Compare commits
35 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 7146f3e8be | |||
| 306914f9d8 | |||
| c408893d5f | |||
| 196d20a92e | |||
| 8ec47fa554 | |||
| e6ebe275a3 | |||
| 415bb3d9a9 | |||
| 7bc5a4bcca | |||
| d838d62103 | |||
| af25d3acc0 | |||
| 223a242f70 | |||
| 6ac2a5c838 | |||
| 3a9e85a114 | |||
| f114ed0bab | |||
| bbc1270356 | |||
| ccac11e01c | |||
| 0c861eae16 | |||
| e364cdbaf7 | |||
| 2c7387523f | |||
| a2d8ebb8e5 | |||
| 4512245d82 | |||
| 558a96f202 | |||
| b1d60e2e4c | |||
| 752fa221e7 | |||
| 6bb122fa71 | |||
| 68f7c87ea4 | |||
| bb80b143c6 | |||
| 958c88a52f | |||
| a45620633f | |||
| 7296c4e879 | |||
| c51b53ce18 | |||
| 57201fb2ec | |||
| 84bc02cf2f | |||
| acd6d57d83 | |||
| 9b900f2131 |
+20
@@ -2,6 +2,8 @@ TYPE=lasuite-drive
|
||||
|
||||
DOMAIN=lasuite-drive.example.com
|
||||
MINIO_DOMAIN="minio.${DOMAIN}"
|
||||
COLLABORA_DOMAIN="collabora.${DOMAIN}"
|
||||
ONLY_OFFICE_DOMAIN="onlyoffice.${DOMAIN}"
|
||||
|
||||
## Domain aliases
|
||||
#EXTRA_DOMAINS=', `www.lasuite-docs.example.com`'
|
||||
@@ -26,6 +28,8 @@ SECRET_MINIO_RU_VERSION=v1
|
||||
SECRET_POSTGRES_P_VERSION=v1
|
||||
# DJANGO_HOST_EMAIL_PASSWORD
|
||||
SECRET_EMAIL_PASS_VERSION=v1
|
||||
# COLLABORA_ADMIN_PASSWORD
|
||||
SECRET_COLLABORA_P_VERSION=v1
|
||||
|
||||
##############################################################################
|
||||
# EMAIL
|
||||
@@ -63,3 +67,19 @@ OIDC_AUTH_REQUEST_EXTRA_PARAMS='{"acr_values": "eidas1"}'
|
||||
LOGGING_LEVEL_HANDLERS_CONSOLE=INFO
|
||||
LOGGING_LEVEL_LOGGERS_ROOT=INFO
|
||||
LOGGING_LEVEL_LOGGERS_APP=INFO
|
||||
|
||||
##############################################################################
|
||||
# COLLABORA ADMIN PANEL
|
||||
##############################################################################
|
||||
# Username for the Collabora admin panel (https://COLLABORA_DOMAIN/browser/dist/admin/admin.html)
|
||||
# Password is managed via Docker secret 'collabora_p'
|
||||
#COLLABORA_ADMIN_USERNAME=admin
|
||||
|
||||
##############################################################################
|
||||
# WOPI SCHEDULING
|
||||
##############################################################################
|
||||
# Celery Beat crontab for the WOPI configuration task (default: daily at 3:00 AM)
|
||||
#WOPI_CONFIGURATION_CRONTAB_MINUTE=0
|
||||
#WOPI_CONFIGURATION_CRONTAB_HOUR=3
|
||||
#WOPI_CONFIGURATION_CRONTAB_DAY_OF_MONTH=*
|
||||
#WOPI_CONFIGURATION_CRONTAB_MONTH_OF_YEAR=*
|
||||
|
||||
@@ -7,29 +7,92 @@
|
||||
* **Category**: Apps
|
||||
* **Status**: 2
|
||||
* **Image**: [`lasuite/drive`](https://hub.docker.com/r/lasuite/drive), 4, upstream
|
||||
* **Healthcheck**: No
|
||||
* **Backups**: No
|
||||
* **Email**: 3
|
||||
* **Healthcheck**: Yes
|
||||
* **Backups**: Yes
|
||||
* **Email**: Yes
|
||||
* **Tests**: No
|
||||
* **SSO**: 3
|
||||
* **SSO**: Yes
|
||||
|
||||
<!-- endmetadata -->
|
||||
|
||||
## Quick start
|
||||
|
||||
Note: this recipe requires two domains. One domain for drive, and one for minio which also needs its own public endpoint (see [https://github.com/suitenumerique/drive/issues/476](https://github.com/suitenumerique/drive/issues/476)]). For example (`drive.yourdomain.tld` and `minio.drive.yourdomain.tld` would work).
|
||||
### Setting Up Domains
|
||||
|
||||
This recipe requires four domains. One domain for drive, and one for minio which also needs its own public endpoint (see [https://github.com/suitenumerique/drive/issues/476](https://github.com/suitenumerique/drive/issues/476)), one domain for collabora, and one domain for onlyoffice. For example (`drive.yourdomain.tld`, `minio.drive.yourdomain.tld`, `collabora.drive.yourdomain.tld`, `onlyoffice.drive.yourdomain.tld`). All of these domains need to have an A record pointing the IP address of your server.
|
||||
|
||||
### Installation Steps
|
||||
|
||||
* Deploy Single Sign On (see [Authentication](#authentication) below)
|
||||
* `abra app new lasuite-drive --secrets`
|
||||
* `abra app config <app-name>`
|
||||
- make sure to set MINIO_DOMAIN, COLLABORA_DOMAIN, ONLY_OFFICE_DOMAIN to the domains you set up for each.
|
||||
* `abra app deploy <app-name>`
|
||||
* `abra app cmd <app-name> backend migrate`
|
||||
* `abra app cmd <app-name> backend migrate` # creates database tables
|
||||
* `abra app restart <app-name> minio-createbuckets` (Note: this will appear to fail, but probably worked! Check `abra app logs <app-name> minio-createbuckets`)
|
||||
|
||||
For more, see [`docs.coopcloud.tech`](https://docs.coopcloud.tech).
|
||||
You should then be able to visit the landing page of your app, but not yet to login. To login, you need to deploy and integrate single sign on (described below in the "Configure Authentication" section).
|
||||
|
||||
## Authentication
|
||||
Wopi discovery is supposed to happen automatically, but if collabora/onlyoffice are not connecting, you can try running:
|
||||
|
||||
Docs **requires** an OpenID Connect (OIDC) single sign-on provider; we recommend [Authentik](https://git.coopcloud.tech/coop-cloud/authentik) or [Keycloak](https://git.coopcloud.tech/coop-cloud/keycloak), both of which are installable using Co-op Cloud.
|
||||
* `abra app cmd <app-name> backend trigger_wopi` # connects only office & collabora (if they stop working, try running this again)
|
||||
|
||||
TODO: add more documentation on how to configure keycloak so oidc secret is integrated.
|
||||
|
||||
## Configure Authentication
|
||||
|
||||
lasuite-drive **requires** an OpenID Connect (OIDC) single sign-on provider; deployment has been tested with [Keycloak](https://git.coopcloud.tech/coop-cloud/keycloak), which we recommend, or you could also try [Authentik](https://git.coopcloud.tech/coop-cloud/authentik), both of which are installable using Co-op Cloud.
|
||||
|
||||
Instructions for integrating keycloak with drive after deploying it, are below.
|
||||
|
||||
* In keycloak, create a realm (save the name of this realm, you will need it later)
|
||||
* Within that realm, create a client
|
||||
* during client creation, ensure:
|
||||
- Standard flow: True
|
||||
- Direct access grants: True
|
||||
- Authorization: True
|
||||
- Client authentication: True
|
||||
- PKCE method: none
|
||||
* Within the client tab, for your client, click on "Credentials". Click on the the copy button to copy "Client Secret" so you can insert this into your coop cloud deployment in the next step.
|
||||
* `abra app secret insert <app-name> oidc_rpcs v2 <yoursecret>`
|
||||
* `abra app config <app-name>` # set SECRET_OIDC_RPCS_VERSION=v2
|
||||
|
||||
* Now create a user for this client within keycloak. Within the Users tab, click "Add User". Any username and password works. Save this info.
|
||||
|
||||
You then additionally need to modify the config of drive to point to your keycloak deployment.
|
||||
|
||||
* `abra app config <app-name>`
|
||||
```
|
||||
OIDC_REALM=<the realm you configured in keycloak>
|
||||
AUTH_DOMAIN=<the domain of your keycloak instance>
|
||||
OIDC_RP_CLIENT_ID=<yourkeycloakclientid>
|
||||
```
|
||||
|
||||
then redeploy drive:
|
||||
`abra app deploy <app-name> --force`
|
||||
|
||||
at this point, when you go to your drive url, you should then be able to click "login" and login with the username and password for the user you created in keycloak.
|
||||
|
||||
you can make additional users in keycloak for this "client" and they will all be able to login to drive and collaborate.
|
||||
|
||||
## Configure E-Mail
|
||||
|
||||
Using `abra app config <app-name>` you need to set the following for your smtp server:
|
||||
|
||||
```
|
||||
DJANGO_EMAIL_HOST="yourmailserver.com"
|
||||
DJANGO_EMAIL_PORT=1025
|
||||
DJANGO_EMAIL_FROM=noreply@example.com
|
||||
```
|
||||
|
||||
You then need to insert the password for your smtp server as a secret:
|
||||
|
||||
* `abra app secret insert <app-name> email_pass v2 <youremailpass>`
|
||||
* `abra app config <app-name>` # set SECRET_EMAIL_PASS_VERSION=v2
|
||||
|
||||
Then redeploy the app, and automated e-mail sending should work:
|
||||
|
||||
`abra app deploy <app-name> --force`
|
||||
|
||||
|
||||
## Maintainers
|
||||
|
||||
coop cloud recipe maintained by @notplants
|
||||
@@ -11,5 +11,12 @@ set -e
|
||||
|
||||
# if not in "env" mode, then execute the original entrypoint and command
|
||||
if [ ! "$1" = "-e" ]; then
|
||||
# Run WOPI configuration on startup if enabled (celery worker service only).
|
||||
# This ensures WOPI clients are configured immediately after each deploy,
|
||||
# rather than waiting for the next celery-beat cron tick (default: 3 AM).
|
||||
if [ "${RUN_WOPI_ON_STARTUP:-}" = "true" ]; then
|
||||
echo "🐳(entrypoint) running WOPI configuration on startup..."
|
||||
python manage.py trigger_wopi_configuration || echo "⚠ WOPI configuration failed (non-fatal, will retry on schedule)"
|
||||
fi
|
||||
exec "$@"
|
||||
fi
|
||||
@@ -1,8 +1,8 @@
|
||||
# Set any config versions here
|
||||
# Docs: https://docs.coopcloud.tech/maintainers/handbook/#manage-configs
|
||||
export ABRA_ENTRYPOINT_VERSION=v5
|
||||
export ABRA_ENTRYPOINT_VERSION=v11
|
||||
export NGINX_CONF_VERSION=v6
|
||||
export ONLYOFFICE_CONF_VERSION=v1
|
||||
export ONLYOFFICE_CONF_VERSION=v2
|
||||
export PG_BACKUP_VERSION=v3
|
||||
|
||||
environment() {
|
||||
@@ -14,3 +14,9 @@ migrate() {
|
||||
environment
|
||||
python manage.py migrate --noinput
|
||||
}
|
||||
|
||||
trigger_wopi() {
|
||||
environment
|
||||
python manage.py trigger_wopi_configuration
|
||||
}
|
||||
|
||||
|
||||
+99
-39
@@ -32,7 +32,7 @@ x-common-env: &common-env
|
||||
# Media
|
||||
STORAGES_STATICFILES_BACKEND: django.contrib.staticfiles.storage.StaticFilesStorage
|
||||
AWS_S3_ENDPOINT_URL: http://minio:9000
|
||||
AWS_S3_DOMAIN_REPLACE: https://minio.lasuite-drive.cctest.autonomic.zone
|
||||
AWS_S3_DOMAIN_REPLACE: https://${MINIO_DOMAIN}
|
||||
# AWS_S3_ACCESS_KEY_ID supplied via secret (this is same MINIO_ROOT_USER)
|
||||
# AWS_S3_SECRET_ACCESS_KEY supplied via secret (this is same as MINIO_ROOT_PASSWORD)
|
||||
MEDIA_BASE_URL: https://${DOMAIN}
|
||||
@@ -51,6 +51,8 @@ x-common-env: &common-env
|
||||
LOGOUT_REDIRECT_URL:
|
||||
OIDC_REDIRECT_ALLOWED_HOSTS:
|
||||
OIDC_AUTH_REQUEST_EXTRA_PARAMS:
|
||||
# REDIS
|
||||
REDIS_URL: redis://${STACK_NAME}_redis:6379/0
|
||||
# AI (Fixme: remove?)
|
||||
AI_FEATURE_ENABLED: "false"
|
||||
AI_BASE_URL: https://openaiendpoint.com
|
||||
@@ -61,9 +63,14 @@ x-common-env: &common-env
|
||||
|
||||
# WOPI
|
||||
WOPI_CLIENTS: "collabora,onlyoffice"
|
||||
WOPI_COLLABORA_DISCOVERY_URL: "https://collabora.lasuite-drive.cctest.autonomic.zone/hosting/discovery"
|
||||
WOPI_ONLYOFFICE_DISCOVERY_URL: "http://onlyoffice/hosting/discovery"
|
||||
WOPI_SRC_BASE_URL: "http://backend:8000"
|
||||
WOPI_COLLABORA_DISCOVERY_URL: "https://${COLLABORA_DOMAIN}/hosting/discovery"
|
||||
WOPI_ONLYOFFICE_DISCOVERY_URL: "https://${ONLY_OFFICE_DOMAIN}/hosting/discovery"
|
||||
WOPI_SRC_BASE_URL: "https://${DOMAIN}"
|
||||
# WOPI scheduling (Celery Beat crontab for WOPI configuration task)
|
||||
WOPI_CONFIGURATION_CRONTAB_MINUTE: ${WOPI_CONFIGURATION_CRONTAB_MINUTE:-0}
|
||||
WOPI_CONFIGURATION_CRONTAB_HOUR: ${WOPI_CONFIGURATION_CRONTAB_HOUR:-3}
|
||||
WOPI_CONFIGURATION_CRONTAB_DAY_OF_MONTH: ${WOPI_CONFIGURATION_CRONTAB_DAY_OF_MONTH:-*}
|
||||
WOPI_CONFIGURATION_CRONTAB_MONTH_OF_YEAR: ${WOPI_CONFIGURATION_CRONTAB_MONTH_OF_YEAR:-*}
|
||||
|
||||
x-postgres-env: &postgres-env
|
||||
# Postgresql db container configuration
|
||||
@@ -85,14 +92,14 @@ services:
|
||||
|
||||
app:
|
||||
user: "${DOCKER_USER:-1000}"
|
||||
image: lasuite/drive-frontend:v0.10.1
|
||||
image: lasuite/drive-frontend:v0.12.0
|
||||
networks:
|
||||
- backend
|
||||
deploy:
|
||||
labels:
|
||||
- "traefik.enable=false"
|
||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
|
||||
- "coop-cloud.${STACK_NAME}.version=0.2.4+v0.10.1"
|
||||
- "coop-cloud.${STACK_NAME}.version=0.7.0+v0.12.0"
|
||||
environment:
|
||||
<<: [ *common-env ]
|
||||
healthcheck:
|
||||
@@ -106,8 +113,7 @@ services:
|
||||
|
||||
backend:
|
||||
user: ${DOCKER_USER:-1000}
|
||||
# image: lasuite/drive-backend:v0.10.1
|
||||
image: lasuite/drive-backend:main
|
||||
image: lasuite/drive-backend:v0.12.0
|
||||
command: [ "gunicorn", "-c", "/usr/local/etc/gunicorn/drive.py", "drive.wsgi:application" ]
|
||||
entrypoint: [ "/abra-entrypoint.sh", "/usr/local/bin/entrypoint" ]
|
||||
environment:
|
||||
@@ -131,11 +137,33 @@ services:
|
||||
|
||||
celery:
|
||||
user: ${DOCKER_USER:-1000}
|
||||
image: lasuite/drive-backend:v0.10.1
|
||||
image: lasuite/drive-backend:v0.12.0
|
||||
networks:
|
||||
- backend
|
||||
command: [ "celery", "-A", "drive.celery_app", "worker", "-l", "INFO" ]
|
||||
entrypoint: ["/abra-entrypoint.sh", "/usr/local/bin/entrypoint"]
|
||||
environment:
|
||||
<<: [*common-env, *postgres-env]
|
||||
RUN_WOPI_ON_STARTUP: "true"
|
||||
configs:
|
||||
- source: abra_entrypoint
|
||||
target: /abra-entrypoint.sh
|
||||
mode: 0555
|
||||
secrets:
|
||||
- django_sk
|
||||
- django_sp
|
||||
- oidc_rpcs
|
||||
- minio_rp
|
||||
- postgres_p
|
||||
- email_pass
|
||||
|
||||
celery-beat:
|
||||
user: ${DOCKER_USER:-1000}
|
||||
image: lasuite/drive-backend:v0.12.0
|
||||
networks:
|
||||
- backend
|
||||
command: [ "celery", "-A", "drive.celery_app", "beat", "-l", "INFO", "--schedule", "/tmp/celerybeat-schedule" ]
|
||||
entrypoint: ["/abra-entrypoint.sh", "/usr/local/bin/entrypoint"]
|
||||
environment:
|
||||
<<: [*common-env, *postgres-env]
|
||||
configs:
|
||||
@@ -151,17 +179,17 @@ services:
|
||||
- email_pass
|
||||
|
||||
db:
|
||||
image: postgres:16
|
||||
image: pgautoupgrade/pgautoupgrade:18-debian
|
||||
networks:
|
||||
- backend
|
||||
healthcheck:
|
||||
test: ["CMD", "pg_isready", "-q", "-U", "docs", "-d", "docs"]
|
||||
test: ["CMD", "pg_isready", "-q", "-U", "drive", "-d", "drive"]
|
||||
interval: 1s
|
||||
timeout: 2s
|
||||
retries: 300
|
||||
environment:
|
||||
<<: *postgres-env
|
||||
PGDATA: var/lib/postgresql/data/pgdata
|
||||
PGDATA: /var/lib/postgresql/data/pgdata
|
||||
volumes:
|
||||
- postgres:/var/lib/postgresql/data/pgdata
|
||||
deploy:
|
||||
@@ -178,9 +206,14 @@ services:
|
||||
- postgres_p
|
||||
|
||||
redis:
|
||||
image: redis:5
|
||||
image: redis:8
|
||||
healthcheck:
|
||||
test: ["CMD", "redis-cli", "ping"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
networks:
|
||||
- backend
|
||||
- backend
|
||||
|
||||
mailcatcher:
|
||||
image: sj26/mailcatcher:v0.10.0
|
||||
@@ -249,29 +282,31 @@ services:
|
||||
- "traefik.http.routers.${STACK_NAME}_minio.middlewares=${STACK_NAME}_minio-cors"
|
||||
|
||||
collabora:
|
||||
image: collabora/code:latest
|
||||
# healthcheck:
|
||||
# test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ]
|
||||
# interval: 30s
|
||||
# retries: 5
|
||||
# start_period: 60s
|
||||
# timeout: 10s
|
||||
image: collabora/code:25.04.9.1.1
|
||||
entrypoint: >
|
||||
sh -c "
|
||||
export password=\"$$(cat /run/secrets/collabora_p)\" &&
|
||||
exec /start-collabora-online.sh"
|
||||
healthcheck:
|
||||
test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ]
|
||||
interval: 30s
|
||||
retries: 5
|
||||
start_period: 60s
|
||||
timeout: 10s
|
||||
networks:
|
||||
- backend
|
||||
- proxy
|
||||
# ports:
|
||||
# - "9980:9980"
|
||||
environment:
|
||||
- extra_params=--o:ssl.enable=false
|
||||
- username=drive
|
||||
- password=password
|
||||
- server_name=collabora.lasuite-drive.cctest.autonomic.zone
|
||||
- aliasgroup1=backend:8000
|
||||
- extra_params=--o:ssl.enable=false --o:ssl.termination=true
|
||||
- username=${COLLABORA_ADMIN_USERNAME:-admin}
|
||||
- server_name=${COLLABORA_DOMAIN}
|
||||
secrets:
|
||||
- collabora_p
|
||||
deploy:
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.routers.${STACK_NAME}_collabora.rule=Host(`collabora.lasuite-drive.cctest.autonomic.zone`)"
|
||||
- "traefik.http.routers.${STACK_NAME}_collabora.rule=Host(`${COLLABORA_DOMAIN}`)"
|
||||
- "traefik.http.routers.${STACK_NAME}_collabora.entrypoints=web-secure"
|
||||
- "traefik.http.routers.${STACK_NAME}_collabora.tls=true"
|
||||
- "traefik.http.routers.${STACK_NAME}_collabora.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||
@@ -284,26 +319,47 @@ services:
|
||||
- "traefik.http.middlewares.${STACK_NAME}_collabora-cors.headers.addVaryHeader=true"
|
||||
- "traefik.http.routers.${STACK_NAME}_collabora.middlewares=${STACK_NAME}_collabora-cors"
|
||||
|
||||
|
||||
onlyoffice:
|
||||
image: onlyoffice/documentserver-de:9.2
|
||||
# healthcheck:
|
||||
# test: [ "CMD", "curl", "-f", "http://localhost/hosting/discovery" ]
|
||||
# interval: 30s
|
||||
# retries: 5
|
||||
# start_period: 60s
|
||||
# timeout: 10s
|
||||
healthcheck:
|
||||
test: [ "CMD", "curl", "-f", "http://localhost/hosting/discovery" ]
|
||||
interval: 30s
|
||||
retries: 5
|
||||
start_period: 60s
|
||||
timeout: 10s
|
||||
environment:
|
||||
TZ: "Europe/Berlin"
|
||||
USE_UNAUTHORIZED_STORAGE: "true"
|
||||
ONLY_OFFICE_DOMAIN: ${ONLY_OFFICE_DOMAIN} # need to make variable available for golang template
|
||||
networks:
|
||||
- backend
|
||||
- proxy
|
||||
configs:
|
||||
- source: onlyoffice_conf
|
||||
target: /etc/onlyoffice/documentserver/local-production-linux.json
|
||||
|
||||
deploy:
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=proxy"
|
||||
- "traefik.http.routers.${STACK_NAME}_onlyoffice.rule=Host(`${ONLY_OFFICE_DOMAIN}`)"
|
||||
- "traefik.http.routers.${STACK_NAME}_onlyoffice.entrypoints=web-secure"
|
||||
- "traefik.http.routers.${STACK_NAME}_onlyoffice.tls=true"
|
||||
- "traefik.http.routers.${STACK_NAME}_onlyoffice.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||
- "traefik.http.services.${STACK_NAME}_onlyoffice.loadbalancer.server.port=80"
|
||||
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlAllowOriginList=https://${DOMAIN}"
|
||||
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlAllowMethods=GET,POST,PUT,DELETE,OPTIONS"
|
||||
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlAllowHeaders=*"
|
||||
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlExposeHeaders=ETag,Content-Length"
|
||||
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.accessControlMaxAge=600"
|
||||
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-cors.headers.addVaryHeader=true"
|
||||
- "traefik.http.routers.${STACK_NAME}_onlyoffice.middlewares=${STACK_NAME}_onlyoffice-cors"
|
||||
- "traefik.http.middlewares.${STACK_NAME}_onlyoffice-fwdproto.headers.customRequestHeaders.X-Forwarded-Proto=https"
|
||||
- "traefik.http.routers.${STACK_NAME}_onlyoffice.middlewares=${STACK_NAME}_onlyoffice-fwdproto"
|
||||
|
||||
|
||||
web:
|
||||
image: nginx:1.25
|
||||
image: nginx:1.29
|
||||
configs:
|
||||
- source: nginx_conf
|
||||
target: /etc/nginx/conf.d/default.conf
|
||||
@@ -347,7 +403,8 @@ configs:
|
||||
file: abra-entrypoint.sh
|
||||
onlyoffice_conf:
|
||||
name: ${STACK_NAME}_onlyoffice_conf_${ONLYOFFICE_CONF_VERSION}
|
||||
file: onlyoffice-config.json
|
||||
file: onlyoffice-config.json.tmpl
|
||||
template_driver: golang
|
||||
|
||||
secrets:
|
||||
django_sk:
|
||||
@@ -367,7 +424,10 @@ secrets:
|
||||
name: ${STACK_NAME}_minio_rp_${SECRET_MINIO_RP_VERSION}
|
||||
minio_ru:
|
||||
external: true
|
||||
name: ${STACK_NAME}_minio_ru_${SECRET_MINIO_RP_VERSION}
|
||||
name: ${STACK_NAME}_minio_ru_${SECRET_MINIO_RU_VERSION}
|
||||
collabora_p:
|
||||
external: true
|
||||
name: ${STACK_NAME}_collabora_p_${SECRET_COLLABORA_P_VERSION}
|
||||
email_pass:
|
||||
external: true
|
||||
name: ${STACK_NAME}_email_pass_${SECRET_EMAIL_PASS_VERSION}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"wopi": {
|
||||
"enable": true,
|
||||
"host": "http://localhost:9981",
|
||||
"host": "https://{{ env "ONLY_OFFICE_DOMAIN" }}",
|
||||
"pdfView": [],
|
||||
"pdfEdit": [],
|
||||
"forms": [],
|
||||
@@ -0,0 +1 @@
|
||||
this first release is at version 0.2.5 becuase we started off by forking the docs recipe which was at version 0.2.4
|
||||
@@ -0,0 +1 @@
|
||||
Switched the database image from postgres:16 to pgautoupgrade/pgautoupgrade:18-debian. This enables automatic PostgreSQL major version upgrades. No action required from the operator — the upgrade from PostgreSQL 16 to 18 is handled automatically by the pgautoupgrade image on first start.
|
||||
@@ -0,0 +1,9 @@
|
||||
**Breaking change:** The Collabora admin panel password is now a secret (`collabora_p`).
|
||||
|
||||
After upgrading, you must generate the new secret for collabora to work:
|
||||
|
||||
```
|
||||
abra app secret generate <app-domain> collabora_p v1
|
||||
abra app config <app-domain> # set SECRET_COLLABORA_P_VERSION=v1
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user