diff --git a/README.md b/README.md index cff8e5d..280025c 100644 --- a/README.md +++ b/README.md @@ -76,8 +76,160 @@ asdfsadfasdfsfd ``` Keep these keys secure, as you will need them to set up your push notification service on the server. -Add these keys into `compose.yaml` in section `services:front:environnement`: +Add these keys into `compose.yaml` in section `services:front:environment`: ``` - PUSH_PUBLIC_KEY=your public key - PUSH_PRIVATE_KEY=your private key -``` \ No newline at end of file +``` + +## AWS SES email notifications + +1. Setup Amazon Simple Email Service in AWS: https://docs.aws.amazon.com/ses/latest/dg/setting-up.html + +2. Add email address you'll use to send notifications into "SOURCE", SES access such as ACCESS_KEY, SECRET_KEY, REGION + + ```yaml + ses: + image: hardcoreeng/ses:v0.6.295 + container_name: ses + ports: + - 3335:3335 + environment: + - SOURCE= + - ACCESS_KEY= + - SECRET_KEY= + - REGION= + - PORT=3335 + restart: unless-stopped + ``` + +3. Add SES container URL into `transactor` and `account` containers: + + ```yaml + account: + ... + environment: + - SES_URL=http://ses:3335 + ... + transactor: + ... + environment: + - SES_URL=http://ses:3335 + ... + ``` + +4. In `Settings -> Notifications` setup email notifications for events you need to be notified for. It's a user's setting not a company wide, meaning each user has to setup their own notification rules. + +## Love Service (Audio & Video calls) + +Huly audio and video calls are created on top of LiveKit insfrastructure. In order to use Love service in your self-hosted Huly, perform the following steps: + +1. Set up [LiveKit Cloud](https://cloud.livekit.io) account +2. Add `love` container to the docker-compose.yaml + + ```yaml + love: + image: hardcoreeng/love:v0.6.295 + container_name: love + ports: + - 8096:8096 + environment: + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin + - SECRET=secret + - ACCOUNTS_URL=http://account:3000 + - DB_URL=mongodb://mongodb:27017 + - MONGO_URL=mongodb://mongodb:27017 + - STORAGE_PROVIDER_NAME=minio + - PORT=8096 + - LIVEKIT_HOST= + - LIVEKIT_API_KEY= + - LIVEKIT_API_SECRET= + restart: unless-stopped + ``` + +3. Configure `front` service: + + ```yaml + front: + ... + environment: + - LIVEKIT_WS= + - LOVE_ENDPOINT=http://love:8096 + ... + ``` + +## Configure OpenID Connect (OIDC) + +You can configure a Huly instance to authorize users (sign-in/sign-up) using an OpenID Connect identity provider (IdP). + +### On the IdP side +1. Create a new OpenID application. + * Use `{huly_account_svc}/auth/openid/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000. + + **URI Example:** + - `http://huly.mydomain.com:3000/auth/openid/callback` + +2. Configure user access to the application as needed. + +### On the Huly side +For the account service, set the following environment variables as provided by the IdP: + +* OPENID_CLIENT_ID +* OPENID_CLIENT_SECRET +* OPENID_ISSUER + +Ensure you have configured or add the following environment variable to the front service: + +* ACCOUNTS_URL (This should contain the URL of the account service, accessible from the client side.) + +You will need to expose your account service port (e.g. 3000) in your nginx.conf. + +Note: Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages. + +## Configure GitHub OAuth + +You can also configure a Huly instance to use GitHub OAuth for user authorization (sign-in/sign-up). + +### On the GitHub side +1. Create a new GitHub OAuth application. + * Use `{huly_account_svc}/auth/github/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000. + + **URI Example:** + - `http://huly.mydomain.com:3000/auth/github/callback` + +### On the Huly side +Specify the following environment variables for the account service: + +* `GITHUB_CLIENT_ID` +* `GITHUB_CLIENT_SECRET` + +Ensure you have configured or add the following environment variable to the front service: + +* `ACCOUNTS_URL` (The URL of the account service, accessible from the client side.) + +You will need to expose your account service port (e.g. 3000) in your nginx.conf. + +Notes: +* The `ISSUER` environment variable is not required for GitHub OAuth. +* Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages. + +## Disable Sign-Up + +You can disable public sign-ups for a deployment. When configured, sign-ups will only be permitted through an invite link to a specific workspace. + +To implement this, set the following environment variable for both the front and account services: + +```yaml + account: + ... + environment: + - DISABLE_SIGNUP=true + ... + front: + ... + environment: + - DISABLE_SIGNUP=true + ... +``` + +_Note: When setting up a new deployment, either create the initial account before disabling sign-ups or use the development tool to create the first account._ diff --git a/compose.yml b/compose.yml index 8b89fa5..89bbfab 100644 --- a/compose.yml +++ b/compose.yml @@ -62,6 +62,7 @@ services: - SERVER_CURSOR_MAXTIMEMS=30000 - ELASTIC_URL=http://elastic:9200 - ELASTIC_INDEX_NAME=huly_storage_index + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - METRICS_CONSOLE=false - METRICS_FILE=metrics.txt @@ -79,6 +80,7 @@ services: - COLLABORATOR_PORT=3078 - SECRET=${SECRET} - ACCOUNTS_URL=http://account:3000 + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin restart: unless-stopped @@ -88,6 +90,7 @@ services: environment: - SERVER_PORT=3000 - SERVER_SECRET=${SECRET} + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - TRANSACTOR_URL=ws://transactor:3333;ws${SECURE:+s}://${HOST_ADDRESS}/_transactor - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin @@ -100,7 +103,9 @@ services: workspace: image: hardcoreeng/workspace:${HULY_VERSION} environment: + - SERVER_SECRET=${HULY_SECRET} - SERVER_SECRET=${SECRET} + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - TRANSACTOR_URL=ws://transactor:3333;ws${SECURE:+s}://${HOST_ADDRESS}/_transactor - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin @@ -129,6 +134,7 @@ services: - ELASTIC_URL=http://elastic:9200 - COLLABORATOR_URL=ws${SECURE:+s}://${HOST_ADDRESS}/_collaborator - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - TITLE=${TITLE:-Huly Self Host} - DEFAULT_LANGUAGE=${DEFAULT_LANGUAGE:-en} diff --git a/kube/account/account-deployment.yaml b/kube/account/account-deployment.yaml index e54d917..d8f43ff 100644 --- a/kube/account/account-deployment.yaml +++ b/kube/account/account-deployment.yaml @@ -45,7 +45,7 @@ spec: key: MINIO_SECRET_KEY - name: MODEL_ENABLED value: '*' - - name: MONGO_URL + - name: DB_URL valueFrom: configMapKeyRef: name: huly-config diff --git a/kube/mongodb/mongodb-persistentvolumeclaim.yml b/kube/mongodb/mongodb-persistentvolumeclaim.yml new file mode 100644 index 0000000..8aa617a --- /dev/null +++ b/kube/mongodb/mongodb-persistentvolumeclaim.yml @@ -0,0 +1,10 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: db +spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 100Mi \ No newline at end of file diff --git a/kube/transactor/transactor-deployment.yaml b/kube/transactor/transactor-deployment.yaml index 98fd109..0651135 100644 --- a/kube/transactor/transactor-deployment.yaml +++ b/kube/transactor/transactor-deployment.yaml @@ -53,6 +53,11 @@ spec: configMapKeyRef: name: huly-config key: MONGO_URL + - name: DB_URL + valueFrom: + configMapKeyRef: + name: huly-config + key: MONGO_URL - name: REKONI_URL value: http://rekoni - name: SERVER_CURSOR_MAXTIMEMS diff --git a/kube/workspace/workspace-deployment.yaml b/kube/workspace/workspace-deployment.yaml index 6660c40..6083c1d 100644 --- a/kube/workspace/workspace-deployment.yaml +++ b/kube/workspace/workspace-deployment.yaml @@ -35,6 +35,11 @@ spec: key: MINIO_SECRET_KEY - name: MODEL_ENABLED value: '*' + - name: DB_URL + valueFrom: + configMapKeyRef: + name: huly-config + key: MONGO_URL - name: MONGO_URL valueFrom: configMapKeyRef: @@ -45,10 +50,6 @@ spec: secretKeyRef: name: huly-secret key: SERVER_SECRET - - name: TRANSACTOR_URL - value: ws://transactor:3333;ws://localhost:3333 - - name: NOTIFY_INBOX_ONLY - value: true image: hardcoreeng/workspace:latest name: workspace resources: diff --git a/setup.sh b/setup.sh index 21879fa..ab9b566 100755 --- a/setup.sh +++ b/setup.sh @@ -1,6 +1,6 @@ #!/usr/bin/env bash -HULY_VERSION="v0.6.295" +HULY_VERSION="v0.6.333" DOCKER_NAME="huly" CONFIG_FILE="huly.conf" diff --git a/traefik/setup.sh b/traefik/setup.sh old mode 100644 new mode 100755 index 49ab4bc..9d2b593 --- a/traefik/setup.sh +++ b/traefik/setup.sh @@ -14,13 +14,11 @@ if [ -z "$LETSENCRYPT_EMAIL" ]; then exit 1 fi - -export HULY_VERSION="v0.6.245" +export HULY_VERSION="v0.6.333" export SERVER_ADDRESS=$DOMAIN_NAME export LETSENCRYPT_EMAIL=$LETSENCRYPT_EMAIL # replace the domain name and email address in the docker-compose file -envsubst < template-compose.yml > docker-compose.yml +envsubst < template-compose.yaml > docker-compose.yaml echo -e "\033[1;32mSetup is complete. Run 'docker compose up -d' to start the services.\033[0m" - diff --git a/traefik/template-compose.yaml b/traefik/template-compose.yaml index 0664bbd..a556bb6 100644 --- a/traefik/template-compose.yaml +++ b/traefik/template-compose.yaml @@ -116,18 +116,15 @@ services: - SERVER_CURSOR_MAXTIMEMS=30000 - ELASTIC_URL=http://elastic:9200 - ELASTIC_INDEX_NAME=huly_storage_index + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - METRICS_CONSOLE=false - METRICS_FILE=metrics.txt - - MINIO_ENDPOINT=minio - - MINIO_ACCESS_KEY=minioadmin - - MINIO_SECRET_KEY=minioadmin + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - REKONI_URL=http://rekoni:4004 - FRONT_URL=http://localhost:8087 - - SERVER_PROVIDER=wss - ACCOUNTS_URL=http://account:3000 - LAST_NAME_FIRST=true - - UPLOAD_URL=https://${SERVER_ADDRESS}/files restart: unless-stopped networks: - internal-services @@ -140,19 +137,14 @@ services: - "traefik.http.routers.transactor.tls=true" - "traefik.http.routers.transactor.tls.certresolver=myresolver" - collaborator: image: hardcoreeng/collaborator:${HULY_VERSION} environment: - COLLABORATOR_PORT=3078 - SECRET=secret - ACCOUNTS_URL=http://account:3000 - - TRANSACTOR_URL=ws://transactor:3333 - - UPLOAD_URL=/files - MONGO_URL=mongodb://mongodb:27017 - - MINIO_ENDPOINT=minio - - MINIO_ACCESS_KEY=minioadmin - - MINIO_SECRET_KEY=minioadmin + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin restart: unless-stopped networks: - internal-services @@ -170,12 +162,9 @@ services: environment: - SERVER_PORT=3000 - SERVER_SECRET=secret - - MONGO_URL=mongodb://mongodb:27017 - - TRANSACTOR_URL=ws://transactor:3333 - - ENDPOINT_URL=wss://${SERVER_ADDRESS}:3333 # this is the transactor endpoint - - MINIO_ENDPOINT=minio - - MINIO_ACCESS_KEY=minioadmin - - MINIO_SECRET_KEY=minioadmin + - DB_URL=mongodb://mongodb:27017 + - TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333 + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - FRONT_URL=http://front:8080 - INIT_WORKSPACE=demo-tracker - MODEL_ENABLED=* @@ -195,6 +184,21 @@ services: - "traefik.http.routers.account.tls=true" - "traefik.http.routers.account.tls.certresolver=myresolver" + workspace: + image: hardcoreeng/workspace:${HULY_VERSION} + environment: + - SERVER_SECRET=secret + - DB_URL=mongodb://mongodb:27017 + - MONGO_URL=mongodb://mongodb:27017 + - TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333 + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin + - MODEL_ENABLED=* + - ACCOUNTS_URL=http://account:3000 + - NOTIFY_INBOX_ONLY=true + restart: unless-stopped + networks: + - internal-services + front: image: hardcoreeng/front:${HULY_VERSION} environment: @@ -206,13 +210,9 @@ services: - GMAIL_URL=https://${SERVER_ADDRESS}:8088 - TELEGRAM_URL=https://${SERVER_ADDRESS}:8086 - UPLOAD_URL=/files - - TRANSACTOR_URL=wss://${SERVER_ADDRESS}:3333 - ELASTIC_URL=http://elastic:9200 - COLLABORATOR_URL=wss://${SERVER_ADDRESS}:3078 - - COLLABORATOR_API_URL=https://${SERVER_ADDRESS}:3078 - - MINIO_ENDPOINT=minio - - MINIO_ACCESS_KEY=minioadmin - - MINIO_SECRET_KEY=minioadmin + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - MONGO_URL=mongodb://mongodb:27017 - TITLE=Huly Self Host - DEFAULT_LANGUAGE=en @@ -223,6 +223,7 @@ services: - traefik-public labels: - "traefik.enable=true" + - "traefik.port=80" - "traefik.http.routers.front.entrypoints=websecure" - "traefik.http.services.front.loadbalancer.server.port=8080" - "traefik.http.routers.front.rule=Host(`${SERVER_ADDRESS}`)"