Generated complete OpenCloud config using 'opencloud init' and created
comprehensive sealed secrets for all 27 required configuration values.
## What's Complete (95%)
### Configuration Discovery
- Ran 'opencloud init' in Kubernetes job to generate full config template
- Documented all required services: proxy, idm, idp, graph, storage, gateway,
ocm, thumbnails, search, audit, settings, sharing, notifications, etc.
- Created complete opencloud.yaml ConfigMap with bash substitution
### Secrets (27 total, all sealed)
- Service account ID & secret (shared across services)
- Storage mount ID & graph application ID
- 4x LDAP bind passwords (graph, idp, users, groups)
- 4x IDM service passwords (admin, idm, reva, idp)
- Collaboration WOPI secret & thumbnails transfer secret
- Core API keys (machine auth, system user, transfer, URL signing)
- JWT secret, OIDC credentials, SMTP credentials (from previous work)
### Files
- opencloud-configmap.yaml: Complete config with ${VAR} substitution
- opencloud-config-sealed.yaml: All 27 secrets sealed
- opencloud-config-secrets-complete.yaml: Unsealed reference
- init-job.yaml: Helper to run 'opencloud init'
- DEPLOYMENT_STATUS.md: Complete documentation
## Remaining Work (5%)
Update opencloud-deployment.yaml to inject ~20 additional environment
variables from opencloud-config-secrets. Template provided in
DEPLOYMENT_STATUS.md. Estimated time: 5-10 minutes.
## Technical Approach
OpenCloud's 12-Factor config system:
1. Config file provides structure (/etc/opencloud/opencloud.yaml)
2. Environment variables override values (highest precedence)
3. Bash substitution bridges them: ${OC_VAR_NAME}
Our solution:
- ConfigMap = complete structure from 'opencloud init'
- SealedSecrets = all sensitive values
- Deployment = injects secrets as env vars
- Runtime = bash substitution resolves into config
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
29 lines
859 B
YAML
29 lines
859 B
YAML
apiVersion: batch/v1
|
|
kind: Job
|
|
metadata:
|
|
name: opencloud-init-generator
|
|
namespace: opencloud
|
|
spec:
|
|
ttlSecondsAfterFinished: 300
|
|
template:
|
|
spec:
|
|
restartPolicy: Never
|
|
containers:
|
|
- name: init
|
|
image: quay.io/opencloudeu/opencloud:7.2.0
|
|
command: ["/bin/sh"]
|
|
args:
|
|
- -c
|
|
- |
|
|
echo "=== Running opencloud init ==="
|
|
OPENCLOUD_URL=https://opencloud.basicstack.de \
|
|
/usr/bin/opencloud init --insecure true
|
|
|
|
echo ""
|
|
echo "=== Generated opencloud.yaml ==="
|
|
if [ -f /etc/opencloud/opencloud.yaml ]; then
|
|
cat /etc/opencloud/opencloud.yaml
|
|
else
|
|
echo "ERROR: opencloud.yaml not found at /etc/opencloud/"
|
|
ls -la /etc/opencloud/ || echo "Directory doesn't exist"
|
|
fi
|