38 Commits

Author SHA1 Message Date
notplants 36ee3451a3 Merge pull request 'chore: Configure Renovate' (#7) from renovate/configure into main
Reviewed-on: coop-cloud/cryptpad#7
2026-06-09 14:48:20 +00:00
notplants 06d98da6db Merge pull request 'Adding OnlyOffice compose' (#11) from ineiti/cryptpad:onlyoffice into main
Reviewed-on: coop-cloud/cryptpad#11
2026-06-09 14:48:09 +00:00
notplants aa8e1d3488 Merge pull request 'chore: upgrade to 0.6.0+v2026.5.1' (#13) from upgrade-0.6.0+v2026.5.1 into main
Reviewed-on: coop-cloud/cryptpad#13
2026-06-09 14:46:30 +00:00
autonomic-bot 9c18c176c5 chore: upgrade to 0.6.0+v2026.5.1 2026-06-05 01:26:43 +00:00
trav 96df5bda68 Merge pull request 'chore: upgrade to 0.5.5+v2026.2.0' (#12) from upgrade-0.5.5+v2026.2.0 into main
Reviewed-on: coop-cloud/cryptpad#12
2026-06-02 16:40:33 +00:00
autonomic-bot e2cbecdc89 chore: upgrade to 0.5.5+v2026.2.0 2026-06-02 03:52:26 +00:00
Linus Gasser 7a66942dd9 Adding OnlyOffice compose
This PR adds a compose.onlyoffice.yaml file and the corresponding
configuration and description in README.md.
2026-05-22 22:22:09 +02:00
notplants bb655259c0 Merge pull request 'Shorten config name to fit char limits' (#10) from shorten into main
Reviewed-on: coop-cloud/cryptpad#10
2026-04-20 17:35:23 +00:00
notplants 6d047f5987 bump to 0.5.4+v2026.2.0 2026-04-20 17:31:08 +00:00
notplants 081c196078 shorten app_config_js config name to fit 64-char Docker limit 2026-04-20 17:30:22 +00:00
notplants a9f451a177 Merge pull request 'Add optional customizatoin for restriction of guest users' (#9) from restrict into main
Reviewed-on: coop-cloud/cryptpad#9
2026-04-20 17:24:17 +00:00
notplants 81119b2eea bump to 0.5.3+v2026.2.0 2026-04-20 13:23:19 -04:00
notplants 38393e1fd1 add RESTRICT_GUEST_ACCESS to block unregistered users from all applications 2026-04-20 13:23:19 -04:00
renovate-bot a72a5c78db Add renovate.json 2026-03-10 17:37:03 +00:00
notplants 9922390ce3 bump to 0.5.2+v2026.2.0 2026-03-01 19:50:02 -05:00
notplants c1ee1d9817 Merge pull request 'split sso compose into two compose' (#6) from two-compose into main
Reviewed-on: coop-cloud/cryptpad#6
2026-03-02 00:49:32 +00:00
notplants d3b1bb4f29 split sso compose into two compose 2026-03-01 19:47:47 -05:00
notplants 800e8426ce add sso to readme 2026-02-28 22:05:44 -05:00
notplants 97209123e0 bump to 0.5.1+v2026.2.0 2026-02-28 22:05:44 -05:00
notplants 899f9d9da0 Merge pull request 'Add SSO Plugin' (#5) from sso into main
Reviewed-on: coop-cloud/cryptpad#5
2026-03-01 03:02:35 +00:00
notplants f31c12299d bump to 0.5.1+v2026.2.0 2026-03-01 02:54:27 +00:00
notplants b8f074e0a7 move SSO client secret to Docker secret, gate SSO entrypoint on SSO_ENABLED 2026-03-01 02:48:46 +00:00
notplants bd2488ffea working sso 2026-02-28 21:01:52 -05:00
notplants 61b41e2866 working on sso 2026-02-28 16:52:32 -05:00
notplants db049838e9 Merge pull request 'upgrade to 0.5.0+version-2026.2.0' (#4) from update into main
Reviewed-on: coop-cloud/cryptpad#4
2026-02-17 16:44:22 +00:00
notplants 694e6b1a72 chore: upgrade to 0.5.0+v2026.2.0
Upgrade CryptPad from version-2025.9.0 to version-2026.2.0 and
nginx from 1.25 to 1.29. Enable healthcheck on the app service.
Update README metadata for healthcheck and backup status.
2026-02-17 16:29:41 +00:00
notplants 3d92f35437 update 2026-02-17 11:03:48 -05:00
notplants 738f1af43e Add backup functionality 2026-02-17 10:32:54 -05:00
notplants 157f439441 Merge pull request 'Modify recipe to use nginx' (#3) from with-nginx into main
Reviewed-on: coop-cloud/cryptpad#3
2026-01-13 18:15:46 +00:00
notplants cfa170509c add env and readme for configuring admin 2026-01-13 12:56:12 -05:00
notplants 2128cc5b6d cleanup of comments 2026-01-12 16:19:24 -05:00
notplants 97ab3f4012 working recipe using nginx 2026-01-12 16:17:42 -05:00
notplants ff217b4086 working on nginx integration 2026-01-12 15:45:15 -05:00
cas 3b80a4c4b1 Fix config (broken) template. Update config ver. 2025-12-31 10:52:11 -08:00
cas 99bf8922ab Add explicit config path to compose 2025-12-15 11:20:01 -08:00
cas 2e7f9a374b Switch the sandbox domain to an explicit choice on the users part
This allows subdomains or separate domains - a convenience for setups that have a wildcard pointing at the CC server.
2025-12-15 10:45:40 -08:00
cas cb2a47fbc8 Update .drone.yml 2025-01-08 10:09:12 -08:00
javielico 08f58b5921 Merge pull request 'Update image to updated one' (#1) from javielico/cryptpad:main into main
Reviewed-on: coop-cloud/cryptpad#1

Merging request as current image is no longer secure.
2024-04-18 17:55:38 +00:00
15 changed files with 416 additions and 35 deletions
+1 -1
View File
@@ -33,7 +33,7 @@ steps:
from_secret: drone_abra-bot_token
fork: true
repositories:
- coop-cloud/auto-recipes-catalogue-json
- toolshed/auto-recipes-catalogue-json
trigger:
event: tag
+33
View File
@@ -1,7 +1,40 @@
TYPE=cryptpad
COMPOSE_FILE="compose.yml"
DOMAIN=cryptpad.example.com
# This is a separate domain for the secure side of Cryptpad. It can be any other domain (subdomain or separate domain)
SANDBOX_DOMAIN=sandbox.cryptpad.example.com
# CRYPTPAD_ADMIN_KEYS
## here is an example of the format for one single key
# CRYPTPAD_ADMIN_KEYS= '"[user1@cryptpad.cctest.autonomic.zone/zew-WaKZimxhNSL3iiVL8SCzVzPB8KhIxZNrRKn+uRo=]",'
## here is an example of the format for multiple keys (including here because it was confusing to me)
# CRYPTPAD_ADMIN_KEYS='"[user1@cryptpad.cctest.autonomic.zone/zew-WaKZimxhNSL3iiVL8SCzVzPB8KhIxZNrRKn+uRo=]","[user2@cryptpad.cctest.autonomic.zone/Z7agNvwPXHm9xuEYOYV2YY53fSofgzum86xvhUxJ4nU=]",'
## Domain aliases
#EXTRA_DOMAINS=', `www.cryptpad.example.com`'
LETS_ENCRYPT_ENV=production
## Set to true to block unregistered users from accessing any CryptPad applications
## See https://docs.cryptpad.org/en/admin_guide/customization.html#restricting-guest-access
#RESTRICT_GUEST_ACCESS=false
## SSO / OIDC (optional — uncomment below and add compose.sso.yml to COMPOSE_FILE to enable)
# COMPOSE_FILE="$COMPOSE_FILE:compose.sso.yml"
#SSO_ENABLED=true
#SSO_ENFORCED=false
#SSO_PROVIDER_NAME=Authentik
#SSO_OIDC_URL=https://authentik.example.com/application/o/cryptpad
#SSO_CLIENT_ID=cryptpad
#SSO_CLIENT_SECRET_VERSION=v1
#SSO_JWT_ALG=RS256
#SSO_PLUGIN_VERSION=0.4.0
## Adding OnlyOffice to cryptpad
#COMPOSE_FILE="$COMPOSE_FILE:compose.onlyoffice.yaml"
## Enables installation of older onlyoffice versions so that older documents
## can also be loaded and converted.
#ONLYOFFICE_OLDEST=v6
+1
View File
@@ -1 +1,2 @@
.envrc
.idea
+63 -5
View File
@@ -5,13 +5,13 @@
<!-- metadata -->
* **Category**: Apps
* **Status**: 0
* **Status**: 3
* **Image**: cryptpad/cryptpad
* **Healthcheck**: No
* **Backups**: No
* **Healthcheck**: Yes
* **Backups**: Yes
* **Email**: No
* **Tests**: No
* **SSO**: No
* **SSO**: Yes
<!-- endmetadata -->
@@ -26,5 +26,63 @@
5. `abra app deploy YOURAPPDOMAIN`
6. Open the configured domain in your browser to finish set-up
At this point, anyone with this domain can register new users with this cryptpad instance.
After you have registered a first user, here is how you can make this user into an admin.
After logging in as your user, go to: https://cryptpad.cctest.autonomic.zone/profile/
Click "Copy Public Key". This will copy your public key into your clipboard.
Then run `abra app config YOURAPPDOMAIN` and set the value of CRYPTPAD_ADMIN_KEYS
to include your public key. The example in .env.sample shows the required format.
Then redeploy with `abra app deploy YOURAPPDOMAIN --force`.
Now when you login as your user, and visit https://cryptpad.cctest.autonomic.zone/admin/,
you should be able to access the admin interface for this cryptpad instance.
## SSO
SSO support is provided by `compose.sso.yml`. To enable it, add the SSO compose file and set the SSO variables in your app config:
```
COMPOSE_FILE="compose.yml:compose.sso.yml"
SSO_ENABLED=true
```
On the next deploy, the [CryptPad SSO plugin](https://github.com/cryptpad/sso) will be installed automatically.
You also need to configure the remaining SSO environment variables for your OIDC provider:
- `SSO_PROVIDER_NAME` — display name shown on the login button (e.g. `Keycloak`, `Authentik`)
- `SSO_OIDC_URL` — OIDC discovery URL for your provider
- `SSO_CLIENT_ID` — OAuth2 client ID
- `SSO_JWT_ALG` — JWT signing algorithm (e.g. `RS256`)
The client secret is stored as a Docker secret. Insert it with:
```
abra app secret insert YOURAPPDOMAIN sso_client_s v1 YOUR_CLIENT_SECRET
```
Then deploy (or redeploy) to apply: `abra app deploy YOURAPPDOMAIN --force`.
## OnlyOffice
OnlyOffice support is provided by `compose.onlyoffice.yaml`. Enable it by adding the compose file to your app config:
```
COMPOSE_FILE="compose.yml:compose.onlyoffice.yaml"
```
On the next deploy, an entrypoint wrapper (`onlyoffice-entrypoint.sh`) prepares the OnlyOffice config volume **before** CryptPad starts, then the app container runs `install-onlyoffice.sh` to download the OnlyOffice assets. Running the prep work inside the app container (rather than a separate init service) is necessary because Docker Swarm ignores `depends_on` at runtime — a sidecar init container would race the app.
To support opening documents created with older OnlyOffice versions, set `ONLYOFFICE_OLDEST` in your app config. This writes (or updates) `oldest_needed_version` in `onlyoffice-conf/onlyoffice.properties`, which `install-onlyoffice.sh` reads to fetch older versions in addition to the latest:
```
ONLYOFFICE_OLDEST=v6
```
If `ONLYOFFICE_OLDEST` is unset, `onlyoffice.properties` is left untouched (CryptPad's own default applies). Only the `oldest_needed_version` key is touched on each deploy, so any other entries in `onlyoffice.properties` are preserved. If you change `ONLYOFFICE_OLDEST` after the assets have already been downloaded, you may need to drop the `cryptpad_oo_dist` volume so `install-onlyoffice.sh` re-runs and pulls the additional versions.
[`abra`]: https://git.coopcloud.tech/coop-cloud/abra
[`coop-cloud/traefik`]: https://git.coopcloud.tech/coop-cloud/traefik
[`coop-cloud/traefik`]: https://git.coopcloud.tech/coop-cloud/traefik
+7 -1
View File
@@ -1 +1,7 @@
export CONFIG_VERSION=v1
export CONFIG_VERSION=v2
export CONFIG_JS_VERSION=v2
export NGINX_CONF_VERSION=v1
export SSO_ENTRYPOINT_VERSION=v6
export SSO_JS_VERSION=v3
export APP_CONFIG_JS_VERSION=v1
export ONLYOFFICE_ENTRYPOINT_VERSION=v1
+24
View File
@@ -0,0 +1,24 @@
// CryptPad application customization — generated from environment variables
// See https://docs.cryptpad.org/en/admin_guide/customization.html
// For default file, see: https://github.com/cryptpad/cryptpad/blob/main/customize.dist/application_config.js
(() => {
const factory = (AppConfig) => {
{{ if eq (env "RESTRICT_GUEST_ACCESS") "true" }}
// Block unregistered users from accessing any applications
AppConfig.registeredOnlyTypes = AppConfig.availablePadTypes.slice();
{{ end }}
return AppConfig;
};
// Do not change code below
if (typeof(module) !== 'undefined' && module.exports) {
module.exports = factory(
require('../www/common/application_config_internal.js')
);
} else if ((typeof(define) !== 'undefined' && define !== null) && (define.amd !== null)) {
define(['/common/application_config_internal.js'], factory);
}
})();
+48
View File
@@ -0,0 +1,48 @@
version: "3.8"
services:
init-onlyoffice-dirs:
image: busybox
user: root
command:
- sh
- -eu
- -c
- |
mkdir -p /cryptpad/www/common/onlyoffice/dist /cryptpad/onlyoffice-conf
chown -R 4001:4001 \
/cryptpad/www/common/onlyoffice/dist \
/cryptpad/onlyoffice-conf
exec tail -f /dev/null
volumes:
- cryptpad_oo_dist:/cryptpad/www/common/onlyoffice/dist
- cryptpad_oo_conf:/cryptpad/onlyoffice-conf/
app:
# onlyoffice-entrypoint.sh auto-chains through /sso-entrypoint.sh if
# compose.sso.yml is also loaded, so order of COMPOSE_FILE doesn't matter.
entrypoint:
- /onlyoffice-entrypoint.sh
- /cryptpad/docker-entrypoint.sh
environment:
- "CPAD_INSTALL_ONLYOFFICE=yes"
- ONLYOFFICE_OLDEST
volumes:
- cryptpad_oo_dist:/cryptpad/www/common/onlyoffice/dist
- cryptpad_oo_conf:/cryptpad/onlyoffice-conf/
configs:
- source: onlyoffice_entrypoint
target: /onlyoffice-entrypoint.sh
mode: 0755
deploy:
labels:
- "backupbot.backup.volumes.cryptpad_oo_dist=false"
volumes:
cryptpad_oo_dist:
cryptpad_oo_conf:
configs:
onlyoffice_entrypoint:
name: ${STACK_NAME}_onlyoffice_entrypoint_${ONLYOFFICE_ENTRYPOINT_VERSION}
file: onlyoffice-entrypoint.sh
+41
View File
@@ -0,0 +1,41 @@
---
version: "3.8"
services:
app:
entrypoint: ["/sso-entrypoint.sh", "/cryptpad/docker-entrypoint.sh"]
environment:
- SSO_PLUGIN_VERSION
- "SSO_ENABLED=${SSO_ENABLED:-false}"
- SSO_ENFORCED
- SSO_PROVIDER_NAME
- SSO_OIDC_URL
- SSO_CLIENT_ID
- SSO_JWT_ALG
secrets:
- sso_client_s
volumes:
- cryptpad_plugins:/cryptpad/lib/plugins
configs:
- source: sso_entrypoint
target: /sso-entrypoint.sh
mode: 0755
- source: sso_js
target: /sso.js
volumes:
cryptpad_plugins:
secrets:
sso_client_s:
external: true
name: ${STACK_NAME}_sso_client_s_${SSO_CLIENT_SECRET_VERSION}
configs:
sso_entrypoint:
name: ${STACK_NAME}_sso_entrypoint_${SSO_ENTRYPOINT_VERSION}
file: sso-entrypoint.sh
sso_js:
name: ${STACK_NAME}_sso_js_${SSO_JS_VERSION}
file: sso.js.tmpl
template_driver: golang
+50 -23
View File
@@ -3,18 +3,20 @@ version: "3.8"
services:
app:
image: cryptpad/cryptpad:version-2024.3.0
image: cryptpad/cryptpad:version-2026.5.1
command: ["npm", "start"]
networks:
- proxy
- backend
environment:
- CRYPTPAD_ADMIN_KEYS
- "CPAD_MAIN_DOMAIN=${DOMAIN}"
- "CPAD_SANDBOX_DOMAIN=sandbox.${DOMAIN}"
# Traefik can't use HTTP2 to communicate with cryptpat_websocket
- "CPAD_SANDBOX_DOMAIN=${SANDBOX_DOMAIN}"
# Traefik can't use HTTP2 to communicate with cryptpad_websocket
# A workaroung is disabling HTTP2 in Nginx
- "CPAD_HTTP2_DISABLE=true"
- "CPAD_REALIP_RECURSIVE=on"
- "CPAD_REALIP_HEADER=X-Real-Ip"
- "CPAD_TRUST_PROXY=1"
- "CPAD_CONF=/cryptpad/config/config.js"
- "RESTRICT_GUEST_ACCESS=${RESTRICT_GUEST_ACCESS:-false}"
volumes:
- cryptpad_blob:/cryptpad/blob
- cryptpad_block:/cryptpad/block
@@ -25,33 +27,50 @@ services:
configs:
- source: config_js
target: /cryptpad/config/config.js
- source: app_config_js
target: /cryptpad/customize/application_config.js
deploy:
restart_policy:
condition: on-failure
labels:
- "traefik.enable=false"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
- "coop-cloud.${STACK_NAME}.version=0.6.0+v2026.5.1"
- "backupbot.backup=true"
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:3000"]
interval: 30s
timeout: 10s
retries: 10
start_period: 1m
web:
image: nginx:1.31
configs:
- source: nginx_conf
target: /etc/nginx/conf.d/default.conf
networks:
proxy:
backend:
depends_on:
- app
environment:
- STACK_NAME
deploy:
labels:
- "traefik.enable=true"
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=80"
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`, `sandbox.${DOMAIN}`${EXTRA_DOMAINS})"
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.docker.network=proxy"
- "traefik.http.routers.${STACK_NAME}.tls=true"
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=8083"
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`, `${SANDBOX_DOMAIN}` ${EXTRA_DOMAINS})"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
# - "traefik.http.routers.${STACK_NAME}.tls.domains[0].main=${DOMAIN}"
# - "traefik.http.routers.${STACK_NAME}.tls.domains[0].sans=sandbox.${DOMAIN}"
## Redirect from EXTRA_DOMAINS to DOMAIN
#- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
#- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
#- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
- "coop-cloud.${STACK_NAME}.version=0.4.0+version-2024.3.0"
# healthcheck:
# test: ["CMD", "curl", "-f", "http://localhost"]
# interval: 30s
# timeout: 10s
# retries: 10
# start_period: 1m
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
networks:
proxy:
external: true
backend:
volumes:
cryptpad_blob:
@@ -66,3 +85,11 @@ configs:
name: ${STACK_NAME}_config_${CONFIG_VERSION}
file: config.js.tmpl
template_driver: golang
nginx_conf:
name: ${STACK_NAME}_nginx_conf_${NGINX_CONF_VERSION}
file: nginx.conf.tmpl
template_driver: golang
app_config_js:
name: ${STACK_NAME}_app_config_js_${APP_CONFIG_JS_VERSION}
file: application_config.js.tmpl
template_driver: golang
+3 -5
View File
@@ -67,7 +67,7 @@ module.exports = {
*
* CUSTOMIZE AND UNCOMMENT THIS FOR PRODUCTION INSTALLATIONS.
*/
httpSafeOrigin: "https://{{ env "CPAD_SANDBOX_DOMAIN" }}",
httpSafeOrigin: 'https://{{ env "CPAD_SANDBOX_DOMAIN" }}',
/* httpAddress specifies the address on which the nodejs server
* should be accessible. By default it will listen on 127.0.0.1
@@ -75,7 +75,7 @@ module.exports = {
* all addresses, including IPv6, set this to '::'.
*
*/
//httpAddress: '::',
httpAddress: '::',
/* httpPort specifies on which port the nodejs server should listen.
* By default it will serve content over port 3000, which is suitable
@@ -111,11 +111,9 @@ module.exports = {
* key, which can be found on the settings page for registered users.
* Entries should be strings separated by a comma.
*/
/*
adminKeys: [
//"[cryptpad-user1@my.awesome.website/YZgXQxKR0Rcb6r6CmxHPdAGLVludrAF2lEnkbx1vVOo=]",
{{ env "CRYPTPAD_ADMIN_KEYS" }}
],
*/
/* =====================
* STORAGE
+39
View File
@@ -0,0 +1,39 @@
server {
listen 8083;
server_name localhost;
access_log /var/log/cpad.log;
error_log /var/log/cpad-error.log;
#access_log /dev/null;
#error_log /dev/null emerg;
# Main CryptPad app
location / {
proxy_pass http://{{ env "STACK_NAME" }}_app:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
client_max_body_size 150m;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection upgrade;
}
# WebSocket endpoint
location ^~ /cryptpad_websocket {
proxy_pass http://{{ env "STACK_NAME" }}_app:3003;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection upgrade;
}
}
+42
View File
@@ -0,0 +1,42 @@
#!/bin/bash
set -e
# OnlyOffice init — runs before the original CryptPad entrypoint.
# Ensures oldest_needed_version in onlyoffice.properties matches
# ONLYOFFICE_OLDEST before install-onlyoffice.sh / CryptPad reads it.
CONF_DIR="/cryptpad/onlyoffice-conf"
PROPS="${CONF_DIR}/onlyoffice.properties"
# Wait for init-onlyoffice-dirs to chown the volumes. Swarm ignores
# depends_on, so the init sidecar and this container start in parallel.
waited=0
while [ ! -w "${CONF_DIR}" ]; do
if [ "${waited}" -ge 60 ]; then
echo "[onlyoffice-entrypoint] timed out waiting for ${CONF_DIR} to become writable" >&2
exit 1
fi
echo "[onlyoffice-entrypoint] waiting for ${CONF_DIR} to be writable (${waited}s)"
sleep 1
waited=$((waited + 1))
done
if [ -n "${ONLYOFFICE_OLDEST:-}" ]; then
mkdir -p "${CONF_DIR}"
touch "${PROPS}"
if grep -q '^oldest_needed_version=' "${PROPS}"; then
sed -i "s|^oldest_needed_version=.*|oldest_needed_version=${ONLYOFFICE_OLDEST}|" "${PROPS}"
else
echo "oldest_needed_version=${ONLYOFFICE_OLDEST}" >> "${PROPS}"
fi
echo "[onlyoffice-entrypoint] oldest_needed_version=${ONLYOFFICE_OLDEST}"
else
echo "[onlyoffice-entrypoint] ONLYOFFICE_OLDEST unset, leaving ${PROPS} untouched"
fi
# Chain through the SSO entrypoint if compose.sso.yml mounted it.
if [ -x /sso-entrypoint.sh ]; then
exec /sso-entrypoint.sh "$@"
fi
exec "$@"
+6
View File
@@ -0,0 +1,6 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended"
]
}
+37
View File
@@ -0,0 +1,37 @@
#!/bin/bash
set -e
# SSO plugin installer — runs before the original CryptPad entrypoint.
# Clones the cryptpad/sso plugin into the plugins volume if not already present
# or if the version has changed.
# Skips SSO setup entirely when SSO_ENABLED is not "true".
if [ "${SSO_ENABLED}" != "true" ]; then
echo "[sso-entrypoint] SSO not enabled, skipping plugin install"
exec "$@"
fi
PLUGIN_DIR="/cryptpad/lib/plugins/sso"
VERSION_FILE="${PLUGIN_DIR}/.version"
SSO_PLUGIN_VERSION="${SSO_PLUGIN_VERSION:-0.4.0}"
# Copy SSO config template into place (mounted as Docker config)
if [ -f /sso.js ]; then
cp /sso.js /cryptpad/config/sso.js
echo "[sso-entrypoint] Copied sso.js config into /cryptpad/config/sso.js"
fi
# Install/update the SSO plugin
if [ -f "${VERSION_FILE}" ] && [ "$(cat "${VERSION_FILE}")" = "${SSO_PLUGIN_VERSION}" ]; then
echo "[sso-entrypoint] SSO plugin ${SSO_PLUGIN_VERSION} already installed"
else
echo "[sso-entrypoint] Installing SSO plugin ${SSO_PLUGIN_VERSION} ..."
rm -rf "${PLUGIN_DIR}"
git clone --depth 1 --branch "${SSO_PLUGIN_VERSION}" \
https://github.com/cryptpad/sso.git "${PLUGIN_DIR}"
echo "${SSO_PLUGIN_VERSION}" > "${VERSION_FILE}"
echo "[sso-entrypoint] SSO plugin installed"
fi
# Hand off to the original CryptPad entrypoint
exec "$@"
+21
View File
@@ -0,0 +1,21 @@
// CryptPad SSO configuration — generated from environment variables
// See https://github.com/cryptpad/sso for documentation
module.exports = {
enabled: "{{ env "SSO_ENABLED" }}" === "true",
enforced: "{{ env "SSO_ENFORCED" }}" === "true",
cpPassword: true,
forceCpPassword: false,
list: [
{
name: "{{ env "SSO_PROVIDER_NAME" }}",
type: "oidc",
url: "{{ env "SSO_OIDC_URL" }}",
client_id: "{{ env "SSO_CLIENT_ID" }}",
client_secret: "{{ secret "sso_client_s" }}",
id_token_alg: "{{ env "SSO_JWT_ALG" }}",
use_pkce: true,
use_nonce: true
}
]
};