Compare commits

...

33 Commits

Author SHA1 Message Date
3wc
53a08095f2 chore: publish 1.0.0+v6.99 release 2023-09-23 20:46:23 +01:00
a9181c180e chore: publish 0.14.0+v6.99 release 2023-07-18 13:51:03 +02:00
bc3b7a4dba fix domain env 2023-07-10 00:43:59 +02:00
d7a3f874c9 chore: publish 0.13.2+v6.81 release 2023-06-26 17:57:44 +02:00
9b84875ea0 chore: formatting 2023-06-26 17:09:43 +02:00
16753c808a chore: point backup to a volume directory 2023-06-26 17:09:25 +02:00
16b48136e7 enable mongo logs 2023-06-26 17:09:10 +02:00
083310a964 fix: remove secret version from abra.sh 2023-06-23 11:42:39 +02:00
d3e1340e03 chore: publish 0.13.1+v6.81 release 2023-04-25 12:10:04 +02:00
28c8f7539a add auto update and timeout env 2023-04-18 18:22:54 +02:00
97a348ce29 add timeout 2023-04-13 20:36:16 +02:00
3d94108785 chore: publish 0.13.0+v6.81 release 2023-04-05 18:33:11 +02:00
3wc
a77f2c1ed9 Switch to self-hosted stack-ssh-deploy image [mass update] 2023-01-21 11:49:56 -08:00
3wc
a07ac5f0df Add drone configs / secrets [mass update] 2023-01-20 21:32:07 -08:00
3wc
f5b210f028 Add CI and catalogue generation [mass update] 2023-01-20 10:45:33 -08:00
2d361c154a chore: publish 0.12.0+v6.68 release 2023-01-08 19:50:23 +01:00
7782fd4d56 chore: publish 0.11.0+v6.67 release 2023-01-06 10:49:38 +01:00
beac62e1c9 chore: publish 0.10.0+v6.60 release 2022-12-02 13:23:07 +01:00
75bfa3f489 chore: publish 0.9.0+v6.34 release 2022-08-08 11:15:10 +02:00
79a695c90a chore: publish 0.8.0+v6.31 release 2022-08-04 17:49:22 +02:00
e46525e512 chore: publish 0.7.0+v6.30 release 2022-07-21 13:58:26 +02:00
246a9229cb add mongodb replicaset mode 2022-06-22 15:04:19 +02:00
9224bb6238 chore: publish 0.6.0+v6.28 release 2022-06-22 13:54:25 +02:00
9f89d5d475 chore: publish 0.5.0+v6.20 release 2022-05-05 15:56:28 +02:00
d97a48af0e v6.20 2022-05-05 15:49:08 +02:00
9b49dad813 v6.12 2022-03-16 13:00:00 +01:00
3c88052a67 v6.12 2022-03-16 11:49:15 +01:00
ccf2c7e223 bump to v6.11 2022-03-07 14:31:35 +01:00
a6ce73bb5b add ldap 2022-03-02 14:31:26 +01:00
4275535838 update entrypoint 2022-03-02 14:28:17 +01:00
688429c257 update entrypoint 2022-02-17 10:22:28 +01:00
d71099a9dc chore: publish 0.2.0+v6.05 release 2022-02-08 09:38:57 +01:00
5ce2801951 chore: publish 0.1.1+v5.98 release 2022-02-04 13:43:45 +01:00
8 changed files with 232 additions and 38 deletions

41
.drone.yml Normal file
View File

@ -0,0 +1,41 @@
---
kind: pipeline
name: deploy to swarm-test.autonomic.zone
steps:
- name: deployment
image: git.coopcloud.tech/coop-cloud/stack-ssh-deploy:latest
settings:
host: swarm-test.autonomic.zone
stack: wekan
generate_secrets: true
purge: true
deploy_key:
from_secret: drone_ssh_swarm_test
networks:
- proxy
environment:
DOMAIN: wekan.swarm-test.autonomic.zone
STACK_NAME: wekan
LETS_ENCRYPT_ENV: production
SECRET_OAUTH2_SECRET_VERSION: v1
ENTRYPOINT_VERSION: v1
SECRET_OAUTH2_SECRET_VERSION: v1
trigger:
branch:
- main
---
kind: pipeline
name: generate recipe catalogue
steps:
- name: release a new version
image: plugins/downstream
settings:
server: https://build.coopcloud.tech
token:
from_secret: drone_abra-bot_token
fork: true
repositories:
- coop-cloud/auto-recipes-catalogue-json
trigger:
event: tag

View File

@ -1,31 +1,102 @@
TYPE=wekan
TIMEOUT=300
ENABLE_AUTO_UPDATE=true
LETS_ENCRYPT_ENV=production
SECRET_OAUTH2_SECRET_VERSION=v1
MONGO_URL=mongodb://db:27017/wekan
COMPOSE_FILE="compose.yml"
DOMAIN=board.example.com
ROOT_URL=https://board.example.com
# Set this to run mongodb in replicaset mode (needs initialisation!)
# COMPOSE_FILE="${COMPOSE_FILE}:compose.rs.yml"
DOMAIN=wekan.example.com
ROOT_URL=https://wekan.example.com
DEBUG=false
OAUTH2_ENABLED=true
OAUTH2_LOGIN_STYLE=redirect
OAUTH2_CLIENT_ID=wekan
OAUTH2_SERVER_URL=https://sso.example.com
OAUTH2_AUTH_ENDPOINT=/application/o/authorize/
OAUTH2_USERINFO_ENDPOINT=/application/o/userinfo/
OAUTH2_TOKEN_ENDPOINT=/application/o/token/
OAUTH2_REQUEST_PERMISSIONS="openid profile email wekan"
OAUTH2_ID_MAP=preferred_username
OAUTH2_USERNAME_MAP=preferred_username
OAUTH2_FULLNAME_MAP=given_name
OAUTH2_EMAIL_MAP=email
PASSWORD_LOGIN_ENABLED=false
MAIL_URL=smtp://smtp:25/?ignoreTLS=true&tls={rejectUnauthorized:false}
MAIL_FROM="[WeKan] Wekan Notifications <noreply@example.org>"
WITH_API=true
RICHER_CARD_COMMENT_EDITOR=false
RICHER_CARD_COMMENT_EDITOR=false
# CORS=*
# CORS_ALLOW_HEADERS=Authorization,Content-Type
# CORS_EXPOSE_HEADERS=*
# PASSWORD_LOGIN_ENABLED=false
### OAUTH2 ###
OAUTH2_ENABLED=false
# OAUTH2_LOGIN_STYLE=redirect
# OAUTH2_CLIENT_ID=wekan
# OAUTH2_SERVER_URL=https://authentik.example.com
# OAUTH2_AUTH_ENDPOINT=/application/o/authorize/
# OAUTH2_USERINFO_ENDPOINT=/application/o/userinfo/
# OAUTH2_TOKEN_ENDPOINT=/application/o/token/
# OAUTH2_REQUEST_PERMISSIONS="openid profile email wekan"
# OAUTH2_ID_MAP=preferred_username
# OAUTH2_USERNAME_MAP=preferred_username
# OAUTH2_FULLNAME_MAP=given_name
# OAUTH2_EMAIL_MAP=email
# PROPAGATE_OIDC_DATA=true
# OIDC_REDIRECTION_ENABLED=true
### LDAP ###
#COMPOSE_FILE="$COMPOSE_FILE:compose.ldap.yml"
# DEFAULT_AUTHENTICATION_METHOD=ldap
# LDAP_ENABLE=true
# LDAP_PORT=389
# LDAP_HOST=ldap.example.org
# LDAP_AD_SIMPLE_AUTH=false
# LDAP_USER_AUTHENTICATION=true
# LDAP_USER_AUTHENTICATION_FIELD=cn
# LDAP_DEFAULT_DOMAIN=mydomain.com
# LDAP_BASEDN=dc=ldap,dc=goauthentik,dc=io
# LDAP_LOGIN_FALLBACK=false
# LDAP_RECONNECT=true
# LDAP_TIMEOUT=10000
# LDAP_IDLE_TIMEOUT=10000
# LDAP_CONNECT_TIMEOUT=10000
# LDAP_AUTHENTIFICATION=true
# LDAP_AUTHENTIFICATION_USERDN=cn=admin,dc=ldap,dc=goauthentik,dc=io"
# LDAP_AUTHENTIFICATION_PASSWORD=secret
# LDAP_LOG_ENABLED=true
# LDAP_BACKGROUND_SYNC=true
# LDAP_BACKGROUND_SYNC_INTERVAL='every 1 hour'
# LDAP_BACKGROUND_SYNC_KEEP_EXISTANT_USERS_UPDATED=true
# LDAP_BACKGROUND_SYNC_IMPORT_NEW_USERS=true
# LDAP_ENCRYPTION=false
# LDAP_CA_CERT=-----BEGIN CERTIFICATE-----MIIE+G2FIdAgIC...-----END CERTIFICATE-----
# LDAP_REJECT_UNAUTHORIZED=false
# LDAP_USER_SEARCH_FILTER=
# LDAP_USER_SEARCH_SCOPE=ou=users,dc=ldap,dc=goauthentik,dc=io
# LDAP_USER_SEARCH_FIELD=cn
# LDAP_SEARCH_PAGE_SIZE=0
# LDAP_SEARCH_SIZE_LIMIT=0
# Enable group filtering. Note the authenticated ldap user must be able to query all relevant group data with own login data from ldap.
# LDAP_GROUP_FILTER_ENABLE=true
# LDAP_GROUP_FILTER_OBJECTCLASS=group
# LDAP_GROUP_FILTER_GROUP_ID_ATTRIBUTE=cn
# LDAP_GROUP_FILTER_GROUP_MEMBER_ATTRIBUTE=member
# LDAP_GROUP_FILTER_GROUP_MEMBER_FORMAT=dn
# LDAP_GROUP_FILTER_GROUP_NAME=
# LDAP_UNIQUE_IDENTIFIER_FIELD=guid
# LDAP_UTF8_NAMES_SLUGIFY=true
# LDAP_USERNAME_FIELD=cn
# LDAP_FULLNAME_FIELD=name
# LDAP_MERGE_EXISTING_USERS=true
# LDAP_EMAIL_MATCH_ENABLE=true
# LDAP_EMAIL_MATCH_REQUIRE=true
# LDAP_EMAIL_MATCH_VERIFIED=true
# LDAP_EMAIL_FIELD=mail
# LDAP_SYNC_USER_DATA=true
# LDAP_SYNC_USER_DATA_FIELDMAP={"cn":"name", "mail":"email"}
# LDAP_SYNC_GROUP_ROLES=
# LDAP_SYNC_ADMIN_STATUS=true
# LDAP_SYNC_ADMIN_GROUPS=admin

View File

@ -27,3 +27,15 @@ See original [docker-compose.yml](https://github.com/wekan/wekan/blob/master/doc
For more, see [`docs.coopcloud.tech`](https://docs.coopcloud.tech).
## use mongodb with replicaset
needed to enable oplog setting in wekan, which isneeded to run bigger instances?
after mongo conaintainer came up the first time run:
```
abra app run wekan.example.org db mongo
> rs.initiate()
```

View File

@ -1,2 +1 @@
export SECRET_OAUTH2_SECRET_VERSION=v1
export ENTRYPOINT_VERSION=v1
export ENTRYPOINT_VERSION=v2

54
compose.ldap.yml Normal file
View File

@ -0,0 +1,54 @@
version: "3.8"
services:
app:
environment:
- LDAP_ENABLE
- LDAP_PORT
- LDAP_HOST
- LDAP_AD_SIMPLE_AUTH
- LDAP_USER_AUTHENTICATION
- LDAP_USER_AUTHENTICATION_FIELD
- LDAP_DEFAULT_DOMAIN
- LDAP_BASEDN
- LDAP_LOGIN_FALLBACK
- LDAP_RECONNECT
- LDAP_TIMEOUT
- LDAP_IDLE_TIMEOUT
- LDAP_CONNECT_TIMEOUT
- LDAP_AUTHENTIFICATION
- LDAP_AUTHENTIFICATION_USERDN
- LDAP_AUTHENTIFICATION_PASSWORD
- LDAP_LOG_ENABLED
- LDAP_BACKGROUND_SYNC
- LDAP_BACKGROUND_SYNC_INTERVAL
- LDAP_BACKGROUND_SYNC_KEEP_EXISTANT_USERS_UPDATED
- LDAP_BACKGROUND_SYNC_IMPORT_NEW_USERS
- LDAP_ENCRYPTION
- LDAP_CA_CERT
- LDAP_REJECT_UNAUTHORIZED
- LDAP_USER_SEARCH_FILTER
- LDAP_USER_SEARCH_SCOPE
- LDAP_USER_SEARCH_FIELD
- LDAP_SEARCH_PAGE_SIZE
- LDAP_SEARCH_SIZE_LIMIT
- LDAP_GROUP_FILTER_ENABLE
- LDAP_GROUP_FILTER_OBJECTCLASS
- LDAP_GROUP_FILTER_GROUP_ID_ATTRIBUTE
- LDAP_GROUP_FILTER_GROUP_MEMBER_ATTRIBUTE
- LDAP_GROUP_FILTER_GROUP_MEMBER_FORMAT
- LDAP_GROUP_FILTER_GROUP_NAME
- LDAP_UNIQUE_IDENTIFIER_FIELD
- LDAP_UTF8_NAMES_SLUGIFY
- LDAP_USERNAME_FIELD
- LDAP_FULLNAME_FIELD
- LDAP_MERGE_EXISTING_USERS
- LDAP_EMAIL_MATCH_ENABLE
- LDAP_EMAIL_MATCH_REQUIRE
- LDAP_EMAIL_MATCH_VERIFIED
- LDAP_EMAIL_FIELD
- LDAP_SYNC_USER_DATA
- LDAP_SYNC_USER_DATA_FIELDMAP
- LDAP_SYNC_GROUP_ROLES
- LDAP_SYNC_ADMIN_STATUS
- LDAP_SYNC_ADMIN_GROUPS

10
compose.rs.yml Normal file
View File

@ -0,0 +1,10 @@
version: "3.8"
services:
db:
command: mongod --oplogSize 128 --replSet rs0
app:
environment:
- MONGO_URL=mongodb://db:27017/wekan?replicaSet=rs01
- MONGO_OPLOG_URL=mongodb://db:27017/local?replicaSet=rsWekan=value

View File

@ -1,8 +1,8 @@
version: '3.8'
services:
db:
image: mongo:4.4
command: mongod --logpath /dev/null --oplogSize 128 --quiet
image: mongo:5.0
command: mongod --oplogSize 128 --quiet
volumes:
- wekan-db:/data/db
networks:
@ -16,17 +16,25 @@ services:
deploy:
labels:
backupbot.backup: "true"
backupbot.backup.pre-hook: "mkdir /tmp/backup/ && mongodump --archive=/tmp/backup/wekan.db"
backupbot.backup.post-hook: "rm -rf /tmp/backup"
backupbot.backup.path: "/tmp/backup/"
backupbot.backup.pre-hook: "mongodump --archive=/data/db/wekan.db"
backupbot.backup.post-hook: "rm -rf /data/db/wekan.db"
backupbot.backup.path: "/data/db/wekan.db"
app:
image: quay.io/wekan/wekan:v5.99
image: quay.io/wekan/wekan:v6.99
environment:
- MONGO_URL
- MONGO_URL=mongodb://db:27017/wekan
- DOMAIN
- ROOT_URL
- DEBUG
- MAIL_URL
- MAIL_FROM
- WITH_API
- RICHER_CARD_COMMENT_EDITOR
- CORS
- CORS_ALLOW_HEADERS
- CORS_EXPOSE_HEADERS
- PASSWORD_LOGIN_ENABLED
- OAUTH2_ENABLED
- OAUTH2_LOGIN_STYLE
- OAUTH2_CLIENT_ID
@ -40,14 +48,12 @@ services:
- OAUTH2_USERNAME_MAP
- OAUTH2_FULLNAME_MAP
- OAUTH2_EMAIL_MAP
- PASSWORD_LOGIN_ENABLED
- MAIL_URL
- MAIL_FROM
- WITH_API
- RICHER_CARD_COMMENT_EDITOR
- DEFAULT_AUTHENTICATION_METHOD
- PROPAGATE_OIDC_DATA
- OIDC_REDIRECTION_ENABLED
networks:
- internal
- proxy
- internal
- proxy
depends_on:
- db
healthcheck:
@ -77,11 +83,12 @@ services:
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`)"
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "coop-cloud.${STACK_NAME}.version=0.1.0+v5.99"
- "coop-cloud.${STACK_NAME}.version=1.0.0+v6.99"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
volumes:
wekan-db:
networks:
proxy:
external: true

View File

@ -25,4 +25,4 @@ file_env() {
}
file_env "OAUTH2_SECRET"
node /build/main.js
bash -c "ulimit -s 65500; exec node --stack-size=65500 /build/main.js"