2019-07-19 10:07:43 +02:00
version : '3'
volumes :
2023-04-05 23:30:51 +02:00
# NOTE: all directories referenced by "device" entries below need to be created manually before starting the containers
# egroupware sources
2019-07-19 10:07:43 +02:00
sources :
2023-04-05 23:30:51 +02:00
driver_opts :
type : none
o : bind
device : $PWD/sources/
# sources for push server, swoolepush is a subdirectory of egroupware sources (within volume "sources")
sources-push :
driver_opts :
type : none
o : bind
2023-04-12 10:29:08 +02:00
device : $PWD/sources/swoolepush
2019-07-19 10:07:43 +02:00
db :
data :
driver_opts :
type : none
o : bind
# to upgrade an existing non-docker installation most easy is to use the existing
# data directory /var/lib/egroupware AND the host database see below
#device: /var/lib/egroupware
# otherwise data is stored in data subdirectory of the current directory
device : $PWD/data
# extra sources with apps not part of egroupware container
#extra:
# driver_opts:
# type: none
# o: bind
# # location of deprecated EGroupware packages like Wiki, SiteMgr, KnowledgeBase
# device: /usr/share/egroupware
# #device: $PWD/extra
2020-06-13 15:14:14 +02:00
# volume to store config.inc.php file / token shared between egroupware and push container
push-config :
2020-06-14 14:11:29 +02:00
sessions :
2023-04-05 10:05:23 +02:00
# collabora-config directory, initially filled by collabora-init container
2023-04-05 23:30:51 +02:00
# additionally some more configuration files are needed in order for collabora to work, which are _not_ generated by the collabora-init container
2020-02-11 09:03:09 +01:00
collabora-config :
driver_opts :
type : none
o : bind
# to upgrade an existing non-docker installation most easy is to use the existing
# data directory /var/lib/egroupware AND the host database see below
#device: /var/lib/egroupware/default/loolwsd
# otherwise data is stored in data subdirectory of the current directory
device : $PWD/data/default/loolwsd
# store Rocket.Chat MongoDB on an (internal) Volume
mongo :
# directory to store MongoDB dumps
rocketchat-dumps :
driver_opts :
type : none
o : bind
device : $PWD/data/default/rocketchat/dump
rocketchat-uploads :
driver_opts :
type : none
o : bind
device : $PWD/data/default/rocketchat/uploads
2019-07-19 10:07:43 +02:00
services :
egroupware :
2023-03-08 15:21:33 +01:00
image : egroupware/egroupware:latest
2020-06-14 14:11:29 +02:00
# EPL image: download.egroupware.org/egroupware/epl:20.1
2019-07-19 10:07:43 +02:00
# setting a default language for a new installation
#environment:
#- LANG=de
volumes :
- sources:/usr/share/egroupware
# extra-sources rsync from entry-point into sources
#- extra:/usr/share/egroupware-extra
- data:/var/lib/egroupware
2020-06-14 14:11:29 +02:00
- sessions:/var/lib/php/sessions
- push-config:/var/lib/egroupware-push
2019-07-19 10:07:43 +02:00
# if you want to use the host database:
# 1. comment out the whole db service below AND
# 2. set EGW_DB_HOST=localhost AND
# 3. uncomment the next line and modify the host path (first one), it depends on your distro:
2020-02-11 09:03:09 +01:00
# - RHEL/CentOS /var/lib/mysql/mysql.sock:/var/run/mysqld/mysqld.sock
2020-02-11 14:24:36 +01:00
# - openSUSE/SLE /var/run/mysql/mysql.sock:/var/run/mysqld/mysqld.sock
2020-02-11 09:03:09 +01:00
# - Debian/Ubuntu /var/run/mysqld:/var/run/mysqld
#- /var/run/mysqld:/var/run/mysqld
# private CA so egroupware can validate your certificate to talk to Collabora or Rocket.Chat
# multiple certificates (eg. a chain) have to be single files in a directory, with one named private-ca.crt!
#- /etc/egroupware-docker/private-ca.crt:/usr/local/share/ca-certificates/private-ca.crt:ro
2019-07-19 10:07:43 +02:00
environment :
# MariaDB/MySQL host to use: for internal service use "db", for host database (socket bind-mounted into container) use "localhost"
- EGW_DB_HOST=db
2019-08-07 21:53:31 +02:00
# grant host is needed for NOT using localhost / unix domain socket for MySQL/MariaDB
2019-08-18 12:44:53 +02:00
- EGW_DB_GRANT_HOST=172.%
2019-07-19 10:07:43 +02:00
# for internal db service you should to specify a root password here AND in db service
# a database "egroupware" with a random password is created for you on installation (password is stored in header.inc.php in data directory)
#- EGW_DB_ROOT=root
- EGW_DB_ROOT_PW=secret
# alternativly you can specify an already existing database with full right by the given user!
#- EGW_DB_NAME=egroupware
#- EGW_DB_USER=egroupware
#- EGW_DB_PASS=
2019-07-22 10:06:48 +02:00
# further post_install.php arguments can be passed as a single enviroment variable with space separated assignments
# "<name1>=<value1> <name2>=<value2>" see https://github.com/EGroupware/egroupware/blob/master/doc/rpm-build/post_install.php#L17
# to configure eg. LDAP for authentication and account storage use
#- EGW_POST_INSTALL='account-auth=ldap,ldap ldap_base=ou=egroupware,dc=example,dc=org ldap_host=tls://ldap.example.org ldap_admin=cn=admin,$base ldap_admin_pw=secret ldap_context=cn=users,$base ldap_group_context=cn=groups,$base'
2019-07-19 10:07:43 +02:00
restart : always
depends_on :
- db
container_name : egroupware
# set the ip-address of your docker host AND your official DNS name so EGroupware
# can access Rocket.Chat or Collabora without the need to go over your firewall
#extra_hosts:
#- "my.host.name:ip-address"
2020-06-14 14:11:29 +02:00
# push server using phpswoole
push :
2023-03-08 15:21:33 +01:00
image : phpswoole/swoole:php8.1-alpine
command :
- /var/www/server.php
environment :
EGW_MAX_PUSH_USERS : 1024
2020-06-14 14:11:29 +02:00
volumes :
- sources-push:/var/www
- sessions:/var/lib/php/sessions
- push-config:/var/lib/egroupware-push
container_name : egroupware-push
restart : always
# as we get our sources from there
depends_on :
- egroupware
2019-07-19 10:07:43 +02:00
nginx :
image : nginx:stable-alpine
volumes :
- sources:/usr/share/egroupware:ro
# to add a certificate create a certificate.pem containing (in that order)
# 1. private key
# 2. public key
# 3. (optional) chain certificates
# uncomment to the next line
# ./certificate.pem:/etc/ssl/private/certificate.pem
# AND uncomment the three lines starting with "listen 443", "ssl_certificate", "ssl_certificate_key" in nginx.conf
- ./nginx.conf:/etc/nginx/conf.d/default.conf:ro
ports :
# if no webserver is running on the host, change (first) number to 80 or 443
- "8080:80"
- "4443:443"
depends_on :
- egroupware
2020-02-18 11:19:48 +01:00
- collabora-key
- rocketchat
2019-07-19 10:07:43 +02:00
container_name : egroupware-nginx
# run an own MariaDB:10.4 (you can use EGroupware's database backup and restore to add your existing database)
db :
2022-09-20 13:44:54 +02:00
image : mariadb:10.6
2019-07-19 10:07:43 +02:00
environment :
#- MYSQL_ROOT=root
- MYSQL_ROOT_PASSWORD=secret
2022-09-20 13:44:54 +02:00
- MARIADB_AUTO_UPGRADE=true
2019-07-19 10:07:43 +02:00
volumes :
- db:/var/lib/mysql
container_name : egroupware-db
# automatic updates of all containers daily at 4am
# see https://containrrr.github.io/watchtower for more information
watchtower :
image : containrrr/watchtower
volumes :
- /var/run/docker.sock:/var/run/docker.sock
2019-10-17 14:15:52 +02:00
# For automatic EPL Updates (not necessary for CE!) you need to pass docker
# credentials into watchtower after running: docker login download.egroupware.org
#- /root/.docker/config.json:/config.json:ro
2019-07-19 10:07:43 +02:00
environment :
- WATCHTOWER_CLEANUP=true # delete old image after update to not fill up the disk
# for email notifications add your email and mail-server here
#- WATCHTOWER_NOTIFICATIONS=email
#- WATCHTOWER_NOTIFICATIONS_LEVEL=info # possible values: panic, fatal, error, warn, info or debug
2020-04-02 21:56:08 +02:00
#- WATCHTOWER_NOTIFICATION_EMAIL_FROM=watchtower@my-domain.com
#- WATCHTOWER_NOTIFICATION_EMAIL_TO=me@my-domain.com"
#- WATCHTOWER_NOTIFICATION_EMAIL_SERVER=mail.my-domain.com # if you give your MX here, you need no user/password
2019-07-19 10:07:43 +02:00
#- WATCHTOWER_NOTIFICATION_EMAIL_SERVER_PORT=25
2020-04-02 21:56:08 +02:00
#- WATCHTOWER_NOTIFICATION_EMAIL_SERVER_USER=watchtower@my-domain.com
2019-07-19 10:07:43 +02:00
#- WATCHTOWER_NOTIFICATION_EMAIL_SERVER_PASSWORD="secret"
command : --schedule "0 0 4 * * *"
container_name : egroupware-watchtower
restart : always
2020-02-11 09:03:09 +01:00
# Collabora Online Office
collabora-key :
image : "quay.io/egroupware/collabora-key:stable"
#image: collabora/code:latest
volumes :
2023-04-12 10:29:08 +02:00
- collabora-config:/etc/coolwsd
2020-02-11 09:03:09 +01:00
restart : always
container_name : collabora-key
# set the ip-address of your docker host AND your official DNS name so Collabora
# can access EGroupware without the need to go over your firewall
#extra_hosts:
#- "my.host.name:ip-address"
2022-07-19 15:45:09 +02:00
depends_on :
- collabora-init
# initialise the collabora-config volume
collabora-init :
image : "quay.io/egroupware/collabora-key:latest"
2023-04-12 10:29:08 +02:00
command : bash -c 'test -f /tmp/coolwsd/coolwsd.xml || (cp -p /etc/coolwsd/* /tmp/coolwsd/; sed "s/<enable type=\"bool\" desc=\"Controls whether SSL encryption between coolwsd and the network is enabled (do not disable for production deployment). If default is false, must first be compiled with SSL support to enable.\" default=\"true\">true</<enable type=\"bool\" desc=\"Controls whether SSL encryption between coolwsd and the network is enabled (do not disable for production deployment). If default is false, must first be compiled with SSL support to enable.\" default=\"true\">false</g" < /etc/coolwsd/coolwsd.xml > /tmp/coolwsd/coolwsd.xml)'
2022-07-19 15:45:09 +02:00
volumes :
- collabora-config:/tmp/coolwsd
2020-02-11 09:03:09 +01:00
# Rocket.Chat server
rocketchat :
image : rocketchat/rocket.chat:latest
command : bash -c 'for i in `seq 1 30`; do node main.js && s=$$? && break || s=$$?; echo "Tried $$i times. Waiting 5 secs..."; sleep 5; done; (exit $$s)'
restart : unless-stopped
volumes :
- rocketchat-uploads:/app/uploads
# if EGroupware uses a certificate from a private CA, OAuth authentication will fail, you need to:
# - have the CA certificate stored at /etc/egroupware-docker/private-ca.crt
# - uncomment the next 2 lines about the private CA:
# - /etc/egroupware-docker/private-ca.crt:/usr/local/share/ca-certificates/private-ca.crt:ro
environment :
# - NODE_EXTRA_CA_CERTS=/usr/local/share/ca-certificates/private-ca.crt
# IMPORTANT: change ROOT_URL to your actual url eg. https://domain.com/rocketchat
- ROOT_URL=http://localhost/rocketchat
- PORT=3000
- MONGO_URL=mongodb://mongo:27017/rocketchat
- MONGO_OPLOG_URL=mongodb://mongo:27017/local
# - HTTP_PROXY=http://proxy.domain.com
# - HTTPS_PROXY=http://proxy.domain.com
depends_on :
- mongo
container_name : rocketchat
# set the ip-address of your docker host AND your official DNS name so Rocket.Chat
# can access EGroupware without the need to go over your firewall
#extra_hosts:
#- "my.host.name:ip-address"
# MongoDB for Rocket.Chat
mongo :
image : mongo:4.0
restart : unless-stopped
volumes :
- mongo:/data/db
- rocketchat-dumps:/dump
command : mongod --smallfiles --oplogSize 128 --replSet rs0 --storageEngine=mmapv1
container_name : rocketchat-mongo
# this container's job is just run the command to initialize the replica set.
# it will run the command and remove himself (it will not stay running)
mongo-init-replica :
image : mongo:4.0
command : 'bash -c "for i in `seq 1 30`; do mongo mongo/rocketchat --eval \"rs.initiate({ _id: ' 'rs0'', members : [ { _id: 0, host : '' localhost:27017'' } ]})\" && s=$$? && break || s=$$?; echo \"Tried $$i times. Waiting 5 secs...\"; sleep 5; done; (exit $$s)"'
depends_on :
- mongo
2020-04-02 21:56:08 +02:00
# Portainer: Docker GUI (needs to be enabled in nginx.conf too!)
# portainer:
# image: portainer/portainer
# command: -H unix:///var/run/docker.sock
# restart: always
# ports:
# - 9000:9000
# - 8000:8000
# volumes:
# - /var/run/docker.sock:/var/run/docker.sock
# - portainer_data:/data
2023-04-12 10:29:08 +02:00
# container_name: portainer