stack.basicstack.de/apps/opencloud
CTO Agent 9e36a16d28 Add OpenCloud backup configuration to Hetzner Object Storage
Created automated daily backup system using rclone and Kubernetes CronJob.

Features:
- Daily backups at 2 AM UTC
- 7-day retention policy
- Backs up data directory and configuration
- Uses Hetzner S3-compatible Object Storage
- Read-only access to OpenCloud volumes

Files:
- backup-cronjob.yaml: CronJob for automated backups
- BACKUP.md: Complete setup and restore documentation

Requires:
- Hetzner Object Storage bucket credentials (sealed secret)
- S3 access key/secret to be provided

Once credentials are configured, backups will run automatically.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-07-04 20:43:40 +00:00
..
backup-cronjob.yaml Add OpenCloud backup configuration to Hetzner Object Storage 2026-07-04 20:43:40 +00:00
BACKUP.md Add OpenCloud backup configuration to Hetzner Object Storage 2026-07-04 20:43:40 +00:00
DEPLOYMENT_STATUS.md Complete OpenCloud configuration initialization 2026-07-04 19:41:22 +00:00
IMPLEMENTATION_STATUS.md Add OpenCloud deployment (partial implementation) 2026-07-04 19:35:08 +00:00
init-job.yaml Complete OpenCloud configuration initialization 2026-07-04 19:41:22 +00:00
opencloud-config-sealed.yaml Complete OpenCloud configuration initialization 2026-07-04 19:41:22 +00:00
opencloud-config-secrets-complete.yaml Complete OpenCloud configuration initialization 2026-07-04 19:41:22 +00:00
opencloud-configmap.yaml Add OpenCloud v7.2.0 deployment to Kubernetes cluster 2026-07-04 20:33:12 +00:00
opencloud-deployment.yaml Fix OpenCloud OIDC authentication 2026-07-04 20:41:44 +00:00
opencloud-jwt-sealed.yaml OpenCloud deployment attempt - blocked on configuration complexity 2026-07-04 18:59:33 +00:00
opencloud-oidc-sealed.yaml OpenCloud deployment attempt - blocked on configuration complexity 2026-07-04 18:59:33 +00:00
opencloud-smtp-sealed.yaml OpenCloud deployment attempt - blocked on configuration complexity 2026-07-04 18:59:33 +00:00
README.md Add OpenCloud deployment (partial implementation) 2026-07-04 19:35:08 +00:00
seal-config-secrets.sh Add OpenCloud deployment (partial implementation) 2026-07-04 19:35:08 +00:00
tika-deployment.yaml Add OpenCloud v7.2.0 deployment to Kubernetes cluster 2026-07-04 20:33:12 +00:00

OpenCloud Deployment

Status: In Progress - Configuration Initialization Needed

Overview

Deployment of OpenCloud v7.2.0, a modern Go-based file sharing platform, configured with Pocket ID OIDC authentication.

Configuration Approach

OpenCloud uses a cloud-native configuration system (12-Factor App principles):

  1. Base configuration in /etc/opencloud/opencloud.yaml (from ConfigMap)
  2. Secrets injected via environment variables (highest precedence)
  3. All sensitive credentials stored as SealedSecrets

Reference: https://docs.opencloud.eu/docs/next/dev/server/configuration/config-system/

Deployed Components

  • ✓ Namespace: opencloud
  • ✓ PVC: 100Gi encrypted hcloud volume
  • ✓ ConfigMap: Base opencloud.yaml configuration
  • ✓ SealedSecrets: OIDC, SMTP, JWT, and config secrets
  • ✓ Ingress: opencloud.basicstack.de with TLS
  • ✓ Service and Deployment manifests

Pocket ID Integration

Files

  • opencloud-deployment.yaml - Main Kubernetes deployment
  • opencloud-configmap.yaml - Base configuration file
  • opencloud-config-sealed.yaml - ⚠️ NEEDS SEALING - Core secrets (machine auth, transfer secret, etc.)
  • opencloud-oidc-sealed.yaml - OIDC credentials (sealed)
  • opencloud-smtp-sealed.yaml - SMTP credentials (sealed)
  • opencloud-jwt-sealed.yaml - JWT token secret (sealed)
  • seal-config-secrets.sh - Helper script to seal config secrets

Next Steps

  1. Seal the config secrets:

    cd apps/opencloud
    bash seal-config-secrets.sh
    
  2. Apply all manifests:

    kubectl apply -f opencloud-configmap.yaml
    kubectl apply -f opencloud-config-sealed.yaml  # After sealing!
    kubectl apply -f opencloud-oidc-sealed.yaml
    kubectl apply -f opencloud-smtp-sealed.yaml
    kubectl apply -f opencloud-jwt-sealed.yaml
    kubectl apply -f opencloud-deployment.yaml
    
  3. Verify deployment:

    kubectl get pods -n opencloud
    kubectl logs -n opencloud deployment/opencloud
    
  4. Test login:

TODO

  • Seal opencloud-config-secrets
  • Configure daily backup to Hetzner bucket
  • Test OIDC authentication
  • Test file upload/download
  • Test SMTP notifications