Compare commits

..

20 Commits

Author SHA1 Message Date
a0e8fdad40 chore: publish 4.0.6+26.0.2-fpm release 2023-06-14 14:59:20 +02:00
6427ce181f fix postgres healtcheck 2023-06-14 14:59:03 +02:00
37f575038b chore: publish 4.0.5+26.0.2-fpm release 2023-06-13 13:46:45 +02:00
7e4c87346a fix: release the fpm handbrake
it seems like php-fpm applys configs in aphabetical order, so that our
fpm-tune was overwritten by the www.conf with default values.

so let's go on highspeed now! :)
2023-06-13 13:20:26 +02:00
944230afe0 chore: publish 4.0.4+26.0.2-fpm release 2023-06-09 15:42:40 +02:00
63a1787ad6 fix env fpm default values overwriteable 2023-06-09 15:38:52 +02:00
3wc
1deee41205 chore: publish 4.0.3+26.0.2-fpm release 2023-06-09 10:31:49 +01:00
b8d209e531 chore: publish 4.0.2+26.0.2-fpm release 2023-06-08 17:52:27 +01:00
f48d314699 chore: publish 4.0.1+26.0.1-fpm release 2023-05-08 11:45:20 +02:00
a6ea635fd4 chore: autoformatting abra.sh 2023-05-08 11:43:45 +02:00
c9b8aec108 fix: set trusted proxies to 10.0.0.0/8 2023-05-08 11:43:24 +02:00
3wc
db39e8dee6 chore: publish 4.0.0+26.0.1-fpm release 2023-04-27 16:59:58 -04:00
3wc
ed68b3e57c chore: publish 3.3.2+25.0.6-fpm release 2023-04-27 16:40:59 -04:00
78ea500d5e add auto update and timeout env 2023-04-18 18:21:48 +02:00
6f219781e5 default authentik admin mapping 2023-04-18 15:24:25 +02:00
162c056f07 add default timeout 2023-04-13 19:52:12 +02:00
3wc
5d537d5173 Drop /auth/ from Keycloak example URL
[ci skip]
2023-04-07 16:42:02 -04:00
7a25bd4835 chore: publish 3.3.0+25.0.5-fpm release 2023-04-05 17:22:32 +02:00
eac7431b13 chore: publish 3.2.0+25.0.4-fpm release 2023-03-22 18:06:06 +01:00
fce0b9f7cb feat: authentik autoconfiguration 2023-03-22 17:47:06 +01:00
6 changed files with 70 additions and 42 deletions

View File

@ -1,4 +1,6 @@
TYPE=nextcloud
TIMEOUT=500
ENABLE_AUTO_UPDATE=true
DOMAIN=nextcloud.example.com
## Domain aliases
@ -17,6 +19,7 @@ SECRET_ADMIN_PASSWORD_VERSION=v1
EXTRA_VOLUME=/dev/null:/tmp/.dummy
PHP_MEMORY_LIMIT=1G
# fpm-tune, see: https://spot13.com/pmcalculator/
FPM_MAX_CHILDREN=131
FPM_START_SERVERS=32

View File

@ -120,7 +120,7 @@ Use [this plugin](https://github.com/pulsejet/nextcloud-oidc-login). Unlike the
```
'oidc_login_client_id' => 'nextcloud',
'oidc_login_client_secret' => 'mysecret',
'oidc_login_provider_url' => 'https://example.com/auth/realms/myrealm',
'oidc_login_provider_url' => 'https://example.com/realms/myrealm',
'oidc_login_disable_registration' => false,
'oidc_login_hide_password_form' => true,
'oidc_login_button_text' => 'Log in with your myssodomain',

25
abra.sh
View File

@ -18,12 +18,10 @@ post_install_occ(){
install_apps() {
install_apps="$@"
if [ -z "$install_apps" ]
then
if [ -z "$install_apps" ]; then
install_apps=$APPS
fi
for app in $install_apps
do
for app in $install_apps; do
run_occ "app:install $app"
done
}
@ -35,6 +33,20 @@ set_app_config(){
run_occ "config:app:set $APP $KEY --value '$VALUE'"
}
set_system_config() {
KEY=$1
VALUE=$2
run_occ "config:system:set $KEY --value '$VALUE'"
}
set_trusted_proxies() {
trusted_proxies="$@"
if [ -z "$1" ]; then
trusted_proxies="$TRUSTED_PROXIES"
fi
set_system_config trusted_proxies "$trusted_proxies"
}
install_bbb() {
install_apps bbb
set_app_config bbb app.navigation true
@ -50,7 +62,7 @@ install_onlyoffice(){
}
set_default_quota() {
set_app_config files default_quota '"$DEFAULT_QUOTA"'
set_app_config files default_quota "$DEFAULT_QUOTA"
}
set_authentik() {
@ -75,7 +87,8 @@ set_app_config sociallogin custom_providers "
\"style\":\"openid\",
\"defaultGroup\":\"\",
\"groupMapping\": {
\"admin\": \"admin\"
\"admin\": \"admin\",
\"authentik Admins\": \"admin\"
}
}
]

View File

@ -22,7 +22,7 @@ services:
secrets:
- db_password
healthcheck:
test: ["CMD-SHELL", "pg_isready"]
test: ["CMD-SHELL", "pg_isready", "-U", "nextcloud"]
interval: 10s
timeout: 5s
retries: 5

View File

@ -1,7 +1,7 @@
version: "3.8"
services:
web:
image: nginx:1.23.3
image: nginx:1.25.0
configs:
- source: nginx_conf
target: /etc/nginx/nginx.conf
@ -41,12 +41,12 @@ services:
start_period: 5m
app:
image: nextcloud:25.0.4-fpm
image: nextcloud:26.0.2-fpm
depends_on:
- db
configs:
- source: fpm_tune
target: /usr/local/etc/php-fpm.d/fpm-tune.conf
target: /usr/local/etc/php-fpm.d/zzz-fpm-tune.conf
- source: entrypoint
target: /custom-entrypoint.sh
mode: 555
@ -64,14 +64,14 @@ services:
- NEXTCLOUD_ADMIN_USER=${ADMIN_USER}
- NEXTCLOUD_ADMIN_PASSWORD_FILE=/run/secrets/admin_password
- NEXTCLOUD_TRUSTED_DOMAINS=${DOMAIN}
- TRUSTED_PROXIES=traefik
- TRUSTED_PROXIES=10.0.0.0/8
- REDIS_HOST=cache
- OVERWRITEPROTOCOL=https
- PHP_MEMORY_LIMIT=1G
- FPM_MAX_CHILDREN=131
- FPM_START_SERVERS=32
- FPM_MIN_SPARE_SERVERS=32
- FPM_MAX_SPARE_SERVERS=98
- PHP_MEMORY_LIMIT=${PHP_MEMORY_LIMIT:-1G}
- FPM_MAX_CHILDREN=${FPM_MAX_CHILDREN:-131}
- FPM_START_SERVERS=${FPM_START_SERVERS:-32}
- FPM_MIN_SPARE_SERVERS=${FPM_MIN_SPARE_SERVERS:-32}
- FPM_MAX_SPARE_SERVERS=${FPM_MAX_SPARE_SERVERS:-98}
- DEFAULT_QUOTA
volumes:
- nextcloud:/var/www/html/
@ -86,7 +86,8 @@ services:
failure_action: rollback
order: start-first
labels:
- "coop-cloud.${STACK_NAME}.version=3.1.2+25.0.4-fpm"
- "coop-cloud.${STACK_NAME}.version=4.0.6+26.0.2-fpm"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
- "backupbot.backup=true"
- "backupbot.backup.path=/var/www/html/config/,/var/www/html/data/,/var/www/html/custom_apps/"
healthcheck:
@ -97,7 +98,7 @@ services:
start_period: 5m
cron:
image: nextcloud:25.0.4-fpm
image: nextcloud:26.0.2-fpm
volumes:
- nextcloud:/var/www/html/
- nextapps:/var/www/html/custom_apps:cached
@ -109,7 +110,7 @@ services:
entrypoint: /cron.sh
cache:
image: redis:7.0.9-alpine
image: redis:7.0.11-alpine
networks:
- internal
volumes:

11
release/3.2.0+25.0.4-fpm Normal file
View File

@ -0,0 +1,11 @@
If the authentik configuration should be handled by abra add the following to the env:
COMPOSE_FILE="$COMPOSE_FILE:compose.authentik.yml"
AUTHENTIK_USER_PREFIX=authentik
AUTHENTIK_DOMAIN=authentik.example.com
AUTHENTIK_SECRET_NAME=authentik_example_com_nextcloud_secret_v1 # the same as in authentik
AUTHENTIK_ID_NAME=authentik_example_com_nextcloud_id_v1 # the same as in authentik
And run:
abra app cmd <app-name> app set_authentik