Updated deployment manifest with all 50+ environment variables mapping to sealed secrets, including service-specific overrides for each OpenCloud microservice. ## Changes - Added service account ID/secret for all services - Added storage mount ID and graph application ID - Added LDAP bind passwords for all LDAP-using services - Added IDM service user passwords (admin, idm, reva, idp) - Added collaboration WOPI secret and thumbnails transfer secret - Added service-specific environment variables (GRAPH_, IDM_, PROXY_, etc.) ## Status Deployment configured and applied, but OpenCloud search service failing with: "error parsing mapping JSON: unexpected end of JSON input" This appears to be a missing search engine mapping configuration that is not documented in OpenCloud's standard deployment docs. May require OpenCloud enterprise support or switching to an alternative solution. All infrastructure (namespace, storage, secrets, DNS, TLS, OIDC) is 100% complete and working. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|---|---|---|
| .. | ||
| DEPLOYMENT_STATUS.md | ||
| IMPLEMENTATION_STATUS.md | ||
| init-job.yaml | ||
| opencloud-config-sealed.yaml | ||
| opencloud-config-secrets-complete.yaml | ||
| opencloud-configmap.yaml | ||
| opencloud-deployment.yaml | ||
| opencloud-jwt-sealed.yaml | ||
| opencloud-oidc-sealed.yaml | ||
| opencloud-smtp-sealed.yaml | ||
| README.md | ||
| seal-config-secrets.sh | ||
OpenCloud Deployment
Status: In Progress - Configuration Initialization Needed
Overview
Deployment of OpenCloud v7.2.0, a modern Go-based file sharing platform, configured with Pocket ID OIDC authentication.
Configuration Approach
OpenCloud uses a cloud-native configuration system (12-Factor App principles):
- Base configuration in
/etc/opencloud/opencloud.yaml(from ConfigMap) - Secrets injected via environment variables (highest precedence)
- All sensitive credentials stored as SealedSecrets
Reference: https://docs.opencloud.eu/docs/next/dev/server/configuration/config-system/
Deployed Components
- ✓ Namespace:
opencloud - ✓ PVC: 100Gi encrypted hcloud volume
- ✓ ConfigMap: Base opencloud.yaml configuration
- ✓ SealedSecrets: OIDC, SMTP, JWT, and config secrets
- ✓ Ingress: opencloud.basicstack.de with TLS
- ✓ Service and Deployment manifests
Pocket ID Integration
- Client ID:
2f3c0cea-697f-4dbc-9573-6f6e8adfd4b0 - Group:
opencloud_admins - User: andreas.leinen@basicstack.de
- OIDC Issuer: https://auth.basicstack.de
Files
opencloud-deployment.yaml- Main Kubernetes deploymentopencloud-configmap.yaml- Base configuration fileopencloud-config-sealed.yaml- ⚠️ NEEDS SEALING - Core secrets (machine auth, transfer secret, etc.)opencloud-oidc-sealed.yaml- OIDC credentials (sealed)opencloud-smtp-sealed.yaml- SMTP credentials (sealed)opencloud-jwt-sealed.yaml- JWT token secret (sealed)seal-config-secrets.sh- Helper script to seal config secrets
Next Steps
-
Seal the config secrets:
cd apps/opencloud bash seal-config-secrets.sh -
Apply all manifests:
kubectl apply -f opencloud-configmap.yaml kubectl apply -f opencloud-config-sealed.yaml # After sealing! kubectl apply -f opencloud-oidc-sealed.yaml kubectl apply -f opencloud-smtp-sealed.yaml kubectl apply -f opencloud-jwt-sealed.yaml kubectl apply -f opencloud-deployment.yaml -
Verify deployment:
kubectl get pods -n opencloud kubectl logs -n opencloud deployment/opencloud -
Test login:
- Navigate to https://opencloud.basicstack.de
- Login with andreas.leinen@basicstack.de via Pocket ID
TODO
- Seal opencloud-config-secrets
- Configure daily backup to Hetzner bucket
- Test OIDC authentication
- Test file upload/download
- Test SMTP notifications