This commit is contained in:
veryCrunchy
2024-12-03 21:50:42 +01:00
9 changed files with 207 additions and 34 deletions
+154 -2
View File
@@ -76,8 +76,160 @@ asdfsadfasdfsfd
```
Keep these keys secure, as you will need them to set up your push notification service on the server.
Add these keys into `compose.yaml` in section `services:front:environnement`:
Add these keys into `compose.yaml` in section `services:front:environment`:
```
- PUSH_PUBLIC_KEY=your public key
- PUSH_PRIVATE_KEY=your private key
```
```
## AWS SES email notifications
1. Setup Amazon Simple Email Service in AWS: https://docs.aws.amazon.com/ses/latest/dg/setting-up.html
2. Add email address you'll use to send notifications into "SOURCE", SES access such as ACCESS_KEY, SECRET_KEY, REGION
```yaml
ses:
image: hardcoreeng/ses:v0.6.295
container_name: ses
ports:
- 3335:3335
environment:
- SOURCE=<EMAIL_FROM>
- ACCESS_KEY=<SES_ACCESS_KEY>
- SECRET_KEY=<SES_SECRET_KEY>
- REGION=<SES_REGION>
- PORT=3335
restart: unless-stopped
```
3. Add SES container URL into `transactor` and `account` containers:
```yaml
account:
...
environment:
- SES_URL=http://ses:3335
...
transactor:
...
environment:
- SES_URL=http://ses:3335
...
```
4. In `Settings -> Notifications` setup email notifications for events you need to be notified for. It's a user's setting not a company wide, meaning each user has to setup their own notification rules.
## Love Service (Audio & Video calls)
Huly audio and video calls are created on top of LiveKit insfrastructure. In order to use Love service in your self-hosted Huly, perform the following steps:
1. Set up [LiveKit Cloud](https://cloud.livekit.io) account
2. Add `love` container to the docker-compose.yaml
```yaml
love:
image: hardcoreeng/love:v0.6.295
container_name: love
ports:
- 8096:8096
environment:
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
- SECRET=secret
- ACCOUNTS_URL=http://account:3000
- DB_URL=mongodb://mongodb:27017
- MONGO_URL=mongodb://mongodb:27017
- STORAGE_PROVIDER_NAME=minio
- PORT=8096
- LIVEKIT_HOST=<LIVEKIT_HOST>
- LIVEKIT_API_KEY=<LIVEKIT_API_KEY>
- LIVEKIT_API_SECRET=<LIVEKIT_API_SECRET>
restart: unless-stopped
```
3. Configure `front` service:
```yaml
front:
...
environment:
- LIVEKIT_WS=<LIVEKIT_HOST>
- LOVE_ENDPOINT=http://love:8096
...
```
## Configure OpenID Connect (OIDC)
You can configure a Huly instance to authorize users (sign-in/sign-up) using an OpenID Connect identity provider (IdP).
### On the IdP side
1. Create a new OpenID application.
* Use `{huly_account_svc}/auth/openid/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000.
**URI Example:**
- `http://huly.mydomain.com:3000/auth/openid/callback`
2. Configure user access to the application as needed.
### On the Huly side
For the account service, set the following environment variables as provided by the IdP:
* OPENID_CLIENT_ID
* OPENID_CLIENT_SECRET
* OPENID_ISSUER
Ensure you have configured or add the following environment variable to the front service:
* ACCOUNTS_URL (This should contain the URL of the account service, accessible from the client side.)
You will need to expose your account service port (e.g. 3000) in your nginx.conf.
Note: Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages.
## Configure GitHub OAuth
You can also configure a Huly instance to use GitHub OAuth for user authorization (sign-in/sign-up).
### On the GitHub side
1. Create a new GitHub OAuth application.
* Use `{huly_account_svc}/auth/github/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000.
**URI Example:**
- `http://huly.mydomain.com:3000/auth/github/callback`
### On the Huly side
Specify the following environment variables for the account service:
* `GITHUB_CLIENT_ID`
* `GITHUB_CLIENT_SECRET`
Ensure you have configured or add the following environment variable to the front service:
* `ACCOUNTS_URL` (The URL of the account service, accessible from the client side.)
You will need to expose your account service port (e.g. 3000) in your nginx.conf.
Notes:
* The `ISSUER` environment variable is not required for GitHub OAuth.
* Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages.
## Disable Sign-Up
You can disable public sign-ups for a deployment. When configured, sign-ups will only be permitted through an invite link to a specific workspace.
To implement this, set the following environment variable for both the front and account services:
```yaml
account:
...
environment:
- DISABLE_SIGNUP=true
...
front:
...
environment:
- DISABLE_SIGNUP=true
...
```
_Note: When setting up a new deployment, either create the initial account before disabling sign-ups or use the development tool to create the first account._
+6
View File
@@ -62,6 +62,7 @@ services:
- SERVER_CURSOR_MAXTIMEMS=30000
- ELASTIC_URL=http://elastic:9200
- ELASTIC_INDEX_NAME=huly_storage_index
- DB_URL=mongodb://mongodb:27017
- MONGO_URL=mongodb://mongodb:27017
- METRICS_CONSOLE=false
- METRICS_FILE=metrics.txt
@@ -79,6 +80,7 @@ services:
- COLLABORATOR_PORT=3078
- SECRET=${SECRET}
- ACCOUNTS_URL=http://account:3000
- DB_URL=mongodb://mongodb:27017
- MONGO_URL=mongodb://mongodb:27017
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
restart: unless-stopped
@@ -88,6 +90,7 @@ services:
environment:
- SERVER_PORT=3000
- SERVER_SECRET=${SECRET}
- DB_URL=mongodb://mongodb:27017
- MONGO_URL=mongodb://mongodb:27017
- TRANSACTOR_URL=ws://transactor:3333;ws${SECURE:+s}://${HOST_ADDRESS}/_transactor
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
@@ -100,7 +103,9 @@ services:
workspace:
image: hardcoreeng/workspace:${HULY_VERSION}
environment:
- SERVER_SECRET=${HULY_SECRET}
- SERVER_SECRET=${SECRET}
- DB_URL=mongodb://mongodb:27017
- MONGO_URL=mongodb://mongodb:27017
- TRANSACTOR_URL=ws://transactor:3333;ws${SECURE:+s}://${HOST_ADDRESS}/_transactor
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
@@ -129,6 +134,7 @@ services:
- ELASTIC_URL=http://elastic:9200
- COLLABORATOR_URL=ws${SECURE:+s}://${HOST_ADDRESS}/_collaborator
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
- DB_URL=mongodb://mongodb:27017
- MONGO_URL=mongodb://mongodb:27017
- TITLE=${TITLE:-Huly Self Host}
- DEFAULT_LANGUAGE=${DEFAULT_LANGUAGE:-en}
+1 -1
View File
@@ -45,7 +45,7 @@ spec:
key: MINIO_SECRET_KEY
- name: MODEL_ENABLED
value: '*'
- name: MONGO_URL
- name: DB_URL
valueFrom:
configMapKeyRef:
name: huly-config
@@ -0,0 +1,10 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: db
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 100Mi
@@ -53,6 +53,11 @@ spec:
configMapKeyRef:
name: huly-config
key: MONGO_URL
- name: DB_URL
valueFrom:
configMapKeyRef:
name: huly-config
key: MONGO_URL
- name: REKONI_URL
value: http://rekoni
- name: SERVER_CURSOR_MAXTIMEMS
+5 -4
View File
@@ -35,6 +35,11 @@ spec:
key: MINIO_SECRET_KEY
- name: MODEL_ENABLED
value: '*'
- name: DB_URL
valueFrom:
configMapKeyRef:
name: huly-config
key: MONGO_URL
- name: MONGO_URL
valueFrom:
configMapKeyRef:
@@ -45,10 +50,6 @@ spec:
secretKeyRef:
name: huly-secret
key: SERVER_SECRET
- name: TRANSACTOR_URL
value: ws://transactor:3333;ws://localhost:3333
- name: NOTIFY_INBOX_ONLY
value: true
image: hardcoreeng/workspace:latest
name: workspace
resources:
+1 -1
View File
@@ -1,6 +1,6 @@
#!/usr/bin/env bash
HULY_VERSION="v0.6.295"
HULY_VERSION="v0.6.333"
DOCKER_NAME="huly"
CONFIG_FILE="huly.conf"
Regular → Executable
+2 -4
View File
@@ -14,13 +14,11 @@ if [ -z "$LETSENCRYPT_EMAIL" ]; then
exit 1
fi
export HULY_VERSION="v0.6.245"
export HULY_VERSION="v0.6.333"
export SERVER_ADDRESS=$DOMAIN_NAME
export LETSENCRYPT_EMAIL=$LETSENCRYPT_EMAIL
# replace the domain name and email address in the docker-compose file
envsubst < template-compose.yml > docker-compose.yml
envsubst < template-compose.yaml > docker-compose.yaml
echo -e "\033[1;32mSetup is complete. Run 'docker compose up -d' to start the services.\033[0m"
+23 -22
View File
@@ -116,18 +116,15 @@ services:
- SERVER_CURSOR_MAXTIMEMS=30000
- ELASTIC_URL=http://elastic:9200
- ELASTIC_INDEX_NAME=huly_storage_index
- DB_URL=mongodb://mongodb:27017
- MONGO_URL=mongodb://mongodb:27017
- METRICS_CONSOLE=false
- METRICS_FILE=metrics.txt
- MINIO_ENDPOINT=minio
- MINIO_ACCESS_KEY=minioadmin
- MINIO_SECRET_KEY=minioadmin
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
- REKONI_URL=http://rekoni:4004
- FRONT_URL=http://localhost:8087
- SERVER_PROVIDER=wss
- ACCOUNTS_URL=http://account:3000
- LAST_NAME_FIRST=true
- UPLOAD_URL=https://${SERVER_ADDRESS}/files
restart: unless-stopped
networks:
- internal-services
@@ -140,19 +137,14 @@ services:
- "traefik.http.routers.transactor.tls=true"
- "traefik.http.routers.transactor.tls.certresolver=myresolver"
collaborator:
image: hardcoreeng/collaborator:${HULY_VERSION}
environment:
- COLLABORATOR_PORT=3078
- SECRET=secret
- ACCOUNTS_URL=http://account:3000
- TRANSACTOR_URL=ws://transactor:3333
- UPLOAD_URL=/files
- MONGO_URL=mongodb://mongodb:27017
- MINIO_ENDPOINT=minio
- MINIO_ACCESS_KEY=minioadmin
- MINIO_SECRET_KEY=minioadmin
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
restart: unless-stopped
networks:
- internal-services
@@ -170,12 +162,9 @@ services:
environment:
- SERVER_PORT=3000
- SERVER_SECRET=secret
- MONGO_URL=mongodb://mongodb:27017
- TRANSACTOR_URL=ws://transactor:3333
- ENDPOINT_URL=wss://${SERVER_ADDRESS}:3333 # this is the transactor endpoint
- MINIO_ENDPOINT=minio
- MINIO_ACCESS_KEY=minioadmin
- MINIO_SECRET_KEY=minioadmin
- DB_URL=mongodb://mongodb:27017
- TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
- FRONT_URL=http://front:8080
- INIT_WORKSPACE=demo-tracker
- MODEL_ENABLED=*
@@ -195,6 +184,21 @@ services:
- "traefik.http.routers.account.tls=true"
- "traefik.http.routers.account.tls.certresolver=myresolver"
workspace:
image: hardcoreeng/workspace:${HULY_VERSION}
environment:
- SERVER_SECRET=secret
- DB_URL=mongodb://mongodb:27017
- MONGO_URL=mongodb://mongodb:27017
- TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
- MODEL_ENABLED=*
- ACCOUNTS_URL=http://account:3000
- NOTIFY_INBOX_ONLY=true
restart: unless-stopped
networks:
- internal-services
front:
image: hardcoreeng/front:${HULY_VERSION}
environment:
@@ -206,13 +210,9 @@ services:
- GMAIL_URL=https://${SERVER_ADDRESS}:8088
- TELEGRAM_URL=https://${SERVER_ADDRESS}:8086
- UPLOAD_URL=/files
- TRANSACTOR_URL=wss://${SERVER_ADDRESS}:3333
- ELASTIC_URL=http://elastic:9200
- COLLABORATOR_URL=wss://${SERVER_ADDRESS}:3078
- COLLABORATOR_API_URL=https://${SERVER_ADDRESS}:3078
- MINIO_ENDPOINT=minio
- MINIO_ACCESS_KEY=minioadmin
- MINIO_SECRET_KEY=minioadmin
- STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin
- MONGO_URL=mongodb://mongodb:27017
- TITLE=Huly Self Host
- DEFAULT_LANGUAGE=en
@@ -223,6 +223,7 @@ services:
- traefik-public
labels:
- "traefik.enable=true"
- "traefik.port=80"
- "traefik.http.routers.front.entrypoints=websecure"
- "traefik.http.services.front.loadbalancer.server.port=8080"
- "traefik.http.routers.front.rule=Host(`${SERVER_ADDRESS}`)"