Merge pull request #874 from owncloud/improve_docs
[docs-only] improve docs
This commit is contained in:
@@ -9,16 +9,15 @@ geekdocFilePath: _index.md
|
||||
|
||||
{{< toc >}}
|
||||
|
||||
## Deployments Scenarios and Examples
|
||||
This section handles deployments and operations for admins. If you are looking for a development setup, start with
|
||||
## Deployments scenarios and examples
|
||||
This section handles deployments and operations for admins. If you are looking for a development setup, start with [Getting started](https://owncloud.github.io/ocis/getting-started/).
|
||||
|
||||
### Setup oCIS
|
||||
oCIS deployments are super simple, yet there are many configrations possible for advanced setups.
|
||||
### Setup oCIS on your server
|
||||
oCIS deployments are super simple, yet there are many configurations possible for advanced setups.
|
||||
|
||||
- Basic setup - download and run
|
||||
- Pick services and manage them individually
|
||||
- SSL offloading with Traefik
|
||||
- Use an external IDP
|
||||
- [Basic oCIS setup]({{< ref "basic-remote-setup.md" >}}) - configure domain, certificates and port
|
||||
- [oCIS setup with Traefik for ssl termination]({{< ref "ocis_traefik.md" >}})
|
||||
- [oCIS setup with external OIDC IDP]({{< ref "ocis_external_idp.md" >}})
|
||||
|
||||
### Migrate an existing ownCloud 10
|
||||
You can run ownCloud 10 and oCIS together. This allows you to use new parts of oCIS already with ownCloud 10 and also to have a smooth transition for users from ownCloud 10 to oCIS.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
---
|
||||
title: "Bridge"
|
||||
date: 2020-02-27T20:35:00+01:00
|
||||
date: 2022-02-27T20:35:00+01:00
|
||||
weight: 30
|
||||
geekdocRepo: https://github.com/owncloud/ocis
|
||||
geekdocEditPath: edit/master/docs/ocis/deployment
|
||||
|
||||
+22
-44
@@ -1,59 +1,36 @@
|
||||
---
|
||||
title: "ocis with konnectd on external node deployment scenario"
|
||||
title: "oCIS with external IDP"
|
||||
date: 2020-10-12T14:39:00+01:00
|
||||
weight: 26
|
||||
geekdocRepo: https://github.com/owncloud/ocis
|
||||
geekdocEditPath: edit/master/docs/ocis/deployment
|
||||
geekdocFilePath: ocis_external_konnectd.md
|
||||
geekdocFilePath: ocis_external_idp.md
|
||||
---
|
||||
|
||||
{{< toc >}}
|
||||
|
||||
This scenario shows how to setup ocis with konnectd as idp running on a separate node. Both node are having separate domains pointing on the servers.
|
||||
This scenario shows how to setup oCIS and konnectd as external IDP (identity provider). Both have separate domains and will be configured to work together.
|
||||
|
||||
## Overview
|
||||
|
||||
* ocis and konnectd running on linux nodes behind traefik as reverse proxy
|
||||
* Cloudflare DNS is resolving the domains
|
||||
* Letsencrypt provides ssl certificates for the domains
|
||||
* Traefik docker container terminates ssl and forwards http requests to the services
|
||||
* Server 1: oCIS running behind traefik as reverse proxy
|
||||
* Server 2: IDP running behind traefik as reverse proxy
|
||||
* Valid ssl certificates for the domains for ssl termination
|
||||
|
||||
## Nodes
|
||||
[Find this example on GitHub](https://github.com/owncloud/ocis/tree/master/deployments/examples/ocis_external_konnectd)
|
||||
|
||||
|
||||
|
||||
## Server Deployment
|
||||
|
||||
### Requirements
|
||||
|
||||
* Server running Ubuntu 20.04 is public availible with a static ip address
|
||||
* Two A-records for both domains are pointing on the servers ip address
|
||||
* Create user
|
||||
* 2 Linux servers, each with docker and docker-compose installed
|
||||
* Two domains set up and pointing to the target server
|
||||
|
||||
`$ sudo adduser username`
|
||||
See also [example server setup]({{< ref "preparing_server.md" >}})
|
||||
|
||||
* Add user to sudo group
|
||||
|
||||
`$ sudo usermod -aG sudo username`
|
||||
|
||||
* Add users pub key to `~/.ssh/authorized_keys`
|
||||
* Setup ssh to permit authorisation only by ssh key
|
||||
* Install docker
|
||||
|
||||
`$ sudo apt install docker.io`
|
||||
|
||||
* Add user to docker group
|
||||
|
||||
`$ sudo usermod -aG docker username`
|
||||
|
||||
* Install docker-compose via
|
||||
|
||||
`$ sudo curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose`
|
||||
|
||||
(docker compose version 1.27.4 as of today)
|
||||
* Make docker-compose executable
|
||||
|
||||
`$ sudo chmod +x /usr/local/bin/docker-compose`
|
||||
|
||||
* Environment variables for OCIS Stack are provided by .env file
|
||||
|
||||
### Setup on ocis server
|
||||
### Install oCIS server
|
||||
|
||||
* Clone ocis repository
|
||||
|
||||
@@ -77,7 +54,7 @@ This scenario shows how to setup ocis with konnectd as idp running on a separate
|
||||
|
||||
`docker-compose up -d`
|
||||
|
||||
### Setup on idp server
|
||||
### Install IDP server
|
||||
|
||||
* Clone ocis repository
|
||||
|
||||
@@ -105,11 +82,7 @@ This scenario shows how to setup ocis with konnectd as idp running on a separate
|
||||
|
||||
`docker-compose up -d`
|
||||
|
||||
### Stack
|
||||
|
||||
On both nodes, a traefik dokcer container is terminating ssl and forwards the http requests to the services. The nodes are named according to their services.
|
||||
|
||||
### Config
|
||||
### Configuration
|
||||
|
||||
#### Repository structure
|
||||
|
||||
@@ -192,3 +165,8 @@ ocis:
|
||||
- 9125:9125
|
||||
...
|
||||
```
|
||||
|
||||
## Local setup
|
||||
For simple local ocis setup see [Getting started]({{< ref "../getting-started.md" >}})
|
||||
|
||||
Local setup coming soon
|
||||
@@ -1,5 +1,5 @@
|
||||
---
|
||||
title: "ocis frontend with oc10 backend deployment scenario"
|
||||
title: "ownCloud Web with ownCloud 10"
|
||||
date: 2020-10-12T14:04:00+01:00
|
||||
weight: 25
|
||||
geekdocRepo: https://github.com/owncloud/ocis
|
||||
@@ -9,58 +9,35 @@ geekdocFilePath: ocis_frontend_oc10_backend.md
|
||||
|
||||
{{< toc >}}
|
||||
|
||||
This deployment scenario shows how to use ocis as frontend for an existing ownCloud 10 production installation. It enables
|
||||
ownCloud 10 users to log in and work with their files using the new ocis-web UI. While the scenario includes
|
||||
This deployment scenario shows how to use ownCloud Web as frontend for an existing ownCloud 10 production installation. It enables
|
||||
ownCloud 10 users to log in and work with their files using the new ownCloud Web. While the scenario includes
|
||||
an ownCloud 10 instance, it only exists to show the necessary configuration for your already existing ownCloud 10
|
||||
installation.
|
||||
|
||||
The described setup can also be used to do a zero-downtime migration from ownCloud 10 to ocis.
|
||||
|
||||
## Overview
|
||||
|
||||
### Node Setup
|
||||
* oCIS setup serving ownCloud Web
|
||||
* ownCloud 10 setup connected to oCIS
|
||||
* DNS is resolving one domain for ocis and one for oc10
|
||||
* Valid ssl certificates for the domains for ssl termination
|
||||
|
||||
* ocis and oc10 running as docker containers behind traefik as reverse proxy
|
||||
* Cloudflare DNS is resolving one domain for ocis and one for oc10
|
||||
* Letsencrypt is providing valid ssl certificate for both domains
|
||||
[Find this example on GitHub](https://github.com/owncloud/ocis/tree/master/deployments/examples/ocis_external_konnectd)
|
||||
|
||||
## Node Deployment
|
||||
## Server Deployment
|
||||
|
||||
### Requirements
|
||||
|
||||
* Server running Ubuntu 20.04 is publicly available with a static ip address
|
||||
* Two A-records for both domains are pointing to the servers ip address
|
||||
* Create user
|
||||
* Linux server(s) with docker and docker-compose installed
|
||||
* Two domains set up and pointing to your server(s)
|
||||
|
||||
`$ sudo adduser username`
|
||||
|
||||
* Add user to sudo group
|
||||
|
||||
`$ sudo usermod -aG sudo username`
|
||||
|
||||
* Add users pub key to `~/.ssh/authorized_keys`
|
||||
* Setup ssh to permit authorisation only by ssh key
|
||||
* Install docker
|
||||
|
||||
`$ sudo apt install docker.io`
|
||||
|
||||
* Add user to docker group
|
||||
|
||||
`$ sudo usermod -aG docker username`
|
||||
|
||||
* Install docker-compose via
|
||||
|
||||
`$ sudo curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose`
|
||||
|
||||
(docker compose version 1.27.4 as of today)
|
||||
* Make docker-compose executable
|
||||
|
||||
`$ sudo chmod +x /usr/local/bin/docker-compose`
|
||||
|
||||
* Environment variables for OCIS Stack are provided by .env file
|
||||
See also [example server setup]({{< ref "preparing_server.md" >}})
|
||||
|
||||
### Setup on server
|
||||
|
||||
The application stack is separated in docker containers. One is a traefik proxy which is terminating ssl and forwards the https requests to the internal docker network. Additionally, traefik is creating two certificates that are stored in the file `letsencrypt/acme.json` of the users home directory. In a local setup, this traefik is not included.
|
||||
The next container is the ocis server which is exposing the webservice on port 9200 to traefik and provides the oidc provider `konnectd` to owncloud.
|
||||
oc10 is running as a three container setup out of owncloud-server, a db container and a redis container as memcache storage.
|
||||
|
||||
* Clone ocis repository
|
||||
|
||||
`git clone https://github.com/owncloud/ocis.git`
|
||||
@@ -84,11 +61,6 @@ The described setup can also be used to do a zero-downtime migration from ownClo
|
||||
|
||||
The domains from your `.env` will be used for building the configuration files during the docker start.
|
||||
|
||||
### Stack
|
||||
|
||||
The application stack is separated in docker containers. One is a traefik proxy which is terminating ssl and forwards the https requests to the internal docker network. Additionally, traefik is creating two certificates that are stored in the file `letsencrypt/acme.json` of the users home directory. In a local setup, this traefik is not included.
|
||||
The next container is the ocis server which is exposing the webservice on port 9200 to traefik and provides the oidc provider `konnectd` to owncloud.
|
||||
oc10 is running as a three container setup out of owncloud-server, a db container and a redis container as memcache storage.
|
||||
|
||||
### Config
|
||||
|
||||
@@ -366,7 +338,8 @@ Constraints: In this setup it's mandatory that the user has an email address set
|
||||
Especially the default admin user doesn't have an email assigned. If your admin user doesn't have an email address, yet, please
|
||||
set one: `docker-compose exec owncloud occ user:modify admin email "admin@example.org"`
|
||||
|
||||
## Local deployment
|
||||
## Local setup
|
||||
For simple local ocis setup see [Getting started]({{< ref "../getting-started.md" >}})
|
||||
|
||||
If you want to start the bridge setup on your local development machine, there are a few steps necessary:
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
---
|
||||
title: "ocis with traefik deployment scenario"
|
||||
title: "oCIS with Traefik"
|
||||
date: 2020-10-12T14:04:00+01:00
|
||||
weight: 24
|
||||
geekdocRepo: https://github.com/owncloud/ocis
|
||||
@@ -11,47 +11,27 @@ geekdocFilePath: ocis_traefik.md
|
||||
|
||||
## Overview
|
||||
|
||||
* ocis running on a hcloud node behind traefik as reverse proxy
|
||||
* Cloudflare DNS is resolving the domain
|
||||
* Letsencrypt provides a ssl certificate for the domain
|
||||
* Traefik docker container terminates ssl and forwards http requests to ocis
|
||||
* oCIS running behind traefik as reverse proxy
|
||||
* Valid ssl certificates for the domains for ssl termination
|
||||
|
||||
## Node
|
||||
[Find this example on GitHub](https://github.com/owncloud/ocis/tree/master/deployments/examples/ocis_traefik)
|
||||
|
||||
|
||||
|
||||
## Server Deployment
|
||||
|
||||
### Requirements
|
||||
|
||||
* Server running Ubuntu 20.04 is public availible with a static ip address
|
||||
* Two A-records for both domains are pointing on the servers ip address
|
||||
* Create user
|
||||
* Linux server(s) with docker and docker-compose installed
|
||||
* Two domains set up and pointing to your server(s)
|
||||
|
||||
`$ sudo adduser username`
|
||||
See also [example server setup]({{< ref "preparing_server.md" >}})
|
||||
|
||||
* Add user to sudo group
|
||||
|
||||
`$ sudo usermod -aG sudo username`
|
||||
### Install oCIS and Traefik
|
||||
|
||||
* Add users pub key to `~/.ssh/authorized_keys`
|
||||
* Setup ssh to permit authorisation only by ssh key
|
||||
* Install docker
|
||||
|
||||
`$ sudo apt install docker.io`
|
||||
|
||||
* Add user to docker group
|
||||
|
||||
`$ sudo usermod -aG docker username`
|
||||
|
||||
* Install docker-compose via
|
||||
|
||||
`$ sudo curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose`
|
||||
|
||||
(docker compose version 1.27.4 as of today)
|
||||
* Make docker-compose executable
|
||||
|
||||
`$ sudo chmod +x /usr/local/bin/docker-compose`
|
||||
|
||||
* Environment variables for OCIS Stack are provided by .env file
|
||||
|
||||
### Setup on server
|
||||
The application stack contains two containers. The first one is a traefik proxy which is terminating ssl and forwards the requests to the internal docker network. Additional, traefik is creating a certificate that is stored in `acme.json` in the folder `letsencrypt` inside the users home directory.
|
||||
The second one is th ocis server which is exposing the webservice on port 9200 to traefik.
|
||||
|
||||
* Clone ocis repository
|
||||
|
||||
@@ -77,12 +57,7 @@ geekdocFilePath: ocis_traefik.md
|
||||
|
||||
`docker-compose up -d`
|
||||
|
||||
### Stack
|
||||
|
||||
The application stack contains two containers. The first one is a traefik proxy which is terminating ssl and forwards the requests to the internal docker network. Additional, traefik is creating a certificate that is stored in `acme.json` in the folder `letsencrypt` inside the users home directory.
|
||||
The second one is th ocis server which is exposing the webservice on port 9200 to traefic.
|
||||
|
||||
### Config
|
||||
### Configuration
|
||||
|
||||
Edit docker-compose.yml file to fit your domain setup
|
||||
|
||||
@@ -146,3 +121,8 @@ To make it availible for ocis inside of the container, `config` hast to be mount
|
||||
KONNECTD_IDENTIFIER_REGISTRATION_CONF: "/etc/ocis/identifier-registration.yml"
|
||||
...
|
||||
```
|
||||
|
||||
## Local setup
|
||||
For simple local ocis setup see [Getting started]({{< ref "../getting-started.md" >}})
|
||||
|
||||
Local setup with Traefik coming soon
|
||||
@@ -0,0 +1,67 @@
|
||||
---
|
||||
title: "Preparing a server"
|
||||
date: 2020-10-12T14:04:00+01:00
|
||||
weight: 10
|
||||
geekdocRepo: https://github.com/owncloud/ocis
|
||||
geekdocEditPath: edit/master/docs/ocis/deployment
|
||||
geekdocFilePath: preparing_server.md
|
||||
---
|
||||
|
||||
{{< toc >}}
|
||||
|
||||
|
||||
## Example for Hetzner Cloud
|
||||
* create server on Hetzner Cloud. Set labels "owner" and "for". Example for hcloud cli:
|
||||
`hcloud server create --type cx21 --image ubuntu-20.04 --ssh-key admin --name ocis-server --label owner=admin --label for=testing`
|
||||
|
||||
* Configure DNS A-records for needed domains pointing on the servers ip address, for example in CloudFlare
|
||||
|
||||
* Access server via ssh as root
|
||||
|
||||
* Create a new user
|
||||
|
||||
`$ adduser --disabled-password --gecos "" admin`
|
||||
|
||||
* Add user to sudo group
|
||||
|
||||
`$ usermod -aG sudo admin`
|
||||
|
||||
* Install docker
|
||||
|
||||
```
|
||||
apt update
|
||||
apt install docker.io
|
||||
```
|
||||
|
||||
* Add user to docker group
|
||||
|
||||
`usermod -aG docker admin`
|
||||
|
||||
* Install docker-compose via
|
||||
|
||||
`curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose`
|
||||
|
||||
(docker compose version 1.27.4 as of today)
|
||||
* Make docker-compose executable
|
||||
|
||||
`chmod +x /usr/local/bin/docker-compose`
|
||||
|
||||
|
||||
* Add users pub key to
|
||||
```
|
||||
mkdir /home/admin/.ssh
|
||||
echo "<pubkey>" >> /home/admin/.ssh/authorized_keys`
|
||||
chown admin:admin -R /home/admin/.ssh
|
||||
```
|
||||
|
||||
* Secure ssh daemon by editing `/etc/ssh/sshd_config`
|
||||
```
|
||||
PermitRootLogin no
|
||||
ChallengeResponseAuthentication no
|
||||
PasswordAuthentication no
|
||||
UsePAM no
|
||||
```
|
||||
|
||||
* restart sshd server to apply settings `systemctl restart sshd`
|
||||
|
||||
* Login as the user you created
|
||||
Reference in New Issue
Block a user