mirror of
https://github.com/hcengineering/huly-selfhost.git
synced 2026-09-28 04:25:05 +02:00
Merge https://github.com/hcengineering/huly-selfhost into nginx
This commit is contained in:
@@ -76,8 +76,160 @@ asdfsadfasdfsfd
|
||||
```
|
||||
Keep these keys secure, as you will need them to set up your push notification service on the server.
|
||||
|
||||
Add these keys into `compose.yaml` in section `services:front:environnement`:
|
||||
Add these keys into `compose.yaml` in section `services:front:environment`:
|
||||
```
|
||||
- PUSH_PUBLIC_KEY=your public key
|
||||
- PUSH_PRIVATE_KEY=your private key
|
||||
```
|
||||
```
|
||||
|
||||
## AWS SES email notifications
|
||||
|
||||
1. Setup Amazon Simple Email Service in AWS: https://docs.aws.amazon.com/ses/latest/dg/setting-up.html
|
||||
|
||||
2. Add email address you'll use to send notifications into "SOURCE", SES access such as ACCESS_KEY, SECRET_KEY, REGION
|
||||
|
||||
```yaml
|
||||
ses:
|
||||
image: hardcoreeng/ses:v0.6.295
|
||||
container_name: ses
|
||||
ports:
|
||||
- 3335:3335
|
||||
environment:
|
||||
- SOURCE=<EMAIL_FROM>
|
||||
- ACCESS_KEY=<SES_ACCESS_KEY>
|
||||
- SECRET_KEY=<SES_SECRET_KEY>
|
||||
- REGION=<SES_REGION>
|
||||
- PORT=3335
|
||||
restart: unless-stopped
|
||||
```
|
||||
|
||||
3. Add SES container URL into `transactor` and `account` containers:
|
||||
|
||||
```yaml
|
||||
account:
|
||||
...
|
||||
environment:
|
||||
- SES_URL=http://ses:3335
|
||||
...
|
||||
transactor:
|
||||
...
|
||||
environment:
|
||||
- SES_URL=http://ses:3335
|
||||
...
|
||||
```
|
||||
|
||||
4. In `Settings -> Notifications` setup email notifications for events you need to be notified for. It's a user's setting not a company wide, meaning each user has to setup their own notification rules.
|
||||
|
||||
## Love Service (Audio & Video calls)
|
||||
|
||||
Huly audio and video calls are created on top of LiveKit insfrastructure. In order to use Love service in your self-hosted Huly, perform the following steps:
|
||||
|
||||
1. Set up [LiveKit Cloud](https://cloud.livekit.io) account
|
||||
2. Add `love` container to the docker-compose.yaml
|
||||
|
||||
```yaml
|
||||
love:
|
||||
image: hardcoreeng/love:v0.6.295
|
||||
container_name: love
|
||||
ports:
|
||||
- 8096:8096
|
||||
environment:
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
- SECRET=secret
|
||||
- ACCOUNTS_URL=http://account:3000
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- STORAGE_PROVIDER_NAME=minio
|
||||
- PORT=8096
|
||||
- LIVEKIT_HOST=<LIVEKIT_HOST>
|
||||
- LIVEKIT_API_KEY=<LIVEKIT_API_KEY>
|
||||
- LIVEKIT_API_SECRET=<LIVEKIT_API_SECRET>
|
||||
restart: unless-stopped
|
||||
```
|
||||
|
||||
3. Configure `front` service:
|
||||
|
||||
```yaml
|
||||
front:
|
||||
...
|
||||
environment:
|
||||
- LIVEKIT_WS=<LIVEKIT_HOST>
|
||||
- LOVE_ENDPOINT=http://love:8096
|
||||
...
|
||||
```
|
||||
|
||||
## Configure OpenID Connect (OIDC)
|
||||
|
||||
You can configure a Huly instance to authorize users (sign-in/sign-up) using an OpenID Connect identity provider (IdP).
|
||||
|
||||
### On the IdP side
|
||||
1. Create a new OpenID application.
|
||||
* Use `{huly_account_svc}/auth/openid/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000.
|
||||
|
||||
**URI Example:**
|
||||
- `http://huly.mydomain.com:3000/auth/openid/callback`
|
||||
|
||||
2. Configure user access to the application as needed.
|
||||
|
||||
### On the Huly side
|
||||
For the account service, set the following environment variables as provided by the IdP:
|
||||
|
||||
* OPENID_CLIENT_ID
|
||||
* OPENID_CLIENT_SECRET
|
||||
* OPENID_ISSUER
|
||||
|
||||
Ensure you have configured or add the following environment variable to the front service:
|
||||
|
||||
* ACCOUNTS_URL (This should contain the URL of the account service, accessible from the client side.)
|
||||
|
||||
You will need to expose your account service port (e.g. 3000) in your nginx.conf.
|
||||
|
||||
Note: Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages.
|
||||
|
||||
## Configure GitHub OAuth
|
||||
|
||||
You can also configure a Huly instance to use GitHub OAuth for user authorization (sign-in/sign-up).
|
||||
|
||||
### On the GitHub side
|
||||
1. Create a new GitHub OAuth application.
|
||||
* Use `{huly_account_svc}/auth/github/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000.
|
||||
|
||||
**URI Example:**
|
||||
- `http://huly.mydomain.com:3000/auth/github/callback`
|
||||
|
||||
### On the Huly side
|
||||
Specify the following environment variables for the account service:
|
||||
|
||||
* `GITHUB_CLIENT_ID`
|
||||
* `GITHUB_CLIENT_SECRET`
|
||||
|
||||
Ensure you have configured or add the following environment variable to the front service:
|
||||
|
||||
* `ACCOUNTS_URL` (The URL of the account service, accessible from the client side.)
|
||||
|
||||
You will need to expose your account service port (e.g. 3000) in your nginx.conf.
|
||||
|
||||
Notes:
|
||||
* The `ISSUER` environment variable is not required for GitHub OAuth.
|
||||
* Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages.
|
||||
|
||||
## Disable Sign-Up
|
||||
|
||||
You can disable public sign-ups for a deployment. When configured, sign-ups will only be permitted through an invite link to a specific workspace.
|
||||
|
||||
To implement this, set the following environment variable for both the front and account services:
|
||||
|
||||
```yaml
|
||||
account:
|
||||
...
|
||||
environment:
|
||||
- DISABLE_SIGNUP=true
|
||||
...
|
||||
front:
|
||||
...
|
||||
environment:
|
||||
- DISABLE_SIGNUP=true
|
||||
...
|
||||
```
|
||||
|
||||
_Note: When setting up a new deployment, either create the initial account before disabling sign-ups or use the development tool to create the first account._
|
||||
|
||||
@@ -62,6 +62,7 @@ services:
|
||||
- SERVER_CURSOR_MAXTIMEMS=30000
|
||||
- ELASTIC_URL=http://elastic:9200
|
||||
- ELASTIC_INDEX_NAME=huly_storage_index
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- METRICS_CONSOLE=false
|
||||
- METRICS_FILE=metrics.txt
|
||||
@@ -79,6 +80,7 @@ services:
|
||||
- COLLABORATOR_PORT=3078
|
||||
- SECRET=${SECRET}
|
||||
- ACCOUNTS_URL=http://account:3000
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
restart: unless-stopped
|
||||
@@ -88,6 +90,7 @@ services:
|
||||
environment:
|
||||
- SERVER_PORT=3000
|
||||
- SERVER_SECRET=${SECRET}
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- TRANSACTOR_URL=ws://transactor:3333;ws${SECURE:+s}://${HOST_ADDRESS}/_transactor
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
@@ -100,7 +103,9 @@ services:
|
||||
workspace:
|
||||
image: hardcoreeng/workspace:${HULY_VERSION}
|
||||
environment:
|
||||
- SERVER_SECRET=${HULY_SECRET}
|
||||
- SERVER_SECRET=${SECRET}
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- TRANSACTOR_URL=ws://transactor:3333;ws${SECURE:+s}://${HOST_ADDRESS}/_transactor
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
@@ -129,6 +134,7 @@ services:
|
||||
- ELASTIC_URL=http://elastic:9200
|
||||
- COLLABORATOR_URL=ws${SECURE:+s}://${HOST_ADDRESS}/_collaborator
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- TITLE=${TITLE:-Huly Self Host}
|
||||
- DEFAULT_LANGUAGE=${DEFAULT_LANGUAGE:-en}
|
||||
|
||||
@@ -45,7 +45,7 @@ spec:
|
||||
key: MINIO_SECRET_KEY
|
||||
- name: MODEL_ENABLED
|
||||
value: '*'
|
||||
- name: MONGO_URL
|
||||
- name: DB_URL
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: huly-config
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: db
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 100Mi
|
||||
@@ -53,6 +53,11 @@ spec:
|
||||
configMapKeyRef:
|
||||
name: huly-config
|
||||
key: MONGO_URL
|
||||
- name: DB_URL
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: huly-config
|
||||
key: MONGO_URL
|
||||
- name: REKONI_URL
|
||||
value: http://rekoni
|
||||
- name: SERVER_CURSOR_MAXTIMEMS
|
||||
|
||||
@@ -35,6 +35,11 @@ spec:
|
||||
key: MINIO_SECRET_KEY
|
||||
- name: MODEL_ENABLED
|
||||
value: '*'
|
||||
- name: DB_URL
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
name: huly-config
|
||||
key: MONGO_URL
|
||||
- name: MONGO_URL
|
||||
valueFrom:
|
||||
configMapKeyRef:
|
||||
@@ -45,10 +50,6 @@ spec:
|
||||
secretKeyRef:
|
||||
name: huly-secret
|
||||
key: SERVER_SECRET
|
||||
- name: TRANSACTOR_URL
|
||||
value: ws://transactor:3333;ws://localhost:3333
|
||||
- name: NOTIFY_INBOX_ONLY
|
||||
value: true
|
||||
image: hardcoreeng/workspace:latest
|
||||
name: workspace
|
||||
resources:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
HULY_VERSION="v0.6.295"
|
||||
HULY_VERSION="v0.6.333"
|
||||
DOCKER_NAME="huly"
|
||||
CONFIG_FILE="huly.conf"
|
||||
|
||||
|
||||
Regular → Executable
+2
-4
@@ -14,13 +14,11 @@ if [ -z "$LETSENCRYPT_EMAIL" ]; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
|
||||
export HULY_VERSION="v0.6.245"
|
||||
export HULY_VERSION="v0.6.333"
|
||||
export SERVER_ADDRESS=$DOMAIN_NAME
|
||||
export LETSENCRYPT_EMAIL=$LETSENCRYPT_EMAIL
|
||||
|
||||
# replace the domain name and email address in the docker-compose file
|
||||
envsubst < template-compose.yml > docker-compose.yml
|
||||
envsubst < template-compose.yaml > docker-compose.yaml
|
||||
|
||||
echo -e "\033[1;32mSetup is complete. Run 'docker compose up -d' to start the services.\033[0m"
|
||||
|
||||
|
||||
@@ -116,18 +116,15 @@ services:
|
||||
- SERVER_CURSOR_MAXTIMEMS=30000
|
||||
- ELASTIC_URL=http://elastic:9200
|
||||
- ELASTIC_INDEX_NAME=huly_storage_index
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- METRICS_CONSOLE=false
|
||||
- METRICS_FILE=metrics.txt
|
||||
- MINIO_ENDPOINT=minio
|
||||
- MINIO_ACCESS_KEY=minioadmin
|
||||
- MINIO_SECRET_KEY=minioadmin
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
- REKONI_URL=http://rekoni:4004
|
||||
- FRONT_URL=http://localhost:8087
|
||||
- SERVER_PROVIDER=wss
|
||||
- ACCOUNTS_URL=http://account:3000
|
||||
- LAST_NAME_FIRST=true
|
||||
- UPLOAD_URL=https://${SERVER_ADDRESS}/files
|
||||
restart: unless-stopped
|
||||
networks:
|
||||
- internal-services
|
||||
@@ -140,19 +137,14 @@ services:
|
||||
- "traefik.http.routers.transactor.tls=true"
|
||||
- "traefik.http.routers.transactor.tls.certresolver=myresolver"
|
||||
|
||||
|
||||
collaborator:
|
||||
image: hardcoreeng/collaborator:${HULY_VERSION}
|
||||
environment:
|
||||
- COLLABORATOR_PORT=3078
|
||||
- SECRET=secret
|
||||
- ACCOUNTS_URL=http://account:3000
|
||||
- TRANSACTOR_URL=ws://transactor:3333
|
||||
- UPLOAD_URL=/files
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- MINIO_ENDPOINT=minio
|
||||
- MINIO_ACCESS_KEY=minioadmin
|
||||
- MINIO_SECRET_KEY=minioadmin
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
restart: unless-stopped
|
||||
networks:
|
||||
- internal-services
|
||||
@@ -170,12 +162,9 @@ services:
|
||||
environment:
|
||||
- SERVER_PORT=3000
|
||||
- SERVER_SECRET=secret
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- TRANSACTOR_URL=ws://transactor:3333
|
||||
- ENDPOINT_URL=wss://${SERVER_ADDRESS}:3333 # this is the transactor endpoint
|
||||
- MINIO_ENDPOINT=minio
|
||||
- MINIO_ACCESS_KEY=minioadmin
|
||||
- MINIO_SECRET_KEY=minioadmin
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
- FRONT_URL=http://front:8080
|
||||
- INIT_WORKSPACE=demo-tracker
|
||||
- MODEL_ENABLED=*
|
||||
@@ -195,6 +184,21 @@ services:
|
||||
- "traefik.http.routers.account.tls=true"
|
||||
- "traefik.http.routers.account.tls.certresolver=myresolver"
|
||||
|
||||
workspace:
|
||||
image: hardcoreeng/workspace:${HULY_VERSION}
|
||||
environment:
|
||||
- SERVER_SECRET=secret
|
||||
- DB_URL=mongodb://mongodb:27017
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
- MODEL_ENABLED=*
|
||||
- ACCOUNTS_URL=http://account:3000
|
||||
- NOTIFY_INBOX_ONLY=true
|
||||
restart: unless-stopped
|
||||
networks:
|
||||
- internal-services
|
||||
|
||||
front:
|
||||
image: hardcoreeng/front:${HULY_VERSION}
|
||||
environment:
|
||||
@@ -206,13 +210,9 @@ services:
|
||||
- GMAIL_URL=https://${SERVER_ADDRESS}:8088
|
||||
- TELEGRAM_URL=https://${SERVER_ADDRESS}:8086
|
||||
- UPLOAD_URL=/files
|
||||
- TRANSACTOR_URL=wss://${SERVER_ADDRESS}:3333
|
||||
- ELASTIC_URL=http://elastic:9200
|
||||
- COLLABORATOR_URL=wss://${SERVER_ADDRESS}:3078
|
||||
- COLLABORATOR_API_URL=https://${SERVER_ADDRESS}:3078
|
||||
- MINIO_ENDPOINT=minio
|
||||
- MINIO_ACCESS_KEY=minioadmin
|
||||
- MINIO_SECRET_KEY=minioadmin
|
||||
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
|
||||
- MONGO_URL=mongodb://mongodb:27017
|
||||
- TITLE=Huly Self Host
|
||||
- DEFAULT_LANGUAGE=en
|
||||
@@ -223,6 +223,7 @@ services:
|
||||
- traefik-public
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.port=80"
|
||||
- "traefik.http.routers.front.entrypoints=websecure"
|
||||
- "traefik.http.services.front.loadbalancer.server.port=8080"
|
||||
- "traefik.http.routers.front.rule=Host(`${SERVER_ADDRESS}`)"
|
||||
|
||||
Reference in New Issue
Block a user