18 Commits

Author SHA1 Message Date
2d15ee2286 add fix_permission function 2025-10-28 17:18:49 +01:00
ea97fa4d01 chore: publish 3.0.0+6.5.0-34 release
All checks were successful
continuous-integration/drone/tag Build is passing
2025-10-23 13:41:49 +02:00
a8f0b7d0c6 fix elasticsearch 2025-10-21 17:24:01 +02:00
b6b52b6e9c chore: publish 2.1.0+6.5.0-34 release
All checks were successful
continuous-integration/drone/tag Build is passing
2025-05-27 16:25:24 +02:00
d7dbf76a53 fix saml logout url 2025-01-21 16:10:01 +01:00
f80f630304 Update .drone.yml 2025-01-08 10:09:13 -08:00
73e9f7bfcc chore: publish 2.0.0+6.4.0-34 release
All checks were successful
continuous-integration/drone/tag Build is passing
2024-12-03 18:34:35 +01:00
3a940d845f update pg_backup.sh 2024-10-22 21:33:15 +02:00
d7b3c1e18e add ENABLE_BACKUPS label 2024-10-22 17:28:22 +02:00
3af308645e chore: publish 1.0.5+6.3.1-95 release
All checks were successful
continuous-integration/drone/tag Build is passing
2024-10-15 19:06:10 +02:00
cb85124b06 Add postgres backup script pg_backup 2024-10-15 17:25:01 +02:00
d68c9ad18c chore: publish 1.0.4+6.3.1-95 release 2024-09-19 23:34:07 +02:00
38682b8503 add backupbot label 2024-09-19 23:23:06 +02:00
ce314169cb move zammad internal backups to compose overwrite 2024-09-19 23:18:28 +02:00
34be0c287e fix elasticsearch resources limits 2024-09-19 23:12:12 +02:00
aab7e022d0 chore: publish 1.0.3+6.3.1-95 release 2024-09-17 12:49:44 +02:00
a7e409b337 fix set_logo and enable_authentik_sso 2024-09-17 12:46:33 +02:00
ffe4fa1c54 fix init: remove LOGO_URL 2024-09-03 19:12:30 +02:00
8 changed files with 147 additions and 69 deletions

View File

@ -32,7 +32,7 @@ steps:
from_secret: drone_abra-bot_token
fork: true
repositories:
- coop-cloud/auto-recipes-catalogue-json
- toolshed/auto-recipes-catalogue-json
trigger:
event: tag

View File

@ -2,11 +2,13 @@ TYPE=zammad
DOMAIN=zammad.example.com
TIMEOUT=600
ENABLE_BACKUPS=true
## Domain aliases
#EXTRA_DOMAINS=', `www.zammad.example.com`'
LETS_ENCRYPT_ENV=production
COMPOSE_FILE="compose.yml"
SECRET_DB_PASSWORD_VERSION=v1
SECRET_SMTP_PASSWORD_VERSION=v1
@ -27,4 +29,10 @@ SMTP_PORT=465
## SAML SSO ##
#SSO_PROVIDER_DOMAIN=authentik.example.com
#IDP_SSO_TARGET_URL=https://authentik.example.com/application/saml/zammad/sso/binding/init/
#IDP_SLO_SERVICE_URL=https://authentik.example.com/application/saml/zammad/slo/binding/redirect/
#IDP_SLO_SERVICE_URL=https://zammad.example.com/auth/saml/slo
## Zammad internal backups
# COMPOSE_FILE="$COMPOSE_FILE:compose.backup.yml"
# BACKUP_TIME=03:00"
# HOLD_DAYS=10

42
abra.sh
View File

@ -1,29 +1,29 @@
export ENTRYPOINT_VERSION=v2
export AUTO_WIZARD_VERSION=v1
export AUTO_WIZARD_VERSION=v2
export PG_BACKUP_VERSION=v2
get_setting_changes() {
/custom-entrypoint.sh "rails r 'puts JSON.pretty_generate(JSON.parse(Setting.all.select{ |setting| setting.state_current != setting.state_initial }.map { |setting| {name: setting.name, value: setting.state_current[\""value\""]} } .to_json))'"
/custom-entrypoint.sh "rails r 'puts JSON.pretty_generate(JSON.parse(Setting.all.select{ |setting| setting.state_current != setting.state_initial }.map { |setting| {name: setting.name, value: setting.state_current[\""value\""]} } .to_json))'"
}
console() {
/custom-entrypoint.sh "rails c"
/custom-entrypoint.sh "rails c"
}
rails_run() {
COMMAND="rails r \"$@\""
/custom-entrypoint.sh "$COMMAND"
COMMAND="rails r \"$@\""
/custom-entrypoint.sh "$COMMAND"
}
init() {
cp -f /opt/zammad/contrib/auto_wizard.json /tmp/auto_wizard.json
/custom-entrypoint.sh "rails zammad:setup:auto_wizard[/tmp/auto_wizard.json]"
cp -f /opt/zammad/contrib/auto_wizard.json /tmp/auto_wizard.json
/custom-entrypoint.sh "rails zammad:setup:auto_wizard[/tmp/auto_wizard.json]"
}
enable_authentik_sso() {
ADMIN_UID=$(abra app cmd -T $SSO_PROVIDER_DOMAIN worker get_user_uid akadmin)
CERT=$(abra app cmd -T $SSO_PROVIDER_DOMAIN worker get_certificate zammad)
COMMAND="
ADMIN_UID=$(abra app cmd -T $SSO_PROVIDER_DOMAIN worker get_user_uid akadmin)
CERT=$(abra app cmd -T $SSO_PROVIDER_DOMAIN worker get_certificate zammad)
COMMAND="
(u = User.find_by(login: 'admin')) && (u.login='$ADMIN_UID') && u.save!;
Setting.set('auth_saml', true);
Setting.set('auth_third_party_auto_link_at_inital_login', true);
@ -35,18 +35,26 @@ enable_authentik_sso() {
'idp_cert_fingerprint'=>'',
'name_identifier_format'=>'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress'})
"
abra app cmd -T -C support.dev.local-it.cloud zammad-railsserver rails_run "$(printf "%q " $COMMAND )"
abra app cmd -T $DOMAIN zammad-railsserver rails_run "$(printf "%q " $COMMAND)"
}
set_logo() {
LOGO_PATH="$1"
abra app cp "$APP_NAME" "$LOGO_PATH" zammad-railsserver:/tmp/
filename="$(basename "$LOGO_PATH")"
COMMAND="
LOGO_PATH="$1"
abra app cp "$APP_NAME" "$LOGO_PATH" zammad-railsserver:/tmp/
filename="$(basename "$LOGO_PATH")"
COMMAND="
logo_path = '/tmp/$filename';
logo_content = File.open(logo_path, 'rb') { |file| file.read };
logo_timestamp = Service::SystemAssets::ProductLogo.store(logo_content);
Setting.set('product_logo', logo_timestamp);
"
abra app cmd -T -C support.dev.local-it.cloud zammad-railsserver rails_run "$(printf "%q " $COMMAND )"
abra app cmd -T $DOMAIN zammad-railsserver rails_run "$(printf "%q " $COMMAND)"
}
fix_permissions() {
i=0
while ! abra app run -t -u 0 $DOMAIN zammad-elasticsearch -- chown elasticsearch -Rv /usr/share/elasticsearch/data && [[ $i -lt 30 ]]; do
((i++))
sleep 1
done
}

View File

@ -46,10 +46,6 @@
"name": "organization",
"value": "{{ env "ORGANIZATION" }}"
},
{
"name": "product_logo",
"value": "{{ env "LOGO_URL" }}"
},
{
"name": "timezone_default",
"value": "{{ env "TZ" }}"

36
compose.backup.yml Normal file
View File

@ -0,0 +1,36 @@
version: "3.8"
services:
zammad-backup:
image: ghcr.io/zammad/zammad:6.5.0-34
command: ["zammad-backup"]
volumes:
- zammad-backup:/var/tmp/zammad
- zammad-storage:/opt/zammad/storage:ro
user: 0:0
deploy:
labels:
backupbot.backup.volumes.zammad-backup: "false"
restart_policy:
condition: on-failure
environment:
POSTGRESQL_DB: zammad_production
POSTGRESQL_HOST: zammad-postgresql
POSTGRESQL_USER: zammad
POSTGRESQL_PASS_FILE: /run/secrets/db_password
POSTGRESQL_PORT: 5432
# Backup settings
BACKUP_DIR: "/var/tmp/zammad"
BACKUP_TIME: "${BACKUP_TIME:-03:00}"
#BACKUP_SLEEP: 86400
HOLD_DAYS: 10
DOMAIN:
entrypoint: /custom-entrypoint.sh
configs:
- source: entrypoint
target: /custom-entrypoint.sh
mode: 0555
secrets:
- db_password
volumes:
zammad-backup:

View File

@ -13,11 +13,6 @@ x-shared:
POSTGRESQL_OPTIONS: ?pool=50
POSTGRESQL_DB_CREATE:
REDIS_URL: redis://zammad-redis:6379
# Backup settings
BACKUP_DIR: "/var/tmp/zammad"
BACKUP_TIME: "${BACKUP_TIME:-03:00}"
#BACKUP_SLEEP: 86400
HOLD_DAYS: 10
TZ: "${TZ:-Europe/Berlin}"
# Allow passing in these variables via .env:
AUTOWIZARD_JSON:
@ -29,6 +24,8 @@ x-shared:
ELASTICSEARCH_NAMESPACE:
ELASTICSEARCH_REINDEX:
ELASTICSEARCH_SSL_VERIFY:
ELASTICSEARCH_USER:
ELASTICSEARCH_PASS:
NGINX_PORT:
NGINX_SERVER_NAME:
NGINX_SERVER_SCHEME: https
@ -48,65 +45,52 @@ x-shared:
SSO_PROVIDER_DOMAIN:
IDP_SSO_TARGET_URL:
IDP_SLO_SERVICE_URL:
image: ghcr.io/zammad/zammad:6.3.1-95
image: ghcr.io/zammad/zammad:6.5.0-34
deploy:
restart_policy:
condition: on-failure
volumes:
- zammad-storage:/opt/zammad/storage
#old: - zammad-data:/opt/zammad
depends_on:
- zammad-memcached
- zammad-postgresql
- zammad-redis
entrypoint: /custom-entrypoint.sh
configs:
- source: entrypoint
target: /custom-entrypoint.sh
mode: 0555
- source: auto_wizard
target: /opt/zammad/contrib/auto_wizard.json
- source: entrypoint
target: /custom-entrypoint.sh
mode: 0555
- source: auto_wizard
target: /opt/zammad/contrib/auto_wizard.json
secrets:
- db_password
- smtp_password
- admin_password
services:
zammad-backup:
<<: *zammad-service
command: ["zammad-backup"]
volumes:
- zammad-backup:/var/tmp/zammad
- zammad-storage:/opt/zammad/storage:ro
#old: - zammad-data:/opt/zammad
user: 0:0
deploy:
labels:
- "backupbot.backup=true"
- "backupbot.backup.path=/var/tmp/zammad"
zammad-elasticsearch:
image: bitnami/elasticsearch:8.14.3
image: elasticsearch:8.18.0
deploy:
restart_policy:
condition: on-failure
volumes:
- elasticsearch-data:/bitnami/elasticsearch/data
environment:
- discovery.type=single-node
healthcheck:
test: "/opt/bitnami/scripts/elasticsearch/healthcheck.sh"
interval: 30s
timeout: 10s
retries: 10
start_period: 5m
deploy:
resources:
limits:
memory: 4G
reservations:
memory: 2G
volumes:
- elasticsearch-data:/usr/share/elasticsearch/data
environment:
discovery.type: single-node
xpack.security.enabled: 'false'
ES_JAVA_OPTS: -Xms1g -Xmx1g
healthcheck:
#test: TODO
interval: 30s
timeout: 10s
retries: 10
start_period: 5m
zammad-init:
<<: *zammad-service
command: ["zammad-init"]
@ -116,7 +100,7 @@ services:
zammad-memcached:
command: memcached -m 256M
image: memcached:1.6.29-alpine
image: memcached:1.6.38-alpine
healthcheck:
test: 'echo "version" | nc -vn -w 1 127.0.0.1 11211'
interval: 30s
@ -150,7 +134,7 @@ services:
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
- "coop-cloud.${STACK_NAME}.version=1.0.2+6.3.1-95"
- "coop-cloud.${STACK_NAME}.version=3.0.0+6.5.0-34"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:8080"]
@ -168,10 +152,19 @@ services:
deploy:
restart_policy:
condition: on-failure
labels:
backupbot.backup: "${ENABLE_BACKUPS:-true}"
backupbot.backup.pre-hook: "/pg_backup.sh backup"
backupbot.backup.volumes.postgresql-data.path: "backup.sql"
backupbot.restore.post-hook: "/pg_backup.sh restore"
backupbot.backup.volumes.elasticsearch-data: "false"
backupbot.backup.volumes.redis-data: "false"
volumes:
- postgresql-data:/var/lib/postgresql/data
# Backup Restore
#- zammad-backup:/var/tmp/zammad:ro
configs:
- source: pg_backup
target: /pg_backup.sh
mode: 0555
secrets:
- db_password
healthcheck:
@ -191,9 +184,8 @@ services:
retries: 10
start_period: 5m
zammad-redis:
image: redis:7.2.5-alpine
image: redis:7.4.3-alpine
deploy:
restart_policy:
condition: on-failure
@ -210,7 +202,7 @@ services:
<<: *zammad-service
command: ["zammad-scheduler"]
healthcheck:
test: 'ps x | grep "[b]ackground-worker.rb"'
test: 'grep -a "background-worker.rb" -r /proc/[0-9]*/cmdline'
interval: 30s
timeout: 10s
retries: 10
@ -230,7 +222,6 @@ volumes:
elasticsearch-data:
postgresql-data:
redis-data:
zammad-backup:
zammad-storage:
networks:
@ -246,6 +237,9 @@ configs:
name: ${STACK_NAME}_auto_wizard_${AUTO_WIZARD_VERSION}
file: auto_wizard.json.tmpl
template_driver: golang
pg_backup:
name: ${STACK_NAME}_pg_backup_${PG_BACKUP_VERSION}
file: pg_backup.sh
secrets:
db_password:

34
pg_backup.sh Normal file
View File

@ -0,0 +1,34 @@
#!/bin/bash
set -e
BACKUP_FILE='/var/lib/postgresql/data/backup.sql'
function backup {
export PGPASSWORD=$(cat /run/secrets/db_password)
pg_dump -U ${POSTGRES_USER} ${POSTGRES_DB} > $BACKUP_FILE
}
function restore {
cd /var/lib/postgresql/data/
restore_config(){
# Restore allowed connections
cat pg_hba.conf.bak > pg_hba.conf
su postgres -c 'pg_ctl reload'
}
# Don't allow any other connections than local
cp pg_hba.conf pg_hba.conf.bak
echo "local all all trust" > pg_hba.conf
su postgres -c 'pg_ctl reload'
trap restore_config EXIT INT TERM
# Recreate Database
psql -U ${POSTGRES_USER} -d postgres -c "DROP DATABASE ${POSTGRES_DB} WITH (FORCE);"
createdb -U ${POSTGRES_USER} ${POSTGRES_DB}
psql -U ${POSTGRES_USER} -d ${POSTGRES_DB} -1 -f $BACKUP_FILE
trap - EXIT INT TERM
restore_config
}
$@

2
release/3.0.0+6.5.0-34 Normal file
View File

@ -0,0 +1,2 @@
Breaking Change. You need to run the following command to change the elasticsearch volume permissions:
abra app cmd --local <APPDOMAIN> fix_permission