[docs-only] work on getting started and deployment examples docs

This commit is contained in:
Willy Kloucek
2020-11-19 14:22:59 +01:00
parent f2a1c06145
commit e91d67e29a
10 changed files with 297 additions and 336 deletions
+7 -8
View File
@@ -9,16 +9,15 @@ geekdocFilePath: _index.md
{{< toc >}}
## Deployments Scenarios and Examples
This section handles deployments and operations for admins. If you are looking for a development setup, start with
## Deployments scenarios and examples
This section handles deployments and operations for admins. If you are looking for a development setup, start with [Getting started](https://owncloud.github.io/ocis/getting-started/).
### Setup oCIS
oCIS deployments are super simple, yet there are many configrations possible for advanced setups.
### Setup oCIS on your server
oCIS deployments are super simple, yet there are many configurations possible for advanced setups.
- Basic setup - download and run
- Pick services and manage them individually
- SSL offloading with Traefik
- Use an external IDP
- [Basic oCIS setup]({{< ref "basic-remote-setup.md" >}}) - configure domain, certificates and port
- [oCIS setup with Traefik for ssl termination]({{< ref "ocis_traefik.md" >}})
- [oCIS setup with external OIDC IDP]({{< ref "ocis_external_idp.md" >}})
### Migrate an existing ownCloud 10
You can run ownCloud 10 and oCIS together. This allows you to use new parts of oCIS already with ownCloud 10 and also to have a smooth transition for users from ownCloud 10 to oCIS.
+1 -1
View File
@@ -1,6 +1,6 @@
---
title: "Bridge"
date: 2020-02-27T20:35:00+01:00
date: 2022-02-27T20:35:00+01:00
weight: 30
geekdocRepo: https://github.com/owncloud/ocis
geekdocEditPath: edit/master/docs/ocis/deployment
@@ -1,59 +1,36 @@
---
title: "ocis with konnectd on external node deployment scenario"
title: "oCIS with external IDP"
date: 2020-10-12T14:39:00+01:00
weight: 26
geekdocRepo: https://github.com/owncloud/ocis
geekdocEditPath: edit/master/docs/ocis/deployment
geekdocFilePath: ocis_external_konnectd.md
geekdocFilePath: ocis_external_idp.md
---
{{< toc >}}
This scenario shows how to setup ocis with konnectd as idp running on a separate node. Both node are having separate domains pointing on the servers.
This scenario shows how to setup oCIS and konnectd as external IDP (identity provider). Both have separate domains and will be configured to work together.
## Overview
* ocis and konnectd running on linux nodes behind traefik as reverse proxy
* Cloudflare DNS is resolving the domains
* Letsencrypt provides ssl certificates for the domains
* Traefik docker container terminates ssl and forwards http requests to the services
* Server 1: oCIS running behind traefik as reverse proxy
* Server 2: IDP running behind traefik as reverse proxy
* Valid ssl certificates for the domains for ssl termination
## Nodes
[Find this example on GitHub](https://github.com/owncloud/ocis/tree/master/deployments/examples/ocis_external_konnectd)
## Server Deployment
### Requirements
* Server running Ubuntu 20.04 is public availible with a static ip address
* Two A-records for both domains are pointing on the servers ip address
* Create user
* 2 Linux servers, each with docker and docker-compose installed
* Two domains set up and pointing to the target server
`$ sudo adduser username`
See also [example server setup]({{< ref "preparing_server.md" >}})
* Add user to sudo group
`$ sudo usermod -aG sudo username`
* Add users pub key to `~/.ssh/authorized_keys`
* Setup ssh to permit authorisation only by ssh key
* Install docker
`$ sudo apt install docker.io`
* Add user to docker group
`$ sudo usermod -aG docker username`
* Install docker-compose via
`$ sudo curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose`
(docker compose version 1.27.4 as of today)
* Make docker-compose executable
`$ sudo chmod +x /usr/local/bin/docker-compose`
* Environment variables for OCIS Stack are provided by .env file
### Setup on ocis server
### Install oCIS server
* Clone ocis repository
@@ -77,7 +54,7 @@ This scenario shows how to setup ocis with konnectd as idp running on a separate
`docker-compose up -d`
### Setup on idp server
### Install IDP server
* Clone ocis repository
@@ -105,11 +82,7 @@ This scenario shows how to setup ocis with konnectd as idp running on a separate
`docker-compose up -d`
### Stack
On both nodes, a traefik dokcer container is terminating ssl and forwards the http requests to the services. The nodes are named according to their services.
### Config
### Configuration
#### Repository structure
@@ -192,3 +165,8 @@ ocis:
- 9125:9125
...
```
## Local setup
For simple local ocis setup see [Getting started]({{< ref "../getting-started.md" >}})
Local setup coming soon
+18 -45
View File
@@ -1,5 +1,5 @@
---
title: "ocis frontend with oc10 backend deployment scenario"
title: "ownCloud Web with ownCloud 10"
date: 2020-10-12T14:04:00+01:00
weight: 25
geekdocRepo: https://github.com/owncloud/ocis
@@ -9,58 +9,35 @@ geekdocFilePath: ocis_frontend_oc10_backend.md
{{< toc >}}
This deployment scenario shows how to use ocis as frontend for an existing ownCloud 10 production installation. It enables
ownCloud 10 users to log in and work with their files using the new ocis-web UI. While the scenario includes
This deployment scenario shows how to use ownCloud Web as frontend for an existing ownCloud 10 production installation. It enables
ownCloud 10 users to log in and work with their files using the new ownCloud Web. While the scenario includes
an ownCloud 10 instance, it only exists to show the necessary configuration for your already existing ownCloud 10
installation.
The described setup can also be used to do a zero-downtime migration from ownCloud 10 to ocis.
## Overview
### Node Setup
* oCIS setup serving ownCloud Web
* ownCloud 10 setup connected to oCIS
* DNS is resolving one domain for ocis and one for oc10
* Valid ssl certificates for the domains for ssl termination
* ocis and oc10 running as docker containers behind traefik as reverse proxy
* Cloudflare DNS is resolving one domain for ocis and one for oc10
* Letsencrypt is providing valid ssl certificate for both domains
[Find this example on GitHub](https://github.com/owncloud/ocis/tree/master/deployments/examples/ocis_external_konnectd)
## Node Deployment
## Server Deployment
### Requirements
* Server running Ubuntu 20.04 is publicly available with a static ip address
* Two A-records for both domains are pointing to the servers ip address
* Create user
* Linux server(s) with docker and docker-compose installed
* Two domains set up and pointing to your server(s)
`$ sudo adduser username`
* Add user to sudo group
`$ sudo usermod -aG sudo username`
* Add users pub key to `~/.ssh/authorized_keys`
* Setup ssh to permit authorisation only by ssh key
* Install docker
`$ sudo apt install docker.io`
* Add user to docker group
`$ sudo usermod -aG docker username`
* Install docker-compose via
`$ sudo curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose`
(docker compose version 1.27.4 as of today)
* Make docker-compose executable
`$ sudo chmod +x /usr/local/bin/docker-compose`
* Environment variables for oCIS Stack are provided by .env file
See also [example server setup]({{< ref "preparing_server.md" >}})
### Setup on server
The application stack is separated in docker containers. One is a traefik proxy which is terminating ssl and forwards the https requests to the internal docker network. Additionally, traefik is creating two certificates that are stored in the file `letsencrypt/acme.json` of the users home directory. In a local setup, this traefik is not included.
The next container is the ocis server which is exposing the webservice on port 9200 to traefik and provides the oidc provider `konnectd` to owncloud.
oc10 is running as a three container setup out of owncloud-server, a db container and a redis container as memcache storage.
* Clone ocis repository
`git clone https://github.com/owncloud/ocis.git`
@@ -84,11 +61,6 @@ The described setup can also be used to do a zero-downtime migration from ownClo
The domains from your `.env` will be used for building the configuration files during the docker start.
### Stack
The application stack is separated in docker containers. One is a traefik proxy which is terminating ssl and forwards the https requests to the internal docker network. Additionally, traefik is creating two certificates that are stored in the file `letsencrypt/acme.json` of the users home directory. In a local setup, this traefik is not included.
The next container is the ocis server which is exposing the webservice on port 9200 to traefik and provides the oidc provider `konnectd` to owncloud.
oc10 is running as a three container setup out of owncloud-server, a db container and a redis container as memcache storage.
### Config
@@ -366,7 +338,8 @@ Constraints: In this setup it's mandatory that the user has an email address set
Especially the default admin user doesn't have an email assigned. If your admin user doesn't have an email address, yet, please
set one: `docker-compose exec owncloud occ user:modify admin email "admin@example.org"`
## Local deployment
## Local setup
For simple local ocis setup see [Getting started]({{< ref "../getting-started.md" >}})
If you want to start the bridge setup on your local development machine, there are a few steps necessary:
+20 -40
View File
@@ -1,5 +1,5 @@
---
title: "ocis with traefik deployment scenario"
title: "oCIS with Traefik"
date: 2020-10-12T14:04:00+01:00
weight: 24
geekdocRepo: https://github.com/owncloud/ocis
@@ -11,47 +11,27 @@ geekdocFilePath: ocis_traefik.md
## Overview
* ocis running on a hcloud node behind traefik as reverse proxy
* Cloudflare DNS is resolving the domain
* Letsencrypt provides a ssl certificate for the domain
* Traefik docker container terminates ssl and forwards http requests to ocis
* oCIS running behind traefik as reverse proxy
* Valid ssl certificates for the domains for ssl termination
## Node
[Find this example on GitHub](https://github.com/owncloud/ocis/tree/master/deployments/examples/ocis_traefik)
## Server Deployment
### Requirements
* Server running Ubuntu 20.04 is public availible with a static ip address
* Two A-records for both domains are pointing on the servers ip address
* Create user
* Linux server(s) with docker and docker-compose installed
* Two domains set up and pointing to your server(s)
`$ sudo adduser username`
See also [example server setup]({{< ref "preparing_server.md" >}})
* Add user to sudo group
`$ sudo usermod -aG sudo username`
### Install oCIS and Traefik
* Add users pub key to `~/.ssh/authorized_keys`
* Setup ssh to permit authorisation only by ssh key
* Install docker
`$ sudo apt install docker.io`
* Add user to docker group
`$ sudo usermod -aG docker username`
* Install docker-compose via
`$ sudo curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose`
(docker compose version 1.27.4 as of today)
* Make docker-compose executable
`$ sudo chmod +x /usr/local/bin/docker-compose`
* Environment variables for oCIS Stack are provided by .env file
### Setup on server
The application stack contains two containers. The first one is a traefik proxy which is terminating ssl and forwards the requests to the internal docker network. Additional, traefik is creating a certificate that is stored in `acme.json` in the folder `letsencrypt` inside the users home directory.
The second one is th ocis server which is exposing the webservice on port 9200 to traefik.
* Clone ocis repository
@@ -77,12 +57,7 @@ geekdocFilePath: ocis_traefik.md
`docker-compose up -d`
### Stack
The application stack contains two containers. The first one is a traefik proxy which is terminating ssl and forwards the requests to the internal docker network. Additional, traefik is creating a certificate that is stored in `acme.json` in the folder `letsencrypt` inside the users home directory.
The second one is th ocis server which is exposing the webservice on port 9200 to traefic.
### Config
### Configuration
Edit docker-compose.yml file to fit your domain setup
@@ -146,3 +121,8 @@ To make it availible for ocis inside of the container, `config` hast to be mount
KONNECTD_IDENTIFIER_REGISTRATION_CONF: "/etc/ocis/identifier-registration.yml"
...
```
## Local setup
For simple local ocis setup see [Getting started]({{< ref "../getting-started.md" >}})
Local setup with Traefik coming soon
+67
View File
@@ -0,0 +1,67 @@
---
title: "Preparing a server"
date: 2020-10-12T14:04:00+01:00
weight: 10
geekdocRepo: https://github.com/owncloud/ocis
geekdocEditPath: edit/master/docs/ocis/deployment
geekdocFilePath: preparing_server.md
---
{{< toc >}}
## Example for Hetzner Cloud
* create server on Hetzner Cloud. Set labels "owner" and "for". Example for hcloud cli:
`hcloud server create --type cx21 --image ubuntu-20.04 --ssh-key admin --name ocis-server --label owner=admin --label for=testing`
* Configure DNS A-records for needed domains pointing on the servers ip address, for example in CloudFlare
* Access server via ssh as root
* Create a new user
`$ adduser --disabled-password --gecos "" admin`
* Add user to sudo group
`$ usermod -aG sudo admin`
* Install docker
```
apt update
apt install docker.io
```
* Add user to docker group
`usermod -aG docker admin`
* Install docker-compose via
`curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose`
(docker compose version 1.27.4 as of today)
* Make docker-compose executable
`chmod +x /usr/local/bin/docker-compose`
* Add users pub key to
```
mkdir /home/admin/.ssh
echo "<pubkey>" >> /home/admin/.ssh/authorized_keys`
chown admin:admin -R /home/admin/.ssh
```
* Secure ssh daemon by editing `/etc/ssh/sshd_config`
```
PermitRootLogin no
ChallengeResponseAuthentication no
PasswordAuthentication no
UsePAM no
```
* restart sshd server to apply settings `systemctl restart sshd`
* Login as the user you created