forked from coop-cloud/nextcloud
Compare commits
25 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 5e728e5141 | |||
| 42506330f7 | |||
| 8e57236f0d | |||
| 4c41c21799 | |||
| f60f10c6dd | |||
| d8f5c23897 | |||
| 7e4cbce41e | |||
| 6619501f5c | |||
| 53d7f765ae | |||
| f76245c34d | |||
| fcf1ca56d3 | |||
| 15a795affd | |||
| 38c426178a | |||
| 38920ae3de | |||
| 6e6c235acd | |||
| 10fdbc92b4 | |||
| 8ce1b9cf30 | |||
| 29431d2a14 | |||
| 66fdde358e | |||
| 4f4ba6db79 | |||
| 93e8f638f9 | |||
| c1e6292630 | |||
| 19e7fbb648 | |||
| 6113ccedde | |||
| 0d0c3b3266 |
-35
@@ -1,40 +1,5 @@
|
|||||||
---
|
---
|
||||||
kind: pipeline
|
kind: pipeline
|
||||||
name: deploy to swarm-test.autonomic.zone
|
|
||||||
steps:
|
|
||||||
- name: deployment
|
|
||||||
image: git.coopcloud.tech/coop-cloud/stack-ssh-deploy:latest
|
|
||||||
settings:
|
|
||||||
host: swarm-test.autonomic.zone
|
|
||||||
stack: nextcloud
|
|
||||||
generate_secrets: true
|
|
||||||
purge: true
|
|
||||||
deploy_key:
|
|
||||||
from_secret: drone_ssh_swarm_test
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
environment:
|
|
||||||
DOMAIN: nextcloud.swarm-test.autonomic.zone
|
|
||||||
STACK_NAME: nextcloud
|
|
||||||
LETS_ENCRYPT_ENV: production
|
|
||||||
ADMIN_USER: foobar
|
|
||||||
FPM_TUNE_VERSION: v1
|
|
||||||
NGINX_CONF_VERSION: v1
|
|
||||||
MY_CNF_VERSION: v1
|
|
||||||
ENTRYPOINT_VERSION: v1
|
|
||||||
CRONTAB_VERSION: v1
|
|
||||||
PG_BACKUP_VERSION: v2
|
|
||||||
SECRET_DB_PASSWORD_VERSION: v1
|
|
||||||
SECRET_DB_ROOT_PASSWORD_VERSION: v1
|
|
||||||
SECRET_ADMIN_PASSWORD_VERSION: v1
|
|
||||||
SECRET_ONLYOFFICE_JWT_VERSION: v1
|
|
||||||
SECRET_BBB_SECRET_VERSION: v1
|
|
||||||
EXTRA_VOLUME: "/dev/null:/tmp/.dummy"
|
|
||||||
trigger:
|
|
||||||
branch:
|
|
||||||
- main
|
|
||||||
---
|
|
||||||
kind: pipeline
|
|
||||||
name: generate recipe catalogue
|
name: generate recipe catalogue
|
||||||
steps:
|
steps:
|
||||||
- name: release a new version
|
- name: release a new version
|
||||||
|
|||||||
+7
-3
@@ -69,6 +69,13 @@ DEFAULT_QUOTA="10 GB"
|
|||||||
# APPS="$APPS onlyoffice"
|
# APPS="$APPS onlyoffice"
|
||||||
# SECRET_ONLYOFFICE_JWT_VERSION=v1
|
# SECRET_ONLYOFFICE_JWT_VERSION=v1
|
||||||
|
|
||||||
|
# Euro-Office runs its own document server in this stack; EUROOFFICE_DOMAIN
|
||||||
|
# needs its own DNS record pointing at this host.
|
||||||
|
# COMPOSE_FILE="$COMPOSE_FILE:compose.eurooffice.yml"
|
||||||
|
# EUROOFFICE_DOMAIN=eurooffice.example.com
|
||||||
|
# APPS="$APPS eurooffice"
|
||||||
|
# SECRET_EUROOFFICE_JWT_VERSION=v1
|
||||||
|
|
||||||
# COMPOSE_FILE="$COMPOSE_FILE:compose.bbb.yml"
|
# COMPOSE_FILE="$COMPOSE_FILE:compose.bbb.yml"
|
||||||
# BBB_URL=https://talk.example.org/bigbluebutton/ # trailing slash!
|
# BBB_URL=https://talk.example.org/bigbluebutton/ # trailing slash!
|
||||||
# SECRET_BBB_SECRET_VERSION=v1
|
# SECRET_BBB_SECRET_VERSION=v1
|
||||||
@@ -102,9 +109,6 @@ DEFAULT_QUOTA="10 GB"
|
|||||||
# USER_OIDC_LOGIN_ONLY=false
|
# USER_OIDC_LOGIN_ONLY=false
|
||||||
# SECRET_USER_OIDC_SECRET_VERSION=v1
|
# SECRET_USER_OIDC_SECRET_VERSION=v1
|
||||||
|
|
||||||
# Image / PDF previews with Imaginary (see README)
|
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.imaginary-preview.yml"
|
|
||||||
|
|
||||||
# HSTS Options
|
# HSTS Options
|
||||||
# Uncomment this line to enable HSTS: https://docs.nextcloud.com/server/30/admin_manual/installation/harden_server.html
|
# Uncomment this line to enable HSTS: https://docs.nextcloud.com/server/30/admin_manual/installation/harden_server.html
|
||||||
#HSTS_ENABLED=1
|
#HSTS_ENABLED=1
|
||||||
|
|||||||
@@ -0,0 +1,91 @@
|
|||||||
|
# Nextcloud Recipe Maintenance
|
||||||
|
|
||||||
|
This document describes how the Nextcloud recipe is maintained. It builds on
|
||||||
|
the floor set by [Federation Resolution
|
||||||
|
025](https://docs.coopcloud.tech/federation/resolutions/passed/025/) and
|
||||||
|
follows the [`MAINTENANCE.md`
|
||||||
|
template](https://docs.coopcloud.tech/maintainers/maintain/#maintenancemd-template)
|
||||||
|
described in the Co-op Cloud maintainers' docs.
|
||||||
|
|
||||||
|
All contributions should be made via a pull request so that quality and
|
||||||
|
consistency stay something others can rely on.
|
||||||
|
|
||||||
|
## Maintainers
|
||||||
|
|
||||||
|
Everyone can apply to be a recipe maintainer.
|
||||||
|
Simply add yourself to the list in the README.md and open a new pull request
|
||||||
|
with the change.
|
||||||
|
|
||||||
|
## Maintainer Responsibilities
|
||||||
|
|
||||||
|
This recipe commits to the following, which is tighter than the floor set by
|
||||||
|
Resolution 025 (stable-recipe category). However, these timelines are
|
||||||
|
best-effort, so we aim for them as good as possible:
|
||||||
|
|
||||||
|
- Respond to PRs / issues within 3 working days
|
||||||
|
- Apply security patches within 1 week of disclosure
|
||||||
|
- Ship patch / minor image updates within 2 weeks of upstream release
|
||||||
|
- Adopt major Nextcloud version updates within 1 release cycle of upstream
|
||||||
|
EOL of the previous major (see below)
|
||||||
|
- Keep documentation current
|
||||||
|
|
||||||
|
In order to meet these responsibilities each maintainer:
|
||||||
|
|
||||||
|
- Watches the repository so notifications arrive
|
||||||
|
- Keeps an eye on [Renovate](./renovate.json) updates and helps shepherd them through
|
||||||
|
- Has a working contact (Matrix handle or email) reachable by the others
|
||||||
|
|
||||||
|
## Release cadence
|
||||||
|
|
||||||
|
The intent is to **track Nextcloud's own release schedule** rather than invent
|
||||||
|
our own. In practice this means:
|
||||||
|
|
||||||
|
- **Patch releases (e.g. `32.0.x`)**: published to this recipe shortly after
|
||||||
|
upstream, ideally within 1 week. `chore(deps)` opens the PRs; a maintainer
|
||||||
|
reviews the release notes and Nextcloud's issue tracker, and merges the PR
|
||||||
|
if it is OK.
|
||||||
|
- **Minor releases**: same flow as patch releases, but one of the maintainer
|
||||||
|
tests it on their own instance before merging.
|
||||||
|
- **Major releases (e.g. `32 → 33`)**: not adopted on day one. We wait for the
|
||||||
|
first one or two upstream patch releases of the new major to land
|
||||||
|
(typically 1–2 months) before promoting it here, to avoid passing the
|
||||||
|
early-adopter cost to operators. Major bumps get their own PR with release
|
||||||
|
notes and an upgrade-path check.
|
||||||
|
Before adding a major release, the following needs to be done:
|
||||||
|
- at least two maintainers update one of their production instances to the
|
||||||
|
new version
|
||||||
|
- the previous release gets a last update pointing to the docker image
|
||||||
|
versions nextcloud:xx-fpm, so that users can auto-update if they wish so
|
||||||
|
- the new release is added to this repo
|
||||||
|
- If people have the time it would be nice to create specially tagged versions
|
||||||
|
for major releases, which reflect that this is 'bleeding edge' and has not
|
||||||
|
been thoroughly tested.
|
||||||
|
- **Co-installed components** (Talk HPB, OnlyOffice, Whiteboard, etc.) are
|
||||||
|
bumped alongside or shortly after the matching Nextcloud release.
|
||||||
|
|
||||||
|
## Pull Requests
|
||||||
|
|
||||||
|
A pull request can be merged once it is approved by at least one maintainer.
|
||||||
|
PRs opened by a maintainer need approval from another maintainer. With three
|
||||||
|
maintainers this is workable; if the group shrinks, the rule should be
|
||||||
|
revisited.
|
||||||
|
|
||||||
|
Approvals should ideally include a smoke test on a real instance for anything
|
||||||
|
beyond a patch bump — Nextcloud upgrades have a long history of surprising us
|
||||||
|
(see the [upgrade notes in `README.md`](./README.md#upgrading-nextcloud)),
|
||||||
|
and silent CI is not enough.
|
||||||
|
|
||||||
|
## Becoming a maintainer
|
||||||
|
|
||||||
|
Everyone is welcome to apply:
|
||||||
|
|
||||||
|
1. Watch the repository so you get notifications.
|
||||||
|
2. Open a pull request adding yourself to the `Maintainer` line in
|
||||||
|
[`README.md`](./README.md) and to the list above.
|
||||||
|
3. Once an existing maintainer merges the PR, you'll be added to the
|
||||||
|
[nextcloud maintainers
|
||||||
|
team](https://git.coopcloud.tech/org/coop-cloud/teams/nextcloud-maintainers).
|
||||||
|
|
||||||
|
Stepping down is symmetrical: open a PR removing yourself, and flag it in
|
||||||
|
the federation channels so the group can plan replacement before falling
|
||||||
|
below the Res. 025 floor of one named maintainer.
|
||||||
@@ -5,6 +5,7 @@
|
|||||||
Fully automated luxury Nextcloud via docker-swarm.
|
Fully automated luxury Nextcloud via docker-swarm.
|
||||||
|
|
||||||
<!-- metadata -->
|
<!-- metadata -->
|
||||||
|
* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti)
|
||||||
* **Category**: Apps
|
* **Category**: Apps
|
||||||
* **Status**: 5
|
* **Status**: 5
|
||||||
* **Image**: [`nextcloud`](https://hub.docker.com/_/nextcloud), 4, upstream
|
* **Image**: [`nextcloud`](https://hub.docker.com/_/nextcloud), 4, upstream
|
||||||
@@ -25,9 +26,9 @@ Fully automated luxury Nextcloud via docker-swarm.
|
|||||||
|
|
||||||
### Onlyoffice Integration
|
### Onlyoffice Integration
|
||||||
|
|
||||||
First install onlyoffice following the instructions in the
|
First, install onlyoffice following the instructions in the
|
||||||
[OnlyOffice Recipe](https://recipes.coopcloud.tech/onlyoffice), and enable
|
[OnlyOffice Recipe](https://recipes.coopcloud.tech/onlyoffice), and enable
|
||||||
the JWT secret.
|
the JWT secret. Then configure your nextcloud instance with:
|
||||||
|
|
||||||
`abra app config <app-name>`
|
`abra app config <app-name>`
|
||||||
|
|
||||||
@@ -43,6 +44,40 @@ Then set the onlyoffice JWT secret from the onlyoffice installation:
|
|||||||
* `abra app secret insert <app-name> onlyoffice_jwt v1 <jwt_secret>`
|
* `abra app secret insert <app-name> onlyoffice_jwt v1 <jwt_secret>`
|
||||||
* `abra app cmd <app-name> app install_onlyoffice`
|
* `abra app cmd <app-name> app install_onlyoffice`
|
||||||
|
|
||||||
|
### Euro-Office Integration
|
||||||
|
|
||||||
|
Euro-Office is the AGPL fork of OnlyOffice that powers "Nextcloud Office" from
|
||||||
|
Nextcloud 34 onwards. Like OnlyOffice it uses a client-side document-server
|
||||||
|
architecture, so a separate document server is required — but this overlay runs
|
||||||
|
that document server **inside the same stack**, so there is no external host to
|
||||||
|
manage. The browser talks to it directly, so it needs its own public HTTPS
|
||||||
|
domain (`EUROOFFICE_DOMAIN`) with a DNS record pointing at this host.
|
||||||
|
|
||||||
|
`abra app config <app-name>`
|
||||||
|
|
||||||
|
Enable the overlay and set the document server's domain:
|
||||||
|
```
|
||||||
|
COMPOSE_FILE="$COMPOSE_FILE:compose.eurooffice.yml"
|
||||||
|
EUROOFFICE_DOMAIN=eurooffice.example.com
|
||||||
|
APPS="$APPS eurooffice"
|
||||||
|
SECRET_EUROOFFICE_JWT_VERSION=v1
|
||||||
|
```
|
||||||
|
|
||||||
|
The overlay runs the document server with its own Postgres and RabbitMQ services
|
||||||
|
(the image's bundled Postgres is unreliable). The document server schema is
|
||||||
|
seeded into that Postgres automatically on first init (see
|
||||||
|
`eurooffice-createdb.sql`). The Postgres is internal-only and uses trust auth, so
|
||||||
|
the only secret to manage is the JWT; generate it, deploy, then wire up the
|
||||||
|
Nextcloud app:
|
||||||
|
|
||||||
|
* `abra app secret generate -a <app-name>`
|
||||||
|
* `abra app deploy <app-name>`
|
||||||
|
* `abra app cmd <app-name> app install_eurooffice`
|
||||||
|
|
||||||
|
> Note: the document server needs ~4 GB RAM (8 GB for multi-user) and pulls the
|
||||||
|
> `ghcr.io/euro-office/documentserver` image, which currently only publishes a
|
||||||
|
> `latest` tag (no semver / Renovate pinning yet).
|
||||||
|
|
||||||
### BBB Integration
|
### BBB Integration
|
||||||
|
|
||||||
`abra app config <app-name>`
|
`abra app config <app-name>`
|
||||||
@@ -315,20 +350,6 @@ docker exec -u www-data $(docker ps -f name=foo_com_app -q) ./occ preview:pre-ge
|
|||||||
|
|
||||||
This app will improve performance of image browsing at the cost of storage space.
|
This app will improve performance of image browsing at the cost of storage space.
|
||||||
|
|
||||||
## Better image previews with `imaginary`
|
|
||||||
|
|
||||||
1. Run `abra app config <domain>` and uncomment the line `#COMPOSE_FILE="$COMPOSE_FILE:compose.imaginary-preview.yml"`.
|
|
||||||
2. Re-deploy the app (`abra app deploy <domain> --force`)
|
|
||||||
3. Edit `/var/www/config/config.php` and add:
|
|
||||||
|
|
||||||
```
|
|
||||||
'enabledPreviewProviders' =>
|
|
||||||
array (
|
|
||||||
0 => 'OC\\Preview\\Imaginary',
|
|
||||||
),
|
|
||||||
'preview_imaginary_url' => 'http://imaginary:9000',
|
|
||||||
```
|
|
||||||
|
|
||||||
## Fulltextsearch using elasticsearch
|
## Fulltextsearch using elasticsearch
|
||||||
|
|
||||||
1. Uncomment the following lines in your env file:
|
1. Uncomment the following lines in your env file:
|
||||||
|
|||||||
@@ -6,11 +6,13 @@ export MY_CNF_VERSION=v6
|
|||||||
export ENTRYPOINT_VERSION=v3
|
export ENTRYPOINT_VERSION=v3
|
||||||
export ENTRYPOINT_WHITEBOARD_VERSION=v1
|
export ENTRYPOINT_WHITEBOARD_VERSION=v1
|
||||||
export ENTRYPOINT_TALK_VERSION=v1
|
export ENTRYPOINT_TALK_VERSION=v1
|
||||||
|
export ENTRYPOINT_EUROOFFICE_VERSION=v3
|
||||||
|
export EUROOFFICE_CREATEDB_VERSION=v1
|
||||||
export CRONTAB_VERSION=v1
|
export CRONTAB_VERSION=v1
|
||||||
export PG_BACKUP_VERSION=v2
|
export PG_BACKUP_VERSION=v2
|
||||||
|
|
||||||
run_occ() {
|
run_occ() {
|
||||||
su -p www-data -s /bin/sh -c "/var/www/html/occ $@"
|
su -p www-data -s /bin/sh -c "/var/www/html/occ $*"
|
||||||
}
|
}
|
||||||
|
|
||||||
install_apps() {
|
install_apps() {
|
||||||
@@ -83,6 +85,13 @@ install_onlyoffice() {
|
|||||||
set_app_config onlyoffice customizationForcesave true
|
set_app_config onlyoffice customizationForcesave true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
install_eurooffice() {
|
||||||
|
install_apps eurooffice
|
||||||
|
set_app_config eurooffice DocumentServerUrl "https://${EUROOFFICE_DOMAIN}"
|
||||||
|
set_app_config eurooffice jwt_secret "$(cat /run/secrets/eurooffice_jwt)"
|
||||||
|
set_app_config eurooffice customizationForcesave true
|
||||||
|
}
|
||||||
|
|
||||||
install_collabora() {
|
install_collabora() {
|
||||||
install_apps richdocuments
|
install_apps richdocuments
|
||||||
set_app_config richdocuments wopi_url "$COLLABORA_URL"
|
set_app_config richdocuments wopi_url "$COLLABORA_URL"
|
||||||
|
|||||||
@@ -0,0 +1,118 @@
|
|||||||
|
version: "3.8"
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
secrets:
|
||||||
|
- eurooffice_jwt
|
||||||
|
environment:
|
||||||
|
- EUROOFFICE_DOMAIN
|
||||||
|
|
||||||
|
eurooffice:
|
||||||
|
image: ghcr.io/euro-office/documentserver:v9.3.2
|
||||||
|
stdin_open: true
|
||||||
|
depends_on:
|
||||||
|
- eurooffice-db
|
||||||
|
- eurooffice-rabbitmq
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
- internal
|
||||||
|
environment:
|
||||||
|
- JWT_ENABLED=true
|
||||||
|
- JWT_SECRET_FILE=/run/secrets/eurooffice_jwt
|
||||||
|
# Use external Postgres + RabbitMQ instead of the flaky bundled ones.
|
||||||
|
# (The all-in-one image ships an uncleanly-shut-down Postgres data dir
|
||||||
|
# whose crash recovery exceeds pg_ctl's start timeout -> restart loop.)
|
||||||
|
- DB_TYPE=postgres
|
||||||
|
- DB_HOST=eurooffice-db
|
||||||
|
- DB_PORT=5432
|
||||||
|
- DB_NAME=eurooffice
|
||||||
|
- DB_USER=eurooffice
|
||||||
|
- AMQP_URI=amqp://guest:guest@eurooffice-rabbitmq
|
||||||
|
volumes:
|
||||||
|
- eurooffice_data:/var/lib/euro-office
|
||||||
|
- eurooffice_config:/etc/euro-office
|
||||||
|
- eurooffice_logs:/var/log/euro-office
|
||||||
|
- eurooffice_fonts:/usr/share/fonts/custom
|
||||||
|
secrets:
|
||||||
|
- eurooffice_jwt
|
||||||
|
configs:
|
||||||
|
- source: entrypoint_eurooffice
|
||||||
|
target: /custom-entrypoint.sh
|
||||||
|
mode: 555
|
||||||
|
entrypoint: /custom-entrypoint.sh
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "curl", "-f", "http://localhost/healthcheck"]
|
||||||
|
interval: 30s
|
||||||
|
timeout: 10s
|
||||||
|
retries: 10
|
||||||
|
start_period: 3m
|
||||||
|
deploy:
|
||||||
|
update_config:
|
||||||
|
failure_action: rollback
|
||||||
|
order: start-first
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.swarm.network=proxy"
|
||||||
|
- "traefik.http.services.${STACK_NAME}_eurooffice.loadbalancer.server.port=80"
|
||||||
|
- "traefik.http.routers.${STACK_NAME}_eurooffice.rule=Host(`${EUROOFFICE_DOMAIN}`)"
|
||||||
|
- "traefik.http.routers.${STACK_NAME}_eurooffice.entrypoints=web-secure"
|
||||||
|
- "traefik.http.routers.${STACK_NAME}_eurooffice.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||||
|
- "traefik.http.routers.${STACK_NAME}_eurooffice.middlewares=${STACK_NAME}_eurooffice-fwdproto"
|
||||||
|
- "traefik.http.middlewares.${STACK_NAME}_eurooffice-fwdproto.headers.customRequestHeaders.X-Forwarded-Proto=https"
|
||||||
|
|
||||||
|
eurooffice-db:
|
||||||
|
image: postgres:16-alpine
|
||||||
|
networks:
|
||||||
|
- internal
|
||||||
|
environment:
|
||||||
|
- POSTGRES_DB=eurooffice
|
||||||
|
- POSTGRES_USER=eurooffice
|
||||||
|
# Internal-only DB holding transient editing state; trust auth on the
|
||||||
|
# private overlay network avoids managing a Swarm secret for it.
|
||||||
|
- POSTGRES_HOST_AUTH_METHOD=trust
|
||||||
|
volumes:
|
||||||
|
- eurooffice_db:/var/lib/postgresql/data
|
||||||
|
configs:
|
||||||
|
# Seed the document server schema on first init. The all-in-one image only
|
||||||
|
# creates its schema in the *bundled* Postgres; with an external DB the
|
||||||
|
# docservice starts against an empty DB, errors on missing task_result /
|
||||||
|
# doc_changes, never binds its port, and gets healthcheck-killed in a loop.
|
||||||
|
- source: eurooffice_createdb
|
||||||
|
target: /docker-entrypoint-initdb.d/createdb.sql
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "pg_isready", "-U", "eurooffice"]
|
||||||
|
interval: 30s
|
||||||
|
timeout: 10s
|
||||||
|
retries: 10
|
||||||
|
start_period: 1m
|
||||||
|
|
||||||
|
eurooffice-rabbitmq:
|
||||||
|
image: rabbitmq:4.3.2
|
||||||
|
networks:
|
||||||
|
- internal
|
||||||
|
healthcheck:
|
||||||
|
test: rabbitmq-diagnostics -q ping
|
||||||
|
interval: 30s
|
||||||
|
timeout: 10s
|
||||||
|
retries: 10
|
||||||
|
start_period: 1m
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
eurooffice_jwt:
|
||||||
|
external: true
|
||||||
|
name: ${STACK_NAME}_eurooffice_jwt_${SECRET_EUROOFFICE_JWT_VERSION}
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
eurooffice_data:
|
||||||
|
eurooffice_config:
|
||||||
|
eurooffice_logs:
|
||||||
|
eurooffice_fonts:
|
||||||
|
eurooffice_db:
|
||||||
|
|
||||||
|
configs:
|
||||||
|
entrypoint_eurooffice:
|
||||||
|
name: ${STACK_NAME}_entrypoint_eurooffice_${ENTRYPOINT_EUROOFFICE_VERSION}
|
||||||
|
file: entrypoint.eurooffice.sh.tmpl
|
||||||
|
template_driver: golang
|
||||||
|
eurooffice_createdb:
|
||||||
|
name: ${STACK_NAME}_eurooffice_createdb_${EUROOFFICE_CREATEDB_VERSION}
|
||||||
|
file: eurooffice-createdb.sql
|
||||||
@@ -2,7 +2,7 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
elasticsearch:
|
elasticsearch:
|
||||||
image: "docker.elastic.co/elasticsearch/elasticsearch:8.17.2"
|
image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.19"
|
||||||
environment:
|
environment:
|
||||||
- cluster.name=docker-cluster
|
- cluster.name=docker-cluster
|
||||||
- bootstrap.memory_lock=true
|
- bootstrap.memory_lock=true
|
||||||
@@ -29,7 +29,7 @@ services:
|
|||||||
mode: 0600
|
mode: 0600
|
||||||
|
|
||||||
searchindexer:
|
searchindexer:
|
||||||
image: nextcloud:32.0.3-fpm
|
image: nextcloud:34.0.2-fpm
|
||||||
volumes:
|
volumes:
|
||||||
- nextcloud:/var/www/html/
|
- nextcloud:/var/www/html/
|
||||||
- nextapps:/var/www/html/custom_apps:cached
|
- nextapps:/var/www/html/custom_apps:cached
|
||||||
|
|||||||
@@ -1,10 +0,0 @@
|
|||||||
---
|
|
||||||
version: '3.8'
|
|
||||||
services:
|
|
||||||
imaginary:
|
|
||||||
image: nextcloud/aio-imaginary:20250822_112758
|
|
||||||
environment:
|
|
||||||
- PORT=9000
|
|
||||||
command: -concurrency 50 -enable-url-source -log-level debug
|
|
||||||
networks:
|
|
||||||
- internal
|
|
||||||
+1
-1
@@ -9,7 +9,7 @@ services:
|
|||||||
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
|
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: "mariadb:11.4"
|
image: "mariadb:12.3"
|
||||||
environment:
|
environment:
|
||||||
- MYSQL_DATABASE=nextcloud
|
- MYSQL_DATABASE=nextcloud
|
||||||
- MYSQL_USER=nextcloud
|
- MYSQL_USER=nextcloud
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ services:
|
|||||||
- NEXTCLOUD_UPDATE=1
|
- NEXTCLOUD_UPDATE=1
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: "postgres:13"
|
image: "pgautoupgrade/pgautoupgrade:14-debian"
|
||||||
command: -c "max_connections=${MAX_DB_CONNECTIONS:-100}"
|
command: -c "max_connections=${MAX_DB_CONNECTIONS:-100}"
|
||||||
volumes:
|
volumes:
|
||||||
- "postgres:/var/lib/postgresql/data"
|
- "postgres:/var/lib/postgresql/data"
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ services:
|
|||||||
- whiteboard_jwt
|
- whiteboard_jwt
|
||||||
|
|
||||||
whiteboard:
|
whiteboard:
|
||||||
image: ghcr.io/nextcloud-releases/whiteboard:v1.5.0
|
image: ghcr.io/nextcloud-releases/whiteboard:v1.5.9
|
||||||
deploy:
|
deploy:
|
||||||
labels:
|
labels:
|
||||||
- traefik.enable=true
|
- traefik.enable=true
|
||||||
|
|||||||
+5
-5
@@ -1,7 +1,7 @@
|
|||||||
version: "3.8"
|
version: "3.8"
|
||||||
services:
|
services:
|
||||||
web:
|
web:
|
||||||
image: nginx:1.29.4
|
image: nginx:1.31.3
|
||||||
depends_on:
|
depends_on:
|
||||||
- app
|
- app
|
||||||
configs:
|
configs:
|
||||||
@@ -48,7 +48,7 @@ services:
|
|||||||
start_period: 5m
|
start_period: 5m
|
||||||
|
|
||||||
app:
|
app:
|
||||||
image: nextcloud:32.0.3-fpm
|
image: nextcloud:34.0.2-fpm
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
configs:
|
configs:
|
||||||
@@ -95,7 +95,7 @@ services:
|
|||||||
failure_action: rollback
|
failure_action: rollback
|
||||||
order: start-first
|
order: start-first
|
||||||
labels:
|
labels:
|
||||||
- "coop-cloud.${STACK_NAME}.version=13.0.1+32.0.3-fpm"
|
- "coop-cloud.${STACK_NAME}.version=15.1.0+34.0.2-fpm"
|
||||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
||||||
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
||||||
- "backupbot.backup.volumes.redis=false"
|
- "backupbot.backup.volumes.redis=false"
|
||||||
@@ -109,7 +109,7 @@ services:
|
|||||||
start_period: 15m
|
start_period: 15m
|
||||||
|
|
||||||
cron:
|
cron:
|
||||||
image: nextcloud:32.0.3-fpm
|
image: nextcloud:34.0.2-fpm
|
||||||
volumes:
|
volumes:
|
||||||
- nextcloud:/var/www/html/
|
- nextcloud:/var/www/html/
|
||||||
- nextapps:/var/www/html/custom_apps:cached
|
- nextapps:/var/www/html/custom_apps:cached
|
||||||
@@ -125,7 +125,7 @@ services:
|
|||||||
|
|
||||||
|
|
||||||
cache:
|
cache:
|
||||||
image: redis:8.4.0-alpine
|
image: redis:8.8.1-alpine
|
||||||
networks:
|
networks:
|
||||||
- internal
|
- internal
|
||||||
volumes:
|
volumes:
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
# Read a Swarm secret file (<VAR>_FILE) into the plain env var the
|
||||||
|
# Euro-Office document server expects, then hand off to its own entrypoint.
|
||||||
|
file_env() {
|
||||||
|
local var="$1"
|
||||||
|
local fileVar="${var}_FILE"
|
||||||
|
local def="${2:-}"
|
||||||
|
|
||||||
|
if [ "${!var:-}" ] && [ "${!fileVar:-}" ]; then
|
||||||
|
echo >&2 "error: both $var and $fileVar are set (but are exclusive)"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
local val="$def"
|
||||||
|
if [ "${!var:-}" ]; then
|
||||||
|
val="${!var}"
|
||||||
|
elif [ "${!fileVar:-}" ]; then
|
||||||
|
val="$(< "${!fileVar}")"
|
||||||
|
fi
|
||||||
|
|
||||||
|
export "$var"="$val"
|
||||||
|
unset "$fileVar"
|
||||||
|
}
|
||||||
|
|
||||||
|
file_env "JWT_SECRET"
|
||||||
|
|
||||||
|
exec /entrypoint.sh
|
||||||
@@ -0,0 +1,73 @@
|
|||||||
|
--
|
||||||
|
-- Create schema onlyoffice
|
||||||
|
--
|
||||||
|
|
||||||
|
-- CREATE DATABASE onlyoffice ENCODING = 'UTF8' CONNECTION LIMIT = -1;
|
||||||
|
|
||||||
|
-- ----------------------------
|
||||||
|
-- Table structure for doc_changes
|
||||||
|
-- ----------------------------
|
||||||
|
CREATE TABLE IF NOT EXISTS "doc_changes" (
|
||||||
|
"tenant" varchar(255) COLLATE "default" NOT NULL,
|
||||||
|
"id" varchar(255) COLLATE "default" NOT NULL,
|
||||||
|
"change_id" int4 NOT NULL,
|
||||||
|
"user_id" varchar(255) COLLATE "default" NOT NULL,
|
||||||
|
"user_id_original" varchar(255) COLLATE "default" NOT NULL,
|
||||||
|
"user_name" varchar(255) COLLATE "default" NOT NULL,
|
||||||
|
"change_data" text COLLATE "default" NOT NULL,
|
||||||
|
"change_date" timestamp without time zone NOT NULL,
|
||||||
|
PRIMARY KEY ("tenant", "id", "change_id")
|
||||||
|
)
|
||||||
|
WITH (OIDS=FALSE);
|
||||||
|
|
||||||
|
-- ----------------------------
|
||||||
|
-- Table structure for task_result
|
||||||
|
-- ----------------------------
|
||||||
|
CREATE TABLE IF NOT EXISTS "task_result" (
|
||||||
|
"tenant" varchar(255) COLLATE "default" NOT NULL,
|
||||||
|
"id" varchar(255) COLLATE "default" NOT NULL,
|
||||||
|
"status" int2 NOT NULL,
|
||||||
|
"status_info" int4 NOT NULL,
|
||||||
|
"created_at" timestamp without time zone DEFAULT NOW(),
|
||||||
|
"last_open_date" timestamp without time zone NOT NULL,
|
||||||
|
"user_index" int4 NOT NULL DEFAULT 1,
|
||||||
|
"change_id" int4 NOT NULL DEFAULT 0,
|
||||||
|
"callback" text COLLATE "default" NOT NULL,
|
||||||
|
"baseurl" text COLLATE "default" NOT NULL,
|
||||||
|
"password" text COLLATE "default" NULL,
|
||||||
|
"additional" text COLLATE "default" NULL,
|
||||||
|
PRIMARY KEY ("tenant", "id")
|
||||||
|
)
|
||||||
|
WITH (OIDS=FALSE);
|
||||||
|
|
||||||
|
CREATE OR REPLACE FUNCTION merge_db(_tenant varchar(255), _id varchar(255), _status int2, _status_info int4, _last_open_date timestamp without time zone, _user_index int4, _change_id int4, _callback text, _baseurl text, OUT isupdate char(5), OUT userindex int4) AS
|
||||||
|
$$
|
||||||
|
DECLARE
|
||||||
|
t_var "task_result"."user_index"%TYPE;
|
||||||
|
BEGIN
|
||||||
|
LOOP
|
||||||
|
-- first try to update the key
|
||||||
|
-- note that "a" must be unique
|
||||||
|
IF ((_callback <> '') IS TRUE) AND ((_baseurl <> '') IS TRUE) THEN
|
||||||
|
UPDATE "task_result" SET last_open_date=_last_open_date, user_index=user_index+1,callback=_callback,baseurl=_baseurl WHERE tenant = _tenant AND id = _id RETURNING user_index into userindex;
|
||||||
|
ELSE
|
||||||
|
UPDATE "task_result" SET last_open_date=_last_open_date, user_index=user_index+1 WHERE tenant = _tenant AND id = _id RETURNING user_index into userindex;
|
||||||
|
END IF;
|
||||||
|
IF found THEN
|
||||||
|
isupdate := 'true';
|
||||||
|
RETURN;
|
||||||
|
END IF;
|
||||||
|
-- not there, so try to insert the key
|
||||||
|
-- if someone else inserts the same key concurrently,
|
||||||
|
-- we could get a unique-key failure
|
||||||
|
BEGIN
|
||||||
|
INSERT INTO "task_result"(tenant, id, status, status_info, last_open_date, user_index, change_id, callback, baseurl) VALUES(_tenant, _id, _status, _status_info, _last_open_date, _user_index, _change_id, _callback, _baseurl) RETURNING user_index into userindex;
|
||||||
|
isupdate := 'false';
|
||||||
|
RETURN;
|
||||||
|
EXCEPTION WHEN unique_violation THEN
|
||||||
|
-- do nothing, and loop to try the UPDATE again
|
||||||
|
END;
|
||||||
|
END LOOP;
|
||||||
|
END;
|
||||||
|
$$
|
||||||
|
LANGUAGE plpgsql;
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
Important:
|
||||||
|
Posgres: Due to end of support for postgres 13 we upgraded to pgautoupgrade-14-debian but we could not test it, so please take backups before the upgrade!
|
||||||
|
Elastic Search: We chose the latest minor update for elasticsearch but we were also not able to test it.
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
chore(deps): update mariadb docker tag to v12
|
||||||
|
chore(deps): update mariadb docker tag to v11.8
|
||||||
|
chore(deps): update nginx docker tag to v1.31.3
|
||||||
|
chore(deps): update docker.elastic.co/elasticsearch/elasticsearch docker tag to v8.19.19
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
Upgrades Nextcloud from 32.0.11 to 33.0.6 (major version upgrade).
|
||||||
|
|
||||||
|
IMPORTANT:
|
||||||
|
- Nextcloud does NOT support downgrades. Take a backup before deploying.
|
||||||
|
- Do not skip major versions: your instance must be on the latest 32.x before
|
||||||
|
upgrading to 33. If you are on an older 32.x, deploy 32.0.11 first.
|
||||||
|
- After deploying, check the logs and run any pending repair/upgrade steps:
|
||||||
|
`abra app cmd <app> app run_occ '"app:update --all"'`
|
||||||
|
- Review app (plug-in) compatibility with Nextcloud 33 before upgrading; some
|
||||||
|
apps may need to be updated or temporarily disabled.
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
Upgrades Nextcloud from 33.0.6 to 34.0.1 (major version upgrade).
|
||||||
|
|
||||||
|
IMPORTANT:
|
||||||
|
- Nextcloud does NOT support downgrades. Take a backup before deploying.
|
||||||
|
- Do not skip major versions: your instance must be on the latest 33.x before
|
||||||
|
upgrading to 34. If you are on 32.x, deploy 14.0.0+33.0.6-fpm first.
|
||||||
|
- After deploying, check the logs and run any pending repair/upgrade steps:
|
||||||
|
`abra app cmd <app> app run_occ '"app:update --all"'`
|
||||||
|
- Review app (plug-in) compatibility with Nextcloud 34 before upgrading; some
|
||||||
|
apps may need to be updated or temporarily disabled.
|
||||||
|
- PostgreSQL: Nextcloud 34 requires PostgreSQL >= 14 (the recipe already ships
|
||||||
|
pgautoupgrade 14). PostgreSQL 14 is now the minimum, so plan a bump to a newer
|
||||||
|
PostgreSQL before the next Nextcloud major.
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
Adds an optional Euro-Office integration (compose.eurooffice.yml).
|
||||||
|
|
||||||
|
Euro-Office is the AGPL fork of OnlyOffice that powers "Nextcloud Office" from
|
||||||
|
Nextcloud 34 onwards. This overlay runs the Euro-Office document server inside
|
||||||
|
the stack, so there is no external document server to manage.
|
||||||
|
|
||||||
|
This change is additive: existing installs are unaffected unless you opt in.
|
||||||
|
|
||||||
|
To enable it (`abra app config <app>`):
|
||||||
|
- COMPOSE_FILE="$COMPOSE_FILE:compose.eurooffice.yml"
|
||||||
|
- EUROOFFICE_DOMAIN=eurooffice.example.com
|
||||||
|
- APPS="$APPS eurooffice"
|
||||||
|
- SECRET_EUROOFFICE_JWT_VERSION=v1
|
||||||
|
|
||||||
|
Then:
|
||||||
|
- Create a DNS record for EUROOFFICE_DOMAIN pointing at this host (the browser
|
||||||
|
talks to the document server directly over HTTPS).
|
||||||
|
- `abra app secret generate -a <app>`
|
||||||
|
- `abra app deploy <app>`
|
||||||
|
- `abra app cmd <app> app install_eurooffice`
|
||||||
|
|
||||||
|
Notes:
|
||||||
|
- The document server needs ~4 GB RAM (8 GB recommended for multi-user).
|
||||||
|
- The `ghcr.io/euro-office/documentserver` image currently only publishes a
|
||||||
|
`latest` tag (no semver pinning yet), so it is not tracked by Renovate.
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
Upgrade to latest nextcloud v34.0.2
|
||||||
|
Merge latest origin from coop-cloud/nextcloud:13.1.4
|
||||||
Reference in New Issue
Block a user