Compare commits

..
Author SHA1 Message Date
autonomic-bot 1ed910dfb0 chore: upgrade lasuite-drive to v0.23.0, collabora to 26.04.4.2.1; bump minio_initialize config to v2
cc-ci/testme cc-ci: success
2026-09-28 21:07:15 +00:00
notplants 58e11f4439 chore: publish 0.13.2+v0.22.0 release 2026-09-28 16:27:00 -04:00
trav 726f4e8f28 chore: publish 0.13.1+v0.22.0 release 2026-09-28 13:12:15 -07:00
notplants e3146f3ca2 Merge pull request 'Use other minio as the quay.io is not available' (#13) from c4dt/lasuite-drive:use_other_minio into main
Reviewed-on: https://git.coopcloud.tech/coop-cloud/lasuite-drive/pulls/13
2026-09-28 19:57:10 +00:00
Linus Gasser 782e3f0965 Use other minio as the quay.io is not available
cc-ci/testme cc-ci: failure
2026-09-28 17:26:36 +02:00
autonomic-bot ce5308c7f5 chore: upgrade lasuite-drive redis to 8.10.2, collabora to 26.04.4.1.1
cc-ci/testme cc-ci: failure
collabora 26.04 images exec coolwsd directly (--use-env-vars; no shell in the
image), so the sh/start-collabora-online.sh entrypoint and extra_params env are
gone: ssl options move to command args, the healthcheck switches to
coolwsd --probe, and the admin panel password moves from the collabora_p
docker secret to the COLLABORA_ADMIN_PASSWORD env var (empty = locked).

redis 8.10.2 is a security release (transaction ACL-revocation bypass,
unauthenticated cluster-bus join; cache sidecar, no cluster mode here).
2026-09-21 21:20:55 +00:00
4 changed files with 28 additions and 27 deletions
+5 -4
View File
@@ -28,8 +28,6 @@ SECRET_MINIO_RU_VERSION=v1
SECRET_POSTGRES_P_VERSION=v1 SECRET_POSTGRES_P_VERSION=v1
# DJANGO_HOST_EMAIL_PASSWORD # DJANGO_HOST_EMAIL_PASSWORD
SECRET_EMAIL_PASS_VERSION=v1 SECRET_EMAIL_PASS_VERSION=v1
# COLLABORA_ADMIN_PASSWORD
SECRET_COLLABORA_P_VERSION=v1
############################################################################## ##############################################################################
# EMAIL # EMAIL
@@ -77,9 +75,12 @@ LOGGING_LEVEL_LOGGERS_APP=INFO
############################################################################## ##############################################################################
# COLLABORA ADMIN PANEL # COLLABORA ADMIN PANEL
############################################################################## ##############################################################################
# Username for the Collabora admin panel (https://COLLABORA_DOMAIN/browser/dist/admin/admin.html) # Credentials for the Collabora admin panel (https://COLLABORA_DOMAIN/browser/dist/admin/admin.html)
# Password is managed via Docker secret 'collabora_p' # Since collabora 26.04 (image execs coolwsd directly; no shell in the image), the panel
# password moved from the retired Docker secret 'collabora_p' to this env var.
# Empty/unset = panel stays locked.
#COLLABORA_ADMIN_USERNAME=admin #COLLABORA_ADMIN_USERNAME=admin
#COLLABORA_ADMIN_PASSWORD=
############################################################################## ##############################################################################
# BACKUPS # BACKUPS
+1 -1
View File
@@ -5,7 +5,7 @@ export NGINX_CONF_VERSION=v6
export ONLYOFFICE_CONF_VERSION=v2 export ONLYOFFICE_CONF_VERSION=v2
export PG_BACKUP_VERSION=v4 export PG_BACKUP_VERSION=v4
export MIGRATE_VERSION=v1 export MIGRATE_VERSION=v1
export MINIO_INITIALIZE_VERSION=v1 export MINIO_INITIALIZE_VERSION=v2
environment() { environment() {
# this exports all the secrets as environment variables # this exports all the secrets as environment variables
+17 -22
View File
@@ -95,14 +95,14 @@ services:
app: app:
user: "${DOCKER_USER:-1000}" user: "${DOCKER_USER:-1000}"
image: lasuite/drive-frontend:v0.22.0 image: lasuite/drive-frontend:v0.23.0
networks: networks:
- backend - backend
deploy: deploy:
labels: labels:
- "traefik.enable=false" - "traefik.enable=false"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
- "coop-cloud.${STACK_NAME}.version=0.13.0+v0.22.0" - "coop-cloud.${STACK_NAME}.version=0.13.2+v0.22.0"
environment: environment:
<<: [ *common-env ] <<: [ *common-env ]
healthcheck: healthcheck:
@@ -116,7 +116,7 @@ services:
backend: backend:
user: ${DOCKER_USER:-1000} user: ${DOCKER_USER:-1000}
image: lasuite/drive-backend:v0.22.0 image: lasuite/drive-backend:v0.23.0
command: [ "gunicorn", "-c", "/usr/local/etc/gunicorn/drive.py", "drive.wsgi:application" ] command: [ "gunicorn", "-c", "/usr/local/etc/gunicorn/drive.py", "drive.wsgi:application" ]
entrypoint: > entrypoint: >
sh -c "if [ \"$$AUTO_MIGRATIONS\" = \"true\" ]; then /migrate.sh; fi && exec /abra-entrypoint.sh /usr/local/bin/entrypoint \"$$@\"" -- sh -c "if [ \"$$AUTO_MIGRATIONS\" = \"true\" ]; then /migrate.sh; fi && exec /abra-entrypoint.sh /usr/local/bin/entrypoint \"$$@\"" --
@@ -145,7 +145,7 @@ services:
celery: celery:
user: ${DOCKER_USER:-1000} user: ${DOCKER_USER:-1000}
image: lasuite/drive-backend:v0.22.0 image: lasuite/drive-backend:v0.23.0
networks: networks:
- backend - backend
command: [ "celery", "-A", "drive.celery_app", "worker", "-l", "INFO" ] command: [ "celery", "-A", "drive.celery_app", "worker", "-l", "INFO" ]
@@ -167,7 +167,7 @@ services:
celery-beat: celery-beat:
user: ${DOCKER_USER:-1000} user: ${DOCKER_USER:-1000}
image: lasuite/drive-backend:v0.22.0 image: lasuite/drive-backend:v0.23.0
networks: networks:
- backend - backend
command: [ "celery", "-A", "drive.celery_app", "beat", "-l", "INFO", "--schedule", "/tmp/celerybeat-schedule" ] command: [ "celery", "-A", "drive.celery_app", "beat", "-l", "INFO", "--schedule", "/tmp/celerybeat-schedule" ]
@@ -214,7 +214,7 @@ services:
- postgres_p - postgres_p
redis: redis:
image: redis:8.10.1 image: redis:8.10.2
healthcheck: healthcheck:
test: ["CMD", "redis-cli", "ping"] test: ["CMD", "redis-cli", "ping"]
interval: 10s interval: 10s
@@ -229,7 +229,8 @@ services:
- backend - backend
minio: minio:
image: quay.io/minio/minio:RELEASE.2025-09-07T16-13-09Z image: bitnamilegacy/minio:2025.7.23-debian-12-r5
user: root
environment: *minio-env environment: *minio-env
healthcheck: healthcheck:
test: ["CMD", "mc", "ready", "local"] test: ["CMD", "mc", "ready", "local"]
@@ -239,11 +240,11 @@ services:
networks: networks:
- backend - backend
- proxy - proxy
command: minio server /data command: /opt/bitnami/scripts/minio/run.sh
entrypoint: > entrypoint: >
sh -c "/minio-initialize.sh & exec /usr/bin/docker-entrypoint.sh \"$$@\"" -- sh -c "/minio-initialize.sh & exec /opt/bitnami/scripts/minio/entrypoint.sh \"$$@\"" --
volumes: volumes:
- minio:/data - minio:/bitnami/minio/data
configs: configs:
- source: abra_entrypoint - source: abra_entrypoint
target: /abra-entrypoint.sh target: /abra-entrypoint.sh
@@ -273,13 +274,12 @@ services:
- "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup=${ENABLE_BACKUPS:-true}"
collabora: collabora:
image: collabora/code:25.04.10.3.1 image: collabora/code:26.04.4.2.1
entrypoint: > # 26.04 images exec coolwsd directly (--use-env-vars; no shell in the image),
sh -c " # so ssl options are passed as args and the panel password comes from the env.
export password=\"$$(cat /run/secrets/collabora_p)\" && command: ["--o:ssl.enable=false", "--o:ssl.termination=true"]
exec /start-collabora-online.sh"
healthcheck: healthcheck:
test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ] test: [ "CMD", "/usr/bin/coolwsd", "--probe", "--o:ssl.enable=false" ]
interval: 30s interval: 30s
retries: 5 retries: 5
start_period: 60s start_period: 60s
@@ -288,11 +288,9 @@ services:
- backend - backend
- proxy - proxy
environment: environment:
- extra_params=--o:ssl.enable=false --o:ssl.termination=true
- username=${COLLABORA_ADMIN_USERNAME:-admin} - username=${COLLABORA_ADMIN_USERNAME:-admin}
- server_name=${COLLABORA_DOMAIN} - server_name=${COLLABORA_DOMAIN}
secrets: - password=${COLLABORA_ADMIN_PASSWORD:-}
- collabora_p
deploy: deploy:
labels: labels:
- "traefik.enable=true" - "traefik.enable=true"
@@ -422,9 +420,6 @@ secrets:
minio_ru: minio_ru:
external: true external: true
name: ${STACK_NAME}_minio_ru_${SECRET_MINIO_RU_VERSION} name: ${STACK_NAME}_minio_ru_${SECRET_MINIO_RU_VERSION}
collabora_p:
external: true
name: ${STACK_NAME}_collabora_p_${SECRET_COLLABORA_P_VERSION}
email_pass: email_pass:
external: true external: true
name: ${STACK_NAME}_email_pass_${SECRET_EMAIL_PASS_VERSION} name: ${STACK_NAME}_email_pass_${SECRET_EMAIL_PASS_VERSION}
+5
View File
@@ -1,6 +1,11 @@
#!/bin/sh #!/bin/sh
set -e set -e
# Use an isolated mc config dir: the bundled Bitnami image runs its own
# internal mc client (as the "minio" user) against the default /.mc path,
# which collides with this script running as root against the same path.
export MC_CONFIG_DIR=/tmp/mc-drive-init
# Wait for minio to be ready (up to 60 seconds) # Wait for minio to be ready (up to 60 seconds)
i=0 i=0
while ! mc ready local 2>/dev/null; do while ! mc ready local 2>/dev/null; do