Compare commits

...

59 Commits

Author SHA1 Message Date
Alexander Ackermann
39f40fa0f7 chore: bump web app maps to v1.0.2 2025-11-10 13:32:39 +01:00
Alex
f24923f95e Merge pull request #146 from opencloud-eu/mount-local-fonts-to-collabora-followup
feat: mount local system font dir to collabora followup
2025-11-07 11:23:09 +01:00
Alexander Ackermann
4f79e9ab7b feat: mount local system font dir to collabora followup 2025-11-07 11:19:22 +01:00
Alex
cd5d97cda9 Merge pull request #144 from opencloud-eu/mount-local-fonts-to-collabora 2025-11-07 11:07:13 +01:00
Alex
b501311d0f Apply suggestion from @kulmann
Co-authored-by: Benedikt Kulmann <benedikt@kulmann.biz>
2025-11-06 13:55:10 +01:00
Alex
85deada0d2 Update weboffice/collabora.yml 2025-11-06 13:48:52 +01:00
Michael Barz
522ced8c96 Merge pull request #99 from opencloud-eu/move_production_to_docs
Move production deployment infos to docs
2025-11-06 12:12:35 +01:00
Alexander Ackermann
0622cf6e60 fix typo 2025-11-06 10:53:37 +01:00
Alexander Ackermann
69b40132c0 feat: mount local system font dir to collabora 2025-11-06 10:51:07 +01:00
Alex
f466650a97 Merge pull request #142 from opencloud-eu/add-app-maps 2025-11-06 08:40:03 +01:00
Alexander Ackermann
a27c40c4dc feat: add app maps 2025-11-05 23:08:30 +01:00
Viktor Scharf
94c8075b36 Merge pull request #140 from opencloud-eu/fix-secure-view
fix: fix app addr for secure view
2025-11-05 15:20:42 +01:00
Michael Barz
7543aa2eec fix: fix app addr for secure view 2025-11-05 15:15:52 +01:00
Viktor Scharf
d51d43825a Merge pull request #139 from a-schuetz/add_collabora_home_mode
feat: add home mode option to Collabora
2025-11-05 15:15:13 +01:00
a-schuetz
723fb73fb4 feat: add home mode option to Collabora 2025-11-05 09:01:01 +00:00
Ralf Haferkamp
16dd321bf2 Merge pull request #130 from opencloud-eu/web/704
feat: Allow collabora to download images from the cloud instance
2025-11-04 16:01:42 +01:00
Michael Barz
df98c14b80 Merge pull request #132 from bilogic/patch-1
document the mandatory OC_DOMAIN
2025-10-30 10:14:45 +01:00
bilogic
53ec7140da document the mandatory OC_DOMAIN 2025-10-30 16:16:03 +08:00
Ralf Haferkamp
d3f0044fe3 feat: Allow collabora to download images from the cloud instance
Related: https://github.com/opencloud-eu/web/issues/704
2025-10-29 12:14:30 +01:00
Thomas Schweiger
9cb8196122 Merge pull request #124 from mwllgr/patch-1
Make external IDP LDAP server start automatically
2025-10-27 15:23:11 +01:00
Ralf Haferkamp
bdd2638f3f Merge pull request #123 from opencloud-eu/fix/android-login-fails
Allow Android logins with OC docker compose stack using Keycloak in shared directory mode
2025-10-27 09:40:41 +01:00
Thomas Schweiger
3558f9c2e1 fix: fix #122 - OIDC login fails with "malformed server configuration" 2025-10-27 09:11:04 +01:00
mwllgr
bc338d7ff4 Make external IDP LDAP server start automatically 2025-10-25 22:14:08 +02:00
Thomas Schweiger
4fc30f0330 Merge pull request #121 from Tronde/fix/remove-misleading-comment
Fix: Remove confusing comment - notifications is not mandatory
2025-10-23 18:29:45 +02:00
Thomas Schweiger
93b8186eb6 fix: rephrase and fix additional typo 2025-10-23 18:09:23 +02:00
Thomas Schweiger
85e3098e1c fix: fix typo 2025-10-23 18:02:04 +02:00
Thomas Schweiger
fed9c09ae5 Merge pull request #116 from opencloud-eu/fix/initialise-ldap-acls
fix: fix #104 - LDAP userPassword attribute can be read without auth
2025-10-23 17:39:24 +02:00
Thomas Schweiger
c689b26275 fix: change acls and how to apply them 2025-10-23 16:09:27 +02:00
Joerg Kastning
c1dcf1d1d9 Fix: Remove confusing comment - notifications is not mandatory
- Solves #118

Signed-off-by: Joerg Kastning <jkastning@my-it-brain.de>
2025-10-22 19:52:19 +02:00
Michael Barz
25b0de4525 Merge pull request #119 from opencloud-eu/flimmy-patch-1
fix typo in .env.example
2025-10-21 20:47:39 +02:00
Michael Flemming
67743a8e19 fix typo in .env.example
a wild character found its way into a comment.
2025-10-21 20:46:09 +02:00
Thomas Schweiger
f253158ae7 fix: fix #104 - LDAP userPassword attribute can be read without auth 2025-10-18 11:21:54 +02:00
Alex
219899adfc Merge pull request #115 from opencloud-eu/add-update-server-to-csp.yaml
chore: add update server to csp.yaml (cors)
2025-10-13 13:22:09 +02:00
Alexander Ackermann
6be2c824ea chore: add update server to csp.yaml (cors) 2025-10-13 13:20:40 +02:00
Thomas Schweiger
3d82f1b60b Merge pull request #110 from opencloud-eu/fix/do-not-expose-ldap-service
enhane: do not expose ldap service
2025-10-07 11:39:06 +02:00
Thomas Schweiger
c55b36b559 enhane: do not expose ldap service 2025-10-07 11:08:35 +02:00
Michael Barz
ce65001eba Merge pull request #107 from mwllgr/main
Change image for OpenLDAP in external-idp to bitnamilegacy
2025-10-04 16:36:45 +02:00
mwllgr
b88b80539b Change image for OpenLDAP in external-idp to bitnamilegacy 2025-10-04 16:23:37 +02:00
Thomas Schweiger
6502f1fee7 Merge pull request #103 from opencloud-eu/fix/enable-password-hashing-for-ldap
fix: fix passwords, changed via Keycloak, are not hashed in LDAP #102
2025-09-30 19:23:21 +02:00
Thomas Schweiger
ef64eb6b92 fix: fix passwords changed via Keycloak are not hashed in LDAP #102 2025-09-30 14:21:11 +02:00
Thomas Schweiger
07183c14fc Merge pull request #101 from opencloud-eu/traefik-enable-local-certs
fix: fix syntax of certs.yml configuration file example
2025-09-29 17:18:09 +02:00
Thomas Schweiger
409d775471 fix: fix typo 2025-09-29 14:42:45 +02:00
Thomas Schweiger
ad89914a81 fix: fix syntax of certs.yml configuration file example 2025-09-29 14:12:37 +02:00
Michael Flemming
5c26c75080 Merge pull request #100 from opencloud-eu/pin_postgres_version
quick fix for breaking changes in postgres 18 by pinning to 17
2025-09-26 17:53:21 +02:00
Michael 'Flimmy' Flemming
27aa8f40f1 quick fix for breaking changes in postgres 18 by pinning to 17 2025-09-26 17:51:38 +02:00
Michael 'Flimmy' Flemming
f3c5f8f591 add link to docs for production deployment 2025-09-26 15:09:52 +02:00
Michael 'Flimmy' Flemming
fc560119f4 remove production deployment section 2025-09-26 15:09:12 +02:00
Michael Barz
b7078d309b Merge pull request #91 from opencloud-eu/collabora-healthcheck
enhancement: improve collabora health check
2025-09-15 16:33:42 +02:00
Michael Barz
c2cd669fc1 Merge pull request #94 from opencloud-eu/fix-external-idp
fix: add script-src to csp
2025-09-15 16:32:55 +02:00
Michael Barz
9a3a217c78 fix: add script-src to csp 2025-09-15 16:04:05 +02:00
Michael Barz
7cd7e19d6f Merge pull request #92 from opencloud-eu/fix-sender
fix: smtp sender cannot use nested env var
2025-09-12 09:47:46 +02:00
Michael Barz
311670fc14 Merge pull request #90 from opencloud-eu/clarify-dns
style: clarify DNS setup
2025-09-12 09:47:24 +02:00
Michael Barz
97fbdbe85f fix: smtp sender cannot use nested env var 2025-09-11 22:26:59 +02:00
Michael Barz
fe3497ec51 enhancement: improve collabora health check 2025-09-11 22:06:03 +02:00
Michael Barz
c8557c3455 style: clarify DNS setup 2025-09-11 21:27:54 +02:00
Michael Barz
779c4e1daf fix: remove unused minio config 2025-09-08 22:23:52 +02:00
Michael Barz
bfc2a64a79 Merge pull request #84 from lxusrbin/traefik-version
Update traefik image tag
2025-09-04 13:03:25 +02:00
Michael Barz
f6d384b411 Merge pull request #85 from opencloud-eu/setDefaultAdminPass
set default admin password
2025-09-04 13:02:56 +02:00
Christian Frost
81904c946a Update traefik image tag 2025-08-29 12:35:56 +02:00
15 changed files with 116 additions and 63 deletions

View File

@@ -59,7 +59,7 @@ TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
# stores: # stores:
# - default # - default
# #
# The certificates need to copied into ./certs/, the absolute path inside the container is /certs/. # The certificates need to be copied into ./certs/, the absolute path inside the container is /certs/.
# You can also use TRAEFIK_CERTS_DIR=/path/on/host to set the path to the certificates directory. # You can also use TRAEFIK_CERTS_DIR=/path/on/host to set the path to the certificates directory.
# Enable the access log for Traefik by setting the following variable to true. # Enable the access log for Traefik by setting the following variable to true.
TRAEFIK_ACCESS_LOG= TRAEFIK_ACCESS_LOG=
@@ -134,15 +134,11 @@ DECOMPOSEDS3_ACCESS_KEY=
DECOMPOSEDS3_SECRET_KEY= DECOMPOSEDS3_SECRET_KEY=
# S3 bucket. Defaults to "opencloud" # S3 bucket. Defaults to "opencloud"
DECOMPOSEDS3_BUCKET= DECOMPOSEDS3_BUCKET=
#
# For testing purposes, add local minio S3 storage to the docker-compose file.
# The leading colon is required to enable the service.
#DECOMPOSEDS3_MINIO=:minio.yml
# Minio domain. Defaults to "minio.opencloud.test".
MINIO_DOMAIN=
# Define SMTP settings if you would like to send OpenCloud email notifications. # Define SMTP settings if you would like to send OpenCloud email notifications.
# To actually send notifications, you also need to enable the 'notifications' service
# by adding it to the START_ADDITIONAL_SERVICES variable below.
# #
# NOTE: when configuring Inbucket, these settings have no effect, see inbucket.yml for details. # NOTE: when configuring Inbucket, these settings have no effect, see inbucket.yml for details.
# SMTP host to connect to. # SMTP host to connect to.
@@ -163,12 +159,11 @@ SMTP_TRANSPORT_ENCRYPTION=
# Allow insecure connections to the SMTP server. Defaults to false. # Allow insecure connections to the SMTP server. Defaults to false.
SMTP_INSECURE= SMTP_INSECURE=
# Addititional services to be started on opencloud startup # Additional services to be started on opencloud startup
# The following list of services is not startet automatically and must be # The following list of services is not started automatically and must be
# manually defined for startup: # manually defined for startup:
# IMPORTANT: The notification service is MANDATORY, do not delete!
# IMPORTANT: Add any services to the startup list comma separated like "notifications,antivirus" etc. # IMPORTANT: Add any services to the startup list comma separated like "notifications,antivirus" etc.
START_ADDITIONAL_SERVICES="notifications" START_ADDITIONAL_SERVICES=""
## Default Enabled Services ## ## Default Enabled Services ##
@@ -209,6 +204,11 @@ COLLABORA_SSL_ENABLE=false
# If you're on an internet-facing server, enable SSL verification for Collabora Online. # If you're on an internet-facing server, enable SSL verification for Collabora Online.
# Please comment out the following line: # Please comment out the following line:
COLLABORA_SSL_VERIFICATION=false COLLABORA_SSL_VERIFICATION=false
# Enable home mode in Collabore Online.
# Home users can enable this setting, which in turn disables welcome screen and user feedback popups,
# but also limits concurrent open connections to 20 and concurrent open documents to 10.
# Default is false if not specified.
COLLABORA_HOME_MODE=
### Virusscanner Settings ### ### Virusscanner Settings ###
@@ -222,7 +222,7 @@ COLLABORA_SSL_VERIFICATION=false
# Defaults to "partial" # Defaults to "partial"
#ANTIVIRUS_MAX_SCAN_SIZE_MODE= #ANTIVIRUS_MAX_SCAN_SIZE_MODE=
# Image version of the ClamAV container. # Image version of the ClamAV container.
# Defaults to "latest"y # Defaults to "latest"
CLAMAV_DOCKER_TAG= CLAMAV_DOCKER_TAG=

1
.gitignore vendored
View File

@@ -5,6 +5,7 @@
# exclude the apps folder # exclude the apps folder
/config/opencloud/apps/* /config/opencloud/apps/*
!/config/opencloud/apps/.gitkeep !/config/opencloud/apps/.gitkeep
!/config/opencloud/apps/maps
# exclude custom compose files # exclude custom compose files
/custom /custom

View File

@@ -2,6 +2,9 @@
This repository provides Docker Compose configurations for deploying OpenCloud in various environments. This repository provides Docker Compose configurations for deploying OpenCloud in various environments.
> [!IMPORTANT]
> Please use the [official docs](https://docs.opencloud.eu/docs/admin/getting-started/container/docker-compose/docker-compose-base) for a **Production Deployment**.
## Overview ## Overview
OpenCloud Compose offers a modular approach to deploying OpenCloud with several configuration options: OpenCloud Compose offers a modular approach to deploying OpenCloud with several configuration options:
@@ -42,8 +45,9 @@ OpenCloud Compose offers a modular approach to deploying OpenCloud with several
3. **Set admin password**: 3. **Set admin password**:
set `INITIAL_ADMIN_PASSWORD=your_secure_password` environment variable in your `.env` file set `INITIAL_ADMIN_PASSWORD=your_secure_password` environment variable in your `.env` file
4. **Domain**:
4. **Configure deployment options**: optionally, set `OC_DOMAIN=your-domain.com` to overwrite the default `cloud.opencloud.test`
5. **Configure deployment options**:
You can deploy using explicit `-f` flags: You can deploy using explicit `-f` flags:
```bash ```bash
@@ -60,42 +64,26 @@ OpenCloud Compose offers a modular approach to deploying OpenCloud with several
docker compose up -d docker compose up -d
``` ```
5. **Add local domains to `/etc/hosts`**: 6. **Add local domains to `/etc/hosts`** (for local development only):
``` ```
127.0.0.1 cloud.opencloud.test 127.0.0.1 cloud.opencloud.test
127.0.0.1 traefik.opencloud.test 127.0.0.1 traefik.opencloud.test
127.0.0.1 keycloak.opencloud.test 127.0.0.1 keycloak.opencloud.test
``` ```
6. **Access OpenCloud**: 7. **Access OpenCloud**:
- URL: https://cloud.opencloud.test - URL: https://cloud.opencloud.test
- Username: `admin` - Username: `admin`
- Password: value of your `INITIAL_ADMIN_PASSWORD` - Password: value of your `INITIAL_ADMIN_PASSWORD`
### Production Deployment
1. **Edit the `.env` file** and configure:
- Domain names
- Admin password
- SSL certificate email
- Storage paths
2. **Configure deployment options** in `.env`:
```
COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml
```
3. **Start OpenCloud**:
```bash
docker compose up -d
```
## Deployment Options ## Deployment Options
### With Keycloak and LDAP using a Shared User Directory ### With Keycloak and LDAP using a Shared User Directory
OpenCloud can be deployed with Keycloak for identity management and LDAP for the shared user directory: OpenCloud can be deployed with Keycloak for identity management and LDAP for the shared user directory:
> **DNS Requirements**: This setup requires DNS entries for both the main OpenCloud domain and the Keycloak subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `keycloak.example.com`) or use a wildcard DNS entry (`*.example.com`).
Using `-f` flags: Using `-f` flags:
```bash ```bash
docker compose -f docker-compose.yml -f idm/ldap-keycloak.yml -f traefik/opencloud.yml -f traefik/ldap-keycloak.yml up -d docker compose -f docker-compose.yml -f idm/ldap-keycloak.yml -f traefik/opencloud.yml -f traefik/ldap-keycloak.yml up -d
@@ -106,10 +94,10 @@ Or by setting in `.env`:
COMPOSE_FILE=docker-compose.yml:idm/ldap-keycloak.yml:traefik/opencloud.yml:traefik/ldap-keycloak.yml COMPOSE_FILE=docker-compose.yml:idm/ldap-keycloak.yml:traefik/opencloud.yml:traefik/ldap-keycloak.yml
``` ```
Add to `/etc/hosts` for local development: > **For local development only**: Add to `/etc/hosts`:
``` > ```
127.0.0.1 keycloak.opencloud.test > 127.0.0.1 keycloak.opencloud.test
``` > ```
This setup includes: This setup includes:
- Keycloak for authentication and identity management - Keycloak for authentication and identity management
@@ -120,6 +108,8 @@ This setup includes:
Include Collabora for document editing using either method: Include Collabora for document editing using either method:
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain, Collabora subdomain, and WOPI server subdomain. Configure DNS A/AAAA records for your domains (e.g., `cloud.example.com`, `collabora.example.com`, `wopiserver.example.com`) or use a wildcard DNS entry (`*.example.com`).
Using `-f` flags: Using `-f` flags:
```bash ```bash
docker compose -f docker-compose.yml -f weboffice/collabora.yml -f traefik/opencloud.yml -f traefik/collabora.yml up -d docker compose -f docker-compose.yml -f weboffice/collabora.yml -f traefik/opencloud.yml -f traefik/collabora.yml up -d
@@ -130,16 +120,18 @@ Or by setting in `.env`:
COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml COMPOSE_FILE=docker-compose.yml:weboffice/collabora.yml:traefik/opencloud.yml:traefik/collabora.yml
``` ```
Add to `/etc/hosts` for local development: > **For local development only**: Add to `/etc/hosts`:
``` > ```
127.0.0.1 collabora.opencloud.test > 127.0.0.1 collabora.opencloud.test
127.0.0.1 wopiserver.opencloud.test > 127.0.0.1 wopiserver.opencloud.test
``` > ```
### With Full Text Search ### With Full Text Search
Enable full text search capabilities with Apache Tika using either method: Enable full text search capabilities with Apache Tika using either method:
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain. Configure a DNS A/AAAA record for your domain (e.g., `cloud.example.com`) or use a wildcard DNS entry (`*.example.com`).
Using `-f` flags: Using `-f` flags:
```bash ```bash
docker compose -f docker-compose.yml -f search/tika.yml -f traefik/opencloud.yml up -d docker compose -f docker-compose.yml -f search/tika.yml -f traefik/opencloud.yml up -d
@@ -159,6 +151,8 @@ This setup includes:
Enable CalDAV (calendars, to-do lists) and CardDAV (contacts) server. Enable CalDAV (calendars, to-do lists) and CardDAV (contacts) server.
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain. Configure a DNS A/AAAA record for your domain (e.g., `cloud.example.com`) or use a wildcard DNS entry (`*.example.com`).
Using `-f` flags: Using `-f` flags:
```bash ```bash
docker compose -f docker-compose.yml -f radicale/radicale.yml -f traefik/opencloud.yml up -d docker compose -f docker-compose.yml -f radicale/radicale.yml -f traefik/opencloud.yml up -d
@@ -177,6 +171,8 @@ This setup includes:
Enable monitoring capabilities with metrics endpoints using either method: Enable monitoring capabilities with metrics endpoints using either method:
> **DNS Requirements**: This setup requires DNS entries for the main OpenCloud domain. Configure a DNS A/AAAA record for your domain (e.g., `cloud.example.com`) or use a wildcard DNS entry (`*.example.com`).
Using `-f` flags: Using `-f` flags:
```bash ```bash
docker compose -f docker-compose.yml -f monitoring/monitoring.yml -f traefik/opencloud.yml up -d docker compose -f docker-compose.yml -f monitoring/monitoring.yml -f traefik/opencloud.yml up -d
@@ -206,6 +202,8 @@ Access metrics endpoints:
If you already have a reverse proxy (Nginx, Caddy, etc.), use either method: If you already have a reverse proxy (Nginx, Caddy, etc.), use either method:
> **DNS Requirements**: When using an external proxy, you need to configure your external proxy to handle DNS and SSL termination. Ensure your DNS entries point to your external proxy server, and configure your proxy to forward requests to the exposed OpenCloud ports.
Using `-f` flags: Using `-f` flags:
```bash ```bash
docker compose -f docker-compose.yml -f weboffice/collabora.yml -f external-proxy/opencloud.yml -f external-proxy/collabora.yml up -d docker compose -f docker-compose.yml -f weboffice/collabora.yml -f external-proxy/opencloud.yml -f external-proxy/collabora.yml up -d
@@ -221,7 +219,6 @@ This exposes the necessary ports:
- Collabora: 9980 - Collabora: 9980
- WOPI server: 9300 - WOPI server: 9300
**Please note:** **Please note:**
If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host. If you're using **Nginx Proxy Manager (NPM)**, you **should NOT** activate **"Block Common Exploits"** for the Proxy Host.
Otherwise, the desktop app authentication will return **error 403 Forbidden**. Otherwise, the desktop app authentication will return **error 403 Forbidden**.

View File

@@ -676,6 +676,7 @@
"profile", "profile",
"roles", "roles",
"groups", "groups",
"OpenCloudUnique_ID",
"basic", "basic",
"email" "email"
], ],
@@ -2336,7 +2337,7 @@
"always" "always"
], ],
"usePasswordModifyExtendedOp": [ "usePasswordModifyExtendedOp": [
"false" "true"
], ],
"trustEmail": [ "trustEmail": [
"false" "false"

11
config/ldap/init-ldap-acls.sh Executable file
View File

@@ -0,0 +1,11 @@
#!/usr/bin/env bash
set -eu
# apply acls
echo -n "Applying acls... "
slapmodify -F /opt/bitnami/openldap/etc/slapd.d -b cn=config -l /opt/bitnami/openldap/etc/schema/50_acls.ldif
if [ $? -eq 0 ]; then
echo "done."
else
echo "failed."
fi

View File

@@ -0,0 +1,9 @@
# OpenCloud ldap acl file which gets applied during the first db initialisation
dn: olcDatabase={2}mdb,cn=config
changetype: modify
replace: olcAccess
olcAccess: {0}to dn.subtree="dc=opencloud,dc=eu" attrs=entry,uid,objectClass,entryUUID
by * read
olcAccess: {1}to attrs=userPassword
by self write
by * auth

File diff suppressed because one or more lines are too long

View File

@@ -0,0 +1,3 @@
{
"entrypoint": "js/maps-uKkx1qsf.js"
}

View File

@@ -8,6 +8,7 @@ directives:
- 'wss://${COMPANION_DOMAIN|companion.opencloud.test}/' - 'wss://${COMPANION_DOMAIN|companion.opencloud.test}/'
- 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/' - 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/'
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}/' - 'https://${IDP_DOMAIN|keycloak.opencloud.test}/'
- 'https://update.opencloud.eu/'
default-src: default-src:
- '''none''' - '''none'''
font-src: font-src:
@@ -27,6 +28,7 @@ directives:
- 'data:' - 'data:'
- 'blob:' - 'blob:'
- 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/' - 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/'
- 'https://tile.openstreetmap.org/'
# In contrary to bash and docker the default is given after the | character # In contrary to bash and docker the default is given after the | character
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}/' - 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}/'
manifest-src: manifest-src:
@@ -39,6 +41,7 @@ directives:
script-src: script-src:
- '''self''' - '''self'''
- '''unsafe-inline''' - '''unsafe-inline'''
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}/'
style-src: style-src:
- '''self''' - '''self'''
- '''unsafe-inline''' - '''unsafe-inline'''

View File

@@ -32,7 +32,7 @@ services:
# email server (if configured) # email server (if configured)
NOTIFICATIONS_SMTP_HOST: "${SMTP_HOST}" NOTIFICATIONS_SMTP_HOST: "${SMTP_HOST}"
NOTIFICATIONS_SMTP_PORT: "${SMTP_PORT}" NOTIFICATIONS_SMTP_PORT: "${SMTP_PORT}"
NOTIFICATIONS_SMTP_SENDER: "${SMTP_SENDER:-OpenCloud notifications <notifications@${OC_DOMAIN:-cloud.opencloud.test}>}" NOTIFICATIONS_SMTP_SENDER: "${SMTP_SENDER:-OpenCloud Notifications <notifications@cloud.opencloud.test>}"
NOTIFICATIONS_SMTP_USERNAME: "${SMTP_USERNAME}" NOTIFICATIONS_SMTP_USERNAME: "${SMTP_USERNAME}"
NOTIFICATIONS_SMTP_PASSWORD: "${SMTP_PASSWORD}" NOTIFICATIONS_SMTP_PASSWORD: "${SMTP_PASSWORD}"
NOTIFICATIONS_SMTP_INSECURE: "${SMTP_INSECURE}" NOTIFICATIONS_SMTP_INSECURE: "${SMTP_INSECURE}"

View File

@@ -44,7 +44,7 @@ services:
# The openCloud users need to be able to edit their account in the externa IdP # The openCloud users need to be able to edit their account in the externa IdP
WEB_OPTION_ACCOUNT_EDIT_LINK_HREF: ${IDP_ACCOUNT_URL} WEB_OPTION_ACCOUNT_EDIT_LINK_HREF: ${IDP_ACCOUNT_URL}
ldap-server: ldap-server:
image: bitnami/openldap:2.6 image: bitnamilegacy/openldap:2.6
networks: networks:
opencloud-net: opencloud-net:
entrypoint: [ "/bin/sh", "/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh", "/opt/bitnami/scripts/openldap/run.sh" ] entrypoint: [ "/bin/sh", "/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh", "/opt/bitnami/scripts/openldap/run.sh" ]
@@ -57,9 +57,6 @@ services:
LDAP_TLS_KEY_FILE: /opt/bitnami/openldap/share/openldap.key LDAP_TLS_KEY_FILE: /opt/bitnami/openldap/share/openldap.key
LDAP_ROOT: "dc=opencloud,dc=eu" LDAP_ROOT: "dc=opencloud,dc=eu"
LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin} LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin}
ports:
- "127.0.0.1:389:1389"
- "127.0.0.1:636:1636"
volumes: volumes:
# Only use the base ldif file to create the base structure # Only use the base ldif file to create the base structure
- ./config/ldap/ldif/10_base.ldif:/ldifs/10_base.ldif - ./config/ldap/ldif/10_base.ldif:/ldifs/10_base.ldif
@@ -68,6 +65,7 @@ services:
- ./config/ldap/docker-entrypoint-override.sh:/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh - ./config/ldap/docker-entrypoint-override.sh:/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh
- ${LDAP_CERTS_DIR:-ldap-certs}:/opt/bitnami/openldap/share - ${LDAP_CERTS_DIR:-ldap-certs}:/opt/bitnami/openldap/share
- ${LDAP_DATA_DIR:-ldap-data}:/bitnami/openldap - ${LDAP_DATA_DIR:-ldap-data}:/bitnami/openldap
restart: always
volumes: volumes:
ldap-certs: ldap-certs:

View File

@@ -51,12 +51,11 @@ services:
LDAP_TLS_KEY_FILE: /opt/bitnami/openldap/share/openldap.key LDAP_TLS_KEY_FILE: /opt/bitnami/openldap/share/openldap.key
LDAP_ROOT: "dc=opencloud,dc=eu" LDAP_ROOT: "dc=opencloud,dc=eu"
LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin} LDAP_ADMIN_PASSWORD: ${LDAP_BIND_PASSWORD:-admin}
ports:
- "127.0.0.1:389:1389"
- "127.0.0.1:636:1636"
volumes: volumes:
- ./config/ldap/ldif/10_base.ldif:/ldifs/10_base.ldif - ./config/ldap/ldif/10_base.ldif:/ldifs/10_base.ldif
- ./config/ldap/ldif/20_admin.ldif:/ldifs/20_admin.ldif - ./config/ldap/ldif/20_admin.ldif:/ldifs/20_admin.ldif
- ./config/ldap/ldif/50_acls.ldif:/opt/bitnami/openldap/etc/schema/50_acls.ldif
- ./config/ldap/init-ldap-acls.sh:/docker-entrypoint-initdb.d/init-ldap-acls.sh
- ./config/ldap/docker-entrypoint-override.sh:/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh - ./config/ldap/docker-entrypoint-override.sh:/opt/bitnami/scripts/openldap/docker-entrypoint-override.sh
- ldap-certs:/opt/bitnami/openldap/share - ldap-certs:/opt/bitnami/openldap/share
- ldap-data:/bitnami/openldap - ldap-data:/bitnami/openldap
@@ -65,7 +64,7 @@ services:
restart: always restart: always
postgres: postgres:
image: postgres:alpine image: postgres:17-alpine
networks: networks:
opencloud-net: opencloud-net:
volumes: volumes:

View File

@@ -1,7 +1,7 @@
--- ---
services: services:
postgres: postgres:
image: postgres:alpine image: postgres:17-alpine
networks: networks:
opencloud-net: opencloud-net:
volumes: volumes:

View File

@@ -9,7 +9,7 @@ services:
- "traefik.http.services.opencloud.loadbalancer.server.port=9200" - "traefik.http.services.opencloud.loadbalancer.server.port=9200"
- "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}" - "traefik.http.routers.opencloud.${TRAEFIK_SERVICES_TLS_CONFIG}"
traefik: traefik:
image: traefik:v3.3.1 image: traefik:v3
# release notes: https://github.com/traefik/traefik/releases # release notes: https://github.com/traefik/traefik/releases
networks: networks:
opencloud-net: opencloud-net:

View File

@@ -9,7 +9,7 @@ services:
NATS_NATS_HOST: 0.0.0.0 NATS_NATS_HOST: 0.0.0.0
GATEWAY_GRPC_ADDR: 0.0.0.0:9142 GATEWAY_GRPC_ADDR: 0.0.0.0:9142
# make collabora the secure view app # make collabora the secure view app
FRONTEND_APP_HANDLER_SECURE_VIEW_APP_ADDR: eu.opencloud.api.collaboration.CollaboraOnline FRONTEND_APP_HANDLER_SECURE_VIEW_APP_ADDR: eu.opencloud.api.collaboration
GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6" GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6"
collaboration: collaboration:
@@ -58,15 +58,25 @@ services:
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \ --o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \
--o:ssl.termination=true \ --o:ssl.termination=true \
--o:welcome.enable=false \ --o:welcome.enable=false \
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test} --o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test} \
--o:net.lok_allow.host[14]=${OC_DOMAIN-cloud.opencloud.test} \
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
username: ${COLLABORA_ADMIN_USER:-admin} username: ${COLLABORA_ADMIN_USER:-admin}
password: ${COLLABORA_ADMIN_PASSWORD:-admin} password: ${COLLABORA_ADMIN_PASSWORD:-admin}
cap_add: cap_add:
- MKNOD - MKNOD
volumes:
# Mount local TrueType fonts so the container can use system fonts
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
logging: logging:
driver: ${LOG_DRIVER:-local} driver: ${LOG_DRIVER:-local}
restart: always restart: always
entrypoint: [ '/bin/bash', '-c' ] entrypoint: [ '/bin/bash', '-c' ]
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ] command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
healthcheck: healthcheck:
test: ["CMD", "bash", "-c", "exec 3<>/dev/tcp/127.0.0.1/9980 && echo -e 'GET /hosting/discovery HTTP/1.1\r\nHost: localhost:9980\r\n\r\n' >&3 && head -n 1 <&3 | grep '200 OK'"] test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ]
interval: 15s
timeout: 10s
retries: 5