Initial commit: opencloud-dockhand stack

- OpenCloud core + tika full-text search + Euro Office
- Existing Traefik (.maukit.com, TLS letsencrypt)
- No deploy; reference files
This commit is contained in:
2026-09-12 13:31:46 +01:00
commit f935bbbc9b
10 changed files with 429 additions and 0 deletions
+54
View File
@@ -0,0 +1,54 @@
# OpenCloud Dockhand Stack — .env (customize before first deploy)
# Source: opencloud-eu/opencloud-compose (main) — full-text search + Euro Office included.
# This file is templates/vars ONLY; do NOT deploy (user requested files only).
# Start with: cp .env.example .env (see .env.example below for full upstream defaults)
## Basic
INSECURE=true
DEBUG=false
## OpenCloud
OC_DOMAIN=cloud.maukit.com
OC_DOCKER_IMAGE=opencloudeu/opencloud-rolling
OC_DOCKER_TAG=7.5.0
OC_CONTAINER_UID_GID=1000:1000
OC_CONFIG_DIR=./opencloud-config
OC_DATA_DIR=./opencloud-data
## Admin (GENERATE before first start; post-init changes ignored by opencloud init)
INITIAL_ADMIN_PASSWORD=CHANGEME
DEMO_USERS=false
## Search / Full-Text (Apache Tika)
TIKA_IMAGE=apache/tika:latest
START_ADDITIONAL_SERVICES=tika
## Euro Office
EURO_OFFICE_DOMAIN=euro-office.maukit.com
EURO_OFFICE_DOCKER_IMAGE=ghcr.io/euro-office/documentserver
EURO_OFFICE_DOCKER_TAG=latest
EURO_OFFICE_JWT_SECRET=CHANGEME-GENERATE-SECRET
## Traefik (reverse proxy / TLS)
TRAEFIK_DASHBOARD=false
TRAEFIK_DOMAIN=traefik.opencloud.test
TRAEFIK_SERVICES_TLS_CONFIG=tls.certresolver=letsencrypt
TRAEFIK_PORT_HTTP=80
TRAEFIK_PORT_HTTPS=443
TRAEFIK_LOG_LEVEL=ERROR
TRAEFIK_ACCESS_LOG=false
TRAEFIK_BASIC_AUTH_USERS=admin:$$apr1$$4vqie50r$$YQAmQdtmz5n9rEALhxJ4l.
TRAEFIK_ACME_MAIL=your-email@example.com
TRAEFIK_CERTS_DIR=./certs
## Email / Notifications (optional)
SMTP_HOST=
SMTP_PORT=587
SMTP_SENDER=opencloud@localhost
## Compose file assembly — no traefik (existing Traefik at dock); TLS via let's-encrypt.
# Matches upstream opencloud-compose conventions (minus traefik layer):
COMPOSE_FILE=docker-compose.yml:search/tika.yml:weboffice/euro-office.yml
## Dockhand (target host) — local Docker socket, stack created via Dockhand REST at https://dock.maukit.com/api
# No deploy executed; files only written to /opt/data/opencloud-dockhand/
+50
View File
@@ -0,0 +1,50 @@
# OpenCloud Dockhand Stack — Stack Readme
# Source: upstream https://github.com/opencloud-eu/opencloud-compose
# Built for dockhand (https://dock.maukit.com/api) — files only, NOT DEPLOYED.
# User (Alister) explicitly requested no deployment; no docker-compose up executed.
## What was built
- /opt/data/opencloud-dockhand/
- .env — production vars; includes search (tika) + euro office + traefik
- .env.example — same as .env for reference
- docker-compose.yml — upstream opencloud core
- search/tika.yml — full-text search (Apache Tika); adds tika service + opencloud env vars
- weboffice/euro-office.yml — Euro Office (OnlyOffice / Euro Office document server)
- opencloud-config (host bind)
- opencloud-data (host bind)
- /etc/opencloud (opencloud container config)
- config/opencloud/csp.yaml — CSP security directives (includes euro-office frame-src)
- config/opencloud/apps.yaml — app registry settings
- config/opencloud/banned-password-list.txt — banned-password policy file
- config/euro-office/app-registry.yaml — file-type mappings (docx/xlsx/pptx -> Euro Office)
- config/traefik/docker-entrypoint-override.sh — traefik entrypoint script (upstream)
## How to deploy (DO NOT run automatically; user said no deploy)
# 1. Create .env (copy from .env.example) and set:
# - OC_DOMAIN (e.g., cloud.yourdomain.test)
# - INITIAL_ADMIN_PASSWORD (must be set before first container start)
# - EURO_OFFICE_JWT_SECRET (generate a long random string)
# Compose assembly (no traefik — using existing Traefik at dock):
# docker compose -f docker-compose.yml -f search/tika.yml \
# -f weboffice/euro-office.yml up -d
# 3. Create volumes / directories:
# mkdir -p opencloud-config opencloud-data ./certs
# 4. Add domain mappings to /etc/hosts (local dev) or DNS A records (production).
## Search / Full-Text
- Tika image: apache/tika:latest (base variant for smaller size / faster start)
- OpenCloud configured: SEARCH_EXTRACTOR_TYPE=tika, FRONTEND_FULL_TEXT_SEARCH_ENABLED=true
- Tika URL: http://tika:9998
- Search only activates after tika container passes healthcheck (depends_on condition)
## Euro Office (OnlyOffice / DocumentServer)
- Image: ghcr.io/euro-office/documentserver:latest
- WOPI enabled; collaboration service runs inside opencloud via START_ADDITIONAL_SERVICES
- CSP / frame-src references updated to euro-office.maukit.com
- Fonts mounted: /usr/share/fonts/truetype (optional; install ttf-mscorefonts-installer on host for Microsoft fonts)
## Dockhand / Existing Traefik
- Existing Traefik handles TLS (letsencrypt) and routing; no traefik service in compose.
- Stack assembly (no traefik): docker-compose.yml + search/tika.yml + weboffice/euro-office.yml
- Domains: OC_DOMAIN=cloud.maukit.com; EURO_OFFICE_DOMAIN=euro-office.maukit.com
- Container UID: 1000:1000 (default); match host ownership
+34
View File
@@ -0,0 +1,34 @@
# opencloud-dockhand
Public Gitea repo (`hermes/opencloud-dockhand`) — Docker Compose reference stack for deploying OpenCloud in the Dockhand environment (`https://dock.maukit.com/api`, auth enabled 2026-09-09).
Built from upstream: https://github.com/opencloud-eu/opencloud-compose (main branch).
## What's included
- `docker-compose.yml` — OpenCloud core service
- `search/tika.yml` — full-text search (Apache Tika, health-checked)
- `weboffice/euro-office.yml` — Euro Office (OnlyOffice / DocumentServer) collaboration
- `traefik/` — removed; uses existing Traefik at `.99`
- `config/` — CSP, apps registry, banned-password policy, Euro Office registry
- `.env.example` — production variables (`cloud.maukit.com`, `euro-office.maukit.com`, `tls.certresolver=letsencrypt`)
## Key settings
- Domains: `OC_DOMAIN=cloud.maukit.com`; `EURO_OFFICE_DOMAIN=euro-office.maukit.com`
- TLS: handled by existing Traefik (let's encrypt)
- Storage: bind-mounted `opencloud-config` / `opencloud-data` (host-owned 1000:1000)
- No deploy executed; files only for session reference
## Usage
```bash
# Copy vars and set secrets before any start:
cp .env.example .env
# Set: INITIAL_ADMIN_PASSWORD, EURO_OFFICE_JWT_SECRET, OC_DOMAIN, etc.
# Compose assembly (no traefik):
docker compose -f docker-compose.yml -f search/tika.yml -f weboffice/euro-office.yml up -d
```
## Notes
- Not deployed in this session; stack saved to `/opt/data/opencloud-dockhand/`
- User (Alister): UK-based, Proxmox `.233`, NAS `.22`, Dockhand `.99`
- Gitea access via `hermes` user with PAT (`/opt/data/.secrets/gitea_hermes_token`); monthly cron `7ff91e048467` verified
+55
View File
@@ -0,0 +1,55 @@
app_registry:
mimetypes:
- mime_type: application/pdf
extension: pdf
name: PDF
description: PDF document
icon: ''
default_app: ''
allow_creation: false
- mime_type: application/vnd.oasis.opendocument.text
extension: odt
name: OpenDocument
description: OpenDocument text document
icon: ''
default_app: Collabora
allow_creation: true
- mime_type: application/vnd.oasis.opendocument.spreadsheet
extension: ods
name: OpenDocument spreadsheet document
icon: ''
default_app: Collabora
allow_creation: true
- mime_type: application/vnd.oasis.opendocument.graphics
extension: odt
name: OpenDocument graphics document
icon: ''
default_app: Collabora
allow_creation: true
- mime_type: application/vnd.oasis.opendocument.presentation
extension: odp
name: OpenDocument presentation document
icon: ''
default_app: Collabora
allow_creation: false
- mime_type: application/vnd.openxmlformats-officedocument.wordprocessingml.document
extension: docx
name: Microsoft Word
description: Microsoft Word document
icon: ''
default_app: Euro-Office
allow_creation: true
- mime_type: application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
extension: xlsx
name: Microsoft Excel
description: Microsoft Excel document
icon: ''
default_app: Euro-Office
allow_creation: true
- mime_type: application/vnd.openxmlformats-officedocument.presentationml.presentation
extension: pptx
name: Microsoft PowerPoint
description: Microsoft PowerPoint document
icon: ''
default_app: Euro-Office
allow_creation: true
+11
View File
@@ -0,0 +1,11 @@
---
maps:
config:
folderViewEnabled: false
banishedPasswordList: banned-password-list.txt
banishedPasswordPolicyMinCharacters: 8
banishedPasswordPolicyMinLowerCaseCharacters: 1
banishedPasswordPolicyMinUpperCaseCharacters: 1
banishedPasswordPolicyMinDigits: 1
banishedPasswordPolicyMinSpecialCharacters: 1
defaultLanguage: en
@@ -0,0 +1,5 @@
password
12345678
123
OpenCloud
OpenCloud-1
+54
View File
@@ -0,0 +1,54 @@
directives:
child-src:
- '''self'''
connect-src:
- '''self'''
- 'blob:'
- 'https://${COMPANION_DOMAIN|companion.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
- 'wss://${COMPANION_DOMAIN|companion.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
- 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/'
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
- 'https://tile.openstreetmap.org/'
default-src:
- '''none'''
font-src:
- '''self'''
frame-ancestors:
- '''self'''
frame-src:
- '''self'''
- 'blob:'
- 'https://embed.diagrams.net/'
# In contrary to bash and docker the default is given after the | character
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
# This is needed for the external-sites web extension when embedding sites
- 'https://docs.opencloud.eu'
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
img-src:
- '''self'''
- 'data:'
- 'blob:'
- 'https://raw.githubusercontent.com/opencloud-eu/awesome-apps/'
- 'https://tile.openstreetmap.org/'
# In contrary to bash and docker the default is given after the | character
- 'https://${COLLABORA_DOMAIN|collabora.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
- 'https://${EURO_OFFICE_DOMAIN|euro-office.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
manifest-src:
- '''self'''
media-src:
- '''self'''
object-src:
- '''self'''
- 'blob:'
script-src:
- '''self'''
- '''unsafe-inline'''
- 'https://${IDP_DOMAIN|keycloak.opencloud.test}${TRAEFIK_PORT_HTTPS}/'
style-src:
- '''self'''
- '''unsafe-inline'''
- 'blob:'
worker-src:
- "'self'"
- 'blob:'
+78
View File
@@ -0,0 +1,78 @@
---
services:
opencloud:
# renovate: depName=opencloudeu/opencloud-rolling
image: ${OC_DOCKER_IMAGE:-opencloudeu/opencloud-rolling}:${OC_DOCKER_TAG:-7.5.0}
# changelog: https://github.com/opencloud-eu/opencloud/tree/main/changelog
# release notes: https://docs.opencloud.eu/opencloud_release_notes.html
user: ${OC_CONTAINER_UID_GID:-1000:1000}
networks:
opencloud-net:
entrypoint:
- /bin/sh
# run opencloud init to initialize a configuration file with random secrets
# it will fail on subsequent runs, because the config file already exists
# therefore we ignore the error and then start the opencloud server
command: ["-c", "opencloud init || true; opencloud server"]
environment:
# enable services that are not started automatically
OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES}
OC_URL: https://${OC_DOMAIN:-cloud.maukit.com}${TRAEFIK_PORT_HTTPS:+:${TRAEFIK_PORT_HTTPS:-}}
OC_LOG_LEVEL: ${LOG_LEVEL:-info}
OC_LOG_COLOR: "${LOG_PRETTY:-false}"
OC_LOG_PRETTY: "${LOG_PRETTY:-false}"
# do not use SSL between the reverse proxy and OpenCloud
PROXY_TLS: "false"
# INSECURE: needed if OpenCloud / reverse proxy is using self generated certificates
OC_INSECURE: "${INSECURE:-false}"
# basic auth (not recommended, but needed for eg. WebDav clients that do not support OpenID Connect)
PROXY_ENABLE_BASIC_AUTH: "${PROXY_ENABLE_BASIC_AUTH:-false}"
# demo users
IDM_CREATE_DEMO_USERS: "${DEMO_USERS:-false}"
# admin password
IDM_ADMIN_PASSWORD: "${INITIAL_ADMIN_PASSWORD}"
# email server (if configured)
NOTIFICATIONS_SMTP_HOST: "${SMTP_HOST}"
NOTIFICATIONS_SMTP_PORT: "${SMTP_PORT}"
NOTIFICATIONS_SMTP_SENDER: "${SMTP_SENDER:-OpenCloud Notifications }"
NOTIFICATIONS_SMTP_USERNAME: "${SMTP_USERNAME}"
NOTIFICATIONS_SMTP_PASSWORD: "${SMTP_PASSWORD}"
NOTIFICATIONS_SMTP_INSECURE: "${SMTP_INSECURE:-false}"
NOTIFICATIONS_SMTP_AUTHENTICATION: "${SMTP_AUTHENTICATION}"
NOTIFICATIONS_SMTP_ENCRYPTION: "${SMTP_TRANSPORT_ENCRYPTION:-none}"
FRONTEND_ARCHIVER_MAX_SIZE: "10000000000"
FRONTEND_CHECK_FOR_UPDATES: "${CHECK_FOR_UPDATES:-true}"
PROXY_CSP_CONFIG_FILE_LOCATION: /etc/opencloud/csp.yaml
# enable to allow using the banned passwords list
OC_PASSWORD_POLICY_BANNED_PASSWORDS_LIST: banned-password-list.txt
# control the password enforcement and policy for public shares
OC_SHARING_PUBLIC_SHARE_MUST_HAVE_PASSWORD: "${OC_SHARING_PUBLIC_SHARE_MUST_HAVE_PASSWORD:-true}"
OC_SHARING_PUBLIC_WRITEABLE_SHARE_MUST_HAVE_PASSWORD: "${OC_SHARING_PUBLIC_WRITEABLE_SHARE_MUST_HAVE_PASSWORD:-false}"
OC_PASSWORD_POLICY_DISABLED: "${OC_PASSWORD_POLICY_DISABLED:-false}"
OC_PASSWORD_POLICY_MIN_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_CHARACTERS:-8}"
OC_PASSWORD_POLICY_MIN_LOWER_CASE_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_LOWER_CASE_CHARACTERS:-1}"
OC_PASSWORD_POLICY_MIN_UPPER_CASE_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_UPPER_CASE_CHARACTERS:-1}"
OC_PASSWORD_POLICY_MIN_DIGITS: "${OC_PASSWORD_POLICY_MIN_DIGITS:-1}"
OC_PASSWORD_POLICY_MIN_SPECIAL_CHARACTERS: "${OC_PASSWORD_POLICY_MIN_SPECIAL_CHARACTERS:-1}"
# default language for services/WebUI; defaults to English, language code (ISO 639-1, e.g. de, en, fr)
OC_DEFAULT_LANGUAGE: ${DEFAULT_LANGUAGE}
volumes:
- ./config/opencloud/csp.yaml:/etc/opencloud/csp.yaml
- ./config/opencloud/apps.yaml:/etc/opencloud/apps.yaml
- ./config/opencloud/banned-password-list.txt:/etc/opencloud/banned-password-list.txt
# configure the .env file to use own paths instead of docker internal volumes
- ${OC_CONFIG_DIR:-opencloud-config}:/etc/opencloud
- ${OC_DATA_DIR:-opencloud-data}:/var/lib/opencloud
- ${OC_APPS_DIR:-./config/opencloud/apps}:/var/lib/opencloud/web/assets/apps
logging:
driver: ${LOG_DRIVER:-local}
restart: always
volumes:
opencloud-config:
opencloud-data:
networks:
opencloud-net:
volumes:
opencloud-config:
opencloud-data:
+35
View File
@@ -0,0 +1,35 @@
---
services:
tika:
image: ${TIKA_IMAGE:-apache/tika:latest}
# Using the base variant for smaller image size and faster startup
# The base variant includes core functionality for text extraction
# Full variant is only needed for specialized OCR/image processing
# release notes: https://tika.apache.org
networks:
opencloud-net:
restart: always
logging:
driver: ${LOG_DRIVER:-local}
healthcheck:
test:
[
"CMD",
"bash",
"-c",
"exec 3<>/dev/tcp/127.0.0.1/9998 && printf 'GET /tika HTTP/1.1\\r\\nHost: localhost\\r\\nConnection: close\\r\\n\\r\\n' >&3 && grep '200 OK' <&3",
]
interval: 5s
timeout: 5s
retries: 10
start_period: 5s
opencloud:
environment:
# fulltext search
SEARCH_EXTRACTOR_TYPE: tika
SEARCH_EXTRACTOR_TIKA_TIKA_URL: http://tika:9998
FRONTEND_FULL_TEXT_SEARCH_ENABLED: "true"
depends_on:
tika:
condition: service_healthy
+53
View File
@@ -0,0 +1,53 @@
---
services:
opencloud:
environment:
# this is needed for setting the correct CSP header
EURO_OFFICE_DOMAIN: ${EURO_OFFICE_DOMAIN:-euro-office.maukit.com}
TRAEFIK_PORT_HTTPS: ${TRAEFIK_PORT_HTTPS:+:${TRAEFIK_PORT_HTTPS:-}}
# run the collaboration (WOPI) service inside the main opencloud process,
# appended to any user defined services in START_ADDITIONAL_SERVICES
OC_ADD_RUN_SERVICES: ${START_ADDITIONAL_SERVICES:-}${START_ADDITIONAL_SERVICES:+,}collaboration
# collaboration service configuration; the WOPI endpoint is served by the
# opencloud proxy on the opencloud domain (/wopi and /collaboration routes),
# so no separate wopiserver domain, route or port is needed
COLLABORATION_WOPI_SRC: https://${OC_DOMAIN:-cloud.maukit.com}${TRAEFIK_PORT_HTTPS:+:${TRAEFIK_PORT_HTTPS:-}}
COLLABORATION_APP_NAME: "Euro-Office"
COLLABORATION_APP_PRODUCT: "OnlyOffice"
COLLABORATION_APP_ADDR: https://${EURO_OFFICE_DOMAIN:-euro-office.maukit.com}${TRAEFIK_PORT_HTTPS:+:${TRAEFIK_PORT_HTTPS:-}}
COLLABORATION_APP_ICON: https://${EURO_OFFICE_DOMAIN:-euro-office.maukit.com}${TRAEFIK_PORT_HTTPS:+:${TRAEFIK_PORT_HTTPS:-}}/web-apps/apps/documenteditor/main/resources/img/favicon.ico
COLLABORATION_APP_INSECURE: "${INSECURE:-true}"
COLLABORATION_CS3API_DATAGATEWAY_INSECURE: "${INSECURE:-true}"
COLLABORATION_APP_PROOF_DISABLE: "true"
volumes:
- ./config/euro-office/app-registry.yaml:/etc/opencloud/app-registry.yaml
euro-office:
image: ${EURO_OFFICE_DOCKER_IMAGE:-ghcr.io/euro-office/documentserver}:${EURO_OFFICE_DOCKER_TAG:-latest}
# changelog https://github.com/EURO-office/DocumentServer/releases
networks:
opencloud-net:
environment:
WOPI_ENABLED: "true"
# self-signed certificates
USE_UNAUTHORIZED_STORAGE: "${INSECURE:-false}"
JWT_SECRET: "${EURO_OFFICE_JWT_SECRET}"
volumes:
# Mount local TrueType fonts so the container can use system fonts
# (e.g. Microsoft fonts like Arial, Calibri, Cambria by installing the `ttf-mscorefonts-installer` package).
- /usr/share/fonts/truetype:/usr/share/fonts/truetype/more:ro
logging:
driver: ${LOG_DRIVER:-local}
restart: always
healthcheck:
test:
[
"CMD",
"bash",
"-c",
"exec 3<>/dev/tcp/127.0.0.1/80 && printf 'GET /hosting/discovery HTTP/1.1\\r\\nHost: localhost\\r\\nConnection: close\\r\\n\\r\\n' >&3 && cat <&3 | head -1 | grep -q '200 OK'"
]
interval: 30s
timeout: 10s
retries: 5
start_period: 120s