Compare commits

...

23 Commits

Author SHA1 Message Date
notplants 3a9e85a114 bump to 0.6.0+v0.12.0
continuous-integration/drone/pr Build is failing
continuous-integration/drone/tag Build is passing
2026-02-18 14:38:22 +00:00
notplants f114ed0bab bump to 0.5.0+v0.12.0
continuous-integration/drone/pr Build is failing
continuous-integration/drone/tag Build is passing
2026-02-18 13:54:20 +00:00
notplants bbc1270356 upgrade to 0.4.0+v0.12.0
continuous-integration/drone/tag Build is passing
2026-02-18 12:03:26 +00:00
notplants ccac11e01c bump to 0.3.0+v0.11.1
continuous-integration/drone/pr Build is failing
continuous-integration/drone/tag Build is passing
2026-02-18 11:47:40 +00:00
notplants 0c861eae16 update to version 0.2.6+v0.11.1
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is failing
2026-01-26 18:34:44 -05:00
notplants e364cdbaf7 update to version 0.2.6+v0.11.1 2026-01-26 18:34:44 -05:00
notplants 2c7387523f automatic wopi configuration
continuous-integration/drone/push Build is failing
2026-01-26 18:18:16 -05:00
notplants a2d8ebb8e5 rename 2026-01-26 17:23:31 -05:00
notplants 4512245d82 working on wopi scheduler 2026-01-26 16:48:49 -05:00
notplants 558a96f202 new release
continuous-integration/drone/tag Build is passing
2026-01-12 10:34:16 -05:00
notplants b1d60e2e4c update version to 0.2.5+v0.10.1
continuous-integration/drone/push Build is failing
2026-01-12 10:30:36 -05:00
notplants 752fa221e7 Update README.md 2026-01-09 15:19:46 +00:00
notplants 6bb122fa71 Merge pull request 'Update README.md' (#1) from notplants-patch-1 into main
Reviewed-on: #1
2026-01-09 15:19:27 +00:00
notplants 68f7c87ea4 Update README.md 2026-01-09 15:08:21 +00:00
notplants bb80b143c6 Update README.md 2026-01-08 23:15:46 +00:00
notplants 958c88a52f Update README.md 2026-01-08 23:15:29 +00:00
notplants a45620633f Update README.md 2026-01-08 23:03:42 +00:00
notplants 7296c4e879 Update README.md 2026-01-08 23:03:22 +00:00
notplants c51b53ce18 polishing 2026-01-08 17:47:14 -05:00
notplants 57201fb2ec working on readme and configs 2026-01-08 17:47:14 -05:00
notplants 84bc02cf2f Update README.md 2026-01-08 21:49:42 +00:00
notplants acd6d57d83 Update README.md 2026-01-08 21:13:31 +00:00
notplants 9b900f2131 working integration with onlyoffice and collabora 2026-01-05 17:09:44 -05:00
9 changed files with 168 additions and 33 deletions
+11
View File
@@ -2,6 +2,8 @@ TYPE=lasuite-drive
DOMAIN=lasuite-drive.example.com
MINIO_DOMAIN="minio.${DOMAIN}"
COLLABORA_DOMAIN="collabora.${DOMAIN}"
ONLY_OFFICE_DOMAIN="onlyoffice.${DOMAIN}"
## Domain aliases
#EXTRA_DOMAINS=', `www.lasuite-docs.example.com`'
@@ -63,3 +65,12 @@ OIDC_AUTH_REQUEST_EXTRA_PARAMS='{"acr_values": "eidas1"}'
LOGGING_LEVEL_HANDLERS_CONSOLE=INFO
LOGGING_LEVEL_LOGGERS_ROOT=INFO
LOGGING_LEVEL_LOGGERS_APP=INFO
##############################################################################
# WOPI SCHEDULING
##############################################################################
# Celery Beat crontab for the WOPI configuration task (default: daily at 3:00 AM)
#WOPI_CONFIGURATION_CRONTAB_MINUTE=0
#WOPI_CONFIGURATION_CRONTAB_HOUR=3
#WOPI_CONFIGURATION_CRONTAB_DAY_OF_MONTH=*
#WOPI_CONFIGURATION_CRONTAB_MONTH_OF_YEAR=*
+70 -7
View File
@@ -17,19 +17,82 @@
## Quick start
Note: this recipe requires two domains. One domain for drive, and one for minio which also needs its own public endpoint (see [https://github.com/suitenumerique/drive/issues/476](https://github.com/suitenumerique/drive/issues/476)]). For example (`drive.yourdomain.tld` and `minio.drive.yourdomain.tld` would work).
### Setting Up Domains
This recipe requires four domains. One domain for drive, and one for minio which also needs its own public endpoint (see [https://github.com/suitenumerique/drive/issues/476](https://github.com/suitenumerique/drive/issues/476)), one domain for collabora, and one domain for onlyoffice. For example (`drive.yourdomain.tld`, `minio.drive.yourdomain.tld`, `collabora.drive.yourdomain.tld`, `onlyoffice.drive.yourdomain.tld`). All of these domains need to have an A record pointing the IP address of your server.
### Installation Steps
* Deploy Single Sign On (see [Authentication](#authentication) below)
* `abra app new lasuite-drive --secrets`
* `abra app config <app-name>`
- make sure to set MINIO_DOMAIN, COLLABORA_DOMAIN, ONLY_OFFICE_DOMAIN to the domains you set up for each.
* `abra app deploy <app-name>`
* `abra app cmd <app-name> backend migrate`
* `abra app cmd <app-name> backend migrate` # creates database tables
* `abra app restart <app-name> minio-createbuckets` (Note: this will appear to fail, but probably worked! Check `abra app logs <app-name> minio-createbuckets`)
For more, see [`docs.coopcloud.tech`](https://docs.coopcloud.tech).
You should then be able to visit the landing page of your app, but not yet to login. To login, you need to deploy and integrate single sign on (described below in the "Configure Authentication" section).
## Authentication
Wopi discovery is supposed to happen automatically, but if collabora/onlyoffice are not connecting, you can try running:
Docs **requires** an OpenID Connect (OIDC) single sign-on provider; we recommend [Authentik](https://git.coopcloud.tech/coop-cloud/authentik) or [Keycloak](https://git.coopcloud.tech/coop-cloud/keycloak), both of which are installable using Co-op Cloud.
* `abra app cmd <app-name> backend trigger_wopi` # connects only office & collabora (if they stop working, try running this again)
TODO: add more documentation on how to configure keycloak so oidc secret is integrated.
## Configure Authentication
lasuite-drive **requires** an OpenID Connect (OIDC) single sign-on provider; deployment has been tested with [Keycloak](https://git.coopcloud.tech/coop-cloud/keycloak), which we recommend, or you could also try [Authentik](https://git.coopcloud.tech/coop-cloud/authentik), both of which are installable using Co-op Cloud.
Instructions for integrating keycloak with drive after deploying it, are below.
* In keycloak, create a realm (save the name of this realm, you will need it later)
* Within that realm, create a client
* during client creation, ensure:
- Standard flow: True
- Direct access grants: True
- Authorization: True
- Client authentication: True
- PKCE method: none
* Within the client tab, for your client, click on "Credentials". Click on the the copy button to copy "Client Secret" so you can insert this into your coop cloud deployment in the next step.
* `abra app secret insert <app-name> oidc_rpcs v2 <yoursecret>`
* `abra app config <app-name>` # set SECRET_OIDC_RPCS_VERSION=v2
* Now create a user for this client within keycloak. Within the Users tab, click "Add User". Any username and password works. Save this info.
You then additionally need to modify the config of drive to point to your keycloak deployment.
* `abra app config <app-name>`
```
OIDC_REALM=<the realm you configured in keycloak>
AUTH_DOMAIN=<the domain of your keycloak instance>
OIDC_RP_CLIENT_ID=<yourkeycloakclientid>
```
then redeploy drive:
`abra app deploy <app-name> --force`
at this point, when you go to your drive url, you shoud then be able to click "login" and login with the username and password for the user you created in keycloak.
you can make additional users in keycloak for this "client" and they will all be able to login to drive and collaborate.
## Configure E-Mail
Using `abra app config <app-name>` you need to set the following for your smtp server:
```
DJANGO_EMAIL_HOST="yourmailserver.com"
DJANGO_EMAIL_PORT=1025
DJANGO_EMAIL_FROM=noreply@example.com
```
You then need to insert the password for your smtp server as a secret:
* `abra app secret insert <app-name> email_pass v2 <youremailpass>`
* `abra app config <app-name>` # set SECRET_EMAIL_PASS_VERSION=v2
Then redeploy the app, and automated e-mail sending should work:
`abra app deploy <app-name> --force`
## Maintainers
coop cloud recipe maintained by @notplants
+7
View File
@@ -11,5 +11,12 @@ set -e
# if not in "env" mode, then execute the original entrypoint and command
if [ ! "$1" = "-e" ]; then
# Run WOPI configuration on startup if enabled (celery worker service only).
# This ensures WOPI clients are configured immediately after each deploy,
# rather than waiting for the next celery-beat cron tick (default: 3 AM).
if [ "${RUN_WOPI_ON_STARTUP:-}" = "true" ]; then
echo "🐳(entrypoint) running WOPI configuration on startup..."
python manage.py trigger_wopi_configuration || echo "⚠ WOPI configuration failed (non-fatal, will retry on schedule)"
fi
exec "$@"
fi
+8 -2
View File
@@ -1,8 +1,8 @@
# Set any config versions here
# Docs: https://docs.coopcloud.tech/maintainers/handbook/#manage-configs
export ABRA_ENTRYPOINT_VERSION=v5
export ABRA_ENTRYPOINT_VERSION=v7
export NGINX_CONF_VERSION=v6
export ONLYOFFICE_CONF_VERSION=v1
export ONLYOFFICE_CONF_VERSION=v2
export PG_BACKUP_VERSION=v3
environment() {
@@ -14,3 +14,9 @@ migrate() {
environment
python manage.py migrate --noinput
}
trigger_wopi() {
environment
python manage.py trigger_wopi_configuration
}
+69 -22
View File
@@ -32,7 +32,7 @@ x-common-env: &common-env
# Media
STORAGES_STATICFILES_BACKEND: django.contrib.staticfiles.storage.StaticFilesStorage
AWS_S3_ENDPOINT_URL: http://minio:9000
AWS_S3_DOMAIN_REPLACE: https://minio.lasuite-drive.cctest.autonomic.zone
AWS_S3_DOMAIN_REPLACE: https://${MINIO_DOMAIN}
# AWS_S3_ACCESS_KEY_ID supplied via secret (this is same MINIO_ROOT_USER)
# AWS_S3_SECRET_ACCESS_KEY supplied via secret (this is same as MINIO_ROOT_PASSWORD)
MEDIA_BASE_URL: https://${DOMAIN}
@@ -51,6 +51,8 @@ x-common-env: &common-env
LOGOUT_REDIRECT_URL:
OIDC_REDIRECT_ALLOWED_HOSTS:
OIDC_AUTH_REQUEST_EXTRA_PARAMS:
# REDIS
REDIS_URL: redis://${STACK_NAME}_redis:6379/0
# AI (Fixme: remove?)
AI_FEATURE_ENABLED: "false"
AI_BASE_URL: https://openaiendpoint.com
@@ -61,9 +63,14 @@ x-common-env: &common-env
# WOPI
WOPI_CLIENTS: "collabora,onlyoffice"
WOPI_COLLABORA_DISCOVERY_URL: "https://collabora.lasuite-drive.cctest.autonomic.zone/hosting/discovery"
WOPI_ONLYOFFICE_DISCOVERY_URL: "http://onlyoffice/hosting/discovery"
WOPI_SRC_BASE_URL: "http://backend:8000"
WOPI_COLLABORA_DISCOVERY_URL: "https://${COLLABORA_DOMAIN}/hosting/discovery"
WOPI_ONLYOFFICE_DISCOVERY_URL: "https://${ONLY_OFFICE_DOMAIN}/hosting/discovery"
WOPI_SRC_BASE_URL: "https://${DOMAIN}"
# WOPI scheduling (Celery Beat crontab for WOPI configuration task)
WOPI_CONFIGURATION_CRONTAB_MINUTE: ${WOPI_CONFIGURATION_CRONTAB_MINUTE:-0}
WOPI_CONFIGURATION_CRONTAB_HOUR: ${WOPI_CONFIGURATION_CRONTAB_HOUR:-3}
WOPI_CONFIGURATION_CRONTAB_DAY_OF_MONTH: ${WOPI_CONFIGURATION_CRONTAB_DAY_OF_MONTH:-*}
WOPI_CONFIGURATION_CRONTAB_MONTH_OF_YEAR: ${WOPI_CONFIGURATION_CRONTAB_MONTH_OF_YEAR:-*}
x-postgres-env: &postgres-env
# Postgresql db container configuration
@@ -85,14 +92,14 @@ services:
app:
user: "${DOCKER_USER:-1000}"
image: lasuite/drive-frontend:v0.10.1
image: lasuite/drive-frontend:v0.12.0
networks:
- backend
deploy:
labels:
- "traefik.enable=false"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
- "coop-cloud.${STACK_NAME}.version=0.2.4+v0.10.1"
- "coop-cloud.${STACK_NAME}.version=0.6.0+v0.12.0"
environment:
<<: [ *common-env ]
healthcheck:
@@ -106,8 +113,7 @@ services:
backend:
user: ${DOCKER_USER:-1000}
# image: lasuite/drive-backend:v0.10.1
image: lasuite/drive-backend:main
image: lasuite/drive-backend:v0.12.0
command: [ "gunicorn", "-c", "/usr/local/etc/gunicorn/drive.py", "drive.wsgi:application" ]
entrypoint: [ "/abra-entrypoint.sh", "/usr/local/bin/entrypoint" ]
environment:
@@ -131,11 +137,33 @@ services:
celery:
user: ${DOCKER_USER:-1000}
image: lasuite/drive-backend:v0.10.1
image: lasuite/drive-backend:v0.12.0
networks:
- backend
command: [ "celery", "-A", "drive.celery_app", "worker", "-l", "INFO" ]
entrypoint: ["/abra-entrypoint.sh", "/usr/local/bin/entrypoint"]
environment:
<<: [*common-env, *postgres-env]
RUN_WOPI_ON_STARTUP: "true"
configs:
- source: abra_entrypoint
target: /abra-entrypoint.sh
mode: 0555
secrets:
- django_sk
- django_sp
- oidc_rpcs
- minio_rp
- postgres_p
- email_pass
celery-beat:
user: ${DOCKER_USER:-1000}
image: lasuite/drive-backend:v0.12.0
networks:
- backend
command: [ "celery", "-A", "drive.celery_app", "beat", "-l", "INFO", "--schedule", "/tmp/celerybeat-schedule" ]
entrypoint: ["/abra-entrypoint.sh", "/usr/local/bin/entrypoint"]
environment:
<<: [*common-env, *postgres-env]
configs:
@@ -151,17 +179,17 @@ services:
- email_pass
db:
image: postgres:16
image: pgautoupgrade/pgautoupgrade:18-debian
networks:
- backend
healthcheck:
test: ["CMD", "pg_isready", "-q", "-U", "docs", "-d", "docs"]
test: ["CMD", "pg_isready", "-q", "-U", "drive", "-d", "drive"]
interval: 1s
timeout: 2s
retries: 300
environment:
<<: *postgres-env
PGDATA: var/lib/postgresql/data/pgdata
PGDATA: /var/lib/postgresql/data/pgdata
volumes:
- postgres:/var/lib/postgresql/data/pgdata
deploy:
@@ -178,7 +206,7 @@ services:
- postgres_p
redis:
image: redis:5
image: redis:8
networks:
- backend
@@ -259,19 +287,16 @@ services:
networks:
- backend
- proxy
# ports:
# - "9980:9980"
environment:
- extra_params=--o:ssl.enable=false
- extra_params=--o:ssl.enable=false --o:ssl.termination=true
- username=drive
- password=password
- server_name=collabora.lasuite-drive.cctest.autonomic.zone
- aliasgroup1=backend:8000
- server_name=${COLLABORA_DOMAIN}
deploy:
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.routers.${STACK_NAME}_collabora.rule=Host(`collabora.lasuite-drive.cctest.autonomic.zone`)"
- "traefik.http.routers.${STACK_NAME}_collabora.rule=Host(`${COLLABORA_DOMAIN}`)"
- "traefik.http.routers.${STACK_NAME}_collabora.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}_collabora.tls=true"
- "traefik.http.routers.${STACK_NAME}_collabora.tls.certresolver=${LETS_ENCRYPT_ENV}"
@@ -284,7 +309,6 @@ services:
- "traefik.http.middlewares.${STACK_NAME}_collabora-cors.headers.addVaryHeader=true"
- "traefik.http.routers.${STACK_NAME}_collabora.middlewares=${STACK_NAME}_collabora-cors"
onlyoffice:
image: onlyoffice/documentserver-de:9.2
# healthcheck:
@@ -296,14 +320,36 @@ services:
environment:
TZ: "Europe/Berlin"
USE_UNAUTHORIZED_STORAGE: "true"
ONLY_OFFICE_DOMAIN: ${ONLY_OFFICE_DOMAIN} # need to make variable available for golang template
networks:
- backend
- proxy
configs:
- source: onlyoffice_conf
target: /etc/onlyoffice/documentserver/local-production-linux.json
deploy:
labels:
- "traefik.enable=true"
- "traefik.docker.network=proxy"
- "traefik.http.routers.${STACK_NAME}_onlyoffice.rule=Host(`${ONLY_OFFICE_DOMAIN}`)"
- "traefik.http.routers.${STACK_NAME}_onlyoffice.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}_onlyoffice.tls=true"
- "traefik.http.routers.${STACK_NAME}_onlyoffice.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.http.services.${STACK_NAME}_onlyoffice.loadbalancer.server.port=80"
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlAllowOriginList=https://${DOMAIN}"
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlAllowMethods=GET,POST,PUT,DELETE,OPTIONS"
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlAllowHeaders=*"
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlExposeHeaders=ETag,Content-Length"
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlMaxAge=600"
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.addVaryHeader=true"
- "traefik.http.routers.${STACK_NAME}_onlyoffice.middlewares=${STACK_NAME}_onlyoffice-cors"
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-fwdproto.headers.customRequestHeaders.X-Forwarded-Proto=https"
- "traefik.http.routers.${STACK_NAME}_onlyoffice.middlewares=${STACK_NAME}_onlyoffice-fwdproto"
web:
image: nginx:1.25
image: nginx:1.29
configs:
- source: nginx_conf
target: /etc/nginx/conf.d/default.conf
@@ -347,7 +393,8 @@ configs:
file: abra-entrypoint.sh
onlyoffice_conf:
name: ${STACK_NAME}_onlyoffice_conf_${ONLYOFFICE_CONF_VERSION}
file: onlyoffice-config.json
file: onlyoffice-config.json.tmpl
template_driver: golang
secrets:
django_sk:
@@ -1,7 +1,7 @@
{
"wopi": {
"enable": true,
"host": "http://localhost:9981",
"host": "https://{{ env "ONLY_OFFICE_DOMAIN" }}",
"pdfView": [],
"pdfEdit": [],
"forms": [],
+1
View File
@@ -0,0 +1 @@
this first release is at version 0.2.5 becuase we started off by forking the docs recipe which was at version 0.2.4
+1
View File
@@ -0,0 +1 @@
Switched the database image from postgres:16 to pgautoupgrade/pgautoupgrade:18-debian. This enables automatic PostgreSQL major version upgrades. No action required from the operator — the upgrade from PostgreSQL 16 to 18 is handled automatically by the pgautoupgrade image on first start.
-1
View File
@@ -1 +0,0 @@
- should collabora and onlyoffice be part of the recipe ... or linked ?