicale/radicale.yml:traefik/opencloud.yml
```
The routes are defined in [`config/opencloud/proxy.yaml`](../config/opencloud/proxy.yaml),
which `radicale.yml` mounts into the opencloud container.
## Connecting clients
### URLs
| Service | URL |
|---|---|
| CalDAV (calendar) | `https://<your-domain>/caldav/` |
| CardDAV (contacts) | `https://<your-domain>/carddav/` |
**The trailing slash is required.** `https://<your-domain>/caldav` (without
the slash) is not routed to Radicale and returns the OpenCloud web UI instead.
Clients that implement DAV service discovery (RFC 6764) can also be pointed
at the bare domain `https://<your-domain>/` — the `/.well-known/caldav` and
`/.well-known/carddav` endpoints redirect them to the URLs above. Clients
that don't (or that get confused by the web UI at the base URL) need the full
URL including the suffix.
### Authentication: use an App Token
DAV clients authenticate with **username + App Token** — not your account
password. With the default configuration (`PROXY_ENABLE_BASIC_AUTH=false`)
the account password is rejected with `401 Unauthorized`; App Tokens work out
of the box.
Create a token either
- in the web UI under **Settings → App Tokens**, or
- on the CLI:
```bash
docker compose exec opencloud opencloud auth-app create --user-name=<user> --expiration=72h
```
### GNOME Online Accounts
GNOME expects a directly answering DAV endpoint per account, so calendars and
contacts are added as two separate accounts:
1. **Settings → Online Accounts → Add Account → Calendar (CalDAV)**
— URL `https://<your-domain>/caldav/`, your username, an App Token as
password.
2. **Settings → Online Accounts → Add Account → Contacts (CardDAV)**
— URL `https://<your-domain>/carddav/`, same credentials.
### Thunderbird
- Calendar: *New Calendar → On the Network*, URL `https://<your-domain>/caldav/`
- Address book: *New Address Book → Add CardDAV Address Book*, URL
`https://<your-domain>/carddav/`
Use an App Token as the password in both dialogs.
## Troubleshooting
| Symptom | Cause |
|---|---|
| `401 Unauthorized` | Account password used instead of an App Token (or the token expired). |
| `405 Method Not Allowed` / HTML response | Trailing slash missing — the request landed on the web UI, not Radicale. |
| Client says "not a (Cal)DAV server" at the base URL | The client doesn't do RFC 6764 discovery. Use the full `/caldav/` / `/carddav/` URL. |

View File

@@ -33,7 +33,8 @@
"customType": "regex", "customType": "regex",
"managerFilePatterns": [ "managerFilePatterns": [
"/^docker-compose\\.yml$/", "/^docker-compose\\.yml$/",
"/^weboffice\\/collabora\\.yml$/" "/^weboffice\\/collabora\\.yml$/",
"/^yjs\\/yjs\\.yml$/"
], ],
"matchStrings": [ "matchStrings": [
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}" "# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"

View File

@@ -15,7 +15,7 @@ services:
restart: always restart: always
keycloak: keycloak:
image: quay.io/keycloak/keycloak:26.7.3 image: quay.io/keycloak/keycloak:26.8.0
networks: networks:
opencloud-net: opencloud-net:
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ] command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]

View File

@@ -16,7 +16,7 @@ services:
- "traefik.http.services.opencloud.loadbalancer.server.port=9200" - "traefik.http.services.opencloud.loadbalancer.server.port=9200"
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}" - "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
traefik: traefik:
image: traefik:v3.7.12 image: traefik:v3.7.13
# release notes: https://github.com/traefik/traefik/releases # release notes: https://github.com/traefik/traefik/releases
user: ${TRAEFIK_CONTAINER_UID_GID:-0:0} user: ${TRAEFIK_CONTAINER_UID_GID:-0:0}
networks: networks:

View File

@@ -29,7 +29,7 @@ services:
# To rotate the key, remove the volume and start again: # To rotate the key, remove the volume and start again:
# docker compose down collabora && docker volume rm <project>_collabora-proof-key # docker compose down collabora && docker volume rm <project>_collabora-proof-key
collabora-proof-key: collabora-proof-key:
image: alpine/openssl:3.5.8 image: alpine/openssl:3.5.9
entrypoint: ["/bin/sh"] entrypoint: ["/bin/sh"]
command: command:
- -ec - -ec
@@ -50,7 +50,7 @@ services:
restart: "no" restart: "no"
collabora: collabora:
image: collabora/code:26.04.3.1.1 image: collabora/code:26.04.4.2.1
# release notes: https://www.collaboraonline.com/release-notes/ # release notes: https://www.collaboraonline.com/release-notes/
networks: networks:
opencloud-net: opencloud-net:

23
yjs/yjs.yml Normal file
View File

@@ -0,0 +1,23 @@
---
services:
opencloud:
environment:
WEB_OPTION_YJS_SERVER_URL: wss://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/yjs
volumes:
# the /yjs route is configured in the proxy
- ./config/opencloud/proxy.yaml:/etc/opencloud/proxy.yaml
yjs:
# renovate: depName=opencloudeu/yjs
image: ${YJS_DOCKER_IMAGE:-opencloudeu/yjs}:${YJS_DOCKER_TAG:-1.1.0}
user: ${OC_CONTAINER_UID_GID:-1000:1000}
networks:
opencloud-net:
environment:
PORT: '1234'
# internal address, no TLS between the containers
OPENCLOUD_URL: ${YJS_OPENCLOUD_URL:-http://opencloud:9200}
SHUTDOWN_GRACE_PERIOD_MS: '${YJS_SHUTDOWN_GRACE_PERIOD_MS:-15000}'
logging:
driver: ${LOG_DRIVER:-local}
restart: always
stop_grace_period: 20s