Created automated daily backup system using rclone and Kubernetes CronJob. Features: - Daily backups at 2 AM UTC - 7-day retention policy - Backs up data directory and configuration - Uses Hetzner S3-compatible Object Storage - Read-only access to OpenCloud volumes Files: - backup-cronjob.yaml: CronJob for automated backups - BACKUP.md: Complete setup and restore documentation Requires: - Hetzner Object Storage bucket credentials (sealed secret) - S3 access key/secret to be provided Once credentials are configured, backups will run automatically. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|---|---|---|
| .. | ||
| backup-cronjob.yaml | ||
| BACKUP.md | ||
| DEPLOYMENT_STATUS.md | ||
| IMPLEMENTATION_STATUS.md | ||
| init-job.yaml | ||
| opencloud-config-sealed.yaml | ||
| opencloud-config-secrets-complete.yaml | ||
| opencloud-configmap.yaml | ||
| opencloud-deployment.yaml | ||
| opencloud-jwt-sealed.yaml | ||
| opencloud-oidc-sealed.yaml | ||
| opencloud-smtp-sealed.yaml | ||
| README.md | ||
| seal-config-secrets.sh | ||
| tika-deployment.yaml | ||
OpenCloud Deployment
Status: In Progress - Configuration Initialization Needed
Overview
Deployment of OpenCloud v7.2.0, a modern Go-based file sharing platform, configured with Pocket ID OIDC authentication.
Configuration Approach
OpenCloud uses a cloud-native configuration system (12-Factor App principles):
- Base configuration in
/etc/opencloud/opencloud.yaml(from ConfigMap) - Secrets injected via environment variables (highest precedence)
- All sensitive credentials stored as SealedSecrets
Reference: https://docs.opencloud.eu/docs/next/dev/server/configuration/config-system/
Deployed Components
- ✓ Namespace:
opencloud - ✓ PVC: 100Gi encrypted hcloud volume
- ✓ ConfigMap: Base opencloud.yaml configuration
- ✓ SealedSecrets: OIDC, SMTP, JWT, and config secrets
- ✓ Ingress: opencloud.basicstack.de with TLS
- ✓ Service and Deployment manifests
Pocket ID Integration
- Client ID:
2f3c0cea-697f-4dbc-9573-6f6e8adfd4b0 - Group:
opencloud_admins - User: andreas.leinen@basicstack.de
- OIDC Issuer: https://auth.basicstack.de
Files
opencloud-deployment.yaml- Main Kubernetes deploymentopencloud-configmap.yaml- Base configuration fileopencloud-config-sealed.yaml- ⚠️ NEEDS SEALING - Core secrets (machine auth, transfer secret, etc.)opencloud-oidc-sealed.yaml- OIDC credentials (sealed)opencloud-smtp-sealed.yaml- SMTP credentials (sealed)opencloud-jwt-sealed.yaml- JWT token secret (sealed)seal-config-secrets.sh- Helper script to seal config secrets
Next Steps
-
Seal the config secrets:
cd apps/opencloud bash seal-config-secrets.sh -
Apply all manifests:
kubectl apply -f opencloud-configmap.yaml kubectl apply -f opencloud-config-sealed.yaml # After sealing! kubectl apply -f opencloud-oidc-sealed.yaml kubectl apply -f opencloud-smtp-sealed.yaml kubectl apply -f opencloud-jwt-sealed.yaml kubectl apply -f opencloud-deployment.yaml -
Verify deployment:
kubectl get pods -n opencloud kubectl logs -n opencloud deployment/opencloud -
Test login:
- Navigate to https://opencloud.basicstack.de
- Login with andreas.leinen@basicstack.de via Pocket ID
TODO
- Seal opencloud-config-secrets
- Configure daily backup to Hetzner bucket
- Test OIDC authentication
- Test file upload/download
- Test SMTP notifications