mirror of
https://github.com/opencloud-eu/opencloud-compose.git
synced 2026-08-07 20:38:42 +08:00
Compare commits
18 Commits
stable-7.2
...
b914288032
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b914288032 | ||
|
|
09e0d8f32a | ||
|
|
aab87f13a7 | ||
|
|
aebf5882f4 | ||
|
|
f292460d32 | ||
|
|
f0277501f0 | ||
|
|
76e41a4848 | ||
|
|
46ad111b94 | ||
|
|
9cac2bd525 | ||
|
|
d965660599 | ||
|
|
f3f0ece32a | ||
|
|
b138f37c98 | ||
|
|
e92718ffa0 | ||
|
|
8c43842e7b | ||
|
|
cc49b063c0 | ||
|
|
7cf59a62a9 | ||
|
|
32b328218f | ||
|
|
c814f08cd5 |
@@ -87,7 +87,7 @@ TRAEFIK_LOG_LEVEL=
|
|||||||
# For production releases: "opencloudeu/opencloud"
|
# For production releases: "opencloudeu/opencloud"
|
||||||
# For rolling releases: "opencloudeu/opencloud-rolling"
|
# For rolling releases: "opencloudeu/opencloud-rolling"
|
||||||
# Defaults to production if not set otherwise
|
# Defaults to production if not set otherwise
|
||||||
OC_DOCKER_IMAGE=opencloudeu/opencloud
|
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling
|
||||||
# The openCloud container version.
|
# The openCloud container version.
|
||||||
# Defaults to the latest version-tag. Use git pull to update.
|
# Defaults to the latest version-tag. Use git pull to update.
|
||||||
OC_DOCKER_TAG=
|
OC_DOCKER_TAG=
|
||||||
|
|||||||
@@ -319,12 +319,12 @@ OpenCloud Compose supports adding SSL certificates for public domains and develo
|
|||||||
### Use Let's Encrypt with ACME Challenge
|
### Use Let's Encrypt with ACME Challenge
|
||||||
|
|
||||||
1. **Enable Let's Encrypt**:
|
1. **Enable Let's Encrypt**:
|
||||||
- Set `TRAEFIK_LETSENCRYPT_EMAIL` to your email address for the ACME challenge
|
- Set `TRAEFIK_ACME_MAIL` to your email address for the ACME challenge
|
||||||
- Set `TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"` to use Let's Encrypt (default value)
|
- Set `TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"` to use Let's Encrypt (default value)
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# In your .env file
|
# In your .env file
|
||||||
TRAEFIK_LETSENCRYPT_EMAIL=devops@your-domain.tld
|
TRAEFIK_ACME_MAIL=devops@your-domain.tld
|
||||||
TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
|
TRAEFIK_SERVICES_TLS_CONFIG="tls.certresolver=letsencrypt"
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -412,7 +412,7 @@ Key variables:
|
|||||||
| `LDAP_BIND_PASSWORD` | LDAP password for the bind user | admin |
|
| `LDAP_BIND_PASSWORD` | LDAP password for the bind user | admin |
|
||||||
| `KC_DB_USERNAME` | Database user for keycloak | keycloak |
|
| `KC_DB_USERNAME` | Database user for keycloak | keycloak |
|
||||||
| `KC_DB_PASSWORD` | Database password for keycloak | keycloak |
|
| `KC_DB_PASSWORD` | Database password for keycloak | keycloak |
|
||||||
| `TRAEFIK_LETSENCRYPT_EMAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
|
| `TRAEFIK_ACME_MAIL` | Email Address for the Let's Encrypt ACME challenge | example@example.org |
|
||||||
| `TRAEFIK_SERVICES_TLS_CONFIG` | Tell traefik and the services which TLS config to use | tls.certresolver=letsencrypt |
|
| `TRAEFIK_SERVICES_TLS_CONFIG` | Tell traefik and the services which TLS config to use | tls.certresolver=letsencrypt |
|
||||||
| `TRAEFIK_CERTS_DIR` | Directory for custom certificates. | ./certs |
|
| `TRAEFIK_CERTS_DIR` | Directory for custom certificates. | ./certs |
|
||||||
|
|
||||||
|
|||||||
@@ -1,8 +1,9 @@
|
|||||||
:root {
|
:root {
|
||||||
--pf-global--primary-color--100: #e2baff;
|
--pf-v5-global--primary-color--100: #e2baff;
|
||||||
--pf-global--primary-color--200: #e2baff;
|
--pf-v5-global--primary-color--200: #e2baff;
|
||||||
--pf-global--primary-color--dark-100: #e2baff;
|
--pf-v5-global--primary-color--dark-100: #e2baff;
|
||||||
--pf-global--Color--light-100: #20434f;
|
--pf-v5-c-button--m-secondary--Color: #e2baff;
|
||||||
|
--pf-v5-global--Color--light-100: #20434f;
|
||||||
}
|
}
|
||||||
|
|
||||||
@font-face {
|
@font-face {
|
||||||
@@ -26,13 +27,31 @@ body {
|
|||||||
}
|
}
|
||||||
|
|
||||||
.kc-logo-text {
|
.kc-logo-text {
|
||||||
background-image: url(../img/logo.svg) !important;
|
display: block;
|
||||||
|
width: 300px;
|
||||||
|
height: 63px;
|
||||||
|
background: url('../img/logo.svg') no-repeat center;
|
||||||
background-size: contain;
|
background-size: contain;
|
||||||
width: 400px;
|
|
||||||
margin: 0 !important;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#kc-header-wrapper{
|
.kc-logo-text span {
|
||||||
|
display: none;
|
||||||
|
}
|
||||||
|
|
||||||
|
#kc-header-wrapper {
|
||||||
display: flex;
|
display: flex;
|
||||||
justify-content: center;
|
justify-content: center;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
.pf-v5-c-login__main-header {
|
||||||
|
border-top: 4px solid var(--pf-v5-global--primary-color--100);
|
||||||
|
}
|
||||||
|
|
||||||
|
@media (min-width: 1200px) {
|
||||||
|
.pf-v5-c-login__container {
|
||||||
|
grid-template-columns: 34rem;
|
||||||
|
grid-template-areas:
|
||||||
|
"header"
|
||||||
|
"main";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -16,4 +16,4 @@ document.addEventListener("DOMContentLoaded", function () {
|
|||||||
}
|
}
|
||||||
|
|
||||||
setLogoUrl('https://opencloud.eu')
|
setLogoUrl('https://opencloud.eu')
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
parent=keycloak
|
parent=keycloak.v2
|
||||||
import=common/keycloak
|
import=common/keycloak
|
||||||
|
|
||||||
styles=css/login.css css/theme.css
|
styles=css/login.css css/theme.css
|
||||||
scripts=js/script.js
|
scripts=js/script.js
|
||||||
|
|||||||
@@ -25,6 +25,7 @@ directives:
|
|||||||
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
# This is needed for the external-sites web extension when embedding sites
|
# This is needed for the external-sites web extension when embedding sites
|
||||||
- 'https://docs.opencloud.eu'
|
- 'https://docs.opencloud.eu'
|
||||||
|
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
|
||||||
img-src:
|
img-src:
|
||||||
- '''self'''
|
- '''self'''
|
||||||
- 'data:'
|
- 'data:'
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
opencloud:
|
opencloud:
|
||||||
# renovate: depName=opencloudeu/opencloud
|
# renovate: depName=opencloudeu/opencloud-rolling
|
||||||
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud}:${OC_DOCKER_TAG:-7.2.3}
|
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.2.0}
|
||||||
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
|
||||||
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
|
||||||
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
user: ${OC_CONTAINER_UID_GID:-1000:1000}
|
||||||
|
|||||||
@@ -1,9 +1,9 @@
|
|||||||
---
|
---
|
||||||
services:
|
services:
|
||||||
opencloud:
|
opencloud:
|
||||||
environment:
|
environment:
|
||||||
# bind to all interfaces
|
# bind to all interfaces
|
||||||
PROXY_HTTP_ADDR: "0.0.0.0:9200"
|
PROXY_HTTP_ADDR: "0.0.0.0:9200"
|
||||||
ports:
|
ports:
|
||||||
# expose the opencloud server on localhost
|
# expose the opencloud server on localhost
|
||||||
- "127.0.0.1:9200:9200"
|
- "127.0.0.1:9200:9200"
|
||||||
|
|||||||
@@ -78,7 +78,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.4
|
image: quay.io/keycloak/keycloak:26.6.3
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
43
renovate.json
Normal file
43
renovate.json
Normal file
@@ -0,0 +1,43 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||||
|
"platformAutomerge": true,
|
||||||
|
"enabledManagers": ["docker-compose", "custom.regex"],
|
||||||
|
"baseBranchPatterns": ["main", "stable-4.0"],
|
||||||
|
"packageRules": [
|
||||||
|
{
|
||||||
|
"matchManagers": ["docker-compose", "custom.regex"],
|
||||||
|
"labels": ["Type:Dependencies", "Bot:Renovate"]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"matchManagers": ["docker-compose"],
|
||||||
|
"matchUpdateTypes": ["patch"],
|
||||||
|
"automerge": true
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"matchBaseBranches": ["stable-4.0"],
|
||||||
|
"matchUpdateTypes": ["major", "minor"],
|
||||||
|
"enabled": false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"matchPackageNames": ["postgres"],
|
||||||
|
"matchManagers": ["docker-compose"],
|
||||||
|
"allowedVersions": "/^17\\.\\d+-alpine$/"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"docker-compose": {
|
||||||
|
"managerFilePatterns": ["/.+\\.ya?ml$/"]
|
||||||
|
},
|
||||||
|
"customManagers": [
|
||||||
|
{
|
||||||
|
"customType": "regex",
|
||||||
|
"managerFilePatterns": [
|
||||||
|
"/^docker-compose\\.yml$/",
|
||||||
|
"/^weboffice\\/collabora\\.yml$/"
|
||||||
|
],
|
||||||
|
"matchStrings": [
|
||||||
|
"# renovate: depName=(?<depName>[^\\s]+)\\n\\s+image: \\$\\{[^}]+\\}:\\$\\{[^}]+-(?<currentValue>[0-9]+\\.[0-9]+\\.[0-9]+)\\}"
|
||||||
|
],
|
||||||
|
"datasourceTemplate": "docker"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
59
search/opensearch.yml
Normal file
59
search/opensearch.yml
Normal file
@@ -0,0 +1,59 @@
|
|||||||
|
---
|
||||||
|
services:
|
||||||
|
opencloud:
|
||||||
|
environment:
|
||||||
|
# Point the search service at OpenSearch instead of the embedded bleve index.
|
||||||
|
SEARCH_ENGINE_TYPE: open-search
|
||||||
|
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_ADDRESSES: http://opensearch:9200
|
||||||
|
SEARCH_ENGINE_OPEN_SEARCH_CLIENT_INSECURE: "true"
|
||||||
|
SEARCH_ENGINE_OPEN_SEARCH_RESOURCE_INDEX_NAME: ${OPENSEARCH_RESOURCE_INDEX:-opencloud-resources}
|
||||||
|
depends_on:
|
||||||
|
opensearch:
|
||||||
|
condition: service_healthy
|
||||||
|
|
||||||
|
opensearch:
|
||||||
|
image: ${OPENSEARCH_DOCKER_IMAGE:-opensearchproject/opensearch}:${OPENSEARCH_DOCKER_TAG:-2.19.5}
|
||||||
|
environment:
|
||||||
|
discovery.type: single-node
|
||||||
|
bootstrap.memory_lock: "true"
|
||||||
|
OPENSEARCH_JAVA_OPTS: ${OPENSEARCH_JAVA_OPTS:--Xms512m -Xmx512m}
|
||||||
|
# Security plugin is disabled: OpenSearch is only reachable on the
|
||||||
|
# internal opencloud-net bridge and no port is published to the host.
|
||||||
|
# Do NOT enable a published port or expose this via the reverse proxy
|
||||||
|
# without first enabling and configuring the security plugin.
|
||||||
|
DISABLE_SECURITY_PLUGIN: "true"
|
||||||
|
DISABLE_INSTALL_DEMO_CONFIG: "true"
|
||||||
|
# Disable the disk-based shard allocation watermarks. By default OpenSearch
|
||||||
|
# marks indices read-only when the host disk is <5% free, which silently
|
||||||
|
# turns bulk upserts into no-ops. Fine to disable on a single-node dev box.
|
||||||
|
cluster.routing.allocation.disk.threshold_enabled: "false"
|
||||||
|
ulimits:
|
||||||
|
memlock:
|
||||||
|
soft: -1
|
||||||
|
hard: -1
|
||||||
|
nofile:
|
||||||
|
soft: 65536
|
||||||
|
hard: 65536
|
||||||
|
networks:
|
||||||
|
opencloud-net:
|
||||||
|
volumes:
|
||||||
|
- ${OPENSEARCH_DATA_DIR:-opensearch-data}:/usr/share/opensearch/data
|
||||||
|
healthcheck:
|
||||||
|
# Single-node clusters can't go green (replicas have nowhere to land), so
|
||||||
|
# yellow is the healthy state. Still gates opencloud until opensearch accepts
|
||||||
|
# requests.
|
||||||
|
test:
|
||||||
|
[
|
||||||
|
"CMD-SHELL",
|
||||||
|
"curl -sf 'http://localhost:9200/_cluster/health?wait_for_status=yellow&timeout=5s' > /dev/null || exit 1"
|
||||||
|
]
|
||||||
|
interval: 5s
|
||||||
|
timeout: 10s
|
||||||
|
retries: 24
|
||||||
|
start_period: 60s
|
||||||
|
logging:
|
||||||
|
driver: ${LOG_DRIVER:-local}
|
||||||
|
restart: always
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
opensearch-data:
|
||||||
@@ -11,6 +11,18 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
|
healthcheck:
|
||||||
|
test:
|
||||||
|
[
|
||||||
|
"CMD",
|
||||||
|
"bash",
|
||||||
|
"-c",
|
||||||
|
"exec 3<>/dev/tcp/127.0.0.1/9998 && printf 'GET /tika HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && grep '200 OK' <&3",
|
||||||
|
]
|
||||||
|
interval: 5s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 10
|
||||||
|
start_period: 5s
|
||||||
|
|
||||||
opencloud:
|
opencloud:
|
||||||
environment:
|
environment:
|
||||||
@@ -18,3 +30,6 @@ services:
|
|||||||
SEARCH_EXTRACTOR_TYPE: tika
|
SEARCH_EXTRACTOR_TYPE: tika
|
||||||
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
|
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
|
||||||
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
|
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
|
||||||
|
depends_on:
|
||||||
|
tika:
|
||||||
|
condition: service_healthy
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ services:
|
|||||||
restart: always
|
restart: always
|
||||||
|
|
||||||
keycloak:
|
keycloak:
|
||||||
image: quay.io/keycloak/keycloak:26.6.4
|
image: quay.io/keycloak/keycloak:26.6.3
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
command: [ "start", "--spi-connections-http-client-default-disable-trust-manager=${INSECURE:-false}", "--import-realm" ]
|
||||||
|
|||||||
@@ -23,50 +23,22 @@ services:
|
|||||||
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
|
||||||
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
|
||||||
|
|
||||||
# One-shot service that generates the WOPI proof key on first start and
|
|
||||||
# keeps it in a named volume, like the proofKeyGeneration feature of the
|
|
||||||
# collabora-online helm chart.
|
|
||||||
# To rotate the key, remove the volume and start again:
|
|
||||||
# docker compose down collabora && docker volume rm <project>_collabora-proof-key
|
|
||||||
collabora-proof-key:
|
|
||||||
image: alpine/openssl:3.5.7
|
|
||||||
entrypoint: ["/bin/sh"]
|
|
||||||
command:
|
|
||||||
- -ec
|
|
||||||
- |
|
|
||||||
if [ ! -s /proof/proof_key ]; then
|
|
||||||
openssl genrsa -traditional -out /proof/proof_key.tmp 4096
|
|
||||||
chown 1001:1001 /proof/proof_key.tmp
|
|
||||||
chmod 400 /proof/proof_key.tmp
|
|
||||||
mv /proof/proof_key.tmp /proof/proof_key
|
|
||||||
echo "WOPI proof key generated"
|
|
||||||
else
|
|
||||||
echo "WOPI proof key already exists"
|
|
||||||
fi
|
|
||||||
volumes:
|
|
||||||
- collabora-proof-key:/proof
|
|
||||||
logging:
|
|
||||||
driver: ${LOG_DRIVER:-local}
|
|
||||||
restart: "no"
|
|
||||||
|
|
||||||
collabora:
|
collabora:
|
||||||
image: collabora/code:26.04.2.4.1
|
image: collabora/code:26.04.1.4.1
|
||||||
# release notes: https://www.collaboraonline.com/release-notes/
|
# release notes: https://www.collaboraonline.com/release-notes/
|
||||||
networks:
|
networks:
|
||||||
opencloud-net:
|
opencloud-net:
|
||||||
depends_on:
|
|
||||||
collabora-proof-key:
|
|
||||||
condition: service_completed_successfully
|
|
||||||
environment:
|
environment:
|
||||||
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
|
# WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain
|
||||||
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
||||||
extra_params: >
|
DONT_GEN_SSL_CERT: "YES"
|
||||||
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true}
|
extra_params: |
|
||||||
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true}
|
--o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} \
|
||||||
--o:ssl.termination=true
|
--o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} \
|
||||||
--o:welcome.enable=false
|
--o:ssl.termination=true \
|
||||||
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
--o:welcome.enable=false \
|
||||||
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}
|
--o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
||||||
|
--o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} \
|
||||||
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
--o:home_mode.enable=${COLLABORA_HOME_MODE:-false}
|
||||||
username: ${COLLABORA_ADMIN_USER:-admin}
|
username: ${COLLABORA_ADMIN_USER:-admin}
|
||||||
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
password: ${COLLABORA_ADMIN_PASSWORD:-admin}
|
||||||
@@ -80,24 +52,19 @@ services:
|
|||||||
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
|
||||||
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
|
||||||
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
- /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro
|
||||||
# WOPI proof key generated by the collabora-proof-key service.
|
|
||||||
- type: volume
|
|
||||||
source: collabora-proof-key
|
|
||||||
target: /etc/coolwsd/proof_key
|
|
||||||
read_only: true
|
|
||||||
volume:
|
|
||||||
subpath: proof_key
|
|
||||||
logging:
|
logging:
|
||||||
driver: ${LOG_DRIVER:-local}
|
driver: ${LOG_DRIVER:-local}
|
||||||
restart: always
|
restart: always
|
||||||
|
entrypoint: [ '/bin/bash', '-c' ]
|
||||||
|
command: [ 'coolconfig generate-proof-key && /start-collabora-online.sh' ]
|
||||||
healthcheck:
|
healthcheck:
|
||||||
# --use-env-vars makes the probe read extra_params, so it probes with
|
test:
|
||||||
# the same http/https scheme the server actually runs with; without it
|
[
|
||||||
# the probe falls back to coolwsd.xml where ssl.enable defaults to true
|
"CMD",
|
||||||
test: ["CMD", "/usr/bin/coolwsd", "--probe", "--use-env-vars"]
|
"bash",
|
||||||
|
"-c",
|
||||||
|
"exec 3<>/dev/tcp/127.0.0.1/9980 && printf 'GET /hosting/discovery HTTP/1.1\r\nHost: localhost\r\nConnection: close\r\n\r\n' >&3 && cat <&3 | head -1 | grep -q '200 OK'"
|
||||||
|
]
|
||||||
interval: 15s
|
interval: 15s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|
||||||
volumes:
|
|
||||||
collabora-proof-key:
|
|
||||||
|
|||||||
Reference in New Issue
Block a user