mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-08-07 12:28:43 +08:00
Compare commits
21 Commits
stable-7.2
...
6b4bb80fe5
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6b4bb80fe5 | ||
|
|
bc0a74dd5a | ||
|
|
b8a0a98a51 | ||
|
|
b914288032 | ||
|
|
09e0d8f32a | ||
|
|
aab87f13a7 | ||
|
|
aebf5882f4 | ||
|
|
f292460d32 | ||
|
|
f0277501f0 | ||
|
|
76e41a4848 | ||
|
|
46ad111b94 | ||
|
|
9cac2bd525 | ||
|
|
d965660599 | ||
|
|
f3f0ece32a | ||
|
|
b138f37c98 | ||
|
|
e92718ffa0 | ||
|
|
8c43842e7b | ||
|
|
cc49b063c0 | ||
|
|
7cf59a62a9 | ||
|
|
32b328218f | ||
|
|
c814f08cd5 |
@@ -319,12 +319,12 @@ OpenCloud Compose supports adding SSL certificates for public domains and develo
|
||||
### Use Let's Encrypt with ACME Challenge
|
||||
|
||||
1. **Enable Let's Encrypt**:
|
||||
- Set `TRAEFIK_LETSENCRYPT_EMAIL` to your email address for the ACME challenge
|
||||
- Set `TRAEFIK_ACME_MAIL` to your email address for the ACME challenge
|
||||
- Set `TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"` to use Let's Encrypt (default value)
|
||||
|
||||
```bash
|
||||
# In your .env file
|
||||
TRAEFIK_LETSENCRYPT_EMAIL=devops@your-domain.tld
|
||||
TRAEFIK_ACME_MAIL=devops@your-domain.tld
|
||||
TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
|
||||
```
|
||||
|
||||
@@ -412,7 +412,7 @@ Key variables:
|
||||
| `LDAP_BIND_PASSWORD` | LDAP password for the bind user | admin |
|
||||
| `KC_DB_USERNAME` | Database user for keycloak | keycloak |
|
||||
| `KC_DB_PASSWORD` | Database password for keycloak | keycloak |
|
||||
| `TRAEFIK_LETSENCRYPT_EMAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
|
||||
| `TRAEFIK_ACME_MAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
|
||||
| `TRAEFIK_SERVICES_TLS_CONFIG` | Tell traefik and the services which TLS config to use | tls.certresolver=letsencrypt |
|
||||
| `TRAEFIK_CERTS_DIR` | Directory for custom certificates. | ./certs |
|
||||
|
||||
|
||||
@@ -1,8 +1,9 @@
|
||||
:root {
|
||||
--pf-global--primary-color--100: #e2baff;
|
||||
--pf-global--primary-color--200: #e2baff;
|
||||
--pf-global--primary-color--dark-100: #e2baff;
|
||||
--pf-global--Color--light-100: #20434f;
|
||||
--pf-v5-global--primary-color--100: #e2baff;
|
||||
--pf-v5-global--primary-color--200: #e2baff;
|
||||
--pf-v5-global--primary-color--dark-100: #e2baff;
|
||||
--pf-v5-c-button--m-secondary--Color: #e2baff;
|
||||
--pf-v5-global--Color--light-100: #20434f;
|
||||
}
|
||||
|
||||
@font-face {
|
||||
@@ -21,18 +22,36 @@
|
||||
|
||||
body {
|
||||
font-family: "OpenCloud", "Open Sans", Helvetica, Arial, sans-serif;
|
||||
background: url(../img/background.png) no-repeat center !important;
|
||||
background: url(../img/background.png) no-repeat center fixed !important;
|
||||
background-size: cover !important;
|
||||
}
|
||||
|
||||
.kc-logo-text {
|
||||
background-image: url(../img/logo.svg) !important;
|
||||
display: block;
|
||||
width: 300px;
|
||||
height: 63px;
|
||||
background: url('../img/logo.svg') no-repeat center;
|
||||
background-size: contain;
|
||||
width: 400px;
|
||||
margin: 0 !important;
|
||||
}
|
||||
|
||||
#kc-header-wrapper{
|
||||
.kc-logo-text span {
|
||||
display: none;
|
||||
}
|
||||
|
||||
#kc-header-wrapper {
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
}
|
||||
|
||||
.pf-v5-c-login__main-header {
|
||||
border-top: 4px solid var(--pf-v5-global--primary-color--100);
|
||||
}
|
||||
|
||||
@media (min-width: 1200px) {
|
||||
.pf-v5-c-login__container {
|
||||
grid-template-columns: 34rem;
|
||||
grid-template-areas:
|
||||
"header"
|
||||
"main";
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
parent=keycloak
|
||||
parent=keycloak.v2
|
||||
import=common/keycloak
|
||||
|
||||
styles=css/login.css css/theme.css
|
||||
|
||||
@@ -25,6 +25,7 @@ directives:
|
||||
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||
# This is needed for the external-sites web extension when embedding sites
|
||||
- 'https://docs.opencloud.eu'
|
||||
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||
img-src:
|
||||
- '''self'''
|
||||
- 'data:'
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
services:
|
||||
opencloud:
|
||||
# renovate: depName=opencloudeu/opencloud-rolling
|
||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-6.2.0}
|
||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.2.0}
|
||||
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
||||
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
||||
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
---
|
||||
services:
|
||||
opencloud:
|
||||
environment:
|
||||
# bind to all interfaces
|
||||
PROXY_HTTP_ADDR: "0.0.0.0:9200"
|
||||
ports:
|
||||
# expose the opencloud server on localhost
|
||||
- "127.0.0.1:9200:9200"
|
||||
environment:
|
||||
# bind to all interfaces
|
||||
PROXY_HTTP_ADDR: "0.0.0.0:9200"
|
||||
ports:
|
||||
# expose the opencloud server on localhost
|
||||
- "127.0.0.1:9200:9200"
|
||||
|
||||
@@ -17,14 +17,14 @@ services:
|
||||
OC_OIDC_CLIENT_ID: ${OC_OIDC_CLIENT_ID}
|
||||
OC_OIDC_CLIENT_SCOPES: ${OC_OIDC_CLIENT_SCOPES}
|
||||
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM: ${PROXY_ROLE_ASSIGNMENT_OIDC_CLAIM:-roles}
|
||||
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID}
|
||||
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES}
|
||||
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID}
|
||||
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES}
|
||||
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID}
|
||||
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES}
|
||||
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID}
|
||||
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES}
|
||||
WEBFINGER_WEB_OIDC_CLIENT_ID: ${WEBFINGER_WEB_OIDC_CLIENT_ID:-web}
|
||||
WEBFINGER_WEB_OIDC_CLIENT_SCOPES: ${WEBFINGER_WEB_OIDC_CLIENT_SCOPES:-openid profile email}
|
||||
WEBFINGER_ANDROID_OIDC_CLIENT_ID: ${WEBFINGER_ANDROID_OIDC_CLIENT_ID:-OpenCloudAndroid}
|
||||
WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES: ${WEBFINGER_ANDROID_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||
WEBFINGER_IOS_OIDC_CLIENT_ID: ${WEBFINGER_IOS_OIDC_CLIENT_ID:-OpenCloudIOS}
|
||||
WEBFINGER_IOS_OIDC_CLIENT_SCOPES: ${WEBFINGER_IOS_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||
WEBFINGER_DESKTOP_OIDC_CLIENT_ID: ${WEBFINGER_DESKTOP_OIDC_CLIENT_ID:-OpenCloudDesktop}
|
||||
WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES: ${WEBFINGER_DESKTOP_OIDC_CLIENT_SCOPES:-openid profile email offline_access}
|
||||
PROXY_ROLE_ASSIGNMENT_DRIVER: ${PROXY_ROLE_ASSIGNMENT_DRIVER:-oidc}
|
||||
OC_OIDC_ISSUER: ${IDP_ISSUER_URL:-https://keycloak.opencloud.test/realms/openCloud}
|
||||
# This specifies to start all services except idm and idp. These are replaced by external services.
|
||||
|
||||
@@ -78,7 +78,7 @@ services:
|
||||
restart: always
|
||||
|
||||
keycloak:
|
||||
image: quay.io/keycloak/keycloak:26.6.3
|
||||
image: quay.io/keycloak/keycloak:26.6.4
|
||||
networks:
|
||||
opencloud-net:
|
||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||
|
||||
59
search/opensearch.yml
Normal file
59
search/opensearch.yml
Normal file
@@ -0,0 +1,59 @@
|
||||
---
|
||||
services:
|
||||
opencloud:
|
||||
environment:
|
||||
# Point the search service at OpenSearch instead of the embedded bleve index.
|
||||
SEARCH_ENGINE_TYPE: open-search
|
||||
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_ADDRESSES: http://opensearch:9200
|
||||
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_INSECURE: "true"
|
||||
SEARCH_ENGINE_OPEN_SEARCH_RESOURCE_INDEX_NAME: ${OPENSEARCH_RESOURCE_INDEX:-opencloud-resources}
|
||||
depends_on:
|
||||
opensearch:
|
||||
condition: service_healthy
|
||||
|
||||
opensearch:
|
||||
image: ${OPENSEARCH_DOCKER_IMAGE:-opensearchproject/opensearch}:${OPENSEARCH_DOCKER_TAG:-2.19.5}
|
||||
environment:
|
||||
discovery.type: single-node
|
||||
bootstrap.memory_lock: "true"
|
||||
OPENSEARCH_JAVA_OPTS: ${OPENSEARCH_JAVA_OPTS:--Xms512m -Xmx512m}
|
||||
# Security plugin is disabled: OpenSearch is only reachable on the
|
||||
# internal opencloud-net bridge and no port is published to the host.
|
||||
# Do NOT enable a published port or expose this via the reverse proxy
|
||||
# without first enabling and configuring the security plugin.
|
||||
DISABLE_SECURITY_PLUGIN: "true"
|
||||
DISABLE_INSTALL_DEMO_CONFIG: "true"
|
||||
# Disable the disk-based shard allocation watermarks. By default OpenSearch
|
||||
# marks indices read-only when the host disk is <5% free, which silently
|
||||
# turns bulk upserts into no-ops. Fine to disable on a single-node dev box.
|
||||
cluster.routing.allocation.disk.threshold_enabled: "false"
|
||||
ulimits:
|
||||
memlock:
|
||||
soft: -1
|
||||
hard: -1
|
||||
nofile:
|
||||
soft: 65536
|
||||
hard: 65536
|
||||
networks:
|
||||
opencloud-net:
|
||||
volumes:
|
||||
- ${OPENSEARCH_DATA_DIR:-opensearch-data}:/usr/share/opensearch/data
|
||||
healthcheck:
|
||||
# Single-node clusters can't go green (replicas have nowhere to land), so
|
||||
# yellow is the healthy state. Still gates opencloud until opensearch accepts
|
||||
# requests.
|
||||
test:
|
||||
[
|
||||
"CMD-SHELL",
|
||||
"curl -sf 'http://localhost:9200/_cluster/health?wait_for_status=yellow&timeout=5s' > /dev/null || exit 1"
|
||||
]
|
||||
interval: 5s
|
||||
timeout: 10s
|
||||
retries: 24
|
||||
start_period: 60s
|
||||
logging:
|
||||
driver: ${LOG_DRIVER:-local}
|
||||
restart: always
|
||||
|
||||
volumes:
|
||||
opensearch-data:
|
||||
@@ -11,6 +11,18 @@ services:
|
||||
restart: always
|
||||
logging:
|
||||
driver: ${LOG_DRIVER:-local}
|
||||
healthcheck:
|
||||
test:
|
||||
[
|
||||
"CMD",
|
||||
"bash",
|
||||
"-c",
|
||||
"exec 3<>/dev/tcp/127.0.0.1/9998 && printf 'GET /tika HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && grep '200 OK' <&3",
|
||||
]
|
||||
interval: 5s
|
||||
timeout: 5s
|
||||
retries: 10
|
||||
start_period: 5s
|
||||
|
||||
opencloud:
|
||||
environment:
|
||||
@@ -18,3 +30,6 @@ services:
|
||||
SEARCH_EXTRACTOR_TYPE: tika
|
||||
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
|
||||
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
|
||||
depends_on:
|
||||
tika:
|
||||
condition: service_healthy
|
||||
|
||||
@@ -15,7 +15,7 @@ services:
|
||||
restart: always
|
||||
|
||||
keycloak:
|
||||
image: quay.io/keycloak/keycloak:26.6.3
|
||||
image: quay.io/keycloak/keycloak:26.6.4
|
||||
networks:
|
||||
opencloud-net:
|
||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||
|
||||
Reference in New Issue
Block a user