diff --git a/apps/opencloud/opencloud-configmap.yaml b/apps/opencloud/opencloud-configmap.yaml index 6fc6d35..413822d 100644 --- a/apps/opencloud/opencloud-configmap.yaml +++ b/apps/opencloud/opencloud-configmap.yaml @@ -6,28 +6,11 @@ metadata: namespace: opencloud data: opencloud.yaml: | - # OpenCloud Complete Configuration - # Generated from 'opencloud init' and customized with our secrets + # OpenCloud Minimal Configuration + # Only non-default settings - environment variables override these - # Core secrets (from our SealedSecrets via environment variables) - token_manager: - jwt_secret: ${OC_TOKEN_MANAGER_JWT_SECRET} - - machine_auth_api_key: ${OC_MACHINE_AUTH_API_KEY} - system_user_api_key: ${OC_SYSTEM_USER_API_KEY} - transfer_secret: ${OC_TRANSFER_SECRET} - url_signing_secret: ${OC_URL_SIGNING_SECRET} - system_user_id: ${OC_SYSTEM_USER_ID} - admin_user_id: ${OC_ADMIN_USER_ID} - - # Graph service (using external OpenLDAP for user storage) + # Graph service - external OpenLDAP configuration graph: - application: - id: ${OC_GRAPH_APPLICATION_ID:-025a50d1-5f8d-4309-a201-dd938e7b0b2f} - events: - tls_insecure: true - spaces: - insecure: true identity: ldap: uri: ldap://openldap.opencloud.svc.cluster.local:389 @@ -37,76 +20,17 @@ data: user_base_dn: ou=users,dc=basicstack,dc=de group_base_dn: ou=groups,dc=basicstack,dc=de insecure: true - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - # IDP service excluded (using external OIDC via Pocket ID for authentication) - # idp: - # ldap: - # bind_password: ${OC_IDP_LDAP_BIND_PASSWORD} - - # IDM service excluded (using external OpenLDAP for user storage) - # idm: - # service_user_passwords: - # admin_password: ${OC_IDM_ADMIN_PASSWORD} - # idm_password: ${OC_IDM_IDM_PASSWORD} - # reva_password: ${OC_IDM_REVA_PASSWORD} - # idp_password: ${OC_IDM_IDP_PASSWORD} - - # Collaboration services - collaboration: - wopi: - secret: ${OC_COLLABORATION_WOPI_SECRET} - app: - insecure: true - - # Proxy service (OIDC integration with auto-provisioning) + # Proxy service - OIDC configuration (already in env vars, kept for reference) proxy: oidc: issuer: https://auth.basicstack.de insecure: false auto_provision_accounts: true - user_oidc_claim: email - role_assignment: - driver: oidc - oidc_role_mapper: - role_claim: groups - role_mapping: - - role_name: admin - claim_value: opencloudAdmin - - role_name: spaceadmin - claim_value: opencloudSpaceAdmin - - role_name: user - claim_value: opencloudUser - - role_name: guest - claim_value: opencloudGuest - # Temporarily enable basic auth for testing (OIDC redirect not working) - enable_basic_auth: true - insecure_backends: true - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} + user_oidc_claim: preferred_username + enable_basic_auth: false - # Frontend service - frontend: - app_handler: - insecure: true - archiver: - insecure: true - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - ocdav: - insecure: true - - # Auth services (OIDC only, no basic auth) - auth_bearer: - auth_providers: - oidc: - insecure: false - - # User/Group services (using external OpenLDAP) + # Users service - external LDAP users: drivers: ldap: @@ -119,6 +43,7 @@ data: user_object_class: inetOrgPerson insecure: true + # Groups service - external LDAP groups: drivers: ldap: @@ -130,103 +55,3 @@ data: group_filter: (objectClass=groupOfNames) group_object_class: groupOfNames insecure: true - - # OCM (Open Cloud Mesh) - ocm: - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - - # Thumbnails - thumbnails: - thumbnail: - transfer_secret: ${OC_THUMBNAILS_TRANSFER_SECRET} - webdav_allow_insecure: true - cs3_allow_insecure: true - - # Search service - DISABLED due to crashes in v7.2.0 - # See: https://github.com/opencloud-eu/opencloud/issues/1740 - # search: - # engine: - # type: bleve - # bleve: - # data_path: /var/lib/opencloud/search - # extractor: - # type: tika - # tika: - # tika_url: http://tika:9998 - # events: - # tls_insecure: true - # service_account: - # service_account_id: ${OC_SERVICE_ACCOUNT_ID} - # service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - - # Audit service - audit: - events: - tls_insecure: true - - # Settings service - settings: - service_account_ids: - - ${OC_SERVICE_ACCOUNT_ID} - - # Sharing service - sharing: - events: - tls_insecure: true - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - - # Storage Users - storage_users: - events: - tls_insecure: true - mount_id: ${OC_STORAGE_MOUNT_ID} - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - - # Notifications - notifications: - notifications: - events: - tls_insecure: true - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - - # NATS - nats: - nats: - tls_skip_verify_client_cert: true - - # Gateway - gateway: - storage_registry: - storage_users_mount_id: ${OC_STORAGE_MOUNT_ID} - - # Userlog - userlog: - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - - # Auth Service - auth_service: - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - - # Client Log - clientlog: - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} - - # Activity Log - activitylog: - service_account: - service_account_id: ${OC_SERVICE_ACCOUNT_ID} - service_account_secret: ${OC_SERVICE_ACCOUNT_SECRET} diff --git a/apps/opencloud/opencloud-deployment.yaml b/apps/opencloud/opencloud-deployment.yaml index 7c88f2b..a1c29dc 100644 --- a/apps/opencloud/opencloud-deployment.yaml +++ b/apps/opencloud/opencloud-deployment.yaml @@ -69,6 +69,139 @@ spec: runAsUser: 1000 runAsGroup: 1000 runAsNonRoot: true + - name: init-config + image: alpine:3.18 + command: + - sh + - -c + - | + # Install envsubst + apk add --no-cache gettext + + # Create output directory + mkdir -p /etc/opencloud-processed + + # Process the config template, expanding environment variables + envsubst < /etc/opencloud-template/opencloud.yaml > /etc/opencloud-processed/opencloud.yaml + + echo "Config file processed successfully" + cat /etc/opencloud-processed/opencloud.yaml | head -20 + env: + # Pass all environment variables needed for substitution + - name: OC_GRAPH_LDAP_BIND_PASSWORD + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: graph-ldap-bind-password + - name: OPENLDAP_ADMIN_PASSWORD + valueFrom: + secretKeyRef: + name: openldap-admin-secret + key: admin-password + - name: OC_IDM_ADMIN_PASSWORD + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: idm-admin-password + - name: OC_IDM_IDM_PASSWORD + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: idm-idm-password + - name: OC_IDM_REVA_PASSWORD + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: idm-reva-password + - name: OC_IDM_IDP_PASSWORD + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: idm-idp-password + - name: OC_TOKEN_MANAGER_JWT_SECRET + valueFrom: + secretKeyRef: + name: opencloud-jwt-secret + key: jwt-secret + - name: OC_MACHINE_AUTH_API_KEY + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: machine-auth-api-key + - name: OC_SYSTEM_USER_API_KEY + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: system-user-api-key + - name: OC_TRANSFER_SECRET + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: transfer-secret + - name: OC_URL_SIGNING_SECRET + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: url-signing-secret + - name: OC_SYSTEM_USER_ID + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: system-user-id + - name: OC_ADMIN_USER_ID + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: admin-user-id + - name: OC_GRAPH_APPLICATION_ID + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: graph-application-id + - name: OC_SERVICE_ACCOUNT_ID + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: service-account-id + - name: OC_SERVICE_ACCOUNT_SECRET + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: service-account-secret + - name: OC_COLLABORATION_WOPI_SECRET + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: collaboration-wopi-secret + - name: OC_THUMBNAILS_TRANSFER_SECRET + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: thumbnails-transfer-secret + - name: OC_STORAGE_MOUNT_ID + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: storage-mount-id + - name: OC_USERS_LDAP_BIND_PASSWORD + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: ldap-bind-password + - name: OC_GROUPS_LDAP_BIND_PASSWORD + valueFrom: + secretKeyRef: + name: opencloud-config-secrets + key: ldap-bind-password + volumeMounts: + - name: opencloud-config-template + mountPath: /etc/opencloud-template + - name: opencloud-config-processed + mountPath: /etc/opencloud-processed + securityContext: + runAsUser: 1000 + runAsGroup: 1000 + runAsNonRoot: true containers: - name: opencloud image: opencloudeu/opencloud-rolling:7.2.0 @@ -448,6 +581,8 @@ spec: volumeMounts: - name: opencloud-data mountPath: /var/lib/opencloud + - name: opencloud-config-processed + mountPath: /etc/opencloud resources: requests: memory: "512Mi" @@ -474,6 +609,11 @@ spec: - name: opencloud-data persistentVolumeClaim: claimName: opencloud-data + - name: opencloud-config-template + configMap: + name: opencloud-config + - name: opencloud-config-processed + emptyDir: {} --- # Ingress apiVersion: networking.k8s.io/v1