diff --git a/.env.sample b/.env.sample index 43bd3d1..779ebcd 100644 --- a/.env.sample +++ b/.env.sample @@ -72,3 +72,37 @@ LOGGING_LEVEL_LOGGERS_APP=INFO ############################################################################## # Set to false to disable automatic migrations on backend startup # AUTO_MIGRATIONS=true + +############################################################################## +# CONVERSION (file upload → Yjs via y-provider) +############################################################################## +# Allow uploading .docx/.md files for conversion to Yjs. +# Recipe sets this to true (upstream default is false). +# CONVERSION_UPLOAD_ENABLED=true +# Upstream defaults (uncomment to override): +# CONVERSION_FILE_MAX_SIZE=20971520 +# CONVERSION_FILE_EXTENSIONS_ALLOWED=.docx,.md +# CONVERSION_API_ENDPOINT=convert +# CONVERSION_API_CONTENT_FIELD=content +# CONVERSION_API_TIMEOUT=30 +# CONVERSION_API_SECURE=false + +############################################################################## +# DATABASE CONNECTION POOL +############################################################################## +# Upstream default (uncomment to override): +# DB_PSYCOPG_POOL_ENABLED=false + +############################################################################## +# EMAIL APP URL +############################################################################## +# DJANGO_EMAIL_URL_APP is set automatically in compose.yml to https://${DOMAIN}. +# Override is not exposed via .env — edit compose.yml directly if needed. +# (Upstream default falls back to Django's Site framework, not configured here.) + +############################################################################## +# MEDIA AUTH HEADER +############################################################################## +# Header the backend reads for media auth subrequests. +# Upstream default matches the recipe's nginx config (X-Original-URL). +# MEDIA_AUTH_ORIGINAL_URL_HEADER=HTTP_X_ORIGINAL_URL diff --git a/MAINTENANCE.md b/MAINTENANCE.md new file mode 100644 index 0000000..5e6ae11 --- /dev/null +++ b/MAINTENANCE.md @@ -0,0 +1,15 @@ +# Lasuite-Docs Recipe Maintenance + +All contributions should be made via pull requests. + +## Pull Requests + +A pull request can be merged directly into `main` by any maintainer. No approval is needed, but pull requests should be tested as working before merge. + +## Become a maintainer + +Everyone can apply to be a recipe maintainer: + +1. Watch the repository to get updates. +2. Add yourself to the list in [README.md](./README.md) and open a pull request with the change. +3. Once the pull request is merged, you will be added to the [La Suite maintainers team](https://git.coopcloud.tech/org/coop-cloud/teams/lasuite-maintainers). diff --git a/README.md b/README.md index 49e32b7..9c0a435 100644 --- a/README.md +++ b/README.md @@ -80,3 +80,8 @@ You then need to insert the password for your smtp server as a secret: Then redeploy the app, and automated e-mail sending should work: `abra app deploy --force` + +## Maintainers + +* @trav +* @notplants diff --git a/abra.sh b/abra.sh index 2cb0ec8..468faea 100755 --- a/abra.sh +++ b/abra.sh @@ -2,7 +2,7 @@ # Docs: https://docs.coopcloud.tech/maintainers/handbook/#manage-configs export ABRA_ENTRYPOINT_VERSION=v5 export NGINX_CONF_VERSION=v3 -export PG_BACKUP_VERSION=v3 +export PG_BACKUP_VERSION=v4 export MINIO_INITIALIZE_VERSION=v1 export MIGRATE_VERSION=v1 diff --git a/compose.yml b/compose.yml index 0887e23..3015562 100644 --- a/compose.yml +++ b/compose.yml @@ -49,13 +49,32 @@ x-common-env: &common-env LOGOUT_REDIRECT_URL: OIDC_REDIRECT_ALLOWED_HOSTS: OIDC_AUTH_REQUEST_EXTRA_PARAMS: - # AI (Fixme: remove?) + # AI AI_FEATURE_ENABLED: "false" - AI_BASE_URL: https://openaiendpoint.com - AI_API_KEY: password + OPENAI_SDK_BASE_URL: https://openaiendpoint.com + OPENAI_SDK_API_KEY: password AI_MODEL: llama # Collaboration COLLABORATION_API_URL: https://$DOMAIN/collaboration/api/ + # Email app URL (used in email templates; matches recipe DOMAIN) + DJANGO_EMAIL_URL_APP: "https://${DOMAIN}" + # Conversion (file upload → Yjs via y-provider) + CONVERSION_UPLOAD_ENABLED: "${CONVERSION_UPLOAD_ENABLED:-true}" + CONVERSION_FILE_MAX_SIZE: + CONVERSION_FILE_EXTENSIONS_ALLOWED: + CONVERSION_API_ENDPOINT: + CONVERSION_API_CONTENT_FIELD: + CONVERSION_API_TIMEOUT: + CONVERSION_API_SECURE: + # Y-Provider base URL + API key (needed when CONVERSION_UPLOAD_ENABLED is true) + Y_PROVIDER_API_BASE_URL: http://y-provider:4444/api/ + Y_PROVIDER_API_KEY_FILE: /run/secrets/y_api_key + # DocSpec — converts .docx → BlockNote JSON, then y-provider turns that into Yjs + DOCSPEC_API_URL: http://docspec:4000/conversion + # Database connection pool + DB_PSYCOPG_POOL_ENABLED: + # Media auth header (matches recipe nginx by default) + MEDIA_AUTH_ORIGINAL_URL_HEADER: x-postgres-env: &postgres-env # Postgresql db container configuration @@ -84,14 +103,14 @@ x-minio-env: &minio-env services: app: - image: lasuite/impress-frontend:v4.5.0 + image: lasuite/impress-frontend:v5.6.1 networks: - backend deploy: labels: - "traefik.enable=false" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}" - - "coop-cloud.${STACK_NAME}.version=0.2.9+v4.5.0" + - "coop-cloud.${STACK_NAME}.version=0.4.3+v5.6.1" user: "${DOCKER_USER:-1000}" healthcheck: test: ["CMD", "curl", "-f", "http://localhost:8080"] @@ -101,7 +120,7 @@ services: start_period: 10s backend: - image: lasuite/impress-backend:v4.5.0 + image: lasuite/impress-backend:v5.6.1 networks: - backend environment: @@ -136,7 +155,7 @@ services: - email_pass celery: - image: lasuite/impress-backend:v4.5.0 + image: lasuite/impress-backend:v5.6.1 networks: - backend healthcheck: @@ -166,7 +185,7 @@ services: y-provider: - image: lasuite/impress-y-provider:v4.5.0 + image: lasuite/impress-y-provider:v5.6.1 networks: - backend healthcheck: @@ -184,6 +203,18 @@ services: secrets: - y_api_key + docspec: + image: ghcr.io/docspecio/api:3.0.2 + networks: + - backend + healthcheck: + # Use 127.0.0.1, which is required instead of localhost for this healtcheck because of elixir/busybox bindings + test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:4000/health"] + interval: 15s + timeout: 5s + retries: 3 + start_period: 10s + db: image: pgautoupgrade/pgautoupgrade:18-debian networks: @@ -212,7 +243,7 @@ services: - postgres_p redis: - image: redis:8.0.5 + image: redis:8.10.1 healthcheck: test: ["CMD", "redis-cli", "ping"] interval: 15s @@ -222,7 +253,8 @@ services: - backend minio: - image: minio/minio:RELEASE.2025-05-24T17-08-30Z + image: bitnamilegacy/minio:2025.7.23-debian-12-r5 + user: root environment: *minio-env healthcheck: test: ["CMD", "mc", "ready", "local"] @@ -231,11 +263,11 @@ services: retries: 300 networks: - backend - command: minio server /data + command: /opt/bitnami/scripts/minio/run.sh entrypoint: > - sh -c "/minio-initialize.sh & exec /usr/bin/docker-entrypoint.sh \"$$@\"" -- + sh -c "/minio-initialize.sh & exec /opt/bitnami/scripts/minio/entrypoint.sh \"$$@\"" -- volumes: - - minio:/data + - minio:/bitnami/minio/data deploy: labels: backupbot.backup: "${ENABLE_BACKUPS:-true}" @@ -252,7 +284,7 @@ services: - minio_ru web: - image: nginx:1.29.5 + image: nginx:1.31.5 healthcheck: test: ["CMD", "curl", "-f", "http://localhost:8083"] interval: 15s diff --git a/minio-initialize.sh b/minio-initialize.sh index 3511083..f0f552e 100644 --- a/minio-initialize.sh +++ b/minio-initialize.sh @@ -1,6 +1,11 @@ #!/bin/sh set -e +# Use an isolated mc config dir: the bundled Bitnami image runs its own +# internal mc client (as the "minio" user) against the default /.mc path, +# which collides with this script running as root against the same path. +export MC_CONFIG_DIR=/tmp/mc-docs-init + # Wait for minio to be ready (up to 60 seconds) i=0 while ! mc ready local 2>/dev/null; do