--- services: opencloud: environment: # this is needed for setting the correct CSP header COLLABORA_DOMAIN: ${COLLABORA_DOMAIN:-collabora.opencloud.test} TRAEFIK_PORT_HTTPS: ${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} # run the collaboration (WOPI) service inside the main opencloud process, # appended to any user defined services in START_ADDITIONAL_SERVICES OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES:-}${START_ADDITIONAL_SERVICES:+,}collaboration # make collabora the secure view app FRONTEND_APP_HANDLER_SECURE_VIEW_APP_ADDR: eu.opencloud.api.collaboration GRAPH_AVAILABLE_ROLES: "b1e2218d-eef8-4d4c-b82d-0f1a1b48f3b5,a8d5fe5e-96e3-418d-825b-534dbdf22b99,fb6c3e19-e378-47e5-b277-9732f9de6e21,58c63c02-1d89-4572-916a-870abc5a1b7d,2d00ce52-1fc2-4dbc-8b95-a73b73395f5a,1c996275-f1c9-4e71-abdf-a42f6495e960,312c0871-5ef7-4b3a-85b6-0e4074c64049,aa97fe03-7980-45ac-9e50-b325749fd7e6" # collaboration service configuration; the WOPI endpoint is served by the # opencloud proxy on the opencloud domain (/wopi and /collaboration routes), # so no separate wopiserver domain, route or port is needed COLLABORATION_WOPI_SRC: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} COLLABORATION_APP_NAME: "CollaboraOnline" COLLABORATION_APP_PRODUCT: "Collabora" COLLABORATION_APP_ADDR: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} COLLABORATION_APP_ICON: https://${COLLABORA_DOMAIN:-collabora.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-}/favicon.ico COLLABORATION_APP_INSECURE: "${INSECURE:-true}" COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}" # One-shot service that generates the WOPI proof key on first start and # keeps it in a named volume, like the proofKeyGeneration feature of the # collabora-online helm chart. # To rotate the key, remove the volume and start again: # docker compose down collabora && docker volume rm _collabora-proof-key collabora-proof-key: image: alpine/openssl:3.5.7 entrypoint: ["/bin/sh"] command: - -ec - | if [ ! -s /proof/proof_key ]; then openssl genrsa -traditional -out /proof/proof_key.tmp 4096 chown 1001:1001 /proof/proof_key.tmp chmod 400 /proof/proof_key.tmp mv /proof/proof_key.tmp /proof/proof_key echo "WOPI proof key generated" else echo "WOPI proof key already exists" fi volumes: - collabora-proof-key:/proof logging: driver: ${LOG_DRIVER:-local} restart: "no" collabora: image: collabora/code:26.04.2.3.1 # release notes: https://www.collaboraonline.com/release-notes/ networks: opencloud-net: depends_on: collabora-proof-key: condition: service_completed_successfully environment: # WOPI host allowlist; the WOPI endpoint is served by the opencloud proxy on the opencloud domain aliasgroup1: https://${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} extra_params: > --o:ssl.enable=${COLLABORA_SSL_ENABLE:-true} --o:ssl.ssl_verification=${COLLABORA_SSL_VERIFICATION:-true} --o:ssl.termination=true --o:welcome.enable=false --o:net.frame_ancestors=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} --o:net.lok_allow.host[14]=${OC_DOMAIN:-cloud.opencloud.test}${TRAEFIK_PORT_HTTPS:+:}${TRAEFIK_PORT_HTTPS:-} --o:home_mode.enable=${COLLABORA_HOME_MODE:-false} username: ${COLLABORA_ADMIN_USER:-admin} password: ${COLLABORA_ADMIN_PASSWORD:-admin} cap_add: - SYS_ADMIN security_opt: - seccomp=unconfined - apparmor:unconfined volumes: # Mount local TrueType fonts so the container can use system fonts # (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package). - /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro - /usr/share/fonts/truetype:/opt/cool/systemplate/usr/share/fonts/truetype/more:ro # WOPI proof key generated by the collabora-proof-key service. - type: volume source: collabora-proof-key target: /etc/coolwsd/proof_key read_only: true volume: subpath: proof_key logging: driver: ${LOG_DRIVER:-local} restart: always healthcheck: # --use-env-vars makes the probe read extra_params, so it probes with # the same http/https scheme the server actually runs with; without it # the probe falls back to coolwsd.xml where ssl.enable defaults to true test: ["CMD", "/usr/bin/coolwsd", "--probe", "--use-env-vars"] interval: 15s timeout: 10s retries: 5 volumes: collabora-proof-key: