feat(nextcloud): release nextcloud
deployment note: - use nextcloud for groupware - consider replacing vikunja and opencloud
This commit is contained in:
@@ -0,0 +1,4 @@
|
||||
<?php
|
||||
$CONFIG = [
|
||||
'maintenance_window_start' => 18,
|
||||
];
|
||||
@@ -0,0 +1,12 @@
|
||||
<?php
|
||||
$CONFIG = [
|
||||
'memcache.local' => '\OC\Memcache\APCu',
|
||||
'memcache.distributed' => '\OC\Memcache\Redis',
|
||||
'memcache.locking' => '\OC\Memcache\Redis',
|
||||
'redis' => [
|
||||
'host' => 'host.containers.internal',
|
||||
'port' => {{ services['nextcloud']['ports']['redis'] }},
|
||||
'timeout' => 1.5,
|
||||
'dbindex' => 0,
|
||||
],
|
||||
];
|
||||
@@ -0,0 +1,9 @@
|
||||
<?php
|
||||
$CONFIG = [
|
||||
'trusted_domains' => [
|
||||
'{{ services['nextcloud']['domain']['public'] }}.{{ domain['public'] }}',
|
||||
],
|
||||
'overwritehost' => '{{ services['nextcloud']['domain']['public'] }}.{{ domain['public'] }}',
|
||||
'overwriteprotocol' => 'https',
|
||||
'overwrite.cli.url' => 'https://{{ services['nextcloud']['domain']['public'] }}.{{ domain['public'] }}',
|
||||
];
|
||||
@@ -0,0 +1,4 @@
|
||||
<?php
|
||||
$CONFIG = [
|
||||
'allow_local_remote_servers' => true,
|
||||
];
|
||||
@@ -0,0 +1,9 @@
|
||||
<?php
|
||||
$CONFIG = [
|
||||
'user_oidc' => [
|
||||
'default_token_endpoint_auth_method' => 'client_secret_post',
|
||||
'auto_provision' => true,
|
||||
'soft_auto_provision' => true,
|
||||
'disable_account_creation' => false,
|
||||
],
|
||||
];
|
||||
@@ -0,0 +1,14 @@
|
||||
; /usr/local/etc/php/conf.d/opcache-recommended.ini
|
||||
; OPcache tuning
|
||||
opcache.enable=1
|
||||
opcache.enable_cli=1
|
||||
opcache.memory_consumption=512
|
||||
opcache.interned_strings_buffer=32
|
||||
opcache.max_accelerated_files=20000
|
||||
opcache.validate_timestamps=0
|
||||
opcache.save_comments=1
|
||||
opcache.revalidate_freq=60
|
||||
opcache.fast_shutdown=1
|
||||
|
||||
; APCu CLI activate
|
||||
apc.enable_cli=1
|
||||
@@ -0,0 +1,6 @@
|
||||
; /usr/local/etc/php/conf.d/nextcloud-upload.ini
|
||||
upload_max_filesize=16G
|
||||
post_max_size=16G
|
||||
memory_limit=1024M
|
||||
max_execution_time=3600
|
||||
max_input_time=3600
|
||||
@@ -0,0 +1,36 @@
|
||||
[Quadlet]
|
||||
DefaultDependencies=false
|
||||
|
||||
[Unit]
|
||||
Description=Nextcloud
|
||||
|
||||
[Container]
|
||||
Image=docker.io/library/nextcloud:{{ version['containers']['nextcloud'] }}
|
||||
ContainerName=nextcloud
|
||||
HostName=nextcloud
|
||||
|
||||
PublishPort={{ services['nextcloud']['ports']['http'] }}:80
|
||||
|
||||
Volume=%h/containers/nextcloud/ssl:/etc/ssl/nextcloud:ro
|
||||
Volume=%h/containers/nextcloud/ini/opcache.ini:/usr/local/etc/php/conf.d/opcache-recommended.ini:ro
|
||||
Volume=%h/containers/nextcloud/ini/upload.ini:/usr/local/etc/php/conf.d/upload.ini:ro
|
||||
Volume=%h/data/containers/nextcloud/html:/var/www/html:rw
|
||||
|
||||
# General
|
||||
Environment="TZ=Asia/Seoul"
|
||||
# PostgreSQL
|
||||
Environment="PGSSLMODE=verify-full"
|
||||
Environment="PGSSLROOTCERT=/etc/ssl/nextcloud/{{ root_cert_filename }}"
|
||||
## libpq in Nextcloud automatically tries to use a client certificate for mTLS. Therefore, when only TLS is required, then disable the option explicitly.
|
||||
Environment="PGSSLCERTMODE=disable"
|
||||
# Redis
|
||||
Environment="REDIS_HOST=host.containers.internal"
|
||||
Environment="REDIS_HOST_PORT={{ services['nextcloud']['ports']['redis'] }}"
|
||||
|
||||
[Service]
|
||||
Restart=always
|
||||
RestartSec=10s
|
||||
TimeoutStopSec=120
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
@@ -0,0 +1,8 @@
|
||||
[Unit]
|
||||
Description=Nextcloud cron.php
|
||||
Requires=nextcloud.service
|
||||
After=nextcloud.service
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
ExecStart=/usr/bin/podman exec -u www-data nextcloud php -f /var/www/html/cron.php
|
||||
@@ -0,0 +1,10 @@
|
||||
[Unit]
|
||||
Description=Run Nextcloud cron every 5 minutes
|
||||
|
||||
[Timer]
|
||||
OnBootSec=5min
|
||||
OnUnitActiveSec=5min
|
||||
Unit=nextcloud-cron.service
|
||||
|
||||
[Install]
|
||||
WantedBy=timers.target
|
||||
@@ -365,3 +365,25 @@ identity_providers:
|
||||
access_token_signed_response_alg: 'none'
|
||||
userinfo_signed_response_alg: 'none'
|
||||
token_endpoint_auth_method: 'client_secret_post'
|
||||
# https://www.authelia.com/integration/openid-connect/clients/nextcloud/#openid-connect-user-backend-app
|
||||
- client_id: 'nextcloud'
|
||||
client_name: 'Nextcloud'
|
||||
client_secret: '{{ hostvars['console']['nextcloud']['oidc']['hash'] }}'
|
||||
public: false
|
||||
authorization_policy: 'one_factor'
|
||||
require_pkce: true
|
||||
pkce_challenge_method: 'S256'
|
||||
redirect_uris:
|
||||
- 'https://{{ services['nextcloud']['domain']['public'] }}.{{ domain['public'] }}/apps/user_oidc/code'
|
||||
scopes:
|
||||
- 'openid'
|
||||
- 'profile'
|
||||
- 'email'
|
||||
- 'groups'
|
||||
response_types:
|
||||
- 'code'
|
||||
grant_types:
|
||||
- 'authorization_code'
|
||||
access_token_signed_response_alg: 'none'
|
||||
userinfo_signed_response_alg: 'none'
|
||||
token_endpoint_auth_method: 'client_secret_post'
|
||||
|
||||
@@ -77,3 +77,9 @@
|
||||
header_up Host {http.request.header.X-Forwarded-Host}
|
||||
}
|
||||
}
|
||||
{{ services['nextcloud']['domain']['internal'] }}.{{ domain['internal'] }} {
|
||||
import private_tls
|
||||
reverse_proxy host.containers.internal:{{ services['nextcloud']['ports']['http'] }} {
|
||||
header_up Host {http.request.header.X-Forwarded-Host}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -136,6 +136,15 @@
|
||||
}
|
||||
}
|
||||
}
|
||||
{{ services['nextcloud']['domain']['public'] }}.{{ domain['public'] }} {
|
||||
import crowdsec_log
|
||||
route {
|
||||
crowdsec
|
||||
reverse_proxy https://{{services['nextcloud']['domain']['internal'] }}.{{ domain['internal'] }} {
|
||||
header_up Host {http.reverse_proxy.upstream.host}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# Internal domain
|
||||
{{ node['name'] }}.{{ domain['internal'] }} {
|
||||
|
||||
Reference in New Issue
Block a user