Files
composes/opencloud/README.md
T

3.1 KiB

opencloud

OpenCloud Server: file sync and share with web, desktop and mobile clients, spaces and WebDAV.

One container, opencloud, running every OpenCloud service in one process, including the built-in identity provider, user directory and NATS. Files and metadata live on disk, so there is no database container.

Setup

  1. Set OC_DOMAIN and INITIAL_ADMIN_PASSWORD.
  2. Map the domain to port 9200 over HTTPS and deploy.
  3. Log in as admin with INITIAL_ADMIN_PASSWORD.

Health check: GET http://127.0.0.1:9205/healthz, the proxy's debug endpoint, also the compose healthcheck. It listens on loopback only.

Environment

Variable Default Purpose
OC_DOMAIN — Public hostname, without scheme; becomes OC_URL
INITIAL_ADMIN_PASSWORD — Password of the admin account
OC_LOG_LEVEL info Optional. Log level
PROXY_ENABLE_BASIC_AUTH false Optional. Basic auth for WebDAV clients without OpenID Connect

OC_URL must be the exact HTTPS URL the browser uses: the built-in identity provider uses it as its issuer and redirect target.

INITIAL_ADMIN_PASSWORD is read only on first start, when the admin account is created. Changing it later does not change the password; use the web UI.

PROXY_TLS=false, PROXY_HTTP_ADDR and OC_INSECURE=false are fixed in compose.yml. The platform proxy terminates TLS and forwards plain HTTP to port 9200, and the certificate it serves is a real one, so certificate checks stay on.

Storage

Volume Mount Holds
opencloud-config /etc/opencloud opencloud.yaml, with the generated secrets
opencloud-data /var/lib/opencloud User files, spaces, the user directory and search index

The two volumes belong together. opencloud.yaml holds the secrets the data was written with; a data volume restored without its config volume, or the reverse, does not start cleanly. Back them up as a pair.

The image creates both directories owned by uid 1000, the user it runs as, so fresh named volumes are writable without an init step.

Choices

  • opencloud init || true; opencloud server. init writes opencloud.yaml with random secrets on first start and fails harmlessly once it exists, as in upstream's own compose.
  • No config files. OpenCloud's built-in CSP and app list cover the web UI and the built-in identity provider. Upstream's csp.yaml and apps.yaml only add origins for an external identity provider, office server and optional web apps.
  • No office integration. Editing documents in the browser needs a separate office server on its own domain, OpenCloud's collaboration service, and a custom csp.yaml allowing that domain. The office server also needs extra kernel capabilities and a WOPI proof key. None of that can be switched on by variables alone, so it is left out.
  • opencloudeu/opencloud:7. The opencloud repository carries the production releases, and 7 tracks the 7.x line. The opencloud-rolling repository, which upstream's compose defaults to, ships a new major every few months.