Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d2560c9304
|
+35
@@ -1,5 +1,40 @@
|
|||||||
---
|
---
|
||||||
kind: pipeline
|
kind: pipeline
|
||||||
|
name: deploy to swarm-test.autonomic.zone
|
||||||
|
steps:
|
||||||
|
- name: deployment
|
||||||
|
image: git.coopcloud.tech/coop-cloud/stack-ssh-deploy:latest
|
||||||
|
settings:
|
||||||
|
host: swarm-test.autonomic.zone
|
||||||
|
stack: nextcloud
|
||||||
|
generate_secrets: true
|
||||||
|
purge: true
|
||||||
|
deploy_key:
|
||||||
|
from_secret: drone_ssh_swarm_test
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
environment:
|
||||||
|
DOMAIN: nextcloud.swarm-test.autonomic.zone
|
||||||
|
STACK_NAME: nextcloud
|
||||||
|
LETS_ENCRYPT_ENV: production
|
||||||
|
ADMIN_USER: foobar
|
||||||
|
FPM_TUNE_VERSION: v1
|
||||||
|
NGINX_CONF_VERSION: v1
|
||||||
|
MY_CNF_VERSION: v1
|
||||||
|
ENTRYPOINT_VERSION: v1
|
||||||
|
CRONTAB_VERSION: v1
|
||||||
|
PG_BACKUP_VERSION: v2
|
||||||
|
SECRET_DB_PASSWORD_VERSION: v1
|
||||||
|
SECRET_DB_ROOT_PASSWORD_VERSION: v1
|
||||||
|
SECRET_ADMIN_PASSWORD_VERSION: v1
|
||||||
|
SECRET_ONLYOFFICE_JWT_VERSION: v1
|
||||||
|
SECRET_BBB_SECRET_VERSION: v1
|
||||||
|
EXTRA_VOLUME: "/dev/null:/tmp/.dummy"
|
||||||
|
trigger:
|
||||||
|
branch:
|
||||||
|
- main
|
||||||
|
---
|
||||||
|
kind: pipeline
|
||||||
name: generate recipe catalogue
|
name: generate recipe catalogue
|
||||||
steps:
|
steps:
|
||||||
- name: release a new version
|
- name: release a new version
|
||||||
|
|||||||
@@ -107,3 +107,7 @@ DEFAULT_QUOTA="10 GB"
|
|||||||
#HSTS_ENABLED=1
|
#HSTS_ENABLED=1
|
||||||
# Uncomment this line to add the `preload` part
|
# Uncomment this line to add the `preload` part
|
||||||
#HSTS_PRELOAD=1
|
#HSTS_PRELOAD=1
|
||||||
|
|
||||||
|
# Metrics
|
||||||
|
# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
|
||||||
|
# SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex
|
||||||
@@ -1,91 +0,0 @@
|
|||||||
# Nextcloud Recipe Maintenance
|
|
||||||
|
|
||||||
This document describes how the Nextcloud recipe is maintained. It builds on
|
|
||||||
the floor set by [Federation Resolution
|
|
||||||
025](https://docs.coopcloud.tech/federation/resolutions/passed/025/) and
|
|
||||||
follows the [`MAINTENANCE.md`
|
|
||||||
template](https://docs.coopcloud.tech/maintainers/maintain/#maintenancemd-template)
|
|
||||||
described in the Co-op Cloud maintainers' docs.
|
|
||||||
|
|
||||||
All contributions should be made via a pull request so that quality and
|
|
||||||
consistency stay something others can rely on.
|
|
||||||
|
|
||||||
## Maintainers
|
|
||||||
|
|
||||||
Everyone can apply to be a recipe maintainer.
|
|
||||||
Simply add yourself to the list in the README.md and open a new pull request
|
|
||||||
with the change.
|
|
||||||
|
|
||||||
## Maintainer Responsibilities
|
|
||||||
|
|
||||||
This recipe commits to the following, which is tighter than the floor set by
|
|
||||||
Resolution 025 (stable-recipe category). However, these timelines are
|
|
||||||
best-effort, so we aim for them as good as possible:
|
|
||||||
|
|
||||||
- Respond to PRs / issues within 3 working days
|
|
||||||
- Apply security patches within 1 week of disclosure
|
|
||||||
- Ship patch / minor image updates within 2 weeks of upstream release
|
|
||||||
- Adopt major Nextcloud version updates within 1 release cycle of upstream
|
|
||||||
EOL of the previous major (see below)
|
|
||||||
- Keep documentation current
|
|
||||||
|
|
||||||
In order to meet these responsibilities each maintainer:
|
|
||||||
|
|
||||||
- Watches the repository so notifications arrive
|
|
||||||
- Keeps an eye on [Renovate](./renovate.json) updates and helps shepherd them through
|
|
||||||
- Has a working contact (Matrix handle or email) reachable by the others
|
|
||||||
|
|
||||||
## Release cadence
|
|
||||||
|
|
||||||
The intent is to **track Nextcloud's own release schedule** rather than invent
|
|
||||||
our own. In practice this means:
|
|
||||||
|
|
||||||
- **Patch releases (e.g. `32.0.x`)**: published to this recipe shortly after
|
|
||||||
upstream, ideally within 1 week. `chore(deps)` opens the PRs; a maintainer
|
|
||||||
reviews the release notes and Nextcloud's issue tracker, and merges the PR
|
|
||||||
if it is OK.
|
|
||||||
- **Minor releases**: same flow as patch releases, but one of the maintainer
|
|
||||||
tests it on their own instance before merging.
|
|
||||||
- **Major releases (e.g. `32 → 33`)**: not adopted on day one. We wait for the
|
|
||||||
first one or two upstream patch releases of the new major to land
|
|
||||||
(typically 1–2 months) before promoting it here, to avoid passing the
|
|
||||||
early-adopter cost to operators. Major bumps get their own PR with release
|
|
||||||
notes and an upgrade-path check.
|
|
||||||
Before adding a major release, the following needs to be done:
|
|
||||||
- at least two maintainers update one of their production instances to the
|
|
||||||
new version
|
|
||||||
- the previous release gets a last update pointing to the docker image
|
|
||||||
versions nextcloud:xx-fpm, so that users can auto-update if they wish so
|
|
||||||
- the new release is added to this repo
|
|
||||||
- If people have the time it would be nice to create specially tagged versions
|
|
||||||
for major releases, which reflect that this is 'bleeding edge' and has not
|
|
||||||
been thoroughly tested.
|
|
||||||
- **Co-installed components** (Talk HPB, OnlyOffice, Whiteboard, etc.) are
|
|
||||||
bumped alongside or shortly after the matching Nextcloud release.
|
|
||||||
|
|
||||||
## Pull Requests
|
|
||||||
|
|
||||||
A pull request can be merged once it is approved by at least one maintainer.
|
|
||||||
PRs opened by a maintainer need approval from another maintainer. With three
|
|
||||||
maintainers this is workable; if the group shrinks, the rule should be
|
|
||||||
revisited.
|
|
||||||
|
|
||||||
Approvals should ideally include a smoke test on a real instance for anything
|
|
||||||
beyond a patch bump — Nextcloud upgrades have a long history of surprising us
|
|
||||||
(see the [upgrade notes in `README.md`](./README.md#upgrading-nextcloud)),
|
|
||||||
and silent CI is not enough.
|
|
||||||
|
|
||||||
## Becoming a maintainer
|
|
||||||
|
|
||||||
Everyone is welcome to apply:
|
|
||||||
|
|
||||||
1. Watch the repository so you get notifications.
|
|
||||||
2. Open a pull request adding yourself to the `Maintainer` line in
|
|
||||||
[`README.md`](./README.md) and to the list above.
|
|
||||||
3. Once an existing maintainer merges the PR, you'll be added to the
|
|
||||||
[nextcloud maintainers
|
|
||||||
team](https://git.coopcloud.tech/org/coop-cloud/teams/nextcloud-maintainers).
|
|
||||||
|
|
||||||
Stepping down is symmetrical: open a PR removing yourself, and flag it in
|
|
||||||
the federation channels so the group can plan replacement before falling
|
|
||||||
below the Res. 025 floor of one named maintainer.
|
|
||||||
@@ -5,7 +5,6 @@
|
|||||||
Fully automated luxury Nextcloud via docker-swarm.
|
Fully automated luxury Nextcloud via docker-swarm.
|
||||||
|
|
||||||
<!-- metadata -->
|
<!-- metadata -->
|
||||||
* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti)
|
|
||||||
* **Category**: Apps
|
* **Category**: Apps
|
||||||
* **Status**: 5
|
* **Status**: 5
|
||||||
* **Image**: [`nextcloud`](https://hub.docker.com/_/nextcloud), 4, upstream
|
* **Image**: [`nextcloud`](https://hub.docker.com/_/nextcloud), 4, upstream
|
||||||
@@ -26,9 +25,9 @@ Fully automated luxury Nextcloud via docker-swarm.
|
|||||||
|
|
||||||
### Onlyoffice Integration
|
### Onlyoffice Integration
|
||||||
|
|
||||||
First, install onlyoffice following the instructions in the
|
First install onlyoffice following the instructions in the
|
||||||
[OnlyOffice Recipe](https://recipes.coopcloud.tech/onlyoffice), and enable
|
[OnlyOffice Recipe](https://recipes.coopcloud.tech/onlyoffice), and enable
|
||||||
the JWT secret. Then configure your nextcloud instance with:
|
the JWT secret.
|
||||||
|
|
||||||
`abra app config <app-name>`
|
`abra app config <app-name>`
|
||||||
|
|
||||||
@@ -129,6 +128,17 @@ To disable dashboard app (since it is so corporate):
|
|||||||
|
|
||||||
- Configure a `defaultapp` in your `config.php` or use [apporder](https://apps.nextcloud.com/apps/apporder)
|
- Configure a `defaultapp` in your `config.php` or use [apporder](https://apps.nextcloud.com/apps/apporder)
|
||||||
|
|
||||||
|
## Metrics
|
||||||
|
|
||||||
|
There is a [metrics exporter](https://github.com/xperimental/nextcloud-exporter) that can be run as sidecar container, also part of the nextcloud helm charts. Its configured via alloys label-based auto-discovery provided by the updated [monitoring-stack](https://git.coopcloud.tech/coop-cloud/monitoring-ng)
|
||||||
|
To enable, uncomment
|
||||||
|
```
|
||||||
|
COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
|
||||||
|
SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex
|
||||||
|
```
|
||||||
|
then generate the secret with abra and run
|
||||||
|
`abra app cmd <domain> app set_metrics_token`
|
||||||
|
|
||||||
## Upgrading Nextcloud
|
## Upgrading Nextcloud
|
||||||
Upgrading Nextcloud can be a hair raising experiance. They [don't support downgrading](https://docs.nextcloud.com/server/latest/admin_manual/maintenance/upgrade.html) even for minor versions.
|
Upgrading Nextcloud can be a hair raising experiance. They [don't support downgrading](https://docs.nextcloud.com/server/latest/admin_manual/maintenance/upgrade.html) even for minor versions.
|
||||||
|
|
||||||
|
|||||||
@@ -193,3 +193,7 @@ set_windowsfriendly_filenames() {
|
|||||||
upgrade_mariadb() {
|
upgrade_mariadb() {
|
||||||
mariadb-upgrade -p`cat /run/secrets/db_root_password`
|
mariadb-upgrade -p`cat /run/secrets/db_root_password`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
set_metrics_token() {
|
||||||
|
run_occ "config:app:set serverinfo token --value '$(cat /run/secrets/metrics_token)'"
|
||||||
|
}
|
||||||
@@ -2,7 +2,7 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
elasticsearch:
|
elasticsearch:
|
||||||
image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.19"
|
image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.16"
|
||||||
environment:
|
environment:
|
||||||
- cluster.name=docker-cluster
|
- cluster.name=docker-cluster
|
||||||
- bootstrap.memory_lock=true
|
- bootstrap.memory_lock=true
|
||||||
@@ -29,7 +29,7 @@ services:
|
|||||||
mode: 0600
|
mode: 0600
|
||||||
|
|
||||||
searchindexer:
|
searchindexer:
|
||||||
image: nextcloud:32-fpm
|
image: nextcloud:32.0.11-fpm
|
||||||
volumes:
|
volumes:
|
||||||
- nextcloud:/var/www/html/
|
- nextcloud:/var/www/html/
|
||||||
- nextapps:/var/www/html/custom_apps:cached
|
- nextapps:/var/www/html/custom_apps:cached
|
||||||
|
|||||||
+1
-1
@@ -9,7 +9,7 @@ services:
|
|||||||
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
|
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: "mariadb:12.3"
|
image: "mariadb:11.4"
|
||||||
environment:
|
environment:
|
||||||
- MYSQL_DATABASE=nextcloud
|
- MYSQL_DATABASE=nextcloud
|
||||||
- MYSQL_USER=nextcloud
|
- MYSQL_USER=nextcloud
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
version: "3.8"
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
secrets:
|
||||||
|
- metrics_token
|
||||||
|
metrics:
|
||||||
|
image: xperimental/nextcloud-exporter:0.9.0
|
||||||
|
environment:
|
||||||
|
- NEXTCLOUD_SERVER=https://$DOMAIN
|
||||||
|
- NEXTCLOUD_AUTH_TOKEN=@/run/secrets/metrics_token
|
||||||
|
secrets:
|
||||||
|
- metrics_token
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
deploy:
|
||||||
|
labels:
|
||||||
|
- "prometheus.io/scrape=true"
|
||||||
|
- "prometheus.io/port=9205"
|
||||||
|
secrets:
|
||||||
|
metrics_token:
|
||||||
|
external: true
|
||||||
|
name: ${STACK_NAME}_metrics_token_${SECRET_METRICS_TOKEN_VERSION}
|
||||||
@@ -11,8 +11,7 @@ services:
|
|||||||
|
|
||||||
db:
|
db:
|
||||||
image: "pgautoupgrade/pgautoupgrade:14-debian"
|
image: "pgautoupgrade/pgautoupgrade:14-debian"
|
||||||
#setting max_connections with -c breaks pgautoupgrade
|
command: -c "max_connections=${MAX_DB_CONNECTIONS:-100}"
|
||||||
#command: -c "max_connections=${MAX_DB_CONNECTIONS:-100}"
|
|
||||||
volumes:
|
volumes:
|
||||||
- "postgres:/var/lib/postgresql/data"
|
- "postgres:/var/lib/postgresql/data"
|
||||||
networks:
|
networks:
|
||||||
|
|||||||
+5
-5
@@ -1,7 +1,7 @@
|
|||||||
version: "3.8"
|
version: "3.8"
|
||||||
services:
|
services:
|
||||||
web:
|
web:
|
||||||
image: nginx:1.31.3
|
image: nginx:1.31.1
|
||||||
depends_on:
|
depends_on:
|
||||||
- app
|
- app
|
||||||
configs:
|
configs:
|
||||||
@@ -48,7 +48,7 @@ services:
|
|||||||
start_period: 5m
|
start_period: 5m
|
||||||
|
|
||||||
app:
|
app:
|
||||||
image: nextcloud:32-fpm
|
image: nextcloud:32.0.11-fpm
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
configs:
|
configs:
|
||||||
@@ -95,7 +95,7 @@ services:
|
|||||||
failure_action: rollback
|
failure_action: rollback
|
||||||
order: start-first
|
order: start-first
|
||||||
labels:
|
labels:
|
||||||
- "coop-cloud.${STACK_NAME}.version=13.1.5+32.0.13-fpm"
|
- "coop-cloud.${STACK_NAME}.version=13.1.0+32.0.11-fpm"
|
||||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
||||||
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
||||||
- "backupbot.backup.volumes.redis=false"
|
- "backupbot.backup.volumes.redis=false"
|
||||||
@@ -109,7 +109,7 @@ services:
|
|||||||
start_period: 15m
|
start_period: 15m
|
||||||
|
|
||||||
cron:
|
cron:
|
||||||
image: nextcloud:32-fpm
|
image: nextcloud:32.0.11-fpm
|
||||||
volumes:
|
volumes:
|
||||||
- nextcloud:/var/www/html/
|
- nextcloud:/var/www/html/
|
||||||
- nextapps:/var/www/html/custom_apps:cached
|
- nextapps:/var/www/html/custom_apps:cached
|
||||||
@@ -125,7 +125,7 @@ services:
|
|||||||
|
|
||||||
|
|
||||||
cache:
|
cache:
|
||||||
image: redis:8.8.1-alpine
|
image: redis:8.8.0-alpine
|
||||||
networks:
|
networks:
|
||||||
- internal
|
- internal
|
||||||
volumes:
|
volumes:
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
chore(deps): update mariadb docker tag to v12
|
|
||||||
chore(deps): update mariadb docker tag to v11.8
|
|
||||||
chore(deps): update nginx docker tag to v1.31.3
|
|
||||||
chore(deps): update docker.elastic.co/elasticsearch/elasticsearch docker tag to v8.19.19
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
Important:
|
|
||||||
The pgautoupgrade switch from 13.1.0+32.0.11-fpm was released untested and had a bug: the db service's `-c max_connections=...` command breaks pgautoupgrade, failing with `initdb: invalid option -- 'c'`. If your db got stuck mid-upgrade on 13.1.0-13.1.4 with that error: restore the old data dir and remove the upgrade lock file. Then redeploy this version.
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
Last release for nextcloud-32, pointing to the latest version of nextcloud-32.
|
|
||||||
Reference in New Issue
Block a user