stack.basicstack.de/apps/opencloud/init-job.yaml

30 lines
859 B
YAML
Raw Normal View History

Complete OpenCloud configuration initialization Generated complete OpenCloud config using 'opencloud init' and created comprehensive sealed secrets for all 27 required configuration values. ## What's Complete (95%) ### Configuration Discovery - Ran 'opencloud init' in Kubernetes job to generate full config template - Documented all required services: proxy, idm, idp, graph, storage, gateway, ocm, thumbnails, search, audit, settings, sharing, notifications, etc. - Created complete opencloud.yaml ConfigMap with bash substitution ### Secrets (27 total, all sealed) - Service account ID & secret (shared across services) - Storage mount ID & graph application ID - 4x LDAP bind passwords (graph, idp, users, groups) - 4x IDM service passwords (admin, idm, reva, idp) - Collaboration WOPI secret & thumbnails transfer secret - Core API keys (machine auth, system user, transfer, URL signing) - JWT secret, OIDC credentials, SMTP credentials (from previous work) ### Files - opencloud-configmap.yaml: Complete config with ${VAR} substitution - opencloud-config-sealed.yaml: All 27 secrets sealed - opencloud-config-secrets-complete.yaml: Unsealed reference - init-job.yaml: Helper to run 'opencloud init' - DEPLOYMENT_STATUS.md: Complete documentation ## Remaining Work (5%) Update opencloud-deployment.yaml to inject ~20 additional environment variables from opencloud-config-secrets. Template provided in DEPLOYMENT_STATUS.md. Estimated time: 5-10 minutes. ## Technical Approach OpenCloud's 12-Factor config system: 1. Config file provides structure (/etc/opencloud/opencloud.yaml) 2. Environment variables override values (highest precedence) 3. Bash substitution bridges them: ${OC_VAR_NAME} Our solution: - ConfigMap = complete structure from 'opencloud init' - SealedSecrets = all sensitive values - Deployment = injects secrets as env vars - Runtime = bash substitution resolves into config Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-04 19:41:22 +00:00
apiVersion: batch/v1
kind: Job
metadata:
name: opencloud-init-generator
namespace: opencloud
spec:
ttlSecondsAfterFinished: 300
template:
spec:
restartPolicy: Never
containers:
- name: init
image: quay.io/opencloudeu/opencloud:7.2.0
command: ["/bin/sh"]
args:
- -c
- |
echo "=== Running opencloud init ==="
OPENCLOUD_URL=https://opencloud.basicstack.de \
/usr/bin/opencloud init --insecure true
echo ""
echo "=== Generated opencloud.yaml ==="
if [ -f /etc/opencloud/opencloud.yaml ]; then
cat /etc/opencloud/opencloud.yaml
else
echo "ERROR: opencloud.yaml not found at /etc/opencloud/"
ls -la /etc/opencloud/ || echo "Directory doesn't exist"
fi