Compare commits

..

1 Commits

Author SHA1 Message Date
hey de3dd72f9d add sso configuration instructions 2026-03-30 11:42:28 -04:00
6 changed files with 40 additions and 27 deletions
+33
View File
@@ -27,5 +27,38 @@
* For environments with 2GB or less RAM, run `abra app config <app-name>` and uncomment the `For low-resource machines` config block
* More info: https://hub.docker.com/r/baserow/baserow/#scaling-options
## Enable SSO with Authenitk
This is how to configure your Baserow server to accept logins from your Authenitk SSO provider. You need at least an advanced Baserow plan to use this feature.
### Configure Authenitk
**Create Application and Provider**
* Log in as administrator of your Authentik instance
* Go to https://your-authentik-domain/if/admin/#/core/applications and choose *Create with Provider*
* Follow these steps to configure the provider, if a field isn't specified here, you can keep the default value
* Application Name: baserow -> **Next**
* Choose OAuth2/OIDC -> **Next**
* Set Authorization flow: `default-provider-authorization-implicit-consent (Authorize Application)`
* Copy the **Client ID** and **Client Secret**, you'll need them later
* Add Redirect URI: Strict - https://your-baserow-domain/api/sso/oauth2/callback/2/ -> **Next**
* **Note**: You may need to change this URI based your baserow settings later
* **Next** and **Submit**
### Configure Baserow
**Create Baserow SSO Provider**
* Log in as adminsitrator of your Baserow instance
* Go to https://your-baserow-domain/admin/auth-providers and choose *Add Provider*
* Name: `authentik`
* URL: `https://<your-authentik-domain>/application/o/baserow`
* Fill out Client ID and Secret with the copied values from the Authentik provisioning
* At this point, check the `Callback URL` at the bottom of the page, it should be the same as the Redirect URI earlier
* If it's not go back to Authentik and under https://your-authentik-domain/if/admin/#/core/providers edit the Baserow provider to use the Callback URL provided by Baserow
**Disable non-SSO login (Optional)**
* Still under the `Authentication Providers` page, uncheck the email and password authentication option
* You can still login to your admin instance at https://your-baserow-domain/login?noredirect
For more, see [`docs.coopcloud.tech`](https://docs.coopcloud.tech).
+1 -1
View File
@@ -1 +1 @@
export PG_BACKUP_CONFIG_VERSION=v2
export PG_BACKUP_CONFIG_VERSION=v1
+3 -14
View File
@@ -2,32 +2,21 @@ if [ "$1" == "pre-backup" ]; then
# Remove any existing db dump and then create a new one
rm -rf $DATA_DIR/postgres/postgres-backup
source /baserow/data/.pgpass
PGPASSWORD=$DATABASE_PASSWORD pg_dump -j 2 -h localhost -U baserow baserow --format=directory -f $DATA_DIR/postgres/postgres-backup
PGPASSWORD=$DATABASE_PASSWORD pg_dump -j 8 -h localhost -U baserow baserow --format=directory -f $DATA_DIR/postgres/postgres-backup
exit
fi
if [ "$1" == "post-backup" ]; then
# rm -rf $DATA_DIR/postgres/postgres-backup
rm -rf $DATA_DIR/postgres/postgres-backup
exit
fi
if [ "$1" == "pre-restore" ]; then
pkill -STOP -f "webfrontend"
pkill -STOP -f "celery"
pkill -STOP -f "caddy"
# Disconnect any remaining idle sessions from the 'baserow' database
# This prevents "database is being accessed by other users" errors during pg_restore -c
source /baserow/data/.pgpass
PGPASSWORD=$DATABASE_PASSWORD psql -h localhost -U baserow -d postgres -c "SELECT pg_terminate_backend(pid) FROM pg_stat_activity WHERE datname = 'baserow' AND pid <> pg_backend_pid();"
exit
fi
if [ "$1" == "post-restore" ]; then
source /baserow/data/.pgpass
PGPASSWORD=$DATABASE_PASSWORD pg_restore -j 2 -h localhost -U baserow -d baserow -c $DATA_DIR/postgres/postgres-backup
pkill -CONT -f "webfrontend"
pkill -CONT -f "celery"
pkill -CONT -f "caddy"
PGPASSWORD=$DATABASE_PASSWORD pg_restore -j 8 -h localhost -U baserow -d baserow -c $DATA_DIR/postgres/postgres-backup
exit
fi
+3 -3
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: baserow/baserow:2.3.3
image: baserow/baserow:2.0.5
networks:
- proxy
environment:
@@ -33,7 +33,7 @@ services:
- "backupbot.backup.pre-hook=/backup.sh pre-backup"
- "backupbot.backup.post-hook=/backup.sh post-backup"
- "backupbot.restore.post-hook=/backup.sh post-restore"
- "coop-cloud.${STACK_NAME}.version=2.3.3+2.3.3"
- "coop-cloud.${STACK_NAME}.version=2.0.0+2.0.5"
healthcheck:
test: ["CMD", "./baserow.sh", "backend-cmd", "backend-healthcheck"]
interval: 30s
@@ -52,7 +52,7 @@ volumes:
configs:
backup-postgres:
name: ${STACK_NAME}_backup-postgres_${PG_BACKUP_CONFIG_VERSION}
name: backup-postgres_${PG_BACKUP_CONFIG_VERSION}
file: ./backup-postgres.sh
networks:
-3
View File
@@ -1,3 +0,0 @@
See release notes here ->
https://baserow.io/blog/baserow-2-2-release-notes
-6
View File
@@ -1,6 +0,0 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended"
]
}