mirror of
https://gitlab.opencode.de/bmi/opendesk/deployment/opendesk.git
synced 2025-12-08 00:11:38 +01:00
fix(ci): Add central branding information
This commit is contained in:
@@ -10,7 +10,7 @@ repositories:
|
||||
releases:
|
||||
- name: "jitsi"
|
||||
chart: "jitsi-repo/sovereign-workplace-jitsi"
|
||||
version: "1.2.5"
|
||||
version: "1.3.0"
|
||||
values:
|
||||
- "values-jitsi.gotmpl"
|
||||
condition: "jitsi.enabled"
|
||||
|
||||
@@ -19,6 +19,9 @@ image:
|
||||
settings:
|
||||
jwtAppSecret: "{{ .Values.secrets.jitsi.jwtAppSecret }}"
|
||||
|
||||
theme:
|
||||
{{ .Values.theme | toYaml | nindent 2 }}
|
||||
|
||||
jitsi:
|
||||
publicURL: "https://{{ .Values.global.hosts.jitsi }}.{{ .Values.global.domain }}"
|
||||
web:
|
||||
|
||||
@@ -19,7 +19,7 @@ repositories:
|
||||
releases:
|
||||
- name: "keycloak-theme"
|
||||
chart: "keycloak-theme-repo/sovereign-workplace-theme"
|
||||
version: "1.0.0"
|
||||
version: "1.1.0"
|
||||
values:
|
||||
- "values-theme.gotmpl"
|
||||
condition: "keycloak.enabled"
|
||||
|
||||
@@ -7,4 +7,7 @@ global:
|
||||
domain: "{{ .Values.global.domain }}"
|
||||
hosts:
|
||||
{{ .Values.global.hosts | toYaml | nindent 4 }}
|
||||
|
||||
theme:
|
||||
{{ .Values.theme | toYaml | nindent 2 }}
|
||||
...
|
||||
|
||||
@@ -14,7 +14,7 @@ repositories:
|
||||
releases:
|
||||
- name: "sovereign-workplace-nextcloud-bootstrap"
|
||||
chart: "sovereign-workplace-nextcloud-bootstrap-repo/sovereign-workplace-nextcloud-bootstrap"
|
||||
version: "2.2.0"
|
||||
version: "2.3.0"
|
||||
wait: true
|
||||
waitForJobs: true
|
||||
values:
|
||||
|
||||
@@ -64,4 +64,7 @@ persistence:
|
||||
|
||||
resources:
|
||||
{{ .Values.resources.nextcloud | toYaml | nindent 2 }}
|
||||
|
||||
theme:
|
||||
{{ .Values.theme | toYaml | nindent 2 }}
|
||||
...
|
||||
|
||||
@@ -11,6 +11,9 @@ config:
|
||||
userOidc:
|
||||
username: "ncoidc"
|
||||
|
||||
ldapSearch:
|
||||
host: "univention-corporate-container"
|
||||
|
||||
cleanup:
|
||||
deletePodsOnSuccess: false
|
||||
...
|
||||
|
||||
@@ -30,6 +30,8 @@ releases:
|
||||
values:
|
||||
- "values-openxchange.yaml"
|
||||
- "values-openxchange.gotmpl"
|
||||
- "values-openxchange-enterprise-contact-picker.yaml"
|
||||
- "values-openxchange-enterprise-contact-picker.gotmpl"
|
||||
condition: "oxAppsuite.enabled"
|
||||
- name: "sovereign-workplace-open-xchange-bootstrap"
|
||||
chart: "sovereign-workplace-open-xchange-bootstrap-repo/sovereign-workplace-open-xchange-bootstrap"
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
{{/*
|
||||
SPDX-FileCopyrightText: 2023 Bundesministerium des Innern und für Heimat, PG ZenDiS "Projektgruppe für Aufbau ZenDiS"
|
||||
SPDX-License-Identifier: Apache-2.0
|
||||
*/}}
|
||||
---
|
||||
appsuite:
|
||||
core-mw:
|
||||
secretYAMLFiles:
|
||||
ldap-client-config.yml:
|
||||
contactsLdapClient:
|
||||
auth:
|
||||
adminDN:
|
||||
password: {{ .Values.secrets.univentionCorporateServer.ldapSearch.ox | quote }}
|
||||
...
|
||||
@@ -0,0 +1,349 @@
|
||||
# SPDX-FileCopyrightText: 2023 Bundesministerium des Innern und für Heimat, PG ZenDiS "Projektgruppe für Aufbau ZenDiS"
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
---
|
||||
appsuite:
|
||||
core-mw:
|
||||
|
||||
properties:
|
||||
# Enterprise contact picker
|
||||
com.openexchange.contacts.ldap.accounts: "opendesk"
|
||||
com.openexchange.admin.bypassAccessCombinationChecks: "true"
|
||||
ENABLE_INTERNAL_USER_EDIT: "false"
|
||||
|
||||
# Enterprise contact picker (see also gotmpl)
|
||||
secretYAMLFiles:
|
||||
ldap-client-config.yml:
|
||||
contactsLdapClient:
|
||||
pool:
|
||||
type: "simple"
|
||||
host:
|
||||
address: "univention-corporate-container"
|
||||
port: 389
|
||||
auth:
|
||||
type: "adminDN"
|
||||
adminDN:
|
||||
dn: "uid=ldapsearch_ox,cn=users,dc=swp-ldap,dc=internal"
|
||||
|
||||
uiSettings:
|
||||
# Enterprise contact picker
|
||||
io.ox/core//features/enterprisePicker/enabled: "true"
|
||||
|
||||
yamlFiles:
|
||||
contacts-provider-ldap.yml:
|
||||
# Example definitions of available LDAP contact providers, together with their corresponding configuration,
|
||||
# referenced LDAP client connection settings and attribute mappings.
|
||||
#
|
||||
# This template contains examples and will be overwritten during updates. To use, copy this file to
|
||||
# /opt/open-xchange/etc/contacts-provider-ldap.yml and configure as needed.
|
||||
#
|
||||
# Each configured contacts provider can be enabled for users using the corresponding identifier used in this
|
||||
# .yml file. For this purpose, the config-cascade-enabled setting "com.openexchange.contacts.provider.ldap"
|
||||
# is available.
|
||||
#
|
||||
# Besides the provider configuration in this file, also accompanying LDAP client and contact property mappings
|
||||
# need to be referenced.
|
||||
#
|
||||
# See also https://documentation.open-xchange.com/latest/middleware/contacts/contacts_provider_ldap.html
|
||||
# for further details and a complete list of available configuration options.
|
||||
#
|
||||
|
||||
# Key will be used as identifier for the contact provider
|
||||
opendesk:
|
||||
|
||||
# The display name of this contacts provider.
|
||||
name: "Example Address Lists"
|
||||
|
||||
# Configures the identifier of the LDAP client configuration settings to use, as defined in
|
||||
# 'ldap-client-config.yml'. There, all further connection-related properties to access the LDAP server can
|
||||
# be specified.
|
||||
ldapClientId: "contactsLdapClient"
|
||||
|
||||
# A reference to the contact property <-> LDAP attribute mapping definitions to use, referencing the
|
||||
# corresponding entry in the file 'contact-provider-ldap-mappings.yml'.
|
||||
mappings: "ucs"
|
||||
|
||||
# Specifies if support for querying deleted objects is enabled or not. When enabled, deleted objects are
|
||||
# identified with the filter 'isDeleted=TRUE', which is usually only available in Active Directory (as
|
||||
# control with OID 1.2.840.113556.1.4.417). If disabled, no results are available for folders from this
|
||||
# provider for the 'deleted' API call, and therefore no incremental synchronizations are possible. See also
|
||||
# 'usedForSync' folders property. Defaults to "false".
|
||||
isDeletedSupport: false
|
||||
|
||||
# Specifies the requested maximum size for paged results. "0" disables paged results. This should be
|
||||
# configured, especially when the there are server-side restrictions towards the maximum result size.
|
||||
# Defaults to "500".
|
||||
maxPageSize: 500
|
||||
|
||||
# Optionally enables a local cache that holds certain properties of all of the provider's contacts in
|
||||
# memory to speed up access. Can only be used if no individual authentication is used to access the
|
||||
# LDAP server.
|
||||
cache:
|
||||
useCache: false
|
||||
|
||||
# Definition of addressbook folders of the contacts provider. Different folder modes are possible, each
|
||||
# one with its specific configuration settings. The template contains examples for all possible modes,
|
||||
# however, only the one specified through 'mode' property is actually used.
|
||||
folders:
|
||||
|
||||
# Configures in which mode addressbook folders are provided by the contacts provider. Possible modes
|
||||
# are "fixedAttributes" to have a common search filter per folder that varies by a fixed set of possible
|
||||
# attribute values, "dynamicAttributes" to use a common filter and retrieve all possible values
|
||||
# dynamically, or "static" to have a static search filter associated with each contact folder.
|
||||
# The corresponding mode-specific section needs to be configured as well.
|
||||
mode: "dynamicAttributes"
|
||||
|
||||
# Configures if the addressbook folders can be synchronized to external clients via CardDAV or not.
|
||||
# If set to "false", the folders are only available in the web client. If set to "true", folders can
|
||||
# be activated for synchronization. Should only be enabled if attribute mappings for the 'changing_date'
|
||||
# and 'uid' contact properties are available, and the LDAP server supports the special
|
||||
# "LDAP Show Deleted Control" to query tombstone entries via 'isDeleted=TRUE'. The 'protected' flag
|
||||
# controls whether the default value can be changed by the client or not.
|
||||
usedForSync:
|
||||
protected: true
|
||||
defaultValue: false
|
||||
|
||||
# Defines whether addressbook folders will be available in the contact picker dialog of App Suite.
|
||||
# If enabled, contacts from this provider can be looked up through this dialog, otherwise they are
|
||||
# hidden. The 'protected' flag controls whether the default value can be changed by the client or not.
|
||||
usedInPicker:
|
||||
protected: false
|
||||
defaultValue: true
|
||||
|
||||
# Defines whether addressbook folders will be shown as 'subscribed' folders in the tree or not.
|
||||
# If enabled, the folders will appear in the contacts module of App Suite as regular, subscribed folder.
|
||||
# Otherwise, they're treated as hidden, unsubscribed folders. The 'protected' flag controls whether
|
||||
# the default value can be changed by the client or not.
|
||||
shownInTree:
|
||||
protected: false
|
||||
defaultValue: true
|
||||
|
||||
# In "static" folder mode, a fixed list of folder definitions is used, each one with its own contact
|
||||
# filter and name (the names must be unique). Additionally, a "commonContactFilter" needs to be
|
||||
# defined, which is used for operations that are not bound to
|
||||
# a specific folder, like lookups across all visible folders.
|
||||
# The filter's search scopes relative to the LDAP client's 'baseDN' can be configured as "one"
|
||||
# (only immediate subordinates) or "sub" (base entry itself and any subordinate entries to any depth),
|
||||
# and all default to "sub" unless specified otherwise.
|
||||
static:
|
||||
commonContactFilter: "(|(objectClass=person)(objectClass=groupOfNames))"
|
||||
commonContactSearchScope: "sub"
|
||||
folders:
|
||||
- name: "Cupertino"
|
||||
contactFilter: "(&(|(objectClass=person)(objectClass=groupOfNames))(l=Cupertino))"
|
||||
contactSearchScope: "sub"
|
||||
- name: "San Mateo"
|
||||
contactFilter: "(&(|(objectClass=person)(objectClass=groupOfNames))(l=San Mateo))"
|
||||
contactSearchScope: "sub"
|
||||
- name: "Redwood Shores"
|
||||
contactFilter: "(&(|(objectClass=person)(objectClass=groupOfNames))(l=Redwood Shores))"
|
||||
contactSearchScope: "sub"
|
||||
- name: "Armonk"
|
||||
contactFilter: "(&(|(objectClass=person)(objectClass=groupOfNames))(l=Armonk))"
|
||||
contactSearchScope: "sub"
|
||||
|
||||
# With mode "dynamic attributes", all possible values for one attribute are fetched periodically and
|
||||
# serve as folders. The list of values is fetched by querying all entries that match the
|
||||
# "contactFilterTemplate" (with the wildcard "*" as value) and "contactSearchScope" ("one"/"sub").
|
||||
# Then, the folders are derived based on all distinct attribute values found, with the value as name.
|
||||
# Depending on the configured authentication mode, this is either done per user individually, or globally.
|
||||
# Therefore, per-user authentication is not recommend in this mode.
|
||||
# The "refreshInterval" determines how often the list of attributes is refreshed, and can be defined
|
||||
# using units of measurement:
|
||||
# "D" (=days), "W" (=weeks), "H" (=hours) and "m" (=minutes). Defaults to "1h". The optional "sortOrder"
|
||||
# allows to sort the attributes lexicographically, either "ascending" or "descending".
|
||||
dynamicAttributes:
|
||||
attributeName: "o"
|
||||
contactFilterTemplate: "(&(univentionObjectType=users/user)(o=[value]))"
|
||||
contactSearchScope: "sub"
|
||||
# refreshInterval: 1h
|
||||
refreshInterval: "5m"
|
||||
sortOrder: "ascending"
|
||||
|
||||
# With mode "fixed attributes", all entries matching a filter and having an attribute set to one of the
|
||||
# defined values do form a folder. Works similar to "dynamic attributes", but with a static list of
|
||||
# possible values.
|
||||
# All items defined in the "attributeValues" array are used as folder (with the value as name). When
|
||||
# listing the contents of a specific folder, this folder's specific attribute value is inserted in the
|
||||
# configured "contactFilterTemplate", using the "contactSearchScope" ("one"/"sub").
|
||||
fixedAttributes:
|
||||
contactFilterTemplate: "(&(|(objectClass=person)(objectClass=groupOfNames))(ou=[value]))"
|
||||
contactSearchScope: "sub"
|
||||
attributeValues:
|
||||
- "Janitorial"
|
||||
- "Product Development"
|
||||
- "Management"
|
||||
- "Human Resources"
|
||||
|
||||
contacts-provider-ldap-mappings.yml:
|
||||
# Example definitions of contact property <-> LDAP attribute mappings.
|
||||
#
|
||||
# This template contains examples and will be overwritten during updates. To use, copy this file to
|
||||
# /opt/open-xchange/etc/contacts-provider-ldap-mappings.yml and configure as needed.
|
||||
#
|
||||
# Each configured set of mappings can be used for an LDAP contact provider (as defined through separate
|
||||
# file contacts-provider-ldap.yml), by using the corresponding identifier used in this .yml file.
|
||||
#
|
||||
# Generally, contact properties are set based on an entry's value of the mapped LDAP attribute name.
|
||||
# Empty mappings are ignored. It's possible to define a second LDAP attribute name for a property that is
|
||||
# used as fall-back if the first one is empty in an LDAP result, e.g. to define multiple attributes for a
|
||||
# display name, or to have multiple mappings for contacts and distribution lists.
|
||||
#
|
||||
# For the data-types, each LDAP attribute value is converted/parsed to the type necessary on the server
|
||||
# (Strings, Numbers, Booleans). Dates are assumed to be in UTC and parsed using the pattern 'yyyyMMddHHmmss'.
|
||||
# Binary properties may be indicated by appending ';binary' to the LDAP attribute name. In order to assign
|
||||
# the internal user- and context identifier based on attributes yielding the corresponding
|
||||
# login information (username / contextname), the special appendix ';logininfo' can be used.
|
||||
# Boolean properties may also be set based on a comparison with the LDAP attribute value, which is defined
|
||||
# by the syntax '[LDAP_ATTRIBUTE_NAME]=[EXPECTED_VALUE]', e.g. to set the 'mark_as_distribution_list'
|
||||
# property based on a specific 'objectClass' value.
|
||||
# Alternatively, a Boolean value may also be assigned based on the the existence of any attribute value
|
||||
# using '*'.
|
||||
#
|
||||
# See also https://documentation.open-xchange.com/latest/middleware/contacts/contacts_provider_ldap.html
|
||||
# for further details and a complete list of available configuration options.
|
||||
#
|
||||
|
||||
# Mappings for a typical OpenLDAP server.
|
||||
ucs:
|
||||
# == ID Mappings =======================================================
|
||||
# The object ID is always required and must be unique for the LDAP server. Will use the DN of the entry
|
||||
# unless overridden.
|
||||
# The 'guid' flag can be passed along to properly decode a Microsoft GUID. For 'regular' UUIDs, the
|
||||
# flag 'binary' should be used.
|
||||
objectid: "uidNumber,gidNumber"
|
||||
# The user and context identifiers can be mapped to certain LDAP attributes to aid resolving contact
|
||||
# entries to internal users, e.g. in scenarios where the default global addressbook folder is disabled.
|
||||
# Will only be considered if an entry's context identifier matches the one from the actual session of
|
||||
# the requesting operation.
|
||||
# If used, they should be mapped to attributes that provide the matching rules "integerMatch" for
|
||||
# "EQUALITY" as well as "integerOrderingMatch" for "ORDERING".
|
||||
# Alternatively, if no internal context- or user identifier is available, also attributes yielding
|
||||
# the corresponding login information (username / contextname) can be used by appending ';logininfo'
|
||||
# to the attribute name.
|
||||
internal_userid: "uid;logininfo"
|
||||
contextid: "oxContextIDNum"
|
||||
# The 'guid' flag can be passed along properly decode a Microsoft GUID. For 'regular' UUIDs in binary
|
||||
# format, the flag 'binary' should be used.
|
||||
# uid : entryUUID;binary;logininfo
|
||||
|
||||
# == String Mappings ===================================================
|
||||
displayname: "oxDisplayName,displayName,name"
|
||||
file_as: "oxDisplayName,displayName,name"
|
||||
givenname: "givenName"
|
||||
surname: "sn"
|
||||
email1: "mailPrimaryAddress"
|
||||
department: "oxDepartment,department"
|
||||
company: "oxCompany,o"
|
||||
branches: "oxBranches"
|
||||
# business_category :
|
||||
postal_code_business: "postalCode"
|
||||
state_business: "oxStateBusiness,st"
|
||||
street_business: "streetAddress"
|
||||
# telephone_callback :
|
||||
city_home: "oxCityHome"
|
||||
commercial_register: "oxCommercialRegister"
|
||||
country_home: "oxCountryHome"
|
||||
email2: "oxEmail2"
|
||||
email3: "oxEmail3"
|
||||
employeetype: "employeeType"
|
||||
fax_business: "oxFaxBusiness,facsimileTelehoneNumber"
|
||||
fax_home: "oxFaxHome"
|
||||
fax_other: "oxFaxOther"
|
||||
instant_messenger1: "oxInstantMessenger1"
|
||||
instant_messenger2: "oxInstantMessenger2"
|
||||
telephone_ip: "oxTelephoneIp"
|
||||
telephone_isdn: "internationaliSDNNumber"
|
||||
marital_status: "oxMaritalStatus"
|
||||
cellular_telephone1: "mobile"
|
||||
# cellular_telephone2 :
|
||||
nickname: "oxNickName"
|
||||
number_of_children: "oxNumOfChildren"
|
||||
number_of_employee: "employeeNumber"
|
||||
note: "oxNote,description"
|
||||
telephone_pager: "oxTelephonePager,pager"
|
||||
telephone_assistant: "oxTelephoneAssistant"
|
||||
telephone_business1: "oxTelephoneBusiness1,telephoneNumber"
|
||||
telephone_business2: "oxTelephoneBusiness2"
|
||||
telephone_car: "oxTelephoneCar"
|
||||
telephone_company: "oxTelephoneCompany"
|
||||
telephone_home1: "oxTelephoneHome1,homePhone"
|
||||
telephone_home2: "oxTelephoneHome2"
|
||||
telephone_other: "oxTelephoneOther"
|
||||
postal_code_home: "oxPostalCodeHome"
|
||||
# telephone_radio :
|
||||
room_number: "roomNumber"
|
||||
sales_volume: "oxSalesVolume"
|
||||
city_other: "oxCityOther"
|
||||
country_other: "oxCountryOther"
|
||||
middle_name: "oxMiddleName,middleName"
|
||||
postal_code_other: "oxPostalCodeOther"
|
||||
state_other: "oxStateOther"
|
||||
street_other: "oxStreetOther"
|
||||
spouse_name: "oxSpouseName"
|
||||
state_home: "oxStateHome"
|
||||
street_home: "oxStreetHome"
|
||||
suffix: "oxSuffix"
|
||||
tax_id: "oxTaxId"
|
||||
telephone_telex: "oxTelephoneTelex,telexNumber"
|
||||
telephone_ttytdd: "oxTelephoneTtydd"
|
||||
url: "oxUrl,wWWHome"
|
||||
userfield01: "oxUserfiels01"
|
||||
userfield02: "oxUserfiels02"
|
||||
userfield03: "oxUserfiels03"
|
||||
userfield04: "oxUserfiels04"
|
||||
userfield05: "oxUserfiels05"
|
||||
userfield06: "oxUserfiels06"
|
||||
userfield07: "oxUserfiels07"
|
||||
userfield08: "oxUserfiels08"
|
||||
userfield09: "oxUserfiels09"
|
||||
userfield10: "oxUserfiels10"
|
||||
userfield11: "oxUserfiels11"
|
||||
userfield12: "oxUserfiels12"
|
||||
userfield13: "oxUserfiels13"
|
||||
userfield14: "oxUserfiels14"
|
||||
userfield15: "oxUserfiels15"
|
||||
userfield16: "oxUserfiels16"
|
||||
userfield17: "oxUserfiels17"
|
||||
userfield18: "oxUserfiels18"
|
||||
userfield19: "oxUserfiels19"
|
||||
userfield20: "oxUserfiels20"
|
||||
city_business: "l"
|
||||
country_business: "oxCountryBusiness,country"
|
||||
# telephone_primary :
|
||||
# categories :
|
||||
title: "title"
|
||||
position: "oxPosition"
|
||||
profession: "oxProfession"
|
||||
|
||||
# == Date Mappings =====================================================
|
||||
birthday: "oxBirthday"
|
||||
anniversary: "oxAnniversary"
|
||||
# The last-modified and creation dates are required by the groupware server, therefore an implicit
|
||||
# default date is assumed when no LDAP attribute is mapped here, and no results are available for this
|
||||
# folder for the 'modified' and 'deleted' API calls. Therefore, any synchronization-based usage will
|
||||
# not be available.
|
||||
lastmodified: "modifyTimestamp"
|
||||
creationdate: "createTimestamp"
|
||||
|
||||
# == Misc Mappings =====================================================
|
||||
# Distribution list members are resolved dynamically using the DNs found in the mapped LDAP attribute.
|
||||
# Alternatively, if the attribute value does not denote a DN reference, the value is assumed to be the
|
||||
# plain email address of the member.
|
||||
distributionlist: "memberUid"
|
||||
# Special mapping where the value is evaluated using a string comparison with, or the existence of
|
||||
# the attribute value.
|
||||
markasdistributionlist: "objectClass=posixGroup"
|
||||
# The values for the for assistant- and manager name mappings are either used as-is, or get resolved
|
||||
# dynamically using the DNs found
|
||||
# in the mapped LDAP attribute.
|
||||
assistant_name: "secretary"
|
||||
manager_name: "oxManagerName,manager"
|
||||
# Contact image, binary format is expected.
|
||||
image1: "jpegPhoto"
|
||||
# Special mapping where the value is evaluated using a string comparison with, or the existence of
|
||||
# the attribute value.
|
||||
number_of_images: "jpegPhoto=*"
|
||||
# Will be set internally if not defined.
|
||||
# image_last_modified :
|
||||
# Will be set automatically to "image/jpeg" if not defined.
|
||||
# image1_content_type :
|
||||
@@ -76,6 +76,16 @@ appsuite:
|
||||
uiSettings:
|
||||
"io.ox.nextcloud//server": "https://{{ .Values.global.hosts.intercomService }}.{{ .Values.global.domain }}/fs/"
|
||||
"io.ox.public-sector//ics/url": "https://{{ .Values.global.hosts.intercomService }}.{{ .Values.global.domain }}/"
|
||||
# Dynamic theme
|
||||
io.ox/dynamic-theme//mainColor: "{{ .Values.theme.colors.primary }}"
|
||||
io.ox/dynamic-theme//logoURL: "https://{{ .Values.global.hosts.univentionCorporateServer }}.{{ .Values.global.domain }}/univention/portal/icons/logos/domain.svg"
|
||||
io.ox/dynamic-theme//topbarBackground: "{{ .Values.theme.colors.white }}"
|
||||
io.ox/dynamic-theme//topbarColor: "{{ .Values.theme.colors.black }}"
|
||||
io.ox/dynamic-theme//listSelected: "{{ .Values.theme.colors.primary15 }}"
|
||||
io.ox/dynamic-theme//listHover: "{{ .Values.theme.colors.secondaryGreyLight }}"
|
||||
io.ox/dynamic-theme//folderBackground: "{{ .Values.theme.colors.white }}"
|
||||
io.ox/dynamic-theme//folderSelected: "{{ .Values.theme.colors.primary15 }}"
|
||||
io.ox/dynamic-theme//folderHover: "{{ .Values.theme.colors.secondaryGreyLight }}"
|
||||
secretETCFiles:
|
||||
# Format of the OX Guard master key:
|
||||
# MC+base64(20 random bytes)
|
||||
|
||||
@@ -63,6 +63,8 @@ appsuite:
|
||||
com.openexchange.capability.guard-mail: "true"
|
||||
com.openexchange.capability.public-sector: "true"
|
||||
com.openexchange.capability.smime: "true"
|
||||
com.openexchange.capability.share_links: "false"
|
||||
com.openexchange.capability.invite_guests: "false"
|
||||
# Secondary Accounts
|
||||
com.openexchange.mail.secondary.authType: "XOAUTH2"
|
||||
com.openexchange.mail.transport.secondary.authType: "xoauth2"
|
||||
@@ -93,6 +95,8 @@ appsuite:
|
||||
bindDN: "uid=ldapsearch_ox,cn=users,dc=swp-ldap,dc=internal"
|
||||
|
||||
uiSettings:
|
||||
io.ox/dynamic-theme//logoWidth: "82"
|
||||
io.ox/dynamic-theme//topbarHover: "rgba(0, 0, 0, 0.1)"
|
||||
# Resources
|
||||
io.ox/core//features/resourceCalendars: "true"
|
||||
io.ox/core//features/managedResources: "true"
|
||||
@@ -107,18 +111,6 @@ appsuite:
|
||||
# io.ox.public-sector//ics/url: "https://ics.<DOMAIN>/"
|
||||
io.ox/core//apps/quickLaunchCount: "0"
|
||||
io.ox/core//coloredIcons: "false"
|
||||
# Dynamic theme
|
||||
io.ox/dynamic-theme//mainColor: "#004B76"
|
||||
io.ox/dynamic-theme//logoURL: "io.ox.public-sector/logo.svg"
|
||||
io.ox/dynamic-theme//logoWidth: "80"
|
||||
io.ox/dynamic-theme//topbarBackground: "#fff"
|
||||
io.ox/dynamic-theme//topbarColor: "#1f1f1f"
|
||||
io.ox/dynamic-theme//topbarHover: "rgba(0, 0, 0, 0.1)"
|
||||
io.ox/dynamic-theme//listSelected: "#ADC8F0"
|
||||
io.ox/dynamic-theme//listHover: "#ddd"
|
||||
io.ox/dynamic-theme//folderBackground: "#fff"
|
||||
io.ox/dynamic-theme//folderSelected: "#ADC8F0"
|
||||
io.ox/dynamic-theme//folderHover: "#ddd"
|
||||
|
||||
asConfig:
|
||||
default:
|
||||
|
||||
@@ -59,6 +59,8 @@ environment:
|
||||
OPENPROJECT_SMTP__PORT: "587" # (default=587)
|
||||
OPENPROJECT_SMTP__SSL: "false" # (default=false)
|
||||
OPENPROJECT_SMTP__ADDRESS: "{{ .Values.smtp.host }}"
|
||||
# Details: https://www.openproject-edge.com/docs/installation-and-operations/configuration/#seeding-ldap-connections
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_BINDPASSWORD: "{{ .Values.secrets.univentionCorporateServer.ldapSearch.openproject }}"
|
||||
|
||||
persistence:
|
||||
size: "{{ .Values.persistence.size.openproject }}"
|
||||
@@ -68,4 +70,5 @@ replicaCount: {{ .Values.replicas.openproject }}
|
||||
|
||||
resources:
|
||||
{{ .Values.resources.openproject | toYaml | nindent 2 }}
|
||||
|
||||
...
|
||||
|
||||
@@ -40,5 +40,22 @@ environment:
|
||||
OPENPROJECT_SMTP__AUTHENTICATION: "plain"
|
||||
OPENPROJECT_SMTP__ENABLE__STARTTLS__AUTO: "true"
|
||||
OPENPROJECT_SMTP__OPENSSL__VERIFY__MODE: "peer"
|
||||
# Details: https://www.openproject-edge.com/docs/installation-and-operations/configuration/#seeding-ldap-connections
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_HOST: "univention-corporate-container"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_PORT: "389"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_SECURITY: "plain_ldap"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_BINDUSER: "uid=ldapsearch_openproject,cn=users,dc=swp-ldap,dc=internal"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_BASEDN: "dc=swp-ldap,dc=internal"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_FILTER: "(&(objectClass=opendeskProjectmanagementUser)(opendeskProjectmanagementEnabled=TRUE))"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_SYNC__USERS: "true"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_LOGIN__MAPPING: "uid"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_FIRSTNAME__MAPPING: "givenName"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_LASTNAME__MAPPING: "sn"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_MAIL__MAPPING: "mailPrimaryAddress"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_ADMIN__MAPPING: "opendeskProjectmanagementAdmin"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_GROUPFILTER_OPENDESK_BASE: "dc=swp-ldap,dc=internal"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_GROUPFILTER_OPENDESK_FILTER: "(&(objectClass=opendeskProjectmanagementGroup)(opendeskProjectmanagementEnabled=TRUE))"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_GROUPFILTER_OPENDESK_SYNC__USERS: "true"
|
||||
OPENPROJECT_SEED_LDAP_OPENDESK_GROUPFILTER_OPENDESK_GROUP__ATTRIBUTE: "cn"
|
||||
|
||||
...
|
||||
|
||||
@@ -41,7 +41,7 @@ releases:
|
||||
condition: "certificates.enabled"
|
||||
- name: "redis"
|
||||
chart: "bitnami-repo/redis"
|
||||
version: "^17.9.3"
|
||||
version: "17.9.3"
|
||||
values:
|
||||
- "values-redis.gotmpl"
|
||||
- "values-redis.yaml"
|
||||
|
||||
@@ -12,6 +12,8 @@ image:
|
||||
repository: "{{ .Values.images.mariadb.repository }}"
|
||||
tag: "{{ .Values.images.mariadb.tag }}"
|
||||
|
||||
# Open-Xchange and XWiki require the permission to create database schemas, so they use the `root` account anyway.
|
||||
# Please refer to `databases.yaml` for details.
|
||||
job:
|
||||
users:
|
||||
- username: "xwiki_user"
|
||||
|
||||
@@ -10,7 +10,7 @@ repositories:
|
||||
releases:
|
||||
- name: "xwiki"
|
||||
chart: "xwiki-repo/xwiki"
|
||||
version: "1.1.1"
|
||||
version: "1.1.2"
|
||||
wait: true
|
||||
timeout: 600
|
||||
values:
|
||||
|
||||
@@ -8,14 +8,23 @@ image:
|
||||
tag: "{{ .Values.images.xwiki.tag }}"
|
||||
|
||||
externalDB:
|
||||
password: "{{ .Values.databases.xwiki.password | default .Values.secrets.mariadb.xwikiUser }}"
|
||||
password: "{{ .Values.databases.xwiki.password | default .Values.secrets.mariadb.rootPassword }}"
|
||||
database: "{{ .Values.databases.xwiki.name }}"
|
||||
user: "{{ .Values.databases.xwiki.username }}"
|
||||
host: "{{ .Values.databases.xwiki.host }}"
|
||||
|
||||
customConfigs:
|
||||
"xwiki.cfg":
|
||||
"xwiki.superadminpassword": {{ .Values.secrets.xwiki.superadminpassword | quote }}
|
||||
"xwiki.superadminpassword": "{{ .Values.secrets.xwiki.superadminpassword }}"
|
||||
## LDAP Server configuration
|
||||
# "xwiki.authentication.ldap.server": "univention-corporate-container"
|
||||
# xwiki.authentication.ldap.port: 389
|
||||
## Authentication to the LDAP server
|
||||
# xwiki.authentication.ldap.bind_DN: "uid=ldapsearch_xwiki,cn=users,dc=swp-ldap,dc=internal"
|
||||
# xwiki.authentication.ldap.bind_pass: "{{ .Values.secrets.univentionCorporateServer.ldapSearch.xwiki }}"
|
||||
## Base DN used for searching for users
|
||||
# xwiki.authentication.ldap.base_DN: "dc=swp-ldap,dc=internal"
|
||||
|
||||
"xwiki.properties":
|
||||
"oidc.endpoint.authorization": "https://{{ .Values.global.hosts.keycloak }}.{{ .Values.global.domain }}/realms/souvap/protocol/openid-connect/auth"
|
||||
"oidc.endpoint.token": "https://{{ .Values.global.hosts.keycloak }}.{{ .Values.global.domain }}/realms/souvap/protocol/openid-connect/token"
|
||||
@@ -25,10 +34,16 @@ customConfigs:
|
||||
"url.trustedDomains": "{{ .Values.global.hosts.keycloak }}.{{ .Values.global.domain }}"
|
||||
"workplaceServices.navigationEndpoint": "https://{{ .Values.global.hosts.univentionCorporateServer }}.{{ .Values.global.domain }}/univention/portal/navigation.json"
|
||||
"workplaceServices.base": "https://{{ .Values.global.hosts.univentionCorporateServer }}.{{ .Values.global.domain }}"
|
||||
"workplaceServices.portalSecret": {{ .Values.secrets.centralnavigation.apiKey }}
|
||||
"workplaceServices.portalSecret": "{{ .Values.secrets.centralnavigation.apiKey }}"
|
||||
|
||||
properties:
|
||||
"attachment:xwiki:FlamingoThemes.Iceberg@logo.svg": "https://{{ .Values.global.hosts.univentionCorporateServer }}.{{ .Values.global.domain }}/univention/portal/icons/logos/domain.svg"
|
||||
"attachment:xwiki:FlamingoThemes.Iceberg@logo.svg": "data:image/svg+xml;base64,{{ .Values.theme.imagery.logoHeaderSvg | b64enc }}"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.brand-primary": "{{ .Values.theme.colors.primary }}"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.navbar-default-bg": "{{ .Values.theme.colors.white }}"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.navbar-default-link-hover-bg": "{{ .Values.theme.colors.secondaryGreyLight }}"
|
||||
## Link LDAP users and users authenticated through OIDC
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.addOIDCObject": 1
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.OIDCIssuer": "https://{{ .Values.global.hosts.keycloak }}.{{ .Values.global.domain }}/realms/souvap"
|
||||
|
||||
ingress:
|
||||
enabled: {{ .Values.ingress.enabled }}
|
||||
|
||||
@@ -33,8 +33,8 @@ mariadb:
|
||||
properties:
|
||||
"property:xwiki:XWiki.XWikiPreferences^XWiki.XWikiPreferences.colorTheme": "FlamingoThemes.Iceberg"
|
||||
"property:xwiki:XWiki.XWikiPreferences^XWiki.XWikiPreferences.default_language": "de"
|
||||
"property:xwiki:XWiki.XWikiPreferences^XWiki.XWikiPreferences.timezone": "Europe/Berlin"
|
||||
"property:xwiki:XWiki.XWikiPreferences^XWiki.XWikiPreferences.languages": "de"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.brand-primary": "#004B76"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.link-color": "@brand-primary"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.btn-primary-bg": "@brand-primary"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.navbar-default-color": "@brand-primary"
|
||||
@@ -43,15 +43,38 @@ properties:
|
||||
"@brand-primary"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.navbar-default-link-active-color":
|
||||
"@brand-primary"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.navbar-default-bg": "#fff"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.navbar-default-link-hover-bg": "#fff"
|
||||
# yamllint disable-line rule:line-length
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.lessCode": "'@list-group-active-border: @list-group-border; @gray-light: #727272; @text-muted: @gray; @xwiki-drawer-menu-item-hover-bg: @list-group-hover-bg; @xwiki-drawer-menu-item-hover-color: @list-group-link-hover-color; @well-bg: @body-bg; .navbar-default { border-bottom: 3px solid @brand-primary !important; } #menuview .navbar-brand img { padding: 5px; }'"
|
||||
"property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.lessCode": "'.navbar-default { background-color: white; border-bottom: 1px solid grey; height: 64px; } #menuview .navbar-brand img { padding: 5px; } div#companylogo { width: 96px; height: auto; padding-top: 6px; padding-left: 5px; } li#tmWorkplaceServices { padding-left: 16px; padding-top: 5px; } .navbar-right { padding-top: 8px; } button { background-color: #ffffff; } .drawer-nav, .drawer-brand { background-color: #ffffff; } #footerglobal { background-color: #ffffff; }'"
|
||||
# "property:xwiki:FlamingoThemes.Iceberg^FlamingoThemesCode.ThemeClass.lessCode": "'@list-group-active-border: @list-group-border; @gray-light: #727272; @text-muted: @gray; @xwiki-drawer-menu-item-hover-bg: @list-group-hover-bg; @xwiki-drawer-menu-item-hover-color: @list-group-link-hover-color; @well-bg: @body-bg; .navbar-default { background-color: #ffffff; border-bottom: 1px solid #dddddd !important; height: 64px; } #menuview .navbar-brand img { padding: 5px; } div#companylogo { width: 96px; height: auto; padding-top: 6px; padding-left: 5px; } li#tmWorkplaceServices { padding-left: 16px; padding-top: 5px; } .navbar-right { padding-top: 8px; } #globalsearch .btn { background-color: #ffffff; color: @brand-primary; }'"
|
||||
|
||||
"property:xwiki:XWiki.AuthService.Configuration^XWiki.AuthService.ConfigurationClass.authService": "oidc"
|
||||
## Fields to search in when importing users from the administration UI (not completely in scope for now)
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.ldapUserAttributes":
|
||||
# "sn,givenname,uid"
|
||||
## Restrict user import in the UI to global administrators
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.usersAllowedToImport": "globalAdmin"
|
||||
## Enable group and user synchronization
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.triggerGroupsUpdate": 1
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.triggerGroupImport": 1
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.forceXWikiUsersGroupMembershipUpdate":
|
||||
# 1
|
||||
## Base DN under which groups should be searched for
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.ldapGroupImportSearchDN":
|
||||
# "dc=swp-ldap,dc=internal"
|
||||
## LDAP filter to only synchronize some groups
|
||||
# "property:xwiki:LDAPUserImport.WebHome^LDAPUserImport.LDAPUserImportConfigClass.ldapGroupImportSearchFilter":
|
||||
# "(&(objectClass=opendeskKnowledgemanagementGroup)(opendeskKnowledgemanagementEnabled=TRUE))"
|
||||
|
||||
customConfigs:
|
||||
xwiki.cfg:
|
||||
xwiki.url.protocol: "https"
|
||||
## Indicate the LDAP field defining the user UID
|
||||
# xwiki.authentication.ldap.UID_attr: "uid"
|
||||
## Indicate the LDAP field defining the user profile picture
|
||||
# xwiki.authentication.ldap.photo_attribute: "jpegPhoto"
|
||||
## Enable the synchronization of the LDAP profile picture
|
||||
# xwiki.authentication.ldap.update_photo: 1
|
||||
|
||||
xwiki.properties:
|
||||
oidc.scope: "openid,profile,email,address,phoenix"
|
||||
oidc.endpoint.userinfo.method: "GET"
|
||||
|
||||
Reference in New Issue
Block a user