Compare commits

...

29 Commits

Author SHA1 Message Date
hey de3dd72f9d add sso configuration instructions 2026-03-30 11:42:28 -04:00
joe-irving 818ec9bc13 Merge pull request 'chore: publish 2.0.0+2.0.5 release' (#8) from v2.0.0 into main
Reviewed-on: coop-cloud/baserow#8
2026-01-05 08:19:04 +00:00
joe-irving af3d655c8f chore: publish 2.0.0+2.0.5 release 2026-01-04 09:09:02 +00:00
marlon 1936226bf5 chore: publish 1.3.0+1.35.3 release 2025-12-10 16:00:00 -05:00
marlon 0865766102 Merge pull request 'backup/restore and merge conflicts' (#7) from linnealovespie/baserow:backup into main
Reviewed-on: coop-cloud/baserow#7
2025-12-10 20:49:50 +00:00
linnealovespie 475484928f Merge remote-tracking branch 'cc/backups' into backup 2025-11-24 19:55:38 -08:00
marlon 3158926e7b chore: publish 1.2.2+1.35.3 release 2025-11-10 18:58:27 -05:00
marlon 8ae0634c82 restore test 2025-11-10 18:15:59 -05:00
marlon ca1e0ec1c3 add abra.sh 2025-11-10 16:43:37 -05:00
marlon 14b65c2ecd fix pg scripting vars 2025-11-10 16:40:14 -05:00
marlon c5994bd7e4 backups test 2025-11-10 16:22:33 -05:00
marlon 136ad45cfb rollback 2025-11-10 20:46:35 +00:00
marlon 26e98e915d rollback 2025-11-10 15:42:04 -05:00
marlon aa6b8472f5 rollback restart condition 2025-11-10 15:40:19 -05:00
marlon f19c498001 chore: publish 1.2.1+1.35.3 release 2025-11-10 12:01:15 -05:00
marlon db18e08971 change restart policy to unless-stopped 2025-11-10 11:58:37 -05:00
marlon e85291cdb6 chore: publish 1.2.0+1.35.3 release 2025-10-22 10:50:26 -04:00
marlon e61e4d9e13 add backup support 2025-10-22 10:46:40 -04:00
marlon 43c7fb2130 chore: publish 1.1.0+1.31.1 release 2025-07-17 13:49:00 -04:00
marlon 48f7153a9b Merge pull request 'add config options for running with low resources' (#4) from low-resource into main
Reviewed-on: coop-cloud/baserow#4
2025-07-17 17:44:57 +00:00
marlon d6f980ef48 add low resources config options 2025-07-17 13:38:12 -04:00
marlon a8ae828568 chore: publish 1.0.0+1.31.1 release 2025-05-08 23:31:55 -04:00
marlon 0b930dd81d Merge pull request 'shorter jwt secret name' (#3) from shorter-secret into main
Reviewed-on: coop-cloud/baserow#3
Reviewed-by: decentral1se <decentral1se@noreply.git.coopcloud.tech>
2025-05-09 03:28:29 +00:00
marlon ccba29e3e4 shorter jwt secret name 2025-05-07 13:34:24 -04:00
3wordchant 53ae1dc377 Fix tag build URL 2025-03-05 12:16:15 -05:00
3wordchant 9d28e3695a chore: publish 0.7.0+1.31.1 release 2025-03-05 12:12:48 -05:00
knoflook 7fd09f34a5 wip: wildcard domain 2025-01-30 11:31:03 +01:00
knoflook 1cc375cf19 chore: publish 0.6.0+1.30.1 release 2025-01-30 02:04:59 +01:00
trav 0591e1bf1c chore: publish 0.5.0+1.29.0 release 2024-11-13 12:43:21 -05:00
9 changed files with 105 additions and 10 deletions
+1 -1
View File
@@ -32,7 +32,7 @@ steps:
from_secret: drone_abra-bot_token
fork: true
repositories:
- coop-cloud/auto-recipes-catalogue-json
- toolshed/auto-recipes-catalogue-json
trigger:
event: tag
+9 -1
View File
@@ -7,8 +7,16 @@ COMPOSE_FILE="compose.yml"
## Domain aliases
#EXTRA_DOMAINS=', `www.baserow.example.com`'
## Automatically use subdomains under following domain (anything.example.com)
#WILDCARD_DOMAIN='example.com'
LETS_ENCRYPT_ENV=production
## For low-resource machines (<2GB ram)
# BASEROW_AMOUNT_OF_GUNICORN_WORKERS=1
# BASEROW_AMOUNT_OF_WORKERS=1
# BASEROW_RUN_MINIMAL=yes
# COMPOSE_FILE="$COMPOSE_FILE:compose.email.yml"
# FROM_EMAIL="No Reply <noreply@example.com>"
# EMAIL_SMTP_USE_TLS=true
@@ -19,5 +27,5 @@ LETS_ENCRYPT_ENV=production
#
SECRET_SECRET_KEY_VERSION=v1
SECRET_BASEROW_JWT_SIGNING_KEY_VERSION=v1
SECRET_JWT_KEY_VERSION=v1
+39
View File
@@ -21,5 +21,44 @@
* `abra app config <app-name>`
* `abra app deploy <app-name>`
## Resources
* Baserow requires over 2GB RAM to run on Co-op Cloud with default settings
* For environments with 2GB or less RAM, run `abra app config <app-name>` and uncomment the `For low-resource machines` config block
* More info: https://hub.docker.com/r/baserow/baserow/#scaling-options
## Enable SSO with Authenitk
This is how to configure your Baserow server to accept logins from your Authenitk SSO provider. You need at least an advanced Baserow plan to use this feature.
### Configure Authenitk
**Create Application and Provider**
* Log in as administrator of your Authentik instance
* Go to https://your-authentik-domain/if/admin/#/core/applications and choose *Create with Provider*
* Follow these steps to configure the provider, if a field isn't specified here, you can keep the default value
* Application Name: baserow -> **Next**
* Choose OAuth2/OIDC -> **Next**
* Set Authorization flow: `default-provider-authorization-implicit-consent (Authorize Application)`
* Copy the **Client ID** and **Client Secret**, you'll need them later
* Add Redirect URI: Strict - https://your-baserow-domain/api/sso/oauth2/callback/2/ -> **Next**
* **Note**: You may need to change this URI based your baserow settings later
* **Next** and **Submit**
### Configure Baserow
**Create Baserow SSO Provider**
* Log in as adminsitrator of your Baserow instance
* Go to https://your-baserow-domain/admin/auth-providers and choose *Add Provider*
* Name: `authentik`
* URL: `https://<your-authentik-domain>/application/o/baserow`
* Fill out Client ID and Secret with the copied values from the Authentik provisioning
* At this point, check the `Callback URL` at the bottom of the page, it should be the same as the Redirect URI earlier
* If it's not go back to Authentik and under https://your-authentik-domain/if/admin/#/core/providers edit the Baserow provider to use the Callback URL provided by Baserow
**Disable non-SSO login (Optional)**
* Still under the `Authentication Providers` page, uncheck the email and password authentication option
* You can still login to your admin instance at https://your-baserow-domain/login?noredirect
For more, see [`docs.coopcloud.tech`](https://docs.coopcloud.tech).
+1
View File
@@ -0,0 +1 @@
export PG_BACKUP_CONFIG_VERSION=v1
+22
View File
@@ -0,0 +1,22 @@
if [ "$1" == "pre-backup" ]; then
# Remove any existing db dump and then create a new one
rm -rf $DATA_DIR/postgres/postgres-backup
source /baserow/data/.pgpass
PGPASSWORD=$DATABASE_PASSWORD pg_dump -j 8 -h localhost -U baserow baserow --format=directory -f $DATA_DIR/postgres/postgres-backup
exit
fi
if [ "$1" == "post-backup" ]; then
rm -rf $DATA_DIR/postgres/postgres-backup
exit
fi
if [ "$1" == "pre-restore" ]; then
exit
fi
if [ "$1" == "post-restore" ]; then
source /baserow/data/.pgpass
PGPASSWORD=$DATABASE_PASSWORD pg_restore -j 8 -h localhost -U baserow -d baserow -c $DATA_DIR/postgres/postgres-backup
exit
fi
+22 -8
View File
@@ -3,44 +3,58 @@ version: "3.8"
services:
app:
image: baserow/baserow:1.28.0
image: baserow/baserow:2.0.5
networks:
- proxy
environment:
- BASEROW_PUBLIC_URL=https://${DOMAIN}
- SECRET_KEY_FILE=/run/secrets/secret_key
- BASEROW_JWT_SIGNING_KEY_FILE=/run/secrets/baserow_jwt_signing_key
- BASEROW_JWT_SIGNING_KEY_FILE=/run/secrets/jwt_key
- BASEROW_CADDY_ADDRESSES=:80
- BASEROW_BUILDER_DOMAINS=${WILDCARD_DOMAIN}
secrets:
- secret_key
- baserow_jwt_signing_key
- jwt_key
deploy:
restart_policy:
condition: on-failure
labels:
- "traefik.enable=true"
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=80"
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS})"
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS}) || HostRegexp(`{subdomain:\\w+}.${WILDCARD_DOMAIN}`)"
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
## Redirect from EXTRA_DOMAINS to DOMAIN
#- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
#- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
#- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
- "coop-cloud.${STACK_NAME}.version=0.4.0+1.28.0"
- "backupbot.backup=true"
- "backupbot.backup.path=/baserow/data"
- "backupbot.backup.pre-hook=/backup.sh pre-backup"
- "backupbot.backup.post-hook=/backup.sh post-backup"
- "backupbot.restore.post-hook=/backup.sh post-restore"
- "coop-cloud.${STACK_NAME}.version=2.0.0+2.0.5"
healthcheck:
test: ["CMD", "./baserow.sh", "backend-cmd", "backend-healthcheck"]
interval: 30s
timeout: 10s
retries: 10
start_period: 1m
volumes:
- baserow_data:/baserow/data
configs:
- source: backup-postgres
target: /backup.sh
mode: 0777
volumes:
baserow_data:
configs:
backup-postgres:
name: backup-postgres_${PG_BACKUP_CONFIG_VERSION}
file: ./backup-postgres.sh
networks:
proxy:
external: true
@@ -49,6 +63,6 @@ secrets:
secret_key:
external: true
name: ${STACK_NAME}_secret_key_${SECRET_SECRET_KEY_VERSION}
baserow_jwt_signing_key:
jwt_key:
external: true
name: ${STACK_NAME}_baserow_jwt_signing_key_${SECRET_BASEROW_JWT_SIGNING_KEY_VERSION}
name: ${STACK_NAME}_jwt_key_${SECRET_JWT_KEY_VERSION}
+7
View File
@@ -0,0 +1,7 @@
This upgrade changes the name of the jwt signing key secret from baserow_jwt_signing_key to jwt_key
EXISTING DEPLOYMENTS MUST COPY THIS SECRET TO THE NEW LOCATION:
# Retrieve the current jwt key value:
docker exec <your_baserow_container_name> cat /run/secrets/baserow_jwt_signing_key
# Create the new secret
abra app secret insert <your_baserow_domain> jwt_key v1 <value returned by previous command>
+1
View File
@@ -0,0 +1 @@
Backup/restore of the postgres database backend will now use pg_dump and pg_restore
+3
View File
@@ -0,0 +1,3 @@
= 1 Breaking Change =
[Builder] Data source now return content with human property names instead of technical ones #4135