Commit graph

229 commits

Author SHA1 Message Date
Paperclip CTO
5e02c64dc4 docs: Add comprehensive Pocket ID OIDC client setup documentation
Document all four OIDC clients for OpenCloud:
- Web application (UUID-based client ID)
- Desktop client (OpenCloudDesktop)
- Android mobile (OpenCloudAndroid)
- iOS mobile (OpenCloudIOS)

Includes configuration details, security notes, and troubleshooting.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-11 12:03:44 +00:00
CTO Agent
d8cd3638fa Fix Stalwart backup CronJob to handle ReadWriteOnce PVC
Implement scale-down/backup/scale-up pattern to work around PVC access mode limitation.

Changes:
- Add RBAC (ServiceAccount, Role, RoleBinding) with statefulsets/scale and pods permissions
- Switch to alpine:3.19 base image with kubectl and restic
- Scale down StatefulSet to 0 replicas before backup
- Run restic backup while pod is stopped
- Scale back up to 1 replica with error handling
- Add cleanup trap to ensure scale-up even on failure
- Set 10-minute timeout and backoff limit

Tested successfully: backup completes in ~32 seconds with minimal downtime.
Resolves DEV-236.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-11 11:21:39 +00:00
CTO Agent
b0f2acf5f3 Stalwart reliability hardening: fix k3s service networking issues
Root cause: k3s service ClusterIP routing instability causing intermittent
failures despite healthy pods. This is the 5th incident - prior fixes treated
symptoms, not the systemic networking fragility.

Changes:
- Add startup probe (60s delay, prevents premature service registration)
- Fix backup job env var substitution (use shell ${VAR}, not K8s $(VAR))
- Add comprehensive monitoring (ServiceMonitor, PrometheusRule, blackbox probes)
- Add alerting for service failures, high latency, pod restarts, backup failures

Evidence:
- Pod healthy (4d15h uptime, 0 restarts) but service ClusterIP routing broken
- Direct pod IP worked, service ClusterIP failed with "Connection reset by peer"
- Iptables rules correct, endpoints correct, but packets not flowing
- Required pod restart + Traefik restart to restore service

Monitoring now tests full service path from outside cluster, not just pod health.
Will alert immediately on failures instead of relying on reactive discovery.

Related: DEV-213, DEV-221, DEV-223, DEV-224, DEV-230, DEV-231

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-11 11:06:36 +00:00
CTO Agent
3b000e1ab1 Document k3s cluster network architecture and DNS requirements
Created comprehensive network documentation for BasicStack k3s cluster:

- NETWORK_ARCHITECTURE.md: Complete network architecture with diagrams,
  node configuration, CNI (Flannel) details, ingress/LoadBalancer setup,
  DNS configuration, TLS certificates, network policies, traffic flows,
  and troubleshooting procedures

- DNS_REQUIREMENTS.md: Complete DNS record requirements for all services
  including A records, MX records, SPF, DKIM, DMARC, and PTR records

- NETWORK_VERIFICATION.md: Verification report documenting current state
  of all network components with findings and recommendations

Updated infrastructure README with links to new network documentation.

Key findings:
- All worker nodes correctly configured with --node-ip set to private IPs
- Flannel VXLAN properly configured with public IP annotations
- Traefik ingress controller operational
- 16/17 TLS certificates valid (registry-tls needs investigation)
- 3 LoadBalancer services properly configured
- Network policies securing database services

Addresses DEV-225: Verify and document k3s cluster network configuration
Related: DEV-224 (node-ip configuration), DEV-223 (DNS issues)

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-11 11:06:36 +00:00
Paperclip CTO
27d26fb11b Document DNS configuration and service CIDR fix
- Fixed Service CIDR documentation (10.96.0.0/16, not 10.43.0.0/16)
- Added comprehensive DNS configuration guide
- Documented kubelet cluster-dns requirements
- Added CoreDNS forward configuration details
- Documented DNS CIDR mismatch troubleshooting (DEV-223)

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-06 18:22:53 +00:00
CTO Agent
f3034af04a Update k3s cluster documentation
- Add CLUSTER_ACCESS.md with comprehensive cluster access guide
- Fix Service CIDR in K3S_OPERATIONS.md (10.43.0.0/16, not 10.96.0.0/12)
- Document API server instability fix (cluster-cidr configuration)
- Add troubleshooting section for CIDR mismatch issues
- Update change history with cluster update details

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-06 17:54:53 +00:00
CTO Agent
2c0e7f22b1 Add k3s cluster management automation and documentation
- Add k3s node provisioning script with version pinning
- Add comprehensive K3S_OPERATIONS.md documentation
- Add k3s system-upgrade-controller configuration

This addresses DEV-221: prevents version skew issues by:
1. Enforcing version pinning when adding new nodes
2. Providing automated provisioning script
3. Setting up automated upgrades via upgrade controller
4. Documenting all cluster operations procedures

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-06 17:08:21 +00:00
CTO Agent
07e2e476ce Fix IDM LDAP port from 9125 to 9236
Corrected the IDM LDAP listener port. Logs show IDM listening on
127.0.0.1:9236, not 9125.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 20:49:14 +00:00
CTO Agent
b4abe71c5d Restore LDAP environment variables for IDM
Restored LDAP-related environment variables. The configmap now uses
IDM password variables (OC_IDM_IDM_PASSWORD, OC_IDM_REVA_PASSWORD)
instead of the external LDAP passwords.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 20:47:59 +00:00
CTO Agent
6b49ba342a Configure graph/users/groups to use IDM's internal LDAP
OpenCloud's IDM service provides an internal LDAP server on localhost:9125.
Updated configuration to connect to IDM's LDAP instead of external OpenLDAP:
- Base DN: o=libregraph-idm (IDM's base DN)
- Graph binds as uid=libregraph,ou=sysusers,o=libregraph-idm
- Users/Groups bind as uid=reva,ou=sysusers,o=libregraph-idm
- Uses IDM service user passwords from secrets

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 20:47:34 +00:00
CTO Agent
c1c85a684e Comment out LDAP environment variables for built-in IDM
When using OpenCloud's built-in IDM service, the graph, users, and groups
services should not use external LDAP. Commented out all LDAP-specific
environment variables that were causing startup failures.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 20:45:19 +00:00
CTO Agent
ab5cc5aaae Configure OpenCloud to use built-in IDM instead of external OpenLDAP
- Enable IDM service by removing it from OC_EXCLUDE_RUN_SERVICES
- Remove external LDAP configuration from configmap (graph, users, groups)
- Built-in IDM will handle user/group storage internally
- OIDC auto-provisioning via Pocket ID remains unchanged

This allows OpenCloud to save new users using its internal IDM service.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 20:41:15 +00:00
CTO Agent
c3fe072be5 fix(opencloud): move schema loading from postStart hook to standalone Job
The postStart lifecycle hook caused osixia/openldap to crash on startup:
its init script does chown -R on /container/service/slapd/assets/, and
the ConfigMap subPath mount there is read-only, killing the container.

Remove the postStart hook and the schema volume mount from the OpenLDAP
deployment. Add a standalone Kubernetes Job (opencloud-ldap-schema-job.yaml)
that connects via network LDAP as cn=admin,cn=config and loads the schema
after OpenLDAP is confirmed ready. The Job is idempotent (skips if the
schema already exists) and retries up to 10 times on failure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-05 16:56:33 +00:00
CTO Agent
a715c8e532 fix(opencloud): load OpenCloud LDAP schema into OpenLDAP on startup
User creation failed with "openCloudUUID: attribute type undefined" because
OpenLDAP was missing the OpenCloud schema (OIDs under 1.3.6.1.4.1.63016).

Changes:
- Add opencloud-ldap-schema.yaml ConfigMap with the official OpenCloud LDAP
  schema defining openCloudUUID, openCloudUser, openCloudExternalIdentity,
  openCloudUserEnabled, openCloudUserType, openCloudLastSignInTimestamp
- Mount the ConfigMap into the OpenLDAP pod
- Add lifecycle postStart hook to load schema via ldapadd -Y EXTERNAL -H ldapi:///
  (idempotent: skips if already loaded)
- Re-exclude IDM in OpenCloud deployment (external LDAP handles user storage)

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 15:51:15 +00:00
CTO Agent
51d70b052f Revert "fix(opencloud): remove external LDAP config, use IDM for user storage"
This reverts commit 5adc38c4d8.
2026-07-05 15:41:56 +00:00
CTO Agent
5adc38c4d8 fix(opencloud): remove external LDAP config, use IDM for user storage
Graph service was routing auto-provisioning to external OpenLDAP which lacks
the OpenCloud schema (openCloudUUID: attribute type undefined). The explicit
graph.identity.ldap, users.drivers.ldap, and groups.drivers.ldap sections in
opencloud.yaml overrode the default IDM LDAP, causing user creation to fail.

Remove all external LDAP sections so Graph/Users/Groups default to IDM's
internal LDAP, which has the full OpenCloud schema. IDM is already running.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 15:37:46 +00:00
CTO Agent
4a674dba6e fix(opencloud): add IDM password config to ConfigMap
The /etc/opencloud mount is read-only (ConfigMap), so opencloud init
cannot write the generated IDM password config. IDM fails to start with
"password of service user IDM has not been set properly".

Add the idm.service_user_passwords section to opencloud.yaml, referencing
the OC_IDM_* env vars that are already populated from the sealed secret.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 15:29:01 +00:00
CTO Agent
67890f299d fix(opencloud): fix user login - default role assignment and re-enable IDM
After Pocket ID OIDC flow completed, users got "Nicht angemeldet" because:
1. PROXY_ROLE_ASSIGNMENT_DRIVER=oidc required an 'opencloud_role' OIDC claim
   that Pocket ID wasn't sending → users got no role → login rejected
2. IDM was excluded, removing the internal user store that auto-provisioning
   needs to create user accounts when they first log in

Fixes:
- Switch to PROXY_ROLE_ASSIGNMENT_DRIVER=default so all OIDC-authenticated
  users automatically receive the standard user role
- Re-enable IDM service so auto-provisioned accounts have a working user store

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 15:23:24 +00:00
CTO Agent
6b29f46f3b fix(opencloud): add CSP config to allow Pocket ID OIDC auth
Browser was blocking fetch of https://auth.basicstack.de/.well-known/openid-configuration
due to missing connect-src directive in Content-Security-Policy.

Adds csp.yaml to the ConfigMap (mounted at /etc/opencloud/csp.yaml) with
extended connect-src that includes auth.basicstack.de and WebSocket origins.
Sets PROXY_CSP_CONFIG_FILE_LOCATION env var so the proxy service picks it up.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 15:14:26 +00:00
CTO Agent
2b460fec5b OpenCloud: Remove client secrets for public SPA with PKCE
OpenCloud's web frontend is a public Single Page Application that uses
PKCE (Proof Key for Code Exchange) and does not need client secrets.

Removed:
- OC_OIDC_CLIENT_SECRET
- WEB_OIDC_CLIENT_SECRET

The Pocket ID OIDC client must be configured as:
- Public Client: Enabled
- PKCE: Enabled
- Callback URLs:
  - https://opencloud.basicstack.de/
  - https://opencloud.basicstack.de/oidc-callback.html
  - https://opencloud.basicstack.de/oidc-silent-redirect.html
- Logout URL: https://opencloud.basicstack.de

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 14:49:49 +00:00
da7dc02bac apps/opencloud/opencloud-deployment.yaml aktualisiert 2026-07-05 14:41:09 +00:00
3e8e5b1497 apps/opencloud/opencloud-deployment.yaml aktualisiert 2026-07-05 14:37:47 +00:00
CTO Agent
3a35b737cb OpenCloud: Exclude auth-basic service for OIDC-only authentication
Removed auth-basic configuration and environment variables:
- Removed auth-basic section from ConfigMap
- Removed AUTH_BASIC_LOG_LEVEL, OC_AUTH_BASIC_LDAP_BIND_PASSWORD,
  and AUTH_BASIC_AUTH_PROVIDERS_LDAP_BIND_PASSWORD env vars
- Added auth-basic to OC_EXCLUDE_RUN_SERVICES

Result: OpenCloud pod running healthy (1/1 Ready)
- All services listening and operational
- https://opencloud.basicstack.de/ responding with HTTP 200
- No auth-basic bind_password errors

Ready for OIDC authentication testing with Pocket ID.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 14:12:07 +00:00
CTO Agent
3db38aded0 OpenCloud: Use native bash substitution in config file
- Removed init-config container (OpenCloud supports native bash substitution)
- Mount opencloud-config ConfigMap directly to /etc/opencloud
- Added gateway storage configuration with ${OC_STORAGE_MOUNT_ID|}
- Updated all LDAP services to use ${OPENLDAP_ADMIN_PASSWORD|} substitution
- Added auth-basic auth_providers structure

Services starting successfully:
- Gateway, users, sharing services running
- Users service connected to external OpenLDAP
- Remaining: auth-basic bind_password configuration issue

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 14:03:49 +00:00
CTO Agent
6f8e50c455 Fix init-config container to use busybox with shell expansion
Changed from alpine+envsubst to busybox with simple shell-based
variable expansion using sed. This avoids permission issues with
apk and works with non-root security context.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 13:40:23 +00:00
CTO Agent
09acb2347c Implement ConfigMap mount with init container for envsubst
Added init-config container that:
- Uses alpine with envsubst to expand environment variables
- Reads ConfigMap template from /etc/opencloud-template
- Writes expanded config to emptyDir at /etc/opencloud-processed
- Main container mounts processed config at /etc/opencloud

Simplified ConfigMap to only essential LDAP configuration:
- Graph service LDAP (external OpenLDAP)
- Users/Groups service LDAP configuration
- Removed default values (env vars override anyway)
- Only  placeholder remains

This follows OpenCloud's config precedence:
1. opencloud.yaml (base config)
2. Environment variables (highest precedence)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 13:39:15 +00:00
CTO Agent
53f358c34f Revert ConfigMap mount - caused crashes
Mounting opencloud-config ConfigMap to /etc/opencloud caused pod crashes
because the YAML contains placeholders like ${ENV_VAR} that aren't expanded.

Issue: OpenCloud expects actual values in config files, but ConfigMaps
don't perform environment variable substitution.

Solution: Use environment variables only (highest precedence per docs).
The current deployment with ENV vars works correctly - no file config needed.

Alternative: If file config is required, use an init container to:
1. Read the ConfigMap template
2. Substitute environment variables
3. Write the expanded config to /etc/opencloud

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 13:37:11 +00:00
CTO Agent
1e22b74a55 Mount opencloud-config ConfigMap to /etc/opencloud
Added volume mount for opencloud-config ConfigMap at /etc/opencloud
so OpenCloud services can read the opencloud.yaml configuration file.

This follows OpenCloud's standard configuration pattern:
- opencloud.yaml provides global defaults
- Environment variables override file configuration
- ConfigMap mounted at /etc/opencloud (container default)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 13:32:47 +00:00
f0e4df95a1 apps/opencloud/opencloud-deployment.yaml aktualisiert 2026-07-05 11:50:58 +00:00
CTO Agent
83e120aa2b Enable trace logging for all auth services
Added trace logging for:
- AUTH_SERVICE_LOG_LEVEL
- AUTH_APP_LOG_LEVEL
- AUTH_BASIC_LOG_LEVEL
- AUTH_MACHINE_LOG_LEVEL

This will provide detailed auth debugging information.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 10:44:39 +00:00
CTO Agent
1126d2e7f6 Enable auth-service trace logging for debugging
Added AUTH_SERVICE_LOG_LEVEL=trace to help debug authentication
redirect issues.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 10:42:40 +00:00
CTO Agent
db46c98584 Enable basic auth temporarily for testing
OIDC redirect still not working after multiple configuration attempts.
Enabled basic auth so user can test LDAP authentication.

Added user: andreas.leinen@basicstack.de
Password: OpenCloud2024!

TODO: Investigate why OIDC redirect isn't happening despite correct
configuration in deployment and configmap.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 10:38:32 +00:00
CTO Agent
c6460d3f10 Add OpenLDAP admin sealed secret
Generated secure passwords for OpenLDAP admin credentials.
Admin DN: cn=admin,dc=basicstack,dc=de

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 10:31:59 +00:00
CTO Agent
41ca29024e Add external OpenLDAP deployment for OpenCloud
- Add OpenLDAP deployment with persistent storage
- Configure OpenCloud to use external LDAP for user/group storage
- Exclude internal IDM service (using external LDAP instead)
- Keep Pocket ID OIDC for authentication
- Add LDAP directory initialization structure
- Add comprehensive deployment guide

Architecture:
- External OpenLDAP (ldap://openldap.opencloud.svc:389)
- Pocket ID OIDC (https://auth.basicstack.de)
- Auto-provision users on first OIDC login to LDAP
- Users: ou=users,dc=basicstack,dc=de
- Groups: ou=groups,dc=basicstack,dc=de

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-05 10:21:11 +00:00
CTO Agent
c149a278dc Add comprehensive OIDC troubleshooting documentation
Problem: Frontend still not redirecting to OIDC after all config changes.

Created detailed troubleshooting doc covering:
- All 6 commits of configuration changes applied
- What's verified working (OIDC config, IDM, no local users)
- Current behavior vs expected behavior
- Possible root causes
- Next investigation steps

Suggests further investigation needed:
- Check OpenCloud web frontend source code
- Test OIDC flow with curl/API
- Consult OpenCloud community/support
- Browser dev tools debugging

All backend config appears correct. Issue likely in frontend SPA logic
or undocumented configuration requirement for OIDC-only mode.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 09:11:50 +00:00
CTO Agent
64ec7094ac Add OC_JWT_SECRET for auth-service
Problem: Auth-service requires OC_JWT_SECRET to mint/validate JWT tokens.
Root cause: Only OC_TOKEN_MANAGER_JWT_SECRET was set, not OC_JWT_SECRET.

According to OpenCloud docs, auth-service needs:
- OC_JWT_SECRET or AUTH_SERVICE_JWT_SECRET

Changes:
- Added OC_JWT_SECRET environment variable
- Points to same jwt-secret as OC_TOKEN_MANAGER_JWT_SECRET

Why: Auth-service uses OC_JWT_SECRET to validate tokens from OIDC flow.
Without it, authentication fails silently.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 09:06:39 +00:00
CTO Agent
56d9063a2d Keep init but remove admin password creation
Problem: Removing init entirely broke OpenCloud - needs init for config setup.
Solution: Keep 'opencloud init' but remove '--admin-password' flag.

Changes:
- Restored 'opencloud init' command (needed for jwt_secret and config)
- Removed '--admin-password' flag (prevents local admin user creation)
- IDM_CREATE_DEMO_USERS=false still set (prevents demo users)

Result: Init runs to setup config, but no local users are created.
Only OIDC auto-provisioned users will exist.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 09:02:11 +00:00
CTO Agent
a3086e7ba7 Remove local admin user creation for OIDC-only mode
Problem: Frontend shows login page because local admin user exists.
Root cause: 'opencloud init --admin-password' creates local admin on every start.

Changes:
- Removed 'opencloud init' command from container startup
- Changed to direct 'opencloud server' execution
- Added IDM_CREATE_DEMO_USERS=false to prevent demo user creation

Why: With external OIDC, we don't need local users. The frontend detects
local users and shows a password login page. By removing local user creation,
the frontend will only offer OIDC authentication.

Auto-provisioning will create users in IDM on first OIDC login.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 08:58:16 +00:00
CTO Agent
4c89d5d159 Fix OpenCloud architecture - Keep IDM for user storage
Problem: Login still showing local page instead of OIDC redirect.
Root cause: Excluded both IDP and IDM, but IDM is needed for user storage.

Architecture Fix:
- IDP (Identity Provider) = EXCLUDED (auth handled by Pocket ID OIDC)
- IDM (Identity Management) = KEPT (provides LDAP storage for users/groups)
- Proxy auto-provisioning = creates users in IDM LDAP on first OIDC login

Changes:
- deployment: OC_EXCLUDE_RUN_SERVICES changed from "search,idp,idm" to "search,idp"
- configmap: Re-enabled IDM service configuration
- configmap: Restored graph.identity.ldap (points to internal IDM)
- configmap: Restored users/groups LDAP drivers (connect to internal IDM)

Flow: User → OIDC (Pocket ID) → Proxy auto-provision → IDM LDAP → User created

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 08:51:26 +00:00
CTO Agent
c993aafd26 Enable OIDC auto-provisioning for OpenCloud
Problem: Users still routed to /login page instead of OIDC redirect.
Root cause: auto_provision_accounts was disabled in proxy OIDC config.

Changes:
- proxy.oidc.auto_provision_accounts: true (enable auto-provisioning)
- proxy.oidc.user_oidc_claim: email (user identification claim)
- proxy.oidc.role_assignment: Added OIDC role mapper for groups
- proxy.enable_basic_auth: false (explicitly disable basic auth)

Result: Users will be auto-created on first OIDC login with group-based roles.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 08:38:07 +00:00
CTO Agent
169cd315cb Fix OpenCloud user/group management for OIDC authentication
Problem: Users routed to /login page instead of OIDC redirect.
Root cause: ConfigMap still configured for LDAP-based user/group management.

Changes:
- Users service: Changed driver from 'ldap' to 'owncloudsql'
- Groups service: Changed driver from 'ldap' to 'owncloudsql'
- Graph service: Removed LDAP identity backend configuration
- Auth services: Removed auth_basic LDAP provider (OIDC only)
- Commented out IDP/IDM service configs (excluded services)

Result: OpenCloud will use owncloudsql driver for OIDC-based auto-provisioning.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 08:36:13 +00:00
CTO Agent
caf32a3b36 Fix OpenCloud authentication - Switch to Pocket ID OIDC only
Problem: OpenCloud was configured for internal authentication but login wasn't working.

Changes:
- Exclude internal IDP/IDM services (OC_EXCLUDE_RUN_SERVICES=search,idp,idm)
- Configure external OIDC with Pocket ID (auth.basicstack.de)
- Disable basic authentication (PROXY_ENABLE_BASIC_AUTH=false)
- Configure web service OIDC client settings
- Remove internal demo user creation (IDM_CREATE_DEMO_USERS)

Result: Users will authenticate via Pocket ID only, no internal auth methods.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-05 08:18:34 +00:00
CTO Agent
ac914386c2 Set fixed admin password for OpenCloud
Changed from random password to fixed password 'OpenCloud2024!'
to provide consistent login credentials.

Admin credentials:
- Username: admin
- Password: OpenCloud2024!

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-04 21:34:24 +00:00
CTO Agent
ac37e2d44d Fix OpenCloud internal authentication with auto-initialization
- Removed read-only ConfigMap mount that prevented initialization
- Added 'opencloud init' to startup command to auto-generate config
- Config is now generated in /etc/opencloud at container startup
- Admin user is automatically created with random password
- Service users are created by init process
- Fixes HTTP 500 error on login

This allows OpenCloud to properly initialize its internal IDM/IDP
services with the necessary service users for inter-service auth.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-04 21:23:55 +00:00
CTO Agent
acfb8618c7 Remove external OIDC configuration for internal auth
Removed all Pocket ID OIDC environment variables. OpenCloud now uses
its internal IDP for authentication instead of external OIDC provider.

The frontend config.json now correctly points to the internal IDP:
- Authority: https://opencloud.basicstack.de (was: auth.basicstack.de)
- Client ID: web (internal IDP client)

This fixes the login redirect issue where users were being sent to
the login page but couldn't see the login form.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-04 21:05:59 +00:00
CTO Agent
1371e69c4f Switch OpenCloud to internal authentication mode
- Enable internal IDP service (remove from OC_EXCLUDE_RUN_SERVICES)
- Enable demo users (IDM_CREATE_DEMO_USERS=true)
- Enable basic auth (PROXY_ENABLE_BASIC_AUTH=true)
- Remove opencloud init command (not needed with ConfigMap)
- Remove conflicting admin user overrides

OpenCloud now uses internal user management instead of external OIDC.
Demo users will be created on first startup (admin, einstein, marie).

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-07-04 21:00:52 +00:00
CTO Agent
d8807a7054 Attempt to fix OIDC with external IDP configuration
Added missing OIDC configuration for external authentication:
- Excluded internal IDP service (OC_EXCLUDE_RUN_SERVICES: idp,search)
- Added OC_OIDC_CLIENT_SCOPES
- Added IDP_DOMAIN for CSP rules
- Changed PROXY_USER_OIDC_CLAIM to email

Issue: OpenCloud still shows internal login page. Root cause appears
to be architectural - OpenCloud requires either:
1. Internal IDP + Internal IDM (default)
2. External LDAP + External OIDC (external-idp mode)

Pure external OIDC without LDAP backend may not be supported.
Next steps: Consider deploying OpenLDAP or using internal IDP.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-04 20:47:57 +00:00
CTO Agent
9e36a16d28 Add OpenCloud backup configuration to Hetzner Object Storage
Created automated daily backup system using rclone and Kubernetes CronJob.

Features:
- Daily backups at 2 AM UTC
- 7-day retention policy
- Backs up data directory and configuration
- Uses Hetzner S3-compatible Object Storage
- Read-only access to OpenCloud volumes

Files:
- backup-cronjob.yaml: CronJob for automated backups
- BACKUP.md: Complete setup and restore documentation

Requires:
- Hetzner Object Storage bucket credentials (sealed secret)
- S3 access key/secret to be provided

Once credentials are configured, backups will run automatically.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-04 20:43:40 +00:00
CTO Agent
e7a888d479 Fix OpenCloud OIDC authentication
Added missing OC_OIDC_CLIENT_SECRET environment variable and configured
Pocket ID client redirect URIs.

Changes:
- Added OC_OIDC_CLIENT_SECRET to deployment (from sealed secret)
- Updated Pocket ID client with callback URLs:
  - https://opencloud.basicstack.de/signin-oidc
  - https://opencloud.basicstack.de/oidc-callback
  - https://opencloud.basicstack.de

OIDC login should now redirect to Pocket ID instead of showing
OpenCloud's internal login page.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-04 20:41:44 +00:00
CTO Agent
182c270b4c Add OpenCloud v7.2.0 deployment to Kubernetes cluster
Deployed OpenCloud file-sharing platform at opencloud.basicstack.de with:
- Namespace: opencloud
- Encrypted hcloud volumes (100Gi PVC)
- Pocket ID OIDC integration (opencloud_admins group)
- SMTP notifications via opencloud@basicstack.de
- All credentials stored as SealedSecrets
- Search service excluded due to v7.2.0 bug (GitHub #1740)

Configuration follows official docker-compose pattern:
- Image: opencloudeu/opencloud-rolling:7.2.0
- Command: opencloud init || true; opencloud server
- External IDP mode with auto-provisioning
- OC_EXCLUDE_RUN_SERVICES: search

Files:
- opencloud-deployment.yaml: Main deployment with OIDC, SMTP config
- opencloud-configmap.yaml: OpenCloud config (search disabled)
- tika-deployment.yaml: Apache Tika for future search enablement

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-04 20:33:12 +00:00