Compare commits

...

20 Commits

Author SHA1 Message Date
stevensting 652fcf0383 chore: publish 3.0.2+7.0.2 release 2026-07-21 16:18:23 +02:00
stevensting 5d891c88c7 Revert "Fix lint issues and improve test suite resilience"
This reverts commit 90d44bd3bc.
2026-07-21 16:09:11 +02:00
stevensting a2bf10a442 chore: publish 3.0.1+7.0.2 release 2026-07-21 14:44:35 +02:00
stevensting b64ab47051 Revert "block XML-RPC"
This reverts commit 3a4c8f9f22.
2026-07-21 14:24:54 +02:00
renovate-bot 96612a988a chore(deps): update wordpress docker tag to v7.0.2 (#72)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| wordpress | patch | `7.0.0` -> `7.0.2` |

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: coop-cloud/wordpress#72
Co-authored-by: Renovate Bot <renovate@coopcloud.tech>
Co-committed-by: Renovate Bot <renovate@coopcloud.tech>
2026-07-21 12:21:52 +00:00
simon 3a4c8f9f22 block XML-RPC 2026-07-21 10:39:26 +02:00
kawaiipunk d8bdf8588f Merge pull request 'chore(deps): update alpine docker tag to v3.24' (#71) from renovate/alpine-3.x into main
Reviewed-on: coop-cloud/wordpress#71
2026-06-18 15:19:44 +00:00
renovate-bot 36591c4d20 chore(deps): update alpine docker tag to v3.24 2026-06-09 21:25:28 +00:00
kawaiipunk f59fef5502 Merge pull request 'chore(deps): update alpine docker tag to v3.23' (#67) from renovate/alpine-3.x into main
Reviewed-on: coop-cloud/wordpress#67
2026-06-09 16:16:03 +00:00
kawaiipunk 6f23a5dfae Merge pull request 'Improve README' (#69) from kawaiipunk/wordpress:main into main
Reviewed-on: coop-cloud/wordpress#69
2026-06-03 20:43:00 +00:00
kawaiipunk 6d1b370cde merge upstream 2026-06-03 20:16:22 +00:00
kawaiipunk c5fb2ebaf3 Improve readme 2026-06-03 21:15:54 +01:00
kawaiipunk a34d7af280 revert 12d1e4e371
revert Merge pull request 'Improved README' (#68) from improve-readme into main

So sorry, that was a mistake!

Reviewed-on: coop-cloud/wordpress#68
2026-06-03 20:14:21 +00:00
kawaiipunk 12d1e4e371 Merge pull request 'Improved README' (#68) from improve-readme into main
Reviewed-on: coop-cloud/wordpress#68
2026-06-03 20:13:38 +00:00
kawaiipunk 8407a00942 Improved README 2026-06-03 21:12:32 +01:00
renovate-bot 90d34543db chore(deps): update alpine docker tag to v3.23 2026-06-03 19:24:48 +00:00
kawaiipunk 47fbba1505 Added additional instructions for running wp-cli 2026-06-03 20:08:20 +01:00
kawaiipunk 32062bff94 Merge pull request 'fix/3wc/wp-cli' (#64) from kawaiipunk/wordpress:fix/3wc/wp-cli into main
Reviewed-on: coop-cloud/wordpress#64
2026-06-03 18:55:12 +00:00
kawaiipunk c7f500c428 Merge pull request 'tests' (#62) from kawaiipunk/wordpress:tests into main
Reviewed-on: coop-cloud/wordpress#62
2026-06-03 18:36:32 +00:00
3wordchant 15dd324102 fix: $* instead of $@, seems to fix #49?
Closes #49
2026-06-02 23:37:23 +01:00
22 changed files with 61 additions and 137 deletions
+1 -1
View File
@@ -4,7 +4,7 @@ name: test
steps:
- name: test
image: alpine:3.21
image: alpine:3.24
environment:
SHELLCHECK_OPTS: -s bash
commands:
+2 -64
View File
@@ -13,52 +13,18 @@ Coöp Cloud + [Wordpress](https://wordpress.org) = 🥳
* **Backups**: Yes
* **Email**: 3
* **Tests**: 2
* **SSO**: No
* **SSO**: 2
<!-- endmetadata -->
## Quick start
* `abra app new wordpress`
* `abra app config <app-name>`
* `abra app secret generate -a <app-name>`
* `abra app deploy <app-name>`
* `abra app cmd <app-name> app core_install`
### Authentik Integration
`abra app config <app-name>`
Configure the following envs:
```
COMPOSE_FILE="$COMPOSE_FILE:compose.authentik.yml"
AUTHENTIK_DOMAIN=authentik.example.com
AUTHENTIK_SECRET_NAME=authentik_example_com_wordpress_secret_v1 # the same as in authentik
AUTHENTIK_ID_NAME=authentik_example_com_wordpress_id_v1 # the same as in authentik
```
`abra app cmd <app-name> app set_authentik`
## Running WP-CLI
`abra app cmd <app-name> app wp -- core check-update --major`
## Network (Multi-site)
1. Set up as above
2. `abra app config <app-name>`, and uncomment `#MULTISITE=enable`
3. `abra app deploy <app-name>`
4. Log into the Wordpress admin dashboard, go to Tools » Network Setup
5. Don't worry about the suggested file changes
6. `abra app config <app-name>` again and set `MULTISITE` to either `subdomain` or `subfolder` depending on your setup.
7. `abra app deploy <app-name>`
## Installing a custom theme
`abra app cp <app-name> ~/path/to/local/theme wordpress:/var/www/html/wp-content/themes/`
## Email
There is a local or remote SMTP relay configuration available.
@@ -74,34 +40,6 @@ Below are the instructions for the local relay.
`$DOMAIN` or in its `$EXTRA_SENDER_DOMAINS`
3. `abra app deploy <app-name>`
## Tests
Run the full test suite:
```sh
bash tests/run.sh
```
### Prerequisites
The test suite uses several tools. Install them with your equivalent of:
```sh
brew install shellcheck gomplate
```
Some tests skip gracefully if their dependencies are missing.
[abra]: https://git.autonomic.zone/autonomic-cooperative/abra
## Migrate from a non-Co-op Cloud Wordpress install
Make a .tar.gz backup of the site's wp-content dir and an .sql.gz backup of the database.
1. `abra app wp.example.com restore app wp-content.tar.gz`
2. `abra app wp.example.com restore db wordpress.sql.gz`
Lastly, if there's a domain name change, run a search and replace:
`abra app wp.example.com wp "search-replace https://old.example.com https://wp.example.com"`
[cc-traefik]: https://git.autonomic.zone/coop-cloud/traefik
[cc-postfix-relay]: https://git.autonomic.zone/coop-cloud/traefik
[cc-postfix-relay]: https://git.autonomic.zone/coop-cloud/postfix-relay
+1 -1
View File
@@ -6,7 +6,7 @@ export HTACCESS_CONF_VERSION=v3
export USERS_CONF_VERSION=v1
wp() {
su -p www-data -s /bin/bash -c "/usr/local/bin/wp $@"
su -p www-data -s /bin/bash -c "/usr/local/bin/wp $*"
}
update() {
+1 -1
View File
@@ -4,4 +4,4 @@ version: "3.8"
services:
ftp:
ports:
- 2220:22
- 2220:22
+1 -1
View File
@@ -4,4 +4,4 @@ version: "3.8"
services:
ftp:
ports:
- 2221:22
- 2221:22
+1 -1
View File
@@ -4,4 +4,4 @@ version: "3.8"
services:
ftp:
ports:
- 2222:22
- 2222:22
+1 -1
View File
@@ -4,4 +4,4 @@ version: "3.8"
services:
ftp:
ports:
- 2223:22
- 2223:22
+1 -1
View File
@@ -4,4 +4,4 @@ version: "3.8"
services:
ftp:
ports:
- 2224:22
- 2224:22
+1 -1
View File
@@ -4,4 +4,4 @@ version: "3.8"
services:
ftp:
ports:
- 2220:22
- 2220:22
+1 -1
View File
@@ -7,4 +7,4 @@ services:
labels:
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect-matrix-well-known"
- "traefik.http.middlewares.${STACK_NAME}-redirect-matrix-well-known.redirectregex.regex=^https://(.*)/.well-known/matrix/(.*)"
- "traefik.http.middlewares.${STACK_NAME}-redirect-matrix-well-known.redirectregex.replacement=https://${MATRIX_DOMAIN}/.well-known/matrix/$$2"
- "traefik.http.middlewares.${STACK_NAME}-redirect-matrix-well-known.redirectregex.replacement=https://${MATRIX_DOMAIN}/.well-known/matrix/$$2"
+1 -1
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: "wordpress:7.0.0"
image: "wordpress:7.0.2"
volumes:
- "wordpress:/var/www/html/"
environment:
+2 -2
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: "wordpress:7.0.0"
image: "wordpress:7.0.2"
volumes:
- "wordpress_content:/var/www/html/wp-content/"
networks:
@@ -62,7 +62,7 @@ services:
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.replacement=https://${DOMAIN}/$${2}"
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.permanent=true"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
- "coop-cloud.${STACK_NAME}.version=3.0.0+7.0.0"
- "coop-cloud.${STACK_NAME}.version=3.0.2+7.0.2"
db:
image: "mariadb:12.3"
+7 -7
View File
@@ -1,13 +1,13 @@
#!/bin/bash
{{ if (getenv "PHP_EXTENSIONS") }}
docker-php-ext-install {{ getenv "PHP_EXTENSIONS" }}
{{ if (env "PHP_EXTENSIONS") }}
docker-php-ext-install {{ env "PHP_EXTENSIONS" }}
{{ end }}
curl -z /usr/local/bin/wp -o /usr/local/bin/wp https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar
chmod +x /usr/local/bin/wp
{{ if eq (getenv "ENABLE_COMPOSER") "1" }}
{{ if eq (env "ENABLE_COMPOSER") "1" }}
mkdir -p /var/www/.composer
chown www-data:www-data /var/www/.composer /var/www/html/composer
@@ -19,18 +19,18 @@ rm /tmp/composer-setup.php
mv /var/www/html/composer.phar /usr/local/bin/composer
{{ end }}
{{ if eq (getenv "CORS_ALLOW_ALL") "1" }}
{{ if eq (env "CORS_ALLOW_ALL") "1" }}
a2enmod headers
sed -ri -e 's/^([ \t]*)(<\/VirtualHost>)/\1\tHeader set Access-Control-Allow-Origin "*"\n\1\2/g' /etc/apache2/sites-available/*.conf
{{ end }}
{{ if eq (getenv "MULTISITE") "enable" }}
{{ if eq (env "MULTISITE") "enable" }}
export WORDPRESS_CONFIG_EXTRA="$WORDPRESS_CONFIG_EXTRA
define('WP_CACHE', false);
define('WP_ALLOW_MULTISITE', true );"
{{ end }}
{{ if or (eq (getenv "MULTISITE") "subdomain") (eq (getenv "MULTISITE") "subfolder") }}
{{ if or (eq (env "MULTISITE") "subdomain") (eq (env "MULTISITE") "subfolder") }}
export WORDPRESS_CONFIG_EXTRA="$WORDPRESS_CONFIG_EXTRA
define('MULTISITE', true);
define('SUBDOMAIN_INSTALL', true);
@@ -56,7 +56,7 @@ fi
chown -R --from=root:root www-data:www-data /var/www/html/wp-content/
if [ $# -gt 0 ]; then
if [ -n "$@" ]; then
"$@"
fi
+3 -3
View File
@@ -3,7 +3,7 @@
Require all denied
</FilesMatch>
{{ if eq (getenv "MULTISITE") "" -}}
{{ if eq (env "MULTISITE") "" -}}
# BEGIN WordPress
RewriteEngine On
@@ -17,7 +17,7 @@ RewriteRule . /index.php [L]
# END WordPress
{{- end -}}
{{- if eq (getenv "MULTISITE") "subfolder" -}}
{{- if eq (env "MULTISITE") "subfolder" -}}
# BEGIN WordPress Multisite
# Using subfolder network type: https://wordpress.org/documentation/article/htaccess/#multisite
@@ -39,7 +39,7 @@ RewriteRule . index.php [L]
# END WordPress Multisite
{{- end -}}
{{- if eq (getenv "MULTISITE") "subdomain" -}}
{{- if eq (env "MULTISITE") "subdomain" -}}
# BEGIN WordPress Multisite
# Using subdomain network type: https://wordpress.org/documentation/article/htaccess/#multisite
+9 -9
View File
@@ -1,19 +1,19 @@
account default
host {{ getenv "SMTP_HOST" }}
from {{ getenv "MAIL_FROM" }}
user {{ or (getenv "SMTP_USER") (getenv "MAIL_FROM") }}
port {{ getenv "SMTP_PORT" }}
host {{ env "SMTP_HOST" }}
from {{ env "MAIL_FROM" }}
user {{ or (env "SMTP_USER") (env "MAIL_FROM") }}
port {{ env "SMTP_PORT" }}
{{ if eq (getenv "SMTP_OVERRIDE_FROM") "on" }}
{{ if eq (env "SMTP_OVERRIDE_FROM") "on" }}
set_from_header on
{{ end }}
{{ if eq (getenv "SMTP_AUTH") "on" }}
auth {{ getenv "SMTP_AUTH" }}
{{ if eq (env "SMTP_AUTH") "on" }}
auth {{ env "SMTP_AUTH" }}
passwordeval "cat /run/secrets/smtp_password"
{{ end }}
{{ if eq (getenv "SMTP_TLS") "on" }}
tls {{ getenv "SMTP_TLS" }}
{{ if eq (env "SMTP_TLS") "on" }}
tls {{ env "SMTP_TLS" }}
tls_trust_file /etc/ssl/certs/ca-certificates.crt
{{ end }}
+1
View File
@@ -0,0 +1 @@
Bumps Wordpress version to 7.0.2 which fixes CVE-2026-63030
+1
View File
@@ -0,0 +1 @@
Fixes last release which is broken.
+1 -1
View File
@@ -19,7 +19,7 @@ done < <(find "$ROOT/.." -maxdepth 1 -name 'compose*.yml' | sort)
SHELL_TMPL_FILES=()
while IFS= read -r f; do
SHELL_TMPL_FILES+=("$f")
done < <(find "$ROOT/.." -maxdepth 1 -name '*.sh.tmpl' | sort)
done < <(find "$ROOT/.." -maxdepth 1 -name '*.tmpl' | sort)
# Track total failures across all test suites
failures=0
+6 -20
View File
@@ -15,7 +15,7 @@ fi
# Validate a compose file against the Docker Compose specification
test_compose_config() {
local file=$1 main=${2:-}
local file=$1
# Skip if Docker Compose is not available on this system
if [ -z "$compose_cmd" ]; then
@@ -23,27 +23,13 @@ test_compose_config() {
return
fi
# Main compose file is validated standalone
if [ -z "$main" ]; then
if $compose_cmd -f "$file" config -q 2>/dev/null; then
echo " PASS $file"
pass=$((pass + 1))
else
echo " FAIL $file"
fail=$((fail + 1))
fi
return
fi
# Override files are validated combined with the main compose file.
# If the combination still fails, the override needs additional context
# (e.g. other override files) and is skipped rather than failed.
if $compose_cmd -f "$main" -f "$file" config -q 2>/dev/null; then
# config -q exits with non-zero if the compose file is invalid
if $compose_cmd -f "$file" config -q 2>/dev/null; then
echo " PASS $file"
pass=$((pass + 1))
else
echo " SKIP $file (partial override, needs additional context)"
pass=$((pass + 1))
echo " FAIL $file"
fail=$((fail + 1))
fi
}
@@ -55,7 +41,7 @@ test_compose_config "$ROOT/compose.yml"
while IFS= read -r f; do
# Skip the main compose file (already tested above)
[ "$f" = "$ROOT/compose.yml" ] && continue
[ -f "$f" ] && test_compose_config "$f" "$ROOT/compose.yml"
[ -f "$f" ] && test_compose_config "$f"
done < <(find "$ROOT" -maxdepth 1 -name 'compose*.yml' | sort)
echo "---"
-9
View File
@@ -4,15 +4,6 @@ set -euo pipefail
pass=0
fail=0
# Skip if shellcheck is not installed
if ! command -v shellcheck &>/dev/null; then
echo "=== ShellCheck ==="
echo " SKIP shellcheck not found"
echo "---"
echo "Passed: 0 Failed: 0"
exit 0
fi
# Allow overriding shellcheck options via env var (e.g. -s bash)
EXTRA_SHELLCHECK_OPTS="${SHELLCHECK_OPTS:-}"
+14 -7
View File
@@ -11,20 +11,27 @@ gomplate="${GOMPLATE_BIN:-gomplate}"
# Ensure gomplate is installed before running template tests
require_gomplate() {
if ! command -v "$gomplate" &>/dev/null; then
echo " SKIP gomplate not found (install from https://github.com/hairyhenderson/gomplate or set GOMPLATE_BIN)"
exit 0
echo "gomplate not found. Install it from https://github.com/hairyhenderson/gomplate"
echo "or set GOMPLATE_BIN env var."
exit 1
fi
}
render() {
local tmpl=$1 envfile=$2
"$gomplate" \
--template t="$tmpl" \
--context "_=fmt:%s" \
--datasource "env=env://?$envfile" \
-f "$tmpl" 2>/dev/null
}
# Render a template by exporting env vars directly
# This avoids gomplate datasource quirks with .env files
render_via_env() {
local tmpl=$1 envfile=$2
set -a
# shellcheck disable=1090,1091
. "$envfile"
set +a
"$gomplate" -f "$tmpl" 2>/dev/null
# shellcheck disable=2046
env $(xargs < "$envfile") "$gomplate" -f "$tmpl" 2>/dev/null
}
# ---------------------------------------------------------------------------
+5 -5
View File
@@ -1,10 +1,10 @@
{{- $upload_max_size := "256M" -}}
{{- if ne (getenv "UPLOAD_MAX_SIZE") "" }}{{ $upload_max_size = getenv "UPLOAD_MAX_SIZE" }}{{ end -}}
{{- $upload_max_time := "30" -}}
{{- if ne (getenv "UPLOAD_MAX_TIME") "" }}{{ $upload_max_time = getenv "UPLOAD_MAX_TIME" }}{{ end -}}
{{ $upload_max_size := "256M" }}
{{ if ne (env "UPLOAD_MAX_SIZE") "" }} {{ $upload_max_size = env "UPLOAD_MAX_SIZE" }} {{ end }}
{{ $upload_max_time := "30" }}
{{ if ne (env "UPLOAD_MAX_TIME") "" }} {{ $upload_max_time = env "UPLOAD_MAX_TIME" }} {{ end }}
file_uploads = On
upload_max_filesize = {{ $upload_max_size }}
upload_max_filesize = {{ $upload_max_size }}
post_max_size = {{ $upload_max_size }}
memory_limit = {{ $upload_max_size }}
max_execution_time = {{ $upload_max_time }}