Compare commits

...

51 Commits

Author SHA1 Message Date
Linus Gasser e2d7283f09 feat: add in-stack Euro-Office integration (15.1.0)
Optional compose.eurooffice.yml overlay that runs the Euro-Office document
server (ghcr.io/euro-office/documentserver) inside the stack, with its own
Postgres and RabbitMQ services. The document server schema is seeded into that
Postgres on first init (eurooffice-createdb.sql). Postgres is internal-only with
trust auth, so the only managed secret is the JWT. A custom entrypoint injects
the JWT from the Swarm secret, then execs the image's entrypoint.

Additive: no effect on existing installs unless enabled. Adds install_eurooffice()
plus EUROOFFICE_DOMAIN / SECRET_EUROOFFICE_JWT_VERSION config.
2026-07-20 09:19:16 +02:00
Linus Gasser 5ce7bc06ca feat: add in-stack Euro-Office integration (15.1.0)
Optional compose.eurooffice.yml overlay that runs the Euro-Office document
server (ghcr.io/euro-office/documentserver) inside the stack, with its own
Postgres and RabbitMQ services. The document server schema is seeded into that
Postgres on first init (eurooffice-createdb.sql). Postgres is internal-only with
trust auth, so the only managed secret is the JWT. A custom entrypoint injects
the JWT from the Swarm secret, then execs the image's entrypoint.

Additive: no effect on existing installs unless enabled. Adds install_eurooffice()
plus EUROOFFICE_DOMAIN / SECRET_EUROOFFICE_JWT_VERSION config.
2026-07-20 09:19:11 +02:00
Linus Gasser d3cb8d2776 chore: publish 15.0.0+34.0.1-fpm release 2026-07-20 09:19:07 +02:00
Linus Gasser f1e7b14b5f chore: update image tags 2026-07-17 15:15:49 +02:00
Linus Gasser 295da9e78a chore: publish 14.0.0+33.0.6-fpm release
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-17 15:15:40 +02:00
Linus Gasser dcc77aa665 chore: update image tags 2026-07-17 15:15:28 +02:00
carla 19e7fbb648 chore: publish 13.1.0+32.0.11-fpm release 2026-06-10 11:51:22 +02:00
carla 6113ccedde chore: switch from postgres to pgautoupgrade 14 2026-06-08 20:59:29 +02:00
carla 0d0c3b3266 chore: update image tags 2026-06-08 20:21:10 +02:00
decentral1se 45d1985ddc Merge pull request 'add user_oidc' (#70) from oxaliq/nextcloud:user_oidc_setup into main
Reviewed-on: coop-cloud/nextcloud#70
2026-03-24 21:27:08 +00:00
decentral1se d49f3c4ef8 Merge pull request 'fix: mention that you need to install OnlyOffice first' (#74) from ineiti/nextcloud:readme_onlyoffice into main
Reviewed-on: coop-cloud/nextcloud#74
Reviewed-by: decentral1se <decentral1se@noreply.git.coopcloud.tech>
2026-03-18 08:26:19 +00:00
Linus Gasser a2395c6399 @decentral1se comment 2026-03-17 22:26:35 +01:00
Linus Gasser e4b3bc4f22 fix: mention that you need to install OnlyOffice first 2026-03-17 22:26:35 +01:00
moritz 21ea1daf83 chore: replace depricated traefik.docker.* with traefik.swarm.* 2026-03-17 17:25:38 +01:00
oxaliq ec5934e191 document user_oidc setup 2026-03-12 09:56:53 -04:00
oxaliq 4c3f6fa14d add command for initializing user_oidc 2026-03-11 15:55:53 -04:00
oxaliq eb3816b9c2 add env and secrets for user_oidc app 2026-03-11 15:55:26 -04:00
simon 8b7ed8142e chore: publish 13.0.1+32.0.3-fpm release 2026-01-14 12:22:05 +01:00
simon 87b064c773 chore: publish 13.0.0+32.0.3-fpm release 2026-01-13 16:34:02 +01:00
iexos d6a77fac4d remove default TIMEOUT (abra #596) 2025-12-30 14:00:00 +01:00
p4u1 f27ea1a2cc chore: publish 12.1.0+31.0.6-fpm release 2025-12-23 14:30:22 +01:00
Apfelwurm c952020194 Implement NC Talk High Performance Backend (#56)
This implements the high performance backend for Nextcloud Talk, which is nessecary if it needs to handle more people (video) calling.
More Details about it: https://nextcloud-talk.readthedocs.io/en/latest/quick-install/

The current implementation is sadly limited to be used once per host, so this might need some additional love in the future, if someone needs it more flexible.

The related traefik pr: coop-cloud/traefik#66

Reviewed-on: coop-cloud/nextcloud#56
Co-authored-by: Apfelwurm <Alexander@volzit.de>
Co-committed-by: Apfelwurm <Alexander@volzit.de>
2025-12-23 13:28:18 +00:00
ammaratef45 aa3ab83a38 Merge pull request 'remove post_install_occ' (#55) from improve_readme into main
Reviewed-on: coop-cloud/nextcloud#55
2025-10-30 17:38:15 +00:00
ammaratef45 dbdf6227e1 remove post_install_occ 2025-10-17 19:05:03 -07:00
ammaratef45 e83ae638eb Merge pull request 'make maximum upload size configurable' (#53) from uploadLimit into main
Reviewed-on: coop-cloud/nextcloud#53
Reviewed-by: 3wordchant <3wordchant@noreply.git.coopcloud.tech>
Reviewed-by: decentral1se <decentral1se@noreply.git.coopcloud.tech>
2025-09-09 20:43:13 +00:00
ammaratef45 96e9a224f3 Merge branch 'main' into uploadLimit 2025-09-09 20:42:54 +00:00
3wordchant afee08ae4d Merge pull request 'Make INNODB_BUFFER_POOL_SIZE configurable' (#51) from feature/innodb-buffer-tune into main
Reviewed-on: coop-cloud/nextcloud#51
Reviewed-by: ammaratef45 <ammaratef45@proton.me>
2025-09-09 20:17:59 +00:00
ammaratef45 5f05ab8f42 make maximum upload size configurable 2025-09-09 12:53:37 -07:00
ammaratef45 65d5af91bc Merge branch 'main' into feature/innodb-buffer-tune 2025-09-09 19:46:26 +00:00
ammaratef45 93037e1a35 Merge pull request 'fix supporting multiple domains' (#52) from sslhost into main
Reviewed-on: coop-cloud/nextcloud#52
Reviewed-by: 3wordchant <3wordchant@noreply.git.coopcloud.tech>
2025-09-08 13:38:09 +00:00
ammaratef45 9986e87db5 fix supporting multiple domains 2025-09-07 14:41:53 -07:00
3wordchant 42c90cce21 Add configurable INNODB_BUFFER_POOL_SIZE 2025-09-01 00:15:52 -04:00
knoflook 8c5d843ba4 chore: publish 12.0.1+31.0.6-fpm release 2025-07-24 17:28:53 +02:00
Ammar Hussein 7074744ba8 chore: publish 12.0.1+31.0.6-fpm release 2025-07-09 10:51:04 -07:00
ammaratef45 cb0a103e04 Merge pull request 'add OVERWRITECLIURL' (#49) from clioverwrite into main
Reviewed-on: coop-cloud/nextcloud#49
2025-07-09 17:24:09 +00:00
Ammar Hussein ff6873a52c add OVERWRITECLIURL 2025-07-06 15:44:19 -07:00
carla 9408a6ab81 chore: publish 12.0.0+31.0.6-fpm release 2025-07-03 14:58:09 +02:00
Ammar Hussein c4bb6d0932 chore: publish 11.4.0+30.0.6-fpm release 2025-06-18 17:34:48 -07:00
ammaratef45 7a6256f78d Merge pull request 'Add HSTS headers' (#48) from hsts into main
Reviewed-on: coop-cloud/nextcloud#48
Reviewed-by: moritz <moritz@noreply.git.coopcloud.tech>
2025-06-19 00:32:01 +00:00
Ammar Hussein 8be413fe71 pump up the config version 2025-06-18 16:07:22 -07:00
Ammar Hussein af36d22633 Add HSTS headers 2025-06-18 12:13:44 -07:00
p4u1 85e5070b8d docs: Adds troubleshooting section for fulltextsearch 2025-05-23 15:32:02 +02:00
simon 36615bc097 chore: publish 11.3.0+30.0.6-fpm release 2025-05-20 18:20:05 +02:00
simon a3cd6741eb improve secret handling for whiteboard 2025-05-20 18:17:46 +02:00
simon cb453e884d chore: publish 11.2.0+30.0.6-fpm release 2025-05-13 23:59:33 +02:00
simon 267f3cbb78 chore: publish 11.1.0+30.0.6-fpm release 2025-02-15 14:43:25 +01:00
iexos b0c4f06af1 chore: publish 11.0.1+30.0.4-fpm release 2025-02-03 13:37:05 +01:00
iexos 750477a409 fix mariadb backup label 2025-02-03 13:19:08 +01:00
cas 7a7da21544 Update .drone.yml 2025-01-08 10:09:13 -08:00
marlon d72a8fdcdb Merge pull request 'upgrade to mariadb 11.4' (#45) from MIR/nextcloud:main into main
Reviewed-on: coop-cloud/nextcloud#45
2024-12-22 21:32:37 +00:00
marlon 7aa4e15034 upgrade to mariadb 11.4 2024-12-21 16:56:09 -05:00
23 changed files with 686 additions and 49 deletions
+1 -1
View File
@@ -45,7 +45,7 @@ steps:
from_secret: drone_abra-bot_token
fork: true
repositories:
- coop-cloud/auto-recipes-catalogue-json
- toolshed/auto-recipes-catalogue-json
trigger:
event: tag
+41 -4
View File
@@ -1,5 +1,5 @@
TYPE=nextcloud
TIMEOUT=900
#TIMEOUT=900
ENABLE_AUTO_UPDATE=true
ENABLE_BACKUPS=true
@@ -15,6 +15,7 @@ COMPOSE_FILE="$COMPOSE_FILE:compose.mariadb.yml"
#MAX_DB_CONNECTIONS=500
ADMIN_USER=admin
TZ=Etc/UTC
SECRET_DB_ROOT_PASSWORD_VERSION=v1
SECRET_DB_PASSWORD_VERSION=v1
@@ -23,6 +24,7 @@ SECRET_ADMIN_PASSWORD_VERSION=v1
EXTRA_VOLUME=/dev/null:/tmp/.dummy
PHP_MEMORY_LIMIT=1G
PHP_UPLOAD_LIMIT=512M
# fpm-tune, see: https://spot13.com/pmcalculator/
FPM_MAX_CHILDREN=16
FPM_START_SERVERS=4
@@ -55,25 +57,60 @@ DEFAULT_QUOTA="10 GB"
# APPS="calendar"
# COLLABORA_URL=https://collabora.example.com
## IMPORTANT FOR SECURITY REASONS WHEN RUNNING COLLABORA
## list of IP addresses that are allowed to make WOPI requests. Use the default
## when running the collabora server on the same machine as nextcloud.
## Otherwise set this to the IP address range of your collabora server(s) i.e. 1.2.3.4/32
## https://docs.nextcloud.com/server/latest/admin_manual/office/configuration.html#wopi-settings
# COLLABORA_ALLOWLIST="172.16.0.0/12"
# COMPOSE_FILE="$COMPOSE_FILE:compose.onlyoffice.yml"
# ONLYOFFICE_URL=https://onlyoffice.example.com
# APPS="$APPS onlyoffice"
# SECRET_ONLYOFFICE_JWT_VERSION=v1
# Euro-Office runs its own document server in this stack; EUROOFFICE_DOMAIN
# needs its own DNS record pointing at this host.
# COMPOSE_FILE="$COMPOSE_FILE:compose.eurooffice.yml"
# EUROOFFICE_DOMAIN=eurooffice.example.com
# APPS="$APPS eurooffice"
# SECRET_EUROOFFICE_JWT_VERSION=v1
# COMPOSE_FILE="$COMPOSE_FILE:compose.bbb.yml"
# BBB_URL=https://talk.example.org/bigbluebutton/ # trailing slash!
# SECRET_BBB_SECRET_VERSION=v1
# COMPOSE_FILE="$COMPOSE_FILE:compose.whiteboard.yml"
# APPS="$APPS whiteboard"
# SECRET_WHITEBOARD_JWT_VERSION=v1
# COMPOSE_FILE="$COMPOSE_FILE:compose.authentik.yml"
# APPS="$APPS sociallogin"
# AUTHENTIK_USER_PREFIX=authentik
# AUTHENTIK_DOMAIN=authentik.example.com
# SECRET_AUTHENTIK_SECRET_VERSION=v1
# SECRET_AUTHENTIK_ID_VERSION=v1
# OCC_CMDS="app:disable dashboard"
# OCC_CMDS="$OCC_CMDS|config:app:set sociallogin auto_create_groups --value 1"
# OCC_CMDS="$OCC_CMDS|config:app:set sociallogin hide_default_login --value 1"
#COMPOSE_FILE="$COMPOSE_FILE:compose.fulltextsearch.yml"
#SECRET_ELASTICSEARCH_PASSWORD_VERSION=v1
#COMPOSE_FILE="$COMPOSE_FILE:compose.talk.yml"
#TALK_DOMAIN=talk.example.com
#SECRET_TALK_INTERNAL_SECRET_VERSION=v1 # length=64 charset=default
#SECRET_TALK_TURN_SECRET_VERSION=v1 # length=64 charset=default
#SECRET_TALK_SIGNALING_SECRET_VERSION=v1 # length=64 charset=default
# COMPOSE_FILE="$COMPOSE_FILE:compose.user_oidc.yml"
# APPS="$APPS user_oidc"
# USER_OIDC_PROVIDER=
# USER_OIDC_ID=
# USER_OIDC_DISCOVERY_URI=
# USER_OIDC_END_SESSION_URI=
# USER_OIDC_LOGIN_ONLY=false
# SECRET_USER_OIDC_SECRET_VERSION=v1
# HSTS Options
# Uncomment this line to enable HSTS: https://docs.nextcloud.com/server/30/admin_manual/installation/harden_server.html
#HSTS_ENABLED=1
# Uncomment this line to add the `preload` part
#HSTS_PRELOAD=1
+124 -16
View File
@@ -25,20 +25,62 @@ Fully automated luxury Nextcloud via docker-swarm.
### Onlyoffice Integration
First install onlyoffice following the instructions in the
[OnlyOffice Recipe](https://recipes.coopcloud.tech/onlyoffice), and enable
the JWT secret.
`abra app config <app-name>`
Configure the following envs:
Configure the following envs with the URL of the onlyoffice service:
```
COMPOSE_FILE="$COMPOSE_FILE:compose.apps.yml"
ONLYOFFICE_URL=https://onlyoffice.example.com
SECRET_ONLYOFFICE_JWT_VERSION=v1
```
`abra app secret insert <app-name> onlyoffice_jwt v1 <jwt_secret>`
`abra app cmd <app-name> app install_onlyoffice`
Then set the onlyoffice JWT secret from the onlyoffice installation:
* `abra app secret insert <app-name> onlyoffice_jwt v1 <jwt_secret>`
* `abra app cmd <app-name> app install_onlyoffice`
### Euro-Office Integration
Euro-Office is the AGPL fork of OnlyOffice that powers "Nextcloud Office" from
Nextcloud 34 onwards. Like OnlyOffice it uses a client-side document-server
architecture, so a separate document server is required — but this overlay runs
that document server **inside the same stack**, so there is no external host to
manage. The browser talks to it directly, so it needs its own public HTTPS
domain (`EUROOFFICE_DOMAIN`) with a DNS record pointing at this host.
`abra app config <app-name>`
Enable the overlay and set the document server's domain:
```
COMPOSE_FILE="$COMPOSE_FILE:compose.eurooffice.yml"
EUROOFFICE_DOMAIN=eurooffice.example.com
APPS="$APPS eurooffice"
SECRET_EUROOFFICE_JWT_VERSION=v1
```
The overlay runs the document server with its own Postgres and RabbitMQ services
(the image's bundled Postgres is unreliable). The document server schema is
seeded into that Postgres automatically on first init (see
`eurooffice-createdb.sql`). The Postgres is internal-only and uses trust auth, so
the only secret to manage is the JWT; generate it, deploy, then wire up the
Nextcloud app:
* `abra app secret generate -a <app-name>`
* `abra app deploy <app-name>`
* `abra app cmd <app-name> app install_eurooffice`
> Note: the document server needs ~4 GB RAM (8 GB for multi-user) and pulls the
> `ghcr.io/euro-office/documentserver` image, which currently only publishes a
> `latest` tag (no semver / Renovate pinning yet).
### BBB Integration
`abra app config <app-name>`
Configure the following envs:
```
COMPOSE_FILE="$COMPOSE_FILE:compose.apps.yml"
@@ -46,8 +88,44 @@ BBB_URL=https://talk.example.org/bigbluebutton/ # trailing slash!
SECRET_BBB_SECRET_VERSION=v1
```
`abra app secret insert <app-name> bbb_secret v1 <bbb_secret>`
`abra app cmd <app-name> app install_bbb`
* `abra app secret insert <app-name> bbb_secret v1 <bbb_secret>`
* `abra app cmd <app-name> app install_bbb`
### Nextcloud Talk High performance Backend
Note: at the moment you are limited to run one Nextcloud high performance backend per docker host with this setup.
`abra app config <app-name>`
Configure the following envs:
```
#COMPOSE_FILE="$COMPOSE_FILE:compose.talk.yml"
#TALK_DOMAIN=talk.example.com
#SECRET_TALK_INTERNAL_SECRET_VERSION=v1 # length=64 charset=default
#SECRET_TALK_TURN_SECRET_VERSION=v1 # length=64 charset=default
#SECRET_TALK_SIGNALING_SECRET_VERSION=v1 # length=64 charset=default
```
* `abra app secret insert <app-name> talk_internal_secret v1 <talk_internal_secret>`
* `abra app secret insert <app-name> talk_turn_secret v1 <talk_turn_secret>`
* `abra app secret insert <app-name> talk_signaling_secret v1 <talk_signaling_secret>`
* `abra app cmd <app-name> app install_talk`
Don't forget to enable the additional env's in your hosts traefik instance:
```
COMPOSE_FILE="$COMPOSE_FILE:compose.nextcloud-talk-hpb.yml"
NEXTCLOUD_TALK_HPB_ENABLED=1
```
Due to a bug in compose that deletes duplacted ports without checking for the protocol, traefik need to get the additional udp binding added after the deployment via ssh (this might take longer than expected!):
```
docker service update --publish-add published=3478,target=3478,protocol=udp traefik_XXX_XXX_app
```
To check if tcp and udp was binded, you can use:
```
docker service inspect traefik_XXX_XXX_app | grep 3478 -a2
```
### Authentik Integration
@@ -64,21 +142,18 @@ AUTHENTIK_ID_NAME=authentik_example_com_nextcloud_id_v1 # the same as in authen
`abra app cmd <app-name> app set_authentik`
### Disable Dashboard
Disable dashboard app since it is so corporate:
`abra app config <app-name>`
Configure the following envs:
```
OCC_CMDS="app:disable dashboard"
```
`abra app cmd <app-name> app post_install_occ`
## Running `occ`
`abra app cmd <app-name> app run_occ '"user:list --help"'`
Read more about [occ command here](https://docs.nextcloud.com/server/stable/admin_manual/occ_command.html).
### Disable Dashboard
To disable dashboard app (since it is so corporate):
`abra app cmd <app-name> app run_occ '"app:disable dashboard"'`
## Default user files
- Follow [these docs](https://docs.nextcloud.com/server/latest/admin_manual/configuration_files/default_files_configuration.html) to set the default files list for each user in the Files app
@@ -153,6 +228,31 @@ We've been able to get this setup by using the [social login](https://apps.nextc
If using Keycloak, you'll want to do [this trick](https://janikvonrotz.ch/2020/10/20/openid-connect-with-nextcloud-and-keycloak/) also.
## How do I enable OpenID Connect (OIDC) providers?
[user_oidc](https://github.com/nextcloud/user_oidc) is the recommended way to integrate Nextcloud with OIDC providers.
Run `abra app config <app-name>`
Set the following envs:
```env
COMPOSE_FILE="$COMPOSE_FILE:compose.user_oidc.yml"
APPS="$APPS user_oidc"
USER_OIDC_PROVIDER=example-provider # this has been tested with keycloak
USER_OIDC_ID=example-client-id # get this from your oidc provider
USER_OIDC_DISCOVERY_URI=example-oidc-provider.com/.well-known/openid-configuration # get this from your oidc provider
USER_OIDC_END_SESSION_URI=example-oidc-provider.com/protocol/openid-connect/logout # get this from your oidc provider
USER_OIDC_LOGIN_ONLY=false # set this to true to automatically redirect all logins to your oidc provider
SECRET_USER_OIDC_SECRET_VERSION=v1
```
Then insert the client secret from your OIDC provider:
```sh
abra app secret insert <app-name> user_oidc_secret v1 <client-secret from oidc provider>
```
After you deploy (or redeploy), run the following to set up the user_oidc Nextcloud app:
`abra app cmd <app-name> app set_user_oidc`
## How can I customise the CSS?
There is some basic stuff in the admin settings.
@@ -286,3 +386,11 @@ And you can populate the index manually and check if any errors occur:
```
abra app cmd <domain> app run_occ '"fulltextsearch:index"'
```
### Troubleshooting fulltextsearch
The fulltextsearch plugin might be stuck with this error: "Index is already running". In that case the following command can get things runing again:
```
abra app run <domain> db /bin/sh -- -c 'echo "delete from oc_fulltextsearch_ticks;" | mariadb -u root -p$(cat /run/secrets/db_root_password) nextcloud'
```
+54 -10
View File
@@ -1,21 +1,18 @@
#!/bin/bash
export FPM_TUNE_VERSION=v5
export NGINX_CONF_VERSION=v7
export MY_CNF_VERSION=v5
export NGINX_CONF_VERSION=v8
export MY_CNF_VERSION=v6
export ENTRYPOINT_VERSION=v3
export ENTRYPOINT_WHITEBOARD_VERSION=v1
export ENTRYPOINT_TALK_VERSION=v1
export ENTRYPOINT_EUROOFFICE_VERSION=v3
export EUROOFFICE_CREATEDB_VERSION=v1
export CRONTAB_VERSION=v1
export PG_BACKUP_VERSION=v2
run_occ() {
su -p www-data -s /bin/sh -c "/var/www/html/occ $@"
}
post_install_occ() {
IFS='|' read -ra CMD <<<"$OCC_CMDS"
for cmd in "${CMD[@]}"; do
run_occ "$cmd"
done
su -p www-data -s /bin/sh -c "/var/www/html/occ $*"
}
install_apps() {
@@ -88,9 +85,35 @@ install_onlyoffice() {
set_app_config onlyoffice customizationForcesave true
}
install_eurooffice() {
install_apps eurooffice
set_app_config eurooffice DocumentServerUrl "https://${EUROOFFICE_DOMAIN}"
set_app_config eurooffice jwt_secret "$(cat /run/secrets/eurooffice_jwt)"
set_app_config eurooffice customizationForcesave true
}
install_collabora() {
install_apps richdocuments
set_app_config richdocuments wopi_url "$COLLABORA_URL"
# important for security reaosns
# https://docs.nextcloud.com/server/latest/admin_manual/office/configuration.html#wopi-settings
set_app_config richdocuments wopi_allowlist "$COLLABORA_ALLOWLIST"
}
install_whiteboard() {
install_apps whiteboard
set_app_config whiteboard collabBackendUrl "https://${DOMAIN}/whiteboard"
set_app_config whiteboard jwt_secret_key "$(cat /run/secrets/whiteboard_jwt)"
}
install_talk() {
install_apps spreed
run_occ "talk:signaling:add --verify 'wss://${TALK_DOMAIN}' '$(cat /run/secrets/talk_signaling_secret)'"
run_occ "talk:stun:add '${TALK_DOMAIN}:3478'"
run_occ "talk:stun:add '${TALK_DOMAIN}:443'"
run_occ "talk:turn:add --secret='$(cat /run/secrets/talk_turn_secret)' turn '${TALK_DOMAIN}:3478' udp,tcp"
}
install_fulltextsearch() {
@@ -145,6 +168,23 @@ set_authentik() {
run_occ 'config:system:set lost_password_link --value=disabled'
}
set_user_oidc() {
install_apps user_oidc
USER_OIDC_SECRET=$(cat /run/secrets/user_oidc_secret)
run_occ "user_oidc:provider \
--clientid=${USER_OIDC_ID} \
--clientsecret=${USER_OIDC_SECRET} \
--discoveryuri=${USER_OIDC_DISCOVERY_URI} \
--endsessionendpointuri=${USER_OIDC_END_SESSION_URI} \
--postlogouturi=https://${DOMAIN} \
--scope='openid email profile' \
${USER_OIDC_PROVIDER}"
# disable non user_oidc login
if [[ ${USER_OIDC_LOGIN_ONLY:-false} = "true" ]]; then
run_occ "config:app:set --value=0 user_oidc allow_multiple_user_backends"
fi
}
disable_skeletondirectory() {
run_occ "config:system:set skeletondirectory --value ''"
}
@@ -158,3 +198,7 @@ set_windowsfriendly_filenames() {
run_occ 'config:system:set forbidden_filename_characters 5 --value=\|'
run_occ 'config:system:set forbidden_filename_characters 6 --value=\"'
}
upgrade_mariadb() {
mariadb-upgrade -p`cat /run/secrets/db_root_password`
}
+118
View File
@@ -0,0 +1,118 @@
version: "3.8"
services:
app:
secrets:
- eurooffice_jwt
environment:
- EUROOFFICE_DOMAIN
eurooffice:
image: ghcr.io/euro-office/documentserver:latest
stdin_open: true
depends_on:
- eurooffice-db
- eurooffice-rabbitmq
networks:
- proxy
- internal
environment:
- JWT_ENABLED=true
- JWT_SECRET_FILE=/run/secrets/eurooffice_jwt
# Use external Postgres + RabbitMQ instead of the flaky bundled ones.
# (The all-in-one image ships an uncleanly-shut-down Postgres data dir
# whose crash recovery exceeds pg_ctl's start timeout -> restart loop.)
- DB_TYPE=postgres
- DB_HOST=eurooffice-db
- DB_PORT=5432
- DB_NAME=eurooffice
- DB_USER=eurooffice
- AMQP_URI=amqp://guest:guest@eurooffice-rabbitmq
volumes:
- eurooffice_data:/var/lib/euro-office
- eurooffice_config:/etc/euro-office
- eurooffice_logs:/var/log/euro-office
- eurooffice_fonts:/usr/share/fonts/custom
secrets:
- eurooffice_jwt
configs:
- source: entrypoint_eurooffice
target: /custom-entrypoint.sh
mode: 555
entrypoint: /custom-entrypoint.sh
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost/healthcheck"]
interval: 30s
timeout: 10s
retries: 10
start_period: 3m
deploy:
update_config:
failure_action: rollback
order: start-first
labels:
- "traefik.enable=true"
- "traefik.swarm.network=proxy"
- "traefik.http.services.${STACK_NAME}_eurooffice.loadbalancer.server.port=80"
- "traefik.http.routers.${STACK_NAME}_eurooffice.rule=Host(`${EUROOFFICE_DOMAIN}`)"
- "traefik.http.routers.${STACK_NAME}_eurooffice.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}_eurooffice.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.http.routers.${STACK_NAME}_eurooffice.middlewares=${STACK_NAME}_eurooffice-fwdproto"
- "traefik.http.middlewares.${STACK_NAME}_eurooffice-fwdproto.headers.customRequestHeaders.X-Forwarded-Proto=https"
eurooffice-db:
image: postgres:16-alpine
networks:
- internal
environment:
- POSTGRES_DB=eurooffice
- POSTGRES_USER=eurooffice
# Internal-only DB holding transient editing state; trust auth on the
# private overlay network avoids managing a Swarm secret for it.
- POSTGRES_HOST_AUTH_METHOD=trust
volumes:
- eurooffice_db:/var/lib/postgresql/data
configs:
# Seed the document server schema on first init. The all-in-one image only
# creates its schema in the *bundled* Postgres; with an external DB the
# docservice starts against an empty DB, errors on missing task_result /
# doc_changes, never binds its port, and gets healthcheck-killed in a loop.
- source: eurooffice_createdb
target: /docker-entrypoint-initdb.d/createdb.sql
healthcheck:
test: ["CMD", "pg_isready", "-U", "eurooffice"]
interval: 30s
timeout: 10s
retries: 10
start_period: 1m
eurooffice-rabbitmq:
image: rabbitmq:4.3.2
networks:
- internal
healthcheck:
test: rabbitmq-diagnostics -q ping
interval: 30s
timeout: 10s
retries: 10
start_period: 1m
secrets:
eurooffice_jwt:
external: true
name: ${STACK_NAME}_eurooffice_jwt_${SECRET_EUROOFFICE_JWT_VERSION}
volumes:
eurooffice_data:
eurooffice_config:
eurooffice_logs:
eurooffice_fonts:
eurooffice_db:
configs:
entrypoint_eurooffice:
name: ${STACK_NAME}_entrypoint_eurooffice_${ENTRYPOINT_EUROOFFICE_VERSION}
file: entrypoint.eurooffice.sh.tmpl
template_driver: golang
eurooffice_createdb:
name: ${STACK_NAME}_eurooffice_createdb_${EUROOFFICE_CREATEDB_VERSION}
file: eurooffice-createdb.sql
+2 -2
View File
@@ -2,7 +2,7 @@ version: "3.8"
services:
elasticsearch:
image: "docker.elastic.co/elasticsearch/elasticsearch:8.17.0"
image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.16"
environment:
- cluster.name=docker-cluster
- bootstrap.memory_lock=true
@@ -29,7 +29,7 @@ services:
mode: 0600
searchindexer:
image: nextcloud:30.0.4-fpm
image: nextcloud:34.0.1-fpm
volumes:
- nextcloud:/var/www/html/
- nextapps:/var/www/html/custom_apps:cached
+5 -4
View File
@@ -9,13 +9,14 @@ services:
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
db:
image: "mariadb:10.5"
image: "mariadb:11.4"
environment:
- MYSQL_DATABASE=nextcloud
- MYSQL_USER=nextcloud
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
- MYSQL_ROOT_PASSWORD_FILE=/run/secrets/db_root_password
- MAX_DB_CONNECTIONS=${MAX_DB_CONNECTIONS:-100}
- INNODB_BUFFER_POOL_SIZE=${INNODB_BUFFER_POOL_SIZE:-1G}"
configs:
- source: my_tune
target: /etc/mysql/conf.d/my-tune.cnf
@@ -28,11 +29,11 @@ services:
- internal
deploy:
labels:
backupbot.backup.pre-hook: 'mysqldump --single-transaction -u root -p"$$(cat /run/secrets/db_root_password)" nextcloud > /var/lib/mysql/backup.sql'
backupbot.backup.pre-hook: 'mariadb-dump --single-transaction -u root -p"$$(cat /run/secrets/db_root_password)" nextcloud > /var/lib/mysql/backup.sql'
backupbot.backup.volumes.mariadb.path: "backup.sql"
backupbot.restore.post-hook: 'mysql -u root -p"$$(cat /run/secrets/db_root_password)" nextcloud < /var/lib/mysql/backup.sql'
backupbot.restore.post-hook: 'mariadb -u root -p"$$(cat /run/secrets/db_root_password)" nextcloud < /var/lib/mysql/backup.sql'
healthcheck:
test: ["CMD-SHELL", 'mysqladmin -p"$$(cat /run/secrets/db_root_password)" ping']
test: ["CMD-SHELL", 'mariadb-admin -p"$$(cat /run/secrets/db_root_password)" ping']
interval: 30s
timeout: 10s
retries: 10
+1 -1
View File
@@ -10,7 +10,7 @@ services:
- NEXTCLOUD_UPDATE=1
db:
image: "postgres:13"
image: "pgautoupgrade/pgautoupgrade:14-debian"
command: -c "max_connections=${MAX_DB_CONNECTIONS:-100}"
volumes:
- "postgres:/var/lib/postgresql/data"
+70
View File
@@ -0,0 +1,70 @@
version: "3.8"
services:
talk:
image: "nextcloud/aio-talk:20251128_084214"
environment:
- NC_DOMAIN=${DOMAIN}
- TALK_HOST=${TALK_DOMAIN}
- TZ
- TALK_PORT=3478
- INTERNAL_SECRET_FILE=/run/secrets/talk_internal_secret
- TURN_SECRET_FILE=/run/secrets/talk_turn_secret
- SIGNALING_SECRET_FILE=/run/secrets/talk_signaling_secret
deploy:
labels:
- traefik.enable=true
- traefik.swarm.network=proxy
- traefik.http.services.${STACK_NAME}_talk.loadbalancer.server.port=8081
- traefik.http.routers.${STACK_NAME}_talk.rule=Host(`${TALK_DOMAIN}`)
- traefik.http.routers.${STACK_NAME}_talk.entrypoints=web-secure
- traefik.http.routers.${STACK_NAME}_talk.tls.certresolver=${LETS_ENCRYPT_ENV}
- traefik.tcp.routers.${STACK_NAME}_nextcloud-talk-hpb.rule=HostSNI(`*`)
- traefik.tcp.routers.${STACK_NAME}_nextcloud-talk-hpb.entrypoints=nextcloud-talk-hpb
- traefik.tcp.routers.${STACK_NAME}_nextcloud-talk-hpb.service=${STACK_NAME}_nextcloud-talk-hpb-svc
- traefik.tcp.services.${STACK_NAME}_nextcloud-talk-hpb-svc.loadbalancer.server.port=3478
- traefik.udp.routers.${STACK_NAME}_nextcloud-talk-hpb-udp.entrypoints=nextcloud-talk-hpb-udp
- traefik.udp.routers.${STACK_NAME}_nextcloud-talk-hpb-udp.service=${STACK_NAME}_nextcloud-talk-hpb-udp-svc
- traefik.udp.services.${STACK_NAME}_nextcloud-talk-hpb-udp-svc.loadbalancer.server.port=3478
networks:
- proxy
configs:
- source: entrypoint_talk
target: /custom-entrypoint.sh
mode: 775
entrypoint: /custom-entrypoint.sh
secrets:
- source: talk_internal_secret
uid: "1000"
gid: "122"
mode: 0600
- source: talk_turn_secret
uid: "1000"
gid: "122"
mode: 0600
- source: talk_signaling_secret
uid: "1000"
gid: "122"
mode: 0600
app:
secrets:
- talk_turn_secret
- talk_signaling_secret
secrets:
talk_internal_secret:
external: true
name: ${STACK_NAME}_talk_internal_secret_${SECRET_TALK_INTERNAL_SECRET_VERSION}
talk_turn_secret:
external: true
name: ${STACK_NAME}_talk_turn_secret_${SECRET_TALK_TURN_SECRET_VERSION}
talk_signaling_secret:
external: true
name: ${STACK_NAME}_talk_signaling_secret_${SECRET_TALK_SIGNALING_SECRET_VERSION}
configs:
entrypoint_talk:
name: ${STACK_NAME}_entrypoint_talk_${ENTRYPOINT_TALK_VERSION}
file: entrypoint.talk.sh.tmpl
template_driver: golang
+10
View File
@@ -0,0 +1,10 @@
version: "3.8"
services:
app:
secrets:
- user_oidc_secret
secrets:
user_oidc_secret:
external: true
name: ${STACK_NAME}_user_oidc_secret_${SECRET_USER_OIDC_SECRET_VERSION}
+44
View File
@@ -0,0 +1,44 @@
version: "3.8"
services:
app:
secrets:
- whiteboard_jwt
whiteboard:
image: ghcr.io/nextcloud-releases/whiteboard:v1.5.9
deploy:
labels:
- traefik.enable=true
- traefik.swarm.network=proxy
- traefik.http.services.${STACK_NAME}_whiteboard.loadbalancer.server.port=3002
- traefik.http.routers.${STACK_NAME}_whiteboard.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS}) && PathPrefix(`/whiteboard`)
- traefik.http.routers.${STACK_NAME}_whiteboard.entrypoints=web-secure
- traefik.http.routers.${STACK_NAME}_whiteboard.tls.certresolver=${LETS_ENCRYPT_ENV}
- traefik.http.middlewares.${STACK_NAME}_whiteboard-stripprefix.stripprefix.prefixes=/whiteboard
- traefik.http.routers.${STACK_NAME}_whiteboard.middlewares=${STACK_NAME}_whiteboard-stripprefix
configs:
- source: entrypoint_whiteboard
target: /custom-entrypoint.sh
entrypoint: ["sh", "/custom-entrypoint.sh"]
user: root
networks:
- proxy
ports:
- 3002:3002
secrets:
- whiteboard_jwt
environment:
- NEXTCLOUD_URL=https://$DOMAIN
- JWT_SECRET_KEY_FILE=/run/secrets/whiteboard_jwt
secrets:
whiteboard_jwt:
external: true
name: ${STACK_NAME}_whiteboard_jwt_${SECRET_WHITEBOARD_JWT_VERSION}
configs:
entrypoint_whiteboard:
name: ${STACK_NAME}_entrypoint_whiteboard_${ENTRYPOINT_WHITEBOARD_VERSION}
file: entrypoint.whiteboard.sh.tmpl
template_driver: golang
+14 -10
View File
@@ -1,7 +1,7 @@
version: "3.8"
services:
web:
image: nginx:1.27.2
image: nginx:1.31.1
depends_on:
- app
configs:
@@ -12,6 +12,8 @@ services:
- X_FRAME_OPTIONS_ENABLED
- DOMAIN
- STACK_NAME
- HSTS_ENABLED
- HSTS_PRELOAD
volumes:
- nextcloud:/var/www/html/
- nextapps:/var/www/html/custom_apps:cached
@@ -27,26 +29,26 @@ services:
order: start-first
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.swarm.network=proxy"
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=80"
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS})"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectscheme.scheme=https"
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectscheme.permanent=true"
- "caddy=${DOMAIN}"
- "caddy.reverse_proxy={{upstreams 80}}"
- "caddy.tls.on_demand="
healthcheck:
test: ["CMD-SHELL", 'curl -s -N curl -Ns localhost/status.php | grep "installed\":true"']
test: ["CMD-SHELL", "curl -fsS http://localhost/status.php | grep -q '\"installed\":true'"]
interval: 30s
timeout: 10s
retries: 10
start_period: 5m
app:
image: nextcloud:30.0.4-fpm
image: nextcloud:34.0.1-fpm
depends_on:
- db
configs:
@@ -72,7 +74,9 @@ services:
- TRUSTED_PROXIES=10.0.0.0/8
- REDIS_HOST=cache
- OVERWRITEPROTOCOL=https
- OVERWRITECLIURL=https://${DOMAIN}
- PHP_MEMORY_LIMIT=${PHP_MEMORY_LIMIT:-1G}
- PHP_UPLOAD_LIMIT=${PHP_UPLOAD_LIMIT:-512M}
- FPM_MAX_CHILDREN=${FPM_MAX_CHILDREN:-131}
- FPM_START_SERVERS=${FPM_START_SERVERS:-32}
- FPM_MIN_SPARE_SERVERS=${FPM_MIN_SPARE_SERVERS:-32}
@@ -91,8 +95,8 @@ services:
failure_action: rollback
order: start-first
labels:
- "coop-cloud.${STACK_NAME}.version=10.0.0+30.0.4-fpm"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
- "coop-cloud.${STACK_NAME}.version=15.1.0+34.0.1-fpm"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
- "backupbot.backup.volumes.redis=false"
#- "backupbot.backup.volumes.nextcloud=false"
@@ -105,7 +109,7 @@ services:
start_period: 15m
cron:
image: nextcloud:30.0.4-fpm
image: nextcloud:34.0.1-fpm
volumes:
- nextcloud:/var/www/html/
- nextapps:/var/www/html/custom_apps:cached
@@ -121,7 +125,7 @@ services:
cache:
image: redis:7.4.1-alpine
image: redis:8.8.0-alpine
networks:
- internal
volumes:
+30
View File
@@ -0,0 +1,30 @@
#!/bin/bash
set -eu
# Read a Swarm secret file (<VAR>_FILE) into the plain env var the
# Euro-Office document server expects, then hand off to its own entrypoint.
file_env() {
local var="$1"
local fileVar="${var}_FILE"
local def="${2:-}"
if [ "${!var:-}" ] && [ "${!fileVar:-}" ]; then
echo >&2 "error: both $var and $fileVar are set (but are exclusive)"
exit 1
fi
local val="$def"
if [ "${!var:-}" ]; then
val="${!var}"
elif [ "${!fileVar:-}" ]; then
val="$(< "${!fileVar}")"
fi
export "$var"="$val"
unset "$fileVar"
}
file_env "JWT_SECRET"
exec /entrypoint.sh
+30
View File
@@ -0,0 +1,30 @@
#!/bin/bash
set -eu
file_env() {
local var="$1"
local fileVar="${var}_FILE"
local def="${2:-}"
if [ "${!var:-}" ] && [ "${!fileVar:-}" ]; then
echo >&2 "error: both $var and $fileVar are set (but are exclusive)"
exit 1
fi
local val="$def"
if [ "${!var:-}" ]; then
val="${!var}"
elif [ "${!fileVar:-}" ]; then
val="$(< "${!fileVar}")"
fi
export "$var"="$val"
unset "$fileVar"
}
file_env "INTERNAL_SECRET"
file_env "TURN_SECRET"
file_env "SIGNALING_SECRET"
/start.sh supervisord -c /supervisord.conf
+6
View File
@@ -0,0 +1,6 @@
#!/bin/sh
set -e
export JWT_SECRET_KEY=$(cat /run/secrets/whiteboard_jwt)
exec npm run server:start
+73
View File
@@ -0,0 +1,73 @@
--
-- Create schema onlyoffice
--
-- CREATE DATABASE onlyoffice ENCODING = 'UTF8' CONNECTION LIMIT = -1;
-- ----------------------------
-- Table structure for doc_changes
-- ----------------------------
CREATE TABLE IF NOT EXISTS "doc_changes" (
"tenant" varchar(255) COLLATE "default" NOT NULL,
"id" varchar(255) COLLATE "default" NOT NULL,
"change_id" int4 NOT NULL,
"user_id" varchar(255) COLLATE "default" NOT NULL,
"user_id_original" varchar(255) COLLATE "default" NOT NULL,
"user_name" varchar(255) COLLATE "default" NOT NULL,
"change_data" text COLLATE "default" NOT NULL,
"change_date" timestamp without time zone NOT NULL,
PRIMARY KEY ("tenant", "id", "change_id")
)
WITH (OIDS=FALSE);
-- ----------------------------
-- Table structure for task_result
-- ----------------------------
CREATE TABLE IF NOT EXISTS "task_result" (
"tenant" varchar(255) COLLATE "default" NOT NULL,
"id" varchar(255) COLLATE "default" NOT NULL,
"status" int2 NOT NULL,
"status_info" int4 NOT NULL,
"created_at" timestamp without time zone DEFAULT NOW(),
"last_open_date" timestamp without time zone NOT NULL,
"user_index" int4 NOT NULL DEFAULT 1,
"change_id" int4 NOT NULL DEFAULT 0,
"callback" text COLLATE "default" NOT NULL,
"baseurl" text COLLATE "default" NOT NULL,
"password" text COLLATE "default" NULL,
"additional" text COLLATE "default" NULL,
PRIMARY KEY ("tenant", "id")
)
WITH (OIDS=FALSE);
CREATE OR REPLACE FUNCTION merge_db(_tenant varchar(255), _id varchar(255), _status int2, _status_info int4, _last_open_date timestamp without time zone, _user_index int4, _change_id int4, _callback text, _baseurl text, OUT isupdate char(5), OUT userindex int4) AS
$$
DECLARE
t_var "task_result"."user_index"%TYPE;
BEGIN
LOOP
-- first try to update the key
-- note that "a" must be unique
IF ((_callback <> '') IS TRUE) AND ((_baseurl <> '') IS TRUE) THEN
UPDATE "task_result" SET last_open_date=_last_open_date, user_index=user_index+1,callback=_callback,baseurl=_baseurl WHERE tenant = _tenant AND id = _id RETURNING user_index into userindex;
ELSE
UPDATE "task_result" SET last_open_date=_last_open_date, user_index=user_index+1 WHERE tenant = _tenant AND id = _id RETURNING user_index into userindex;
END IF;
IF found THEN
isupdate := 'true';
RETURN;
END IF;
-- not there, so try to insert the key
-- if someone else inserts the same key concurrently,
-- we could get a unique-key failure
BEGIN
INSERT INTO "task_result"(tenant, id, status, status_info, last_open_date, user_index, change_id, callback, baseurl) VALUES(_tenant, _id, _status, _status_info, _last_open_date, _user_index, _change_id, _callback, _baseurl) RETURNING user_index into userindex;
isupdate := 'false';
RETURN;
EXCEPTION WHEN unique_violation THEN
-- do nothing, and loop to try the UPDATE again
END;
END LOOP;
END;
$$
LANGUAGE plpgsql;
+1 -1
View File
@@ -4,7 +4,7 @@
# https://mariadb.com/kb/en/library/performance-schema-overview/
[server]
innodb_buffer_pool_size = 1G
innodb_buffer_pool_size = {{ env "INNODB_BUFFER_POOL_SIZE" }}
innodb_flush_log_at_trx_commit = 2
innodb_log_buffer_size = 32M
innodb_max_dirty_pages_pct = 90
+7
View File
@@ -45,6 +45,13 @@ http {
# could take several months.
#add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload;" always;
{{ if eq (env "HSTS_ENABLED") "1" }}
{{ if eq (env "HSTS_PRELOAD") "1" }}
add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload;" always;
{{ else }}
add_header Strict-Transport-Security "max-age=15768000; includeSubDomains;" always;
{{ end }}
{{ end }}
# set max upload size
client_max_body_size 512M;
+4
View File
@@ -0,0 +1,4 @@
Upgrades mariadb from 10.5 to 11.4
NOTE: If your Nextcloud instance is using mariadb, after running this update you MUST run the database upgrade command:
`abra app command nextcloud.yourserver.org db upgrade_mariadb`
More info: https://mariadb.com/kb/en/upgrading-from-mariadb-10-11-to-mariadb-11-4/
+3
View File
@@ -0,0 +1,3 @@
Important:
Posgres: Due to end of support for postgres 13 we upgraded to pgautoupgrade-14-debian but we could not test it, so please take backups before the upgrade!
Elastic Search: We chose the latest minor update for elasticsearch but we were also not able to test it.
+10
View File
@@ -0,0 +1,10 @@
Upgrades Nextcloud from 32.0.11 to 33.0.6 (major version upgrade).
IMPORTANT:
- Nextcloud does NOT support downgrades. Take a backup before deploying.
- Do not skip major versions: your instance must be on the latest 32.x before
upgrading to 33. If you are on an older 32.x, deploy 32.0.11 first.
- After deploying, check the logs and run any pending repair/upgrade steps:
`abra app cmd <app> app run_occ '"app:update --all"'`
- Review app (plug-in) compatibility with Nextcloud 33 before upgrading; some
apps may need to be updated or temporarily disabled.
+13
View File
@@ -0,0 +1,13 @@
Upgrades Nextcloud from 33.0.6 to 34.0.1 (major version upgrade).
IMPORTANT:
- Nextcloud does NOT support downgrades. Take a backup before deploying.
- Do not skip major versions: your instance must be on the latest 33.x before
upgrading to 34. If you are on 32.x, deploy 14.0.0+33.0.6-fpm first.
- After deploying, check the logs and run any pending repair/upgrade steps:
`abra app cmd <app> app run_occ '"app:update --all"'`
- Review app (plug-in) compatibility with Nextcloud 34 before upgrading; some
apps may need to be updated or temporarily disabled.
- PostgreSQL: Nextcloud 34 requires PostgreSQL >= 14 (the recipe already ships
pgautoupgrade 14). PostgreSQL 14 is now the minimum, so plan a bump to a newer
PostgreSQL before the next Nextcloud major.
+25
View File
@@ -0,0 +1,25 @@
Adds an optional Euro-Office integration (compose.eurooffice.yml).
Euro-Office is the AGPL fork of OnlyOffice that powers "Nextcloud Office" from
Nextcloud 34 onwards. This overlay runs the Euro-Office document server inside
the stack, so there is no external document server to manage.
This change is additive: existing installs are unaffected unless you opt in.
To enable it (`abra app config <app>`):
- COMPOSE_FILE="$COMPOSE_FILE:compose.eurooffice.yml"
- EUROOFFICE_DOMAIN=eurooffice.example.com
- APPS="$APPS eurooffice"
- SECRET_EUROOFFICE_JWT_VERSION=v1
Then:
- Create a DNS record for EUROOFFICE_DOMAIN pointing at this host (the browser
talks to the document server directly over HTTPS).
- `abra app secret generate -a <app>`
- `abra app deploy <app>`
- `abra app cmd <app> app install_eurooffice`
Notes:
- The document server needs ~4 GB RAM (8 GB recommended for multi-user).
- The `ghcr.io/euro-office/documentserver` image currently only publishes a
`latest` tag (no semver pinning yet), so it is not tracked by Renovate.