feat: domain list refactor + demo-gymburgdorf fixes
- Refactor: collapse `*_domain` + `*_extra_domains` into a single `*_domains` list across authentik, collabora, garage and nextcloud roles. First entry is the canonical FQDN (used for OVERWRITEHOST, BASE_URL, notify_push setup and garage root_domain). - Authentik blueprint: guard the OAuth sources block so an empty `authentik_login_sources` no longer renders an invalid YAML key. - Nextcloud: introduce `nextcloud_collabora_public_domain` and set Collabora's `public_wopi_url` separately from the server-to-server `wopi_url` so browsers can reach Collabora via the public name while Nextcloud still talks to it on the internal one. - Nextcloud: URL-encode the postgres user/password in DATABASE_URL.
This commit is contained in:
parent
c11f019aae
commit
c3cf779532
12 changed files with 64 additions and 15 deletions
|
|
@ -13,7 +13,11 @@ garage_docker_volume_dir: "{{ docker_volume_base_dir }}/{{ garage_service_name }
|
|||
|
||||
# Garage service configuration
|
||||
garage_image: "dxflrs/garage:v2.1.0"
|
||||
garage_s3_domain: "storage.local.test"
|
||||
# FQDNs the garage S3 router accepts. The first entry is the canonical
|
||||
# domain and is also used as the virtual-hosted-style root_domain in
|
||||
# garage.toml; further entries cover internal *.int.* names.
|
||||
garage_s3_domains:
|
||||
- "storage.local.test"
|
||||
garage_web_domain: "web.storage.local.test"
|
||||
garage_webui_domain: "console.storage.local.test"
|
||||
|
||||
|
|
|
|||
|
|
@ -14,10 +14,13 @@ services:
|
|||
- traefik.enable=true
|
||||
- traefik.docker.network={{ garage_traefik_network }}
|
||||
# S3 API endpoint
|
||||
- traefik.http.routers.{{ garage_service_name }}.rule=Host(`{{ garage_s3_domain }}`)
|
||||
- traefik.http.routers.{{ garage_service_name }}.rule=Host({% for d in garage_s3_domains %}`{{ d }}`{% if not loop.last %}, {% endif %}{% endfor %})
|
||||
{% if garage_use_ssl %}
|
||||
- traefik.http.routers.{{ garage_service_name }}.entrypoints=websecure
|
||||
- traefik.http.routers.{{ garage_service_name }}.tls=true
|
||||
{% if traefik_cert_mode | default('selfsigned') == 'acme' %}
|
||||
- traefik.http.routers.{{ garage_service_name }}.tls.certresolver={{ traefik_ssl_cert_resolver | default('dns') }}
|
||||
{% endif %}
|
||||
{% else %}
|
||||
- traefik.http.routers.{{ garage_service_name }}.entrypoints=web
|
||||
{% endif %}
|
||||
|
|
@ -48,6 +51,9 @@ services:
|
|||
{% if garage_use_ssl %}
|
||||
- traefik.http.routers.{{ garage_service_name }}-console.entrypoints=websecure
|
||||
- traefik.http.routers.{{ garage_service_name }}-console.tls=true
|
||||
{% if traefik_cert_mode | default('selfsigned') == 'acme' %}
|
||||
- traefik.http.routers.{{ garage_service_name }}-console.tls.certresolver={{ traefik_ssl_cert_resolver | default('dns') }}
|
||||
{% endif %}
|
||||
{% else %}
|
||||
- traefik.http.routers.{{ garage_service_name }}-console.entrypoints=web
|
||||
{% endif %}
|
||||
|
|
|
|||
|
|
@ -14,7 +14,7 @@ rpc_secret = "{{ garage_rpc_secret }}"
|
|||
[s3_api]
|
||||
s3_region = "{{ garage_s3_region }}"
|
||||
api_bind_addr = "[::]:{{ garage_s3_api_port }}"
|
||||
root_domain = ".s3.{{ garage_s3_domain }}"
|
||||
root_domain = ".s3.{{ garage_s3_domains[0] }}"
|
||||
|
||||
[s3_web]
|
||||
bind_addr = "[::]:{{ garage_s3_web_port }}"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue