feat: domain list refactor + demo-gymburgdorf fixes
- Refactor: collapse `*_domain` + `*_extra_domains` into a single `*_domains` list across authentik, collabora, garage and nextcloud roles. First entry is the canonical FQDN (used for OVERWRITEHOST, BASE_URL, notify_push setup and garage root_domain). - Authentik blueprint: guard the OAuth sources block so an empty `authentik_login_sources` no longer renders an invalid YAML key. - Nextcloud: introduce `nextcloud_collabora_public_domain` and set Collabora's `public_wopi_url` separately from the server-to-server `wopi_url` so browsers can reach Collabora via the public name while Nextcloud still talks to it on the internal one. - Nextcloud: URL-encode the postgres user/password in DATABASE_URL.
This commit is contained in:
parent
78095cca1d
commit
36e3a4b688
12 changed files with 64 additions and 15 deletions
|
|
@ -12,7 +12,11 @@ authentik_docker_compose_dir: "{{ docker_compose_base_dir }}/{{ authentik_servic
|
||||||
authentik_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ authentik_service_name }}"
|
authentik_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ authentik_service_name }}"
|
||||||
|
|
||||||
# Authentik service configuration
|
# Authentik service configuration
|
||||||
authentik_domain: "authentik.local.test"
|
# FQDNs the authentik router accepts. The first entry is the canonical
|
||||||
|
# domain; further entries cover internal *.int.* names used for
|
||||||
|
# server-to-server traffic so backend calls don't hairpin via DMZ.
|
||||||
|
authentik_domains:
|
||||||
|
- "authentik.local.test"
|
||||||
authentik_image: "ghcr.io/goauthentik/server:2026.2.2"
|
authentik_image: "ghcr.io/goauthentik/server:2026.2.2"
|
||||||
authentik_port: 9000
|
authentik_port: 9000
|
||||||
authentik_secret_key: "changeme-generate-a-random-string"
|
authentik_secret_key: "changeme-generate-a-random-string"
|
||||||
|
|
|
||||||
|
|
@ -16,8 +16,10 @@ entries:
|
||||||
{% for field in authentik_login_user_fields %}
|
{% for field in authentik_login_user_fields %}
|
||||||
- {{ field }}
|
- {{ field }}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
{% if authentik_login_sources %}
|
||||||
# OAuth/social login sources (use !Find to reference sources from other blueprints)
|
# OAuth/social login sources (use !Find to reference sources from other blueprints)
|
||||||
sources:
|
sources:
|
||||||
{% for src in authentik_login_sources %}
|
{% for src in authentik_login_sources %}
|
||||||
- !Find [authentik_sources_oauth.oauthsource, [slug, {{ src.slug }}]]
|
- !Find [authentik_sources_oauth.oauthsource, [slug, {{ src.slug }}]]
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
|
||||||
|
|
@ -48,10 +48,13 @@ services:
|
||||||
labels:
|
labels:
|
||||||
- traefik.enable=true
|
- traefik.enable=true
|
||||||
- traefik.docker.network={{ authentik_traefik_network }}
|
- traefik.docker.network={{ authentik_traefik_network }}
|
||||||
- traefik.http.routers.{{ authentik_service_name }}.rule=Host(`{{ authentik_domain }}`)
|
- traefik.http.routers.{{ authentik_service_name }}.rule=Host({% for d in authentik_domains %}`{{ d }}`{% if not loop.last %}, {% endif %}{% endfor %})
|
||||||
{% if authentik_use_ssl %}
|
{% if authentik_use_ssl %}
|
||||||
- traefik.http.routers.{{ authentik_service_name }}.entrypoints=websecure
|
- traefik.http.routers.{{ authentik_service_name }}.entrypoints=websecure
|
||||||
- traefik.http.routers.{{ authentik_service_name }}.tls=true
|
- traefik.http.routers.{{ authentik_service_name }}.tls=true
|
||||||
|
{% if traefik_cert_mode | default('selfsigned') == 'acme' %}
|
||||||
|
- traefik.http.routers.{{ authentik_service_name }}.tls.certresolver={{ traefik_ssl_cert_resolver | default('dns') }}
|
||||||
|
{% endif %}
|
||||||
{% else %}
|
{% else %}
|
||||||
- traefik.http.routers.{{ authentik_service_name }}.entrypoints=web
|
- traefik.http.routers.{{ authentik_service_name }}.entrypoints=web
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
|
||||||
|
|
@ -12,7 +12,11 @@ collabora_docker_compose_dir: "{{ docker_compose_base_dir }}/{{ collabora_servic
|
||||||
collabora_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ collabora_service_name }}"
|
collabora_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ collabora_service_name }}"
|
||||||
|
|
||||||
# Service configuration
|
# Service configuration
|
||||||
collabora_domain: "office.local.test"
|
# FQDNs the collabora router accepts. The first entry is the canonical
|
||||||
|
# domain; further entries cover internal *.int.* names used for
|
||||||
|
# server-to-server WOPI discovery.
|
||||||
|
collabora_domains:
|
||||||
|
- "office.local.test"
|
||||||
collabora_image: "collabora/code:latest"
|
collabora_image: "collabora/code:latest"
|
||||||
collabora_port: 9980
|
collabora_port: 9980
|
||||||
collabora_extra_hosts: []
|
collabora_extra_hosts: []
|
||||||
|
|
|
||||||
|
|
@ -20,11 +20,14 @@ services:
|
||||||
labels:
|
labels:
|
||||||
- traefik.enable=true
|
- traefik.enable=true
|
||||||
- traefik.docker.network={{ collabora_traefik_network }}
|
- traefik.docker.network={{ collabora_traefik_network }}
|
||||||
- traefik.http.routers.{{ collabora_service_name }}.rule=Host(`{{ collabora_domain }}`)
|
- traefik.http.routers.{{ collabora_service_name }}.rule=Host({% for d in collabora_domains %}`{{ d }}`{% if not loop.last %}, {% endif %}{% endfor %})
|
||||||
- traefik.http.services.{{ collabora_service_name }}.loadbalancer.server.port={{ collabora_port }}
|
- traefik.http.services.{{ collabora_service_name }}.loadbalancer.server.port={{ collabora_port }}
|
||||||
{% if collabora_use_ssl %}
|
{% if collabora_use_ssl %}
|
||||||
- traefik.http.routers.{{ collabora_service_name }}.entrypoints=websecure
|
- traefik.http.routers.{{ collabora_service_name }}.entrypoints=websecure
|
||||||
- traefik.http.routers.{{ collabora_service_name }}.tls=true
|
- traefik.http.routers.{{ collabora_service_name }}.tls=true
|
||||||
|
{% if traefik_cert_mode | default('selfsigned') == 'acme' %}
|
||||||
|
- traefik.http.routers.{{ collabora_service_name }}.tls.certresolver={{ traefik_ssl_cert_resolver | default('dns') }}
|
||||||
|
{% endif %}
|
||||||
{% else %}
|
{% else %}
|
||||||
- traefik.http.routers.{{ collabora_service_name }}.entrypoints=web
|
- traefik.http.routers.{{ collabora_service_name }}.entrypoints=web
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
|
||||||
|
|
@ -13,7 +13,11 @@ garage_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ garage_service_name }
|
||||||
|
|
||||||
# Garage service configuration
|
# Garage service configuration
|
||||||
garage_image: "dxflrs/garage:v2.1.0"
|
garage_image: "dxflrs/garage:v2.1.0"
|
||||||
garage_s3_domain: "storage.local.test"
|
# FQDNs the garage S3 router accepts. The first entry is the canonical
|
||||||
|
# domain and is also used as the virtual-hosted-style root_domain in
|
||||||
|
# garage.toml; further entries cover internal *.int.* names.
|
||||||
|
garage_s3_domains:
|
||||||
|
- "storage.local.test"
|
||||||
garage_web_domain: "web.storage.local.test"
|
garage_web_domain: "web.storage.local.test"
|
||||||
garage_webui_domain: "console.storage.local.test"
|
garage_webui_domain: "console.storage.local.test"
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -14,10 +14,13 @@ services:
|
||||||
- traefik.enable=true
|
- traefik.enable=true
|
||||||
- traefik.docker.network={{ garage_traefik_network }}
|
- traefik.docker.network={{ garage_traefik_network }}
|
||||||
# S3 API endpoint
|
# S3 API endpoint
|
||||||
- traefik.http.routers.{{ garage_service_name }}.rule=Host(`{{ garage_s3_domain }}`)
|
- traefik.http.routers.{{ garage_service_name }}.rule=Host({% for d in garage_s3_domains %}`{{ d }}`{% if not loop.last %}, {% endif %}{% endfor %})
|
||||||
{% if garage_use_ssl %}
|
{% if garage_use_ssl %}
|
||||||
- traefik.http.routers.{{ garage_service_name }}.entrypoints=websecure
|
- traefik.http.routers.{{ garage_service_name }}.entrypoints=websecure
|
||||||
- traefik.http.routers.{{ garage_service_name }}.tls=true
|
- traefik.http.routers.{{ garage_service_name }}.tls=true
|
||||||
|
{% if traefik_cert_mode | default('selfsigned') == 'acme' %}
|
||||||
|
- traefik.http.routers.{{ garage_service_name }}.tls.certresolver={{ traefik_ssl_cert_resolver | default('dns') }}
|
||||||
|
{% endif %}
|
||||||
{% else %}
|
{% else %}
|
||||||
- traefik.http.routers.{{ garage_service_name }}.entrypoints=web
|
- traefik.http.routers.{{ garage_service_name }}.entrypoints=web
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
@ -48,6 +51,9 @@ services:
|
||||||
{% if garage_use_ssl %}
|
{% if garage_use_ssl %}
|
||||||
- traefik.http.routers.{{ garage_service_name }}-console.entrypoints=websecure
|
- traefik.http.routers.{{ garage_service_name }}-console.entrypoints=websecure
|
||||||
- traefik.http.routers.{{ garage_service_name }}-console.tls=true
|
- traefik.http.routers.{{ garage_service_name }}-console.tls=true
|
||||||
|
{% if traefik_cert_mode | default('selfsigned') == 'acme' %}
|
||||||
|
- traefik.http.routers.{{ garage_service_name }}-console.tls.certresolver={{ traefik_ssl_cert_resolver | default('dns') }}
|
||||||
|
{% endif %}
|
||||||
{% else %}
|
{% else %}
|
||||||
- traefik.http.routers.{{ garage_service_name }}-console.entrypoints=web
|
- traefik.http.routers.{{ garage_service_name }}-console.entrypoints=web
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
|
||||||
|
|
@ -14,7 +14,7 @@ rpc_secret = "{{ garage_rpc_secret }}"
|
||||||
[s3_api]
|
[s3_api]
|
||||||
s3_region = "{{ garage_s3_region }}"
|
s3_region = "{{ garage_s3_region }}"
|
||||||
api_bind_addr = "[::]:{{ garage_s3_api_port }}"
|
api_bind_addr = "[::]:{{ garage_s3_api_port }}"
|
||||||
root_domain = ".s3.{{ garage_s3_domain }}"
|
root_domain = ".s3.{{ garage_s3_domains[0] }}"
|
||||||
|
|
||||||
[s3_web]
|
[s3_web]
|
||||||
bind_addr = "[::]:{{ garage_s3_web_port }}"
|
bind_addr = "[::]:{{ garage_s3_web_port }}"
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,12 @@ nextcloud_service_name: nextcloud
|
||||||
nextcloud_docker_compose_dir: "{{ docker_compose_base_dir }}/{{ nextcloud_service_name }}"
|
nextcloud_docker_compose_dir: "{{ docker_compose_base_dir }}/{{ nextcloud_service_name }}"
|
||||||
nextcloud_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ nextcloud_service_name }}"
|
nextcloud_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ nextcloud_service_name }}"
|
||||||
|
|
||||||
nextcloud_domain: "nextcloud.local.test"
|
# FQDNs the nextcloud router accepts. The first entry is the canonical
|
||||||
|
# domain (used for OVERWRITEHOST and the notify_push setup); further
|
||||||
|
# entries cover internal *.int.* names so collabora's WOPI callback
|
||||||
|
# hits us on a name with a valid cert.
|
||||||
|
nextcloud_domains:
|
||||||
|
- "nextcloud.local.test"
|
||||||
nextcloud_image: "nextcloud:fpm"
|
nextcloud_image: "nextcloud:fpm"
|
||||||
nextcloud_redis_image: "redis:latest"
|
nextcloud_redis_image: "redis:latest"
|
||||||
nextcloud_port: 80
|
nextcloud_port: 80
|
||||||
|
|
|
||||||
|
|
@ -1,11 +1,17 @@
|
||||||
#SPDX-License-Identifier: MIT-0
|
#SPDX-License-Identifier: MIT-0
|
||||||
---
|
---
|
||||||
# tasks file for configuring Collabora in Nextcloud
|
# tasks file for configuring Collabora in Nextcloud
|
||||||
- name: Configure Collabora WOPI URL
|
- name: Configure Collabora WOPI URL (server-to-server)
|
||||||
community.docker.docker_container_exec:
|
community.docker.docker_container_exec:
|
||||||
container: "{{ nextcloud_docker_compose_dir | basename }}-nextcloud-1"
|
container: "{{ nextcloud_docker_compose_dir | basename }}-nextcloud-1"
|
||||||
command: php /var/www/html/occ config:app:set richdocuments wopi_url --value=https://{{ nextcloud_collabora_domain }}
|
command: php /var/www/html/occ config:app:set richdocuments wopi_url --value=https://{{ nextcloud_collabora_domain }}
|
||||||
|
|
||||||
|
- name: Configure Collabora public WOPI URL (browser-facing)
|
||||||
|
community.docker.docker_container_exec:
|
||||||
|
container: "{{ nextcloud_docker_compose_dir | basename }}-nextcloud-1"
|
||||||
|
command: php /var/www/html/occ config:app:set richdocuments public_wopi_url --value=https://{{ nextcloud_collabora_public_domain }}
|
||||||
|
when: nextcloud_collabora_public_domain is defined and nextcloud_collabora_public_domain != nextcloud_collabora_domain
|
||||||
|
|
||||||
- name: Configure certificate verification for Collabora
|
- name: Configure certificate verification for Collabora
|
||||||
community.docker.docker_container_exec:
|
community.docker.docker_container_exec:
|
||||||
container: "{{ nextcloud_docker_compose_dir | basename }}-nextcloud-1"
|
container: "{{ nextcloud_docker_compose_dir | basename }}-nextcloud-1"
|
||||||
|
|
|
||||||
|
|
@ -5,4 +5,4 @@
|
||||||
- name: Configure notify_push base endpoint
|
- name: Configure notify_push base endpoint
|
||||||
community.docker.docker_container_exec:
|
community.docker.docker_container_exec:
|
||||||
container: "{{ nextcloud_docker_compose_dir | basename }}-nextcloud-1"
|
container: "{{ nextcloud_docker_compose_dir | basename }}-nextcloud-1"
|
||||||
command: php /var/www/html/occ notify_push:setup https://{{ nextcloud_domain }}/push
|
command: php /var/www/html/occ notify_push:setup https://{{ nextcloud_domains[0] }}/push
|
||||||
|
|
@ -35,10 +35,13 @@ services:
|
||||||
labels:
|
labels:
|
||||||
- traefik.enable=true
|
- traefik.enable=true
|
||||||
- traefik.docker.network={{ nextcloud_traefik_network }}
|
- traefik.docker.network={{ nextcloud_traefik_network }}
|
||||||
- traefik.http.routers.{{ nextcloud_service_name }}.rule=Host(`{{ nextcloud_domain }}`)
|
- traefik.http.routers.{{ nextcloud_service_name }}.rule=Host({% for d in nextcloud_domains %}`{{ d }}`{% if not loop.last %}, {% endif %}{% endfor %})
|
||||||
{% if nextcloud_use_ssl %}
|
{% if nextcloud_use_ssl %}
|
||||||
- traefik.http.routers.{{ nextcloud_service_name }}.entrypoints=websecure
|
- traefik.http.routers.{{ nextcloud_service_name }}.entrypoints=websecure
|
||||||
- traefik.http.routers.{{ nextcloud_service_name }}.tls=true
|
- traefik.http.routers.{{ nextcloud_service_name }}.tls=true
|
||||||
|
{% if traefik_cert_mode | default('selfsigned') == 'acme' %}
|
||||||
|
- traefik.http.routers.{{ nextcloud_service_name }}.tls.certresolver={{ traefik_ssl_cert_resolver | default('dns') }}
|
||||||
|
{% endif %}
|
||||||
{% else %}
|
{% else %}
|
||||||
- traefik.http.routers.{{ nextcloud_service_name }}.entrypoints=web
|
- traefik.http.routers.{{ nextcloud_service_name }}.entrypoints=web
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
@ -60,7 +63,7 @@ services:
|
||||||
PHP_MEMORY_LIMIT: {{ nextcloud_memory_limit_mb }}M
|
PHP_MEMORY_LIMIT: {{ nextcloud_memory_limit_mb }}M
|
||||||
PHP_UPLOAD_LIMIT: {{ nextcloud_upload_limit_mb }}M
|
PHP_UPLOAD_LIMIT: {{ nextcloud_upload_limit_mb }}M
|
||||||
OVERWRITEPROTOCOL: https
|
OVERWRITEPROTOCOL: https
|
||||||
OVERWRITEHOST: {{ nextcloud_domain }}
|
OVERWRITEHOST: {{ nextcloud_domains[0] }}
|
||||||
TRUSTED_PROXIES: "{{ nextcloud_trusted_proxies }}"
|
TRUSTED_PROXIES: "{{ nextcloud_trusted_proxies }}"
|
||||||
volumes:
|
volumes:
|
||||||
- {{ nextcloud_docker_volume_dir }}/nextcloud/:/var/www/html
|
- {{ nextcloud_docker_volume_dir }}/nextcloud/:/var/www/html
|
||||||
|
|
@ -69,6 +72,12 @@ services:
|
||||||
{% for net in nextcloud_extra_networks %}
|
{% for net in nextcloud_extra_networks %}
|
||||||
- {{ net }}
|
- {{ net }}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
{% if nextcloud_extra_hosts is defined and nextcloud_extra_hosts | length > 0 %}
|
||||||
|
extra_hosts:
|
||||||
|
{% for host in nextcloud_extra_hosts %}
|
||||||
|
- "{{ host }}"
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
nextcloud:
|
nextcloud:
|
||||||
image: {{ nextcloud_image }}
|
image: {{ nextcloud_image }}
|
||||||
|
|
@ -88,7 +97,7 @@ services:
|
||||||
PHP_MEMORY_LIMIT: {{ nextcloud_memory_limit_mb }}M
|
PHP_MEMORY_LIMIT: {{ nextcloud_memory_limit_mb }}M
|
||||||
PHP_UPLOAD_LIMIT: {{ nextcloud_upload_limit_mb }}M
|
PHP_UPLOAD_LIMIT: {{ nextcloud_upload_limit_mb }}M
|
||||||
OVERWRITEPROTOCOL: https
|
OVERWRITEPROTOCOL: https
|
||||||
OVERWRITEHOST: {{ nextcloud_domain }}
|
OVERWRITEHOST: {{ nextcloud_domains[0] }}
|
||||||
TRUSTED_PROXIES: "{{ nextcloud_trusted_proxies }}"
|
TRUSTED_PROXIES: "{{ nextcloud_trusted_proxies }}"
|
||||||
{% if nextcloud_use_s3_storage %}
|
{% if nextcloud_use_s3_storage %}
|
||||||
OBJECTSTORE_S3_KEY: {{ nextcloud_s3_key }}
|
OBJECTSTORE_S3_KEY: {{ nextcloud_s3_key }}
|
||||||
|
|
@ -127,7 +136,7 @@ services:
|
||||||
environment:
|
environment:
|
||||||
PORT: "7867"
|
PORT: "7867"
|
||||||
REDIS_URL: "redis://redis:6379"
|
REDIS_URL: "redis://redis:6379"
|
||||||
DATABASE_URL: "postgres://{{ nextcloud_postgres_user }}:{{ nextcloud_postgres_password }}@db:5432/{{ nextcloud_postgres_db }}"
|
DATABASE_URL: "postgres://{{ nextcloud_postgres_user | urlencode }}:{{ nextcloud_postgres_password | urlencode }}@db:5432/{{ nextcloud_postgres_db }}"
|
||||||
DATABASE_PREFIX: "oc_"
|
DATABASE_PREFIX: "oc_"
|
||||||
NEXTCLOUD_URL: "http://nginx"
|
NEXTCLOUD_URL: "http://nginx"
|
||||||
networks:
|
networks:
|
||||||
|
|
@ -136,11 +145,14 @@ services:
|
||||||
labels:
|
labels:
|
||||||
- traefik.enable=true
|
- traefik.enable=true
|
||||||
- traefik.docker.network={{ nextcloud_traefik_network }}
|
- traefik.docker.network={{ nextcloud_traefik_network }}
|
||||||
- traefik.http.routers.{{ nextcloud_service_name }}-push.rule=Host(`{{ nextcloud_domain }}`) && PathPrefix(`/push`)
|
- traefik.http.routers.{{ nextcloud_service_name }}-push.rule=Host(`{{ nextcloud_domains[0] }}`) && PathPrefix(`/push`)
|
||||||
- traefik.http.services.{{ nextcloud_service_name }}-push.loadbalancer.server.port=7867
|
- traefik.http.services.{{ nextcloud_service_name }}-push.loadbalancer.server.port=7867
|
||||||
{% if nextcloud_use_ssl %}
|
{% if nextcloud_use_ssl %}
|
||||||
- traefik.http.routers.{{ nextcloud_service_name }}-push.entrypoints=websecure
|
- traefik.http.routers.{{ nextcloud_service_name }}-push.entrypoints=websecure
|
||||||
- traefik.http.routers.{{ nextcloud_service_name }}-push.tls=true
|
- traefik.http.routers.{{ nextcloud_service_name }}-push.tls=true
|
||||||
|
{% if traefik_cert_mode | default('selfsigned') == 'acme' %}
|
||||||
|
- traefik.http.routers.{{ nextcloud_service_name }}-push.tls.certresolver={{ traefik_ssl_cert_resolver | default('dns') }}
|
||||||
|
{% endif %}
|
||||||
{% else %}
|
{% else %}
|
||||||
- traefik.http.routers.{{ nextcloud_service_name }}-push.entrypoints=web
|
- traefik.http.routers.{{ nextcloud_service_name }}-push.entrypoints=web
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue