Compare commits

..
2 Commits
Author SHA1 Message Date
autonomic-bot 1ed910dfb0 chore: upgrade lasuite-drive to v0.23.0, collabora to 26.04.4.2.1; bump minio_initialize config to v2
cc-ci/testme cc-ci: success
2026-09-28 21:07:15 +00:00
autonomic-bot ce5308c7f5 chore: upgrade lasuite-drive redis to 8.10.2, collabora to 26.04.4.1.1
cc-ci/testme cc-ci: failure
collabora 26.04 images exec coolwsd directly (--use-env-vars; no shell in the
image), so the sh/start-collabora-online.sh entrypoint and extra_params env are
gone: ssl options move to command args, the healthcheck switches to
coolwsd --probe, and the admin panel password moves from the collabora_p
docker secret to the COLLABORA_ADMIN_PASSWORD env var (empty = locked).

redis 8.10.2 is a security release (transaction ACL-revocation bypass,
unauthenticated cluster-bus join; cache sidecar, no cluster mode here).
2026-09-21 21:20:55 +00:00
6 changed files with 23 additions and 44 deletions
+5 -4
View File
@@ -28,8 +28,6 @@ SECRET_MINIO_RU_VERSION=v1
SECRET_POSTGRES_P_VERSION=v1
# DJANGO_HOST_EMAIL_PASSWORD
SECRET_EMAIL_PASS_VERSION=v1
# COLLABORA_ADMIN_PASSWORD
SECRET_COLLABORA_P_VERSION=v1
##############################################################################
# EMAIL
@@ -77,9 +75,12 @@ LOGGING_LEVEL_LOGGERS_APP=INFO
##############################################################################
# COLLABORA ADMIN PANEL
##############################################################################
# Username for the Collabora admin panel (https://COLLABORA_DOMAIN/browser/dist/admin/admin.html)
# Password is managed via Docker secret 'collabora_p'
# Credentials for the Collabora admin panel (https://COLLABORA_DOMAIN/browser/dist/admin/admin.html)
# Since collabora 26.04 (image execs coolwsd directly; no shell in the image), the panel
# password moved from the retired Docker secret 'collabora_p' to this env var.
# Empty/unset = panel stays locked.
#COLLABORA_ADMIN_USERNAME=admin
#COLLABORA_ADMIN_PASSWORD=
##############################################################################
# BACKUPS
-15
View File
@@ -1,15 +0,0 @@
# Lasuite-Drive Recipe Maintenance
All contributions should be made via pull requests.
## Pull Requests
A pull request can be merged directly into `main` by any maintainer. No approval is needed, but pull requests should be tested as working before merge.
## Become a maintainer
Everyone can apply to be a recipe maintainer:
1. Watch the repository to get updates.
2. Add yourself to the list in [README.md](./README.md) and open a pull request with the change.
3. Once the pull request is merged, you will be added to the [La Suite maintainers team](https://git.coopcloud.tech/org/coop-cloud/teams/lasuite-maintainers).
+6 -1
View File
@@ -3,7 +3,7 @@
> [Drive](https://github.com/suitenumerique/drive) (part of [La Suite Numerique](https://lasuite.numerique.gouv.fr/en)) for Co-op Cloud
<!-- metadata -->
* **Maintainer**: [@trav](https://git.coopcloud.tech/trav), [@notplants](https://git.coopcloud.tech/notplants), [@ineiti](https://git.coopcloud.tech/ineiti)
* **Category**: Apps
* **Status**: 2
* **Image**: [`lasuite/drive`](https://hub.docker.com/r/lasuite/drive), 4, upstream
@@ -92,3 +92,8 @@ You then need to insert the password for your smtp server as a secret:
Then redeploy the app, and automated e-mail sending should work:
`abra app deploy <app-name> --force`
## Maintainers
coop cloud recipe maintained by @notplants
+1 -1
View File
@@ -5,7 +5,7 @@ export NGINX_CONF_VERSION=v6
export ONLYOFFICE_CONF_VERSION=v2
export PG_BACKUP_VERSION=v4
export MIGRATE_VERSION=v1
export MINIO_INITIALIZE_VERSION=v1
export MINIO_INITIALIZE_VERSION=v2
environment() {
# this exports all the secrets as environment variables
+11 -17
View File
@@ -95,7 +95,7 @@ services:
app:
user: "${DOCKER_USER:-1000}"
image: lasuite/drive-frontend:v0.22.0
image: lasuite/drive-frontend:v0.23.0
networks:
- backend
deploy:
@@ -116,7 +116,7 @@ services:
backend:
user: ${DOCKER_USER:-1000}
image: lasuite/drive-backend:v0.22.0
image: lasuite/drive-backend:v0.23.0
command: [ "gunicorn", "-c", "/usr/local/etc/gunicorn/drive.py", "drive.wsgi:application" ]
entrypoint: >
sh -c "if [ \"$$AUTO_MIGRATIONS\" = \"true\" ]; then /migrate.sh; fi && exec /abra-entrypoint.sh /usr/local/bin/entrypoint \"$$@\"" --
@@ -145,7 +145,7 @@ services:
celery:
user: ${DOCKER_USER:-1000}
image: lasuite/drive-backend:v0.22.0
image: lasuite/drive-backend:v0.23.0
networks:
- backend
command: [ "celery", "-A", "drive.celery_app", "worker", "-l", "INFO" ]
@@ -167,7 +167,7 @@ services:
celery-beat:
user: ${DOCKER_USER:-1000}
image: lasuite/drive-backend:v0.22.0
image: lasuite/drive-backend:v0.23.0
networks:
- backend
command: [ "celery", "-A", "drive.celery_app", "beat", "-l", "INFO", "--schedule", "/tmp/celerybeat-schedule" ]
@@ -214,7 +214,7 @@ services:
- postgres_p
redis:
image: redis:8.10.1
image: redis:8.10.2
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 10s
@@ -274,13 +274,12 @@ services:
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
collabora:
image: collabora/code:25.04.10.3.1
entrypoint: >
sh -c "
export password=\"$$(cat /run/secrets/collabora_p)\" &&
exec /start-collabora-online.sh"
image: collabora/code:26.04.4.2.1
# 26.04 images exec coolwsd directly (--use-env-vars; no shell in the image),
# so ssl options are passed as args and the panel password comes from the env.
command: ["--o:ssl.enable=false", "--o:ssl.termination=true"]
healthcheck:
test: [ "CMD", "curl", "-f", "http://localhost:9980/hosting/discovery" ]
test: [ "CMD", "/usr/bin/coolwsd", "--probe", "--o:ssl.enable=false" ]
interval: 30s
retries: 5
start_period: 60s
@@ -289,11 +288,9 @@ services:
- backend
- proxy
environment:
- extra_params=--o:ssl.enable=false --o:ssl.termination=true
- username=${COLLABORA_ADMIN_USERNAME:-admin}
- server_name=${COLLABORA_DOMAIN}
secrets:
- collabora_p
- password=${COLLABORA_ADMIN_PASSWORD:-}
deploy:
labels:
- "traefik.enable=true"
@@ -423,9 +420,6 @@ secrets:
minio_ru:
external: true
name: ${STACK_NAME}_minio_ru_${SECRET_MINIO_RU_VERSION}
collabora_p:
external: true
name: ${STACK_NAME}_collabora_p_${SECRET_COLLABORA_P_VERSION}
email_pass:
external: true
name: ${STACK_NAME}_email_pass_${SECRET_EMAIL_PASS_VERSION}
-6
View File
@@ -1,6 +0,0 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended"
]
}