From 83a249820773d06d8cb6ad11d9b8843e439d8473 Mon Sep 17 00:00:00 2001 From: Sergey Belov Date: Tue, 24 Sep 2024 08:45:55 -0600 Subject: [PATCH 01/19] AWS SES email notifications --- README.md | 33 ++++++++++++++++++++++++++++++++- 1 file changed, 32 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 9b1ada7..3774a86 100644 --- a/README.md +++ b/README.md @@ -78,4 +78,35 @@ Add these keys into `compose.yaml` in section `services:front:environnement`: ``` - PUSH_PUBLIC_KEY=your public key - PUSH_PRIVATE_KEY=your private key -``` \ No newline at end of file +``` + +## AWS SES email notifications + +1. Setup Amazon Simple Email Service in AWS: https://docs.aws.amazon.com/ses/latest/dg/setting-up.html + +2. Add email address you'll use to send notifications into "SOURCE", SES access such as ACCESS_KEY, SECRET_KEY, REGION + +``` + ses: + image: hardcoreeng/ses:v0.6.295 + container_name: ses + ports: + - 3335:3335 + environment: + - SOURCE= + - ACCESS_KEY= + - SECRET_KEY= + - REGION= + - PORT=3335 + restart: unless-stopped +``` + +3. Add SES container URL into transactor and account containers + +`transactor:environment` AND `account:environment`: + +``` +- SES_URL=http://ses:3335 +``` + +4. In `Settings -> Notifications` setup email notifications for events you need to be notified for. It's a user's setting not a company wide, meaning each user has to setup their own notification rules. \ No newline at end of file From 3c4453873649bff2a4c528566f093131f6fe7abf Mon Sep 17 00:00:00 2001 From: Alexey Zinoviev Date: Tue, 1 Oct 2024 16:08:01 +0400 Subject: [PATCH 02/19] Add OpenID connect configuration Signed-off-by: Alexey Zinoviev --- README.md | 26 +++++++++++++++++++++++++- 1 file changed, 25 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 9b1ada7..1bba02b 100644 --- a/README.md +++ b/README.md @@ -78,4 +78,28 @@ Add these keys into `compose.yaml` in section `services:front:environnement`: ``` - PUSH_PUBLIC_KEY=your public key - PUSH_PRIVATE_KEY=your private key -``` \ No newline at end of file +``` + +## Configure OpenId Connect + +You can configure a Huly instance to authorize users (sign-in/sign-up) using an OpenID Connect identity provider (IdP). + +### On the IdP side + +* Create a new OpenID application. +* Configure user access to the application as needed. + +### On the Huly side + +Specify the following environment variables (provided by the IdP) for the account service: + +* OPENID_CLIENT_ID +* OPENID_CLIENT_SECRET +* OPENID_ISSUER + + +Ensure you have configured or add the following environment variable to the front service: + +* ACCOUNTS_URL (This should contain the URL of the account service, accessible from the client side.) + +Note: Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages. From 2918c543464d8b47f0466505f2b290b1fd6363a1 Mon Sep 17 00:00:00 2001 From: Alexey Zinoviev Date: Thu, 3 Oct 2024 19:05:13 +0400 Subject: [PATCH 03/19] Update v313 Signed-off-by: Alexey Zinoviev --- nginx/setup.sh | 2 +- setup.sh | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/nginx/setup.sh b/nginx/setup.sh index 502e64d..dd47285 100755 --- a/nginx/setup.sh +++ b/nginx/setup.sh @@ -31,7 +31,7 @@ case "$NGINX_BEHIND_SSL" in esac -export HULY_VERSION="v0.6.295" +export HULY_VERSION="v0.6.313" export NGINX_SERVICE_PORT=$NGINX_SERVICE_PORT export NGINX_HTTP_SCHEME=$NGINX_HTTP_SCHEME export NGINX_WS_SCHEME=$NGINX_WS_SCHEME diff --git a/setup.sh b/setup.sh index 8d2e5a0..2f32b65 100755 --- a/setup.sh +++ b/setup.sh @@ -7,4 +7,4 @@ echo "Setting Huly Server Address: $SERVER_ADDRESS" envsubst < template.conf > nginx.conf envsubst < template.env > .env -./use-version.sh v0.6.295 +./use-version.sh v0.6.313 From 7411fbf60c4008bc8bc93396e1ef30d9f6299abd Mon Sep 17 00:00:00 2001 From: Jonathan Brockhaus Date: Tue, 8 Oct 2024 21:41:36 +0200 Subject: [PATCH 04/19] fix: Traefik setup script with incorrect template filename --- traefik/setup.sh | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/traefik/setup.sh b/traefik/setup.sh index 49ab4bc..7b6f781 100644 --- a/traefik/setup.sh +++ b/traefik/setup.sh @@ -20,7 +20,6 @@ export SERVER_ADDRESS=$DOMAIN_NAME export LETSENCRYPT_EMAIL=$LETSENCRYPT_EMAIL # replace the domain name and email address in the docker-compose file -envsubst < template-compose.yml > docker-compose.yml +envsubst < template-compose.yaml > docker-compose.yaml echo -e "\033[1;32mSetup is complete. Run 'docker compose up -d' to start the services.\033[0m" - From 04aabf9324cc5a23ae5a91af2399d96797bc3820 Mon Sep 17 00:00:00 2001 From: Channing Babb Date: Thu, 10 Oct 2024 14:10:11 -0500 Subject: [PATCH 05/19] Update README.md Environment typo in the IdP section. Signed-off-by: Channing Babb --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 1bba02b..417dfde 100644 --- a/README.md +++ b/README.md @@ -74,7 +74,7 @@ asdfsadfasdfsfd ``` Keep these keys secure, as you will need them to set up your push notification service on the server. -Add these keys into `compose.yaml` in section `services:front:environnement`: +Add these keys into `compose.yaml` in section `services:front:environment`: ``` - PUSH_PUBLIC_KEY=your public key - PUSH_PRIVATE_KEY=your private key From 70392329454c4300a5117ce49c579a1ec81b6f9f Mon Sep 17 00:00:00 2001 From: ja49619 <107350002+ja49619@users.noreply.github.com> Date: Sun, 13 Oct 2024 13:22:47 +0400 Subject: [PATCH 06/19] remove the links directives from the compose file remove the links directives from the compose file Signed-off-by: ja49619 <107350002+ja49619@users.noreply.github.com> --- template.compose.yaml | 21 --------------------- 1 file changed, 21 deletions(-) diff --git a/template.compose.yaml b/template.compose.yaml index e14c65a..464e029 100644 --- a/template.compose.yaml +++ b/template.compose.yaml @@ -43,9 +43,6 @@ services: restart: unless-stopped account: image: hardcoreeng/account:${HULY_VERSION} - links: - - mongodb - - minio ports: - 3000:3000 environment: @@ -61,9 +58,6 @@ services: restart: unless-stopped workspace: image: hardcoreeng/workspace:${HULY_VERSION} - links: - - mongodb - - minio environment: - SERVER_SECRET=${HULY_SECRET} - MONGO_URL=mongodb://mongodb:27017 @@ -75,12 +69,6 @@ services: restart: unless-stopped front: image: hardcoreeng/front:${HULY_VERSION} - links: - - mongodb - - minio - - elastic - - collaborator - - transactor ports: - 8087:8080 environment: @@ -102,10 +90,6 @@ services: restart: unless-stopped collaborator: image: hardcoreeng/collaborator:${HULY_VERSION} - links: - - mongodb - - minio - - transactor ports: - 3078:3078 environment: @@ -117,11 +101,6 @@ services: restart: unless-stopped transactor: image: hardcoreeng/transactor:${HULY_VERSION} - links: - - mongodb - - elastic - - minio - - account ports: - 3333:3333 environment: From 2c3054b9178770c93c118778a14d004f8db62d23 Mon Sep 17 00:00:00 2001 From: Alexander Onnikov Date: Mon, 14 Oct 2024 12:51:49 +0700 Subject: [PATCH 07/19] fix: update traefic config to v313 Signed-off-by: Alexander Onnikov --- traefik/setup.sh | 5 ++--- traefik/template-compose.yaml | 41 +++++++++++++++++------------------ 2 files changed, 22 insertions(+), 24 deletions(-) mode change 100644 => 100755 traefik/setup.sh diff --git a/traefik/setup.sh b/traefik/setup.sh old mode 100644 new mode 100755 index 49ab4bc..4c7f56c --- a/traefik/setup.sh +++ b/traefik/setup.sh @@ -14,13 +14,12 @@ if [ -z "$LETSENCRYPT_EMAIL" ]; then exit 1 fi - -export HULY_VERSION="v0.6.245" +export HULY_VERSION="v0.6.313" export SERVER_ADDRESS=$DOMAIN_NAME export LETSENCRYPT_EMAIL=$LETSENCRYPT_EMAIL # replace the domain name and email address in the docker-compose file -envsubst < template-compose.yml > docker-compose.yml +envsubst < template-compose.yaml > docker-compose.yaml echo -e "\033[1;32mSetup is complete. Run 'docker compose up -d' to start the services.\033[0m" diff --git a/traefik/template-compose.yaml b/traefik/template-compose.yaml index 0664bbd..5994e91 100644 --- a/traefik/template-compose.yaml +++ b/traefik/template-compose.yaml @@ -119,15 +119,11 @@ services: - MONGO_URL=mongodb://mongodb:27017 - METRICS_CONSOLE=false - METRICS_FILE=metrics.txt - - MINIO_ENDPOINT=minio - - MINIO_ACCESS_KEY=minioadmin - - MINIO_SECRET_KEY=minioadmin + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - REKONI_URL=http://rekoni:4004 - FRONT_URL=http://localhost:8087 - - SERVER_PROVIDER=wss - ACCOUNTS_URL=http://account:3000 - LAST_NAME_FIRST=true - - UPLOAD_URL=https://${SERVER_ADDRESS}/files restart: unless-stopped networks: - internal-services @@ -140,19 +136,14 @@ services: - "traefik.http.routers.transactor.tls=true" - "traefik.http.routers.transactor.tls.certresolver=myresolver" - collaborator: image: hardcoreeng/collaborator:${HULY_VERSION} environment: - COLLABORATOR_PORT=3078 - SECRET=secret - ACCOUNTS_URL=http://account:3000 - - TRANSACTOR_URL=ws://transactor:3333 - - UPLOAD_URL=/files - MONGO_URL=mongodb://mongodb:27017 - - MINIO_ENDPOINT=minio - - MINIO_ACCESS_KEY=minioadmin - - MINIO_SECRET_KEY=minioadmin + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin restart: unless-stopped networks: - internal-services @@ -171,11 +162,8 @@ services: - SERVER_PORT=3000 - SERVER_SECRET=secret - MONGO_URL=mongodb://mongodb:27017 - - TRANSACTOR_URL=ws://transactor:3333 - - ENDPOINT_URL=wss://${SERVER_ADDRESS}:3333 # this is the transactor endpoint - - MINIO_ENDPOINT=minio - - MINIO_ACCESS_KEY=minioadmin - - MINIO_SECRET_KEY=minioadmin + - TRANSACTOR_URL=ws://transactor:3333;ws://${SERVER_ADDRESS}:3333 + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - FRONT_URL=http://front:8080 - INIT_WORKSPACE=demo-tracker - MODEL_ENABLED=* @@ -195,6 +183,20 @@ services: - "traefik.http.routers.account.tls=true" - "traefik.http.routers.account.tls.certresolver=myresolver" + workspace: + image: hardcoreeng/workspace:${HULY_VERSION} + environment: + - SERVER_SECRET=secret + - MONGO_URL=mongodb://mongodb:27017 + - TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333 + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin + - MODEL_ENABLED=* + - ACCOUNTS_URL=http://account:3000 + - NOTIFY_INBOX_ONLY=true + restart: unless-stopped + networks: + - internal-services + front: image: hardcoreeng/front:${HULY_VERSION} environment: @@ -206,13 +208,9 @@ services: - GMAIL_URL=https://${SERVER_ADDRESS}:8088 - TELEGRAM_URL=https://${SERVER_ADDRESS}:8086 - UPLOAD_URL=/files - - TRANSACTOR_URL=wss://${SERVER_ADDRESS}:3333 - ELASTIC_URL=http://elastic:9200 - COLLABORATOR_URL=wss://${SERVER_ADDRESS}:3078 - - COLLABORATOR_API_URL=https://${SERVER_ADDRESS}:3078 - - MINIO_ENDPOINT=minio - - MINIO_ACCESS_KEY=minioadmin - - MINIO_SECRET_KEY=minioadmin + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - MONGO_URL=mongodb://mongodb:27017 - TITLE=Huly Self Host - DEFAULT_LANGUAGE=en @@ -223,6 +221,7 @@ services: - traefik-public labels: - "traefik.enable=true" + - "traefik.port=80" - "traefik.http.routers.front.entrypoints=websecure" - "traefik.http.services.front.loadbalancer.server.port=8080" - "traefik.http.routers.front.rule=Host(`${SERVER_ADDRESS}`)" From 73cae8abcef371821984772e48c3f7b700efc7fe Mon Sep 17 00:00:00 2001 From: Tejas <47889755+0xtejas@users.noreply.github.com> Date: Mon, 14 Oct 2024 22:24:22 +0530 Subject: [PATCH 08/19] Fix NOTIFY_INBOX_ONLY value in workspace deployment --- kube/workspace/workspace-deployment.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kube/workspace/workspace-deployment.yaml b/kube/workspace/workspace-deployment.yaml index 6660c40..1ae8ebb 100644 --- a/kube/workspace/workspace-deployment.yaml +++ b/kube/workspace/workspace-deployment.yaml @@ -48,7 +48,7 @@ spec: - name: TRANSACTOR_URL value: ws://transactor:3333;ws://localhost:3333 - name: NOTIFY_INBOX_ONLY - value: true + value: "true" image: hardcoreeng/workspace:latest name: workspace resources: From 6203ebb591229f1793993e040dd8407a48a8816e Mon Sep 17 00:00:00 2001 From: Tejas <47889755+0xtejas@users.noreply.github.com> Date: Mon, 14 Oct 2024 22:34:51 +0530 Subject: [PATCH 09/19] Update elastic-deployment.yaml with namespace, security context, and minor improvements - Added namespace: huly under metadata. - Added curl installation in the container's args. - Set initialDelaySeconds for livenessProbe to 60. --- kube/elastic/elastic-deployment.yaml | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/kube/elastic/elastic-deployment.yaml b/kube/elastic/elastic-deployment.yaml index e98300a..8711575 100644 --- a/kube/elastic/elastic-deployment.yaml +++ b/kube/elastic/elastic-deployment.yaml @@ -4,6 +4,7 @@ metadata: labels: app: elastic name: elastic + namespace: huly spec: replicas: 1 selector: @@ -16,11 +17,17 @@ spec: labels: app: elastic spec: + securityContext: + runAsUser: 1000 + runAsGroup: 1000 + fsGroup: 1000 containers: - args: - /bin/sh - -c - |- + chown -R 1000:1000 /usr/share/elasticsearch/data; + apt-get update && apt-get install -y curl; ./bin/elasticsearch-plugin list | grep -q ingest-attachment || yes | ./bin/elasticsearch-plugin install --silent ingest-attachment; /usr/local/bin/docker-entrypoint.sh eswrapper env: @@ -40,9 +47,12 @@ spec: livenessProbe: exec: command: + - /bin/sh + - -c - curl -s http://localhost:9200/_cluster/health | grep -vq '"status":"red"' - failureThreshold: 10 + initialDelaySeconds: 60 periodSeconds: 20 + failureThreshold: 10 name: elastic ports: - containerPort: 9200 @@ -55,4 +65,4 @@ spec: volumes: - name: elastic persistentVolumeClaim: - claimName: elastic + claimName: elastic \ No newline at end of file From 1b81199f40c600d3582e0e7015deae9f9e450e0a Mon Sep 17 00:00:00 2001 From: Tejas <47889755+0xtejas@users.noreply.github.com> Date: Mon, 14 Oct 2024 22:45:21 +0530 Subject: [PATCH 10/19] Revert "Update elastic-deployment.yaml with namespace, security context, and minor improvements" This reverts commit 6203ebb591229f1793993e040dd8407a48a8816e. --- kube/elastic/elastic-deployment.yaml | 14 ++------------ 1 file changed, 2 insertions(+), 12 deletions(-) diff --git a/kube/elastic/elastic-deployment.yaml b/kube/elastic/elastic-deployment.yaml index 8711575..e98300a 100644 --- a/kube/elastic/elastic-deployment.yaml +++ b/kube/elastic/elastic-deployment.yaml @@ -4,7 +4,6 @@ metadata: labels: app: elastic name: elastic - namespace: huly spec: replicas: 1 selector: @@ -17,17 +16,11 @@ spec: labels: app: elastic spec: - securityContext: - runAsUser: 1000 - runAsGroup: 1000 - fsGroup: 1000 containers: - args: - /bin/sh - -c - |- - chown -R 1000:1000 /usr/share/elasticsearch/data; - apt-get update && apt-get install -y curl; ./bin/elasticsearch-plugin list | grep -q ingest-attachment || yes | ./bin/elasticsearch-plugin install --silent ingest-attachment; /usr/local/bin/docker-entrypoint.sh eswrapper env: @@ -47,12 +40,9 @@ spec: livenessProbe: exec: command: - - /bin/sh - - -c - curl -s http://localhost:9200/_cluster/health | grep -vq '"status":"red"' - initialDelaySeconds: 60 - periodSeconds: 20 failureThreshold: 10 + periodSeconds: 20 name: elastic ports: - containerPort: 9200 @@ -65,4 +55,4 @@ spec: volumes: - name: elastic persistentVolumeClaim: - claimName: elastic \ No newline at end of file + claimName: elastic From aff5d74dd0449947fb320cb000e0b0c402b85651 Mon Sep 17 00:00:00 2001 From: Tejas <47889755+0xtejas@users.noreply.github.com> Date: Mon, 14 Oct 2024 23:00:55 +0530 Subject: [PATCH 11/19] Add MongoDB persistent volume claim configuration --- kube/mongodb/mongodb-persistentvolumeclaim.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) create mode 100644 kube/mongodb/mongodb-persistentvolumeclaim.yml diff --git a/kube/mongodb/mongodb-persistentvolumeclaim.yml b/kube/mongodb/mongodb-persistentvolumeclaim.yml new file mode 100644 index 0000000..8aa617a --- /dev/null +++ b/kube/mongodb/mongodb-persistentvolumeclaim.yml @@ -0,0 +1,10 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: db +spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 100Mi \ No newline at end of file From 75f4b72694053240fbb537f1064b588ab36404e4 Mon Sep 17 00:00:00 2001 From: Alexey Zinoviev Date: Wed, 16 Oct 2024 15:36:28 +0400 Subject: [PATCH 12/19] Update configs for v0.6.325 Signed-off-by: Alexey Zinoviev --- kube/account/account-deployment.yaml | 2 +- kube/transactor/transactor-deployment.yaml | 5 +++++ kube/workspace/workspace-deployment.yaml | 5 +++++ nginx/setup.sh | 2 +- nginx/template-compose.yaml | 4 +++- setup.sh | 2 +- template.compose.yaml | 4 +++- traefik/setup.sh | 2 +- traefik/template-compose.yaml | 4 +++- 9 files changed, 23 insertions(+), 7 deletions(-) diff --git a/kube/account/account-deployment.yaml b/kube/account/account-deployment.yaml index e54d917..d8f43ff 100644 --- a/kube/account/account-deployment.yaml +++ b/kube/account/account-deployment.yaml @@ -45,7 +45,7 @@ spec: key: MINIO_SECRET_KEY - name: MODEL_ENABLED value: '*' - - name: MONGO_URL + - name: DB_URL valueFrom: configMapKeyRef: name: huly-config diff --git a/kube/transactor/transactor-deployment.yaml b/kube/transactor/transactor-deployment.yaml index 98fd109..0651135 100644 --- a/kube/transactor/transactor-deployment.yaml +++ b/kube/transactor/transactor-deployment.yaml @@ -53,6 +53,11 @@ spec: configMapKeyRef: name: huly-config key: MONGO_URL + - name: DB_URL + valueFrom: + configMapKeyRef: + name: huly-config + key: MONGO_URL - name: REKONI_URL value: http://rekoni - name: SERVER_CURSOR_MAXTIMEMS diff --git a/kube/workspace/workspace-deployment.yaml b/kube/workspace/workspace-deployment.yaml index 6660c40..e8d6d48 100644 --- a/kube/workspace/workspace-deployment.yaml +++ b/kube/workspace/workspace-deployment.yaml @@ -35,6 +35,11 @@ spec: key: MINIO_SECRET_KEY - name: MODEL_ENABLED value: '*' + - name: DB_URL + valueFrom: + configMapKeyRef: + name: huly-config + key: MONGO_URL - name: MONGO_URL valueFrom: configMapKeyRef: diff --git a/nginx/setup.sh b/nginx/setup.sh index dd47285..2b641f6 100755 --- a/nginx/setup.sh +++ b/nginx/setup.sh @@ -31,7 +31,7 @@ case "$NGINX_BEHIND_SSL" in esac -export HULY_VERSION="v0.6.313" +export HULY_VERSION="v0.6.325" export NGINX_SERVICE_PORT=$NGINX_SERVICE_PORT export NGINX_HTTP_SCHEME=$NGINX_HTTP_SCHEME export NGINX_WS_SCHEME=$NGINX_WS_SCHEME diff --git a/nginx/template-compose.yaml b/nginx/template-compose.yaml index 7be25ce..e310469 100644 --- a/nginx/template-compose.yaml +++ b/nginx/template-compose.yaml @@ -74,6 +74,7 @@ services: - SERVER_CURSOR_MAXTIMEMS=30000 - ELASTIC_URL=http://elastic:9200 - ELASTIC_INDEX_NAME=huly_storage_index + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - METRICS_CONSOLE=false - METRICS_FILE=metrics.txt @@ -107,7 +108,7 @@ services: environment: - SERVER_PORT=3000 - SERVER_SECRET=${HULY_SECRET} - - MONGO_URL=mongodb://mongodb:27017 + - DB_URL=mongodb://mongodb:27017 - TRANSACTOR_URL=ws://transactor:3333;${NGINX_WS_SCHEME}://${SERVER_ADDRESS}/_transactor - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - FRONT_URL=http://front:8080 @@ -123,6 +124,7 @@ services: image: hardcoreeng/workspace:${HULY_VERSION} environment: - SERVER_SECRET=${HULY_SECRET} + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - TRANSACTOR_URL=ws://transactor:3333;${NGINX_WS_SCHEME}://${SERVER_ADDRESS}/_transactor - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin diff --git a/setup.sh b/setup.sh index 2f32b65..8c72eb4 100755 --- a/setup.sh +++ b/setup.sh @@ -7,4 +7,4 @@ echo "Setting Huly Server Address: $SERVER_ADDRESS" envsubst < template.conf > nginx.conf envsubst < template.env > .env -./use-version.sh v0.6.313 +./use-version.sh v0.6.325 diff --git a/template.compose.yaml b/template.compose.yaml index e14c65a..ca406c6 100644 --- a/template.compose.yaml +++ b/template.compose.yaml @@ -51,7 +51,7 @@ services: environment: - SERVER_PORT=3000 - SERVER_SECRET=${HULY_SECRET} - - MONGO_URL=mongodb://mongodb:27017 + - DB_URL=mongodb://mongodb:27017 - TRANSACTOR_URL=ws://transactor:3333;ws://${SERVER_ADDRESS}:3333 - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - FRONT_URL=http://front:8080 @@ -66,6 +66,7 @@ services: - minio environment: - SERVER_SECRET=${HULY_SECRET} + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - TRANSACTOR_URL=ws://transactor:3333;ws://${SERVER_ADDRESS}:3333 - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin @@ -130,6 +131,7 @@ services: - SERVER_CURSOR_MAXTIMEMS=30000 - ELASTIC_URL=http://elastic:9200 - ELASTIC_INDEX_NAME=huly_storage_index + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - METRICS_CONSOLE=false - METRICS_FILE=metrics.txt diff --git a/traefik/setup.sh b/traefik/setup.sh index db463dd..681c61a 100755 --- a/traefik/setup.sh +++ b/traefik/setup.sh @@ -14,7 +14,7 @@ if [ -z "$LETSENCRYPT_EMAIL" ]; then exit 1 fi -export HULY_VERSION="v0.6.313" +export HULY_VERSION="v0.6.325" export SERVER_ADDRESS=$DOMAIN_NAME export LETSENCRYPT_EMAIL=$LETSENCRYPT_EMAIL diff --git a/traefik/template-compose.yaml b/traefik/template-compose.yaml index 5994e91..c779d60 100644 --- a/traefik/template-compose.yaml +++ b/traefik/template-compose.yaml @@ -116,6 +116,7 @@ services: - SERVER_CURSOR_MAXTIMEMS=30000 - ELASTIC_URL=http://elastic:9200 - ELASTIC_INDEX_NAME=huly_storage_index + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - METRICS_CONSOLE=false - METRICS_FILE=metrics.txt @@ -161,7 +162,7 @@ services: environment: - SERVER_PORT=3000 - SERVER_SECRET=secret - - MONGO_URL=mongodb://mongodb:27017 + - DB_URL=mongodb://mongodb:27017 - TRANSACTOR_URL=ws://transactor:3333;ws://${SERVER_ADDRESS}:3333 - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - FRONT_URL=http://front:8080 @@ -187,6 +188,7 @@ services: image: hardcoreeng/workspace:${HULY_VERSION} environment: - SERVER_SECRET=secret + - DB_URL=mongodb://mongodb:27017 - MONGO_URL=mongodb://mongodb:27017 - TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333 - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin From f24b77eb8555256347c6a163716eaf6899468458 Mon Sep 17 00:00:00 2001 From: Alexander Onnikov Date: Thu, 17 Oct 2024 10:51:32 +0700 Subject: [PATCH 13/19] fix: use wss schema for external transactor url Signed-off-by: Alexander Onnikov --- traefik/template-compose.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/traefik/template-compose.yaml b/traefik/template-compose.yaml index c779d60..a556bb6 100644 --- a/traefik/template-compose.yaml +++ b/traefik/template-compose.yaml @@ -163,7 +163,7 @@ services: - SERVER_PORT=3000 - SERVER_SECRET=secret - DB_URL=mongodb://mongodb:27017 - - TRANSACTOR_URL=ws://transactor:3333;ws://${SERVER_ADDRESS}:3333 + - TRANSACTOR_URL=ws://transactor:3333;wss://${SERVER_ADDRESS}:3333 - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin - FRONT_URL=http://front:8080 - INIT_WORKSPACE=demo-tracker From 06a354f40d505fb3bebb91a0eba2d5e9076ffce1 Mon Sep 17 00:00:00 2001 From: Alexander Onnikov Date: Fri, 18 Oct 2024 11:34:50 +0700 Subject: [PATCH 14/19] readme: add love service configuration example Signed-off-by: Alexander Onnikov --- README.md | 84 ++++++++++++++++++++++++++++++++++++++++++------------- 1 file changed, 64 insertions(+), 20 deletions(-) diff --git a/README.md b/README.md index fd73e76..29eb5ca 100644 --- a/README.md +++ b/README.md @@ -86,31 +86,75 @@ Add these keys into `compose.yaml` in section `services:front:environment`: 2. Add email address you'll use to send notifications into "SOURCE", SES access such as ACCESS_KEY, SECRET_KEY, REGION -``` - ses: - image: hardcoreeng/ses:v0.6.295 - container_name: ses - ports: - - 3335:3335 - environment: - - SOURCE= - - ACCESS_KEY= - - SECRET_KEY= - - REGION= - - PORT=3335 - restart: unless-stopped -``` + ```yaml + ses: + image: hardcoreeng/ses:v0.6.295 + container_name: ses + ports: + - 3335:3335 + environment: + - SOURCE= + - ACCESS_KEY= + - SECRET_KEY= + - REGION= + - PORT=3335 + restart: unless-stopped + ``` -3. Add SES container URL into transactor and account containers +3. Add SES container URL into `transactor` and `account` containers: -`transactor:environment` AND `account:environment`: - -``` -- SES_URL=http://ses:3335 -``` + ```yaml + account: + ... + environment: + - SES_URL=http://ses:3335 + ... + transactor: + ... + environment: + - SES_URL=http://ses:3335 + ... + ``` 4. In `Settings -> Notifications` setup email notifications for events you need to be notified for. It's a user's setting not a company wide, meaning each user has to setup their own notification rules. +## Love Service (Audio & Video calls) + +Huly audio and video calls are created on top of LiveKit insfrastructure. In order to use Love service in your self-hosted Huly, perform the following steps: + +1. Set up [LiveKit Cloud](https://cloud.livekit.io) account +2. Add `love` container to the docker-compose.yaml + + ```yaml + love: + image: hardcoreeng/love:v0.6.295 + container_name: love + ports: + - 8096:8096 + environment: + - STORAGE_CONFIG=minio|minio?accessKey=minioadmin&secretKey=minioadmin + - SECRET=secret + - ACCOUNTS_URL=http://account:3000 + - DB_URL=mongodb://mongodb:27017 + - MONGO_URL=mongodb://mongodb:27017 + - STORAGE_PROVIDER_NAME=minio + - PORT=8096 + - LIVEKIT_HOST= + - LIVEKIT_API_KEY= + - LIVEKIT_API_SECRET= + restart: unless-stopped + ``` + +3. Configure `front` service: + + ```yaml + front: + ... + environment: + - LIVEKIT_WS= + - LOVE_ENDPOINT=http://love:8096 + ... + ``` ## Configure OpenId Connect From 7f567013c6521b9367aebc71a0ff247bd7018f33 Mon Sep 17 00:00:00 2001 From: Tejas <47889755+0xtejas@users.noreply.github.com> Date: Sat, 19 Oct 2024 11:54:29 +0530 Subject: [PATCH 15/19] Update workspace-deployment.yaml to remove unused environment variables --- kube/workspace/workspace-deployment.yaml | 3 --- 1 file changed, 3 deletions(-) diff --git a/kube/workspace/workspace-deployment.yaml b/kube/workspace/workspace-deployment.yaml index 1ae8ebb..6857dd2 100644 --- a/kube/workspace/workspace-deployment.yaml +++ b/kube/workspace/workspace-deployment.yaml @@ -45,9 +45,6 @@ spec: secretKeyRef: name: huly-secret key: SERVER_SECRET - - name: TRANSACTOR_URL - value: ws://transactor:3333;ws://localhost:3333 - - name: NOTIFY_INBOX_ONLY value: "true" image: hardcoreeng/workspace:latest name: workspace From 8d99225c4c220150ccc8800659ea8b35aa84c3d0 Mon Sep 17 00:00:00 2001 From: Tejas <47889755+0xtejas@users.noreply.github.com> Date: Sun, 20 Oct 2024 12:12:15 +0530 Subject: [PATCH 16/19] Remove unused environment variable in workspace-deployment.yaml --- kube/workspace/workspace-deployment.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/kube/workspace/workspace-deployment.yaml b/kube/workspace/workspace-deployment.yaml index 6857dd2..2365f3f 100644 --- a/kube/workspace/workspace-deployment.yaml +++ b/kube/workspace/workspace-deployment.yaml @@ -45,7 +45,6 @@ spec: secretKeyRef: name: huly-secret key: SERVER_SECRET - value: "true" image: hardcoreeng/workspace:latest name: workspace resources: From f3bd7967945e8d29496c16d1f7a3625fa2cf091e Mon Sep 17 00:00:00 2001 From: Alexey Zinoviev Date: Mon, 21 Oct 2024 10:57:11 +0400 Subject: [PATCH 17/19] v333 and disable sign-up instructions --- README.md | 20 ++++++++++++++++++++ nginx/setup.sh | 2 +- setup.sh | 2 +- traefik/setup.sh | 2 +- 4 files changed, 23 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 29eb5ca..175c1c8 100644 --- a/README.md +++ b/README.md @@ -180,3 +180,23 @@ Ensure you have configured or add the following environment variable to the fron Note: Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages. +## Disable Sign-Up + +You can disable public sign-ups for a deployment. When configured, sign-ups will only be permitted through an invite link to a specific workspace. + +To implement this, set the following environment variable for both the front and account services: + +```yaml + account: + ... + environment: + - DISABLE_SIGNUP=true + ... + front: + ... + environment: + - DISABLE_SIGNUP=true + ... +``` + +_Note: When setting up a new deployment, either create the initial account before disabling sign-ups or use the development tool to create the first account._ diff --git a/nginx/setup.sh b/nginx/setup.sh index 2b641f6..33de132 100755 --- a/nginx/setup.sh +++ b/nginx/setup.sh @@ -31,7 +31,7 @@ case "$NGINX_BEHIND_SSL" in esac -export HULY_VERSION="v0.6.325" +export HULY_VERSION="v0.6.333" export NGINX_SERVICE_PORT=$NGINX_SERVICE_PORT export NGINX_HTTP_SCHEME=$NGINX_HTTP_SCHEME export NGINX_WS_SCHEME=$NGINX_WS_SCHEME diff --git a/setup.sh b/setup.sh index 8c72eb4..da7c18c 100755 --- a/setup.sh +++ b/setup.sh @@ -7,4 +7,4 @@ echo "Setting Huly Server Address: $SERVER_ADDRESS" envsubst < template.conf > nginx.conf envsubst < template.env > .env -./use-version.sh v0.6.325 +./use-version.sh v0.6.333 diff --git a/traefik/setup.sh b/traefik/setup.sh index 681c61a..9d2b593 100755 --- a/traefik/setup.sh +++ b/traefik/setup.sh @@ -14,7 +14,7 @@ if [ -z "$LETSENCRYPT_EMAIL" ]; then exit 1 fi -export HULY_VERSION="v0.6.325" +export HULY_VERSION="v0.6.333" export SERVER_ADDRESS=$DOMAIN_NAME export LETSENCRYPT_EMAIL=$LETSENCRYPT_EMAIL From 1de321afd111445aff44ea632131838174eae770 Mon Sep 17 00:00:00 2001 From: Alexey Zinoviev Date: Wed, 23 Oct 2024 10:40:22 +0400 Subject: [PATCH 18/19] Add OIDC redirect uri to docs --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 175c1c8..f8ef48e 100644 --- a/README.md +++ b/README.md @@ -163,6 +163,7 @@ You can configure a Huly instance to authorize users (sign-in/sign-up) using an ### On the IdP side * Create a new OpenID application. + * Use `{huly_account_svc}/auth/openid/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000. * Configure user access to the application as needed. ### On the Huly side From b8d6d37e1f2fcd24da01d52133cbfb39527dbeab Mon Sep 17 00:00:00 2001 From: shanzez <78763240+shanzez@users.noreply.github.com> Date: Fri, 22 Nov 2024 03:47:19 -0500 Subject: [PATCH 19/19] Update for GitHub OAuth (#100) Signed-off-by: shanzez <78763240+shanzez@users.noreply.github.com> --- README.md | 44 +++++++++++++++++++++++++++++++++++++------- 1 file changed, 37 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index f8ef48e..fb6815f 100644 --- a/README.md +++ b/README.md @@ -156,31 +156,61 @@ Huly audio and video calls are created on top of LiveKit insfrastructure. In ord ... ``` -## Configure OpenId Connect +## Configure OpenID Connect (OIDC) You can configure a Huly instance to authorize users (sign-in/sign-up) using an OpenID Connect identity provider (IdP). ### On the IdP side +1. Create a new OpenID application. + * Use `{huly_account_svc}/auth/openid/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000. -* Create a new OpenID application. - * Use `{huly_account_svc}/auth/openid/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000. -* Configure user access to the application as needed. + **URI Example:** + - `http://huly.mydomain.com:3000/auth/openid/callback` + +2. Configure user access to the application as needed. ### On the Huly side - -Specify the following environment variables (provided by the IdP) for the account service: +For the account service, set the following environment variables as provided by the IdP: * OPENID_CLIENT_ID * OPENID_CLIENT_SECRET * OPENID_ISSUER - Ensure you have configured or add the following environment variable to the front service: * ACCOUNTS_URL (This should contain the URL of the account service, accessible from the client side.) +You will need to expose your account service port (e.g. 3000) in your nginx.conf. + Note: Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages. +## Configure GitHub OAuth + +You can also configure a Huly instance to use GitHub OAuth for user authorization (sign-in/sign-up). + +### On the GitHub side +1. Create a new GitHub OAuth application. + * Use `{huly_account_svc}/auth/github/callback` as the sign-in redirect URI. The `huly_account_svc` is the hostname for the account service of the deployment, which should be accessible externally from the client/browser side. In the provided example setup, the account service runs on port 3000. + + **URI Example:** + - `http://huly.mydomain.com:3000/auth/github/callback` + +### On the Huly side +Specify the following environment variables for the account service: + +* `GITHUB_CLIENT_ID` +* `GITHUB_CLIENT_SECRET` + +Ensure you have configured or add the following environment variable to the front service: + +* `ACCOUNTS_URL` (The URL of the account service, accessible from the client side.) + +You will need to expose your account service port (e.g. 3000) in your nginx.conf. + +Notes: +* The `ISSUER` environment variable is not required for GitHub OAuth. +* Once all the required environment variables are configured, you will see an additional button on the sign-in/sign-up pages. + ## Disable Sign-Up You can disable public sign-ups for a deployment. When configured, sign-ups will only be permitted through an invite link to a specific workspace.