Compare commits

..

13 Commits

17 changed files with 203 additions and 72 deletions

View File

@@ -3,7 +3,7 @@ Description=Gitea Container
[Container] [Container]
ContainerName=gitea ContainerName=gitea
Image=docker.io/gitea/gitea:latest Image=ghcr.io/go-gitea/gitea:latest
# Enable auto-update container # Enable auto-update container
AutoUpdate=registry AutoUpdate=registry

View File

@@ -4,7 +4,7 @@ Description=Headscale Container
[Container] [Container]
Network=host Network=host
ContainerName=headscale ContainerName=headscale
Image=docker.io/headscale/headscale:latest Image=ghcr.io/juanfont/headscale:latest
Exec=serve Exec=serve
# Enable auto-update container # Enable auto-update container

View File

@@ -12,6 +12,7 @@ AutoUpdate=registry
Volume=%h/podman/homeassistant/config:/config Volume=%h/podman/homeassistant/config:/config
Volume=/etc/localtime:/etc/localtime:ro Volume=/etc/localtime:/etc/localtime:ro
Volume=/run/dbus:/run/dbus:ro Volume=/run/dbus:/run/dbus:ro
Volume=/tmp/unbound_stats:/tmp/unbound_stats
[Service] [Service]
Restart=always Restart=always

View File

@@ -4,5 +4,3 @@ Description=HomeAssistant Pod
[Pod] [Pod]
PodName=homeassistant PodName=homeassistant
Network=host Network=host
UserNS=keep-id

View File

@@ -6,7 +6,3 @@ PodName=immich
#PublishPort=2283:2283 #PublishPort=2283:2283
Network=host Network=host
Volume=%h/podman/immich/.socket:/tmp/immich Volume=%h/podman/immich/.socket:/tmp/immich
# to satisfy immich bitch permissions problems
UIDMap=1000:0:1
UIDMap=0:1:1000

View File

@@ -5,12 +5,13 @@ Description=Immich Valkey Container
Pod=immich.pod Pod=immich.pod
ContainerName=immich_valkey ContainerName=immich_valkey
Image=ghcr.io/valkey-io/valkey:alpine Image=ghcr.io/valkey-io/valkey:alpine
Exec=--port 0 --unixsocket /tmp/immich/valkey.sock --unixsocketperm 777 Exec=--port 0 --unixsocket ${REDIS_SOCKET} --unixsocketperm 777
# Enable auto-update container # Enable auto-update container
AutoUpdate=registry AutoUpdate=registry
[Service] [Service]
EnvironmentFile=%h/.config/containers/systemd/immich/.env
Restart=always Restart=always
TimeoutStartSec=300 TimeoutStartSec=300

View File

@@ -6,7 +6,7 @@ After=synapse_db.service
[Container] [Container]
Pod=matrix.pod Pod=matrix.pod
ContainerName=synapse ContainerName=synapse
Image=docker.io/matrixdotorg/synapse:latest Image=ghcr.io/element-hq/synapse:latest
# Enable auto-update container # Enable auto-update container
AutoUpdate=registry AutoUpdate=registry

View File

@@ -1,8 +1,37 @@
# db
MARIADB_ROOT_PASSWORD= MARIADB_ROOT_PASSWORD=
MARIADB_PASSWORD= MARIADB_PASSWORD=
MARIADB_DATABASE=nextcloud MARIADB_DATABASE=nextcloud
MARIADB_USER=nextcloud MARIADB_USER=nextcloud
TZ=Asia/Kolkata MARIADB_HOST=/tmp/docker/mysqld.sock
EXTERNAL_DIR=/media/vault/nextcloud
# redis
REDIS_HOST=/tmp/docker/valkey.sock
REDIS_HOST_PORT=0
# Misc
TZ=Etc/UTC
# Directories
EXTERNAL_DIR=
# notify push
SOCKET_PATH=/tmp/docker/notify_push.sock SOCKET_PATH=/tmp/docker/notify_push.sock
NEXTCLOUD_URL=https://cloud.example.com
# reverse proxy
OVERWRITEPROTOCOL=https
OVERWRITECLIURL=https://cloud.example.com
TRUSTED_PROXIES=127.0.0.1 ::1
# SMTP
SMTP_HOST=smtp.example.com
SMTP_SECURE=ssl
SMTP_NAME=
SMTP_PASSWORD=
MAIL_FROM_ADDRESS=
MAIL_DOMAIN=
# PHP Optimizations
PHP_MEMORY_LIMIT=2G
PHP_UPLOAD_LIMIT=100G
PHP_OPCACHE_MEMORY_CONSUMPTION=256

View File

@@ -0,0 +1,54 @@
#!/bin/sh
set -eu
####################
# My Special Sauce #
####################
#################################################################
# This script is to make the www-data in /entrypoint.sh to #
# any user specified by $PUID environment variable, #
# so that your nextcloud can run or update properly. #
#################################################################
# fix nextcloud not setting Local Time zone
apk add --no-cache tzdata
# default to UID=1000 if not set
TARGET_UID="${PUID:-1000}"
# add user as the su in image doesn't know user ID we will pass
adduser -D -u "${TARGET_UID}" "abc" || true
# Overwrite /usr/local/etc/php-fpm.d/zz-docker.conf to make php-fpm listen on unix socket
cat <<EOF >/usr/local/etc/php-fpm.d/zz-docker.conf
; Generated by /nextcloud-entrypoint.sh
; DO NOT EDIT THIS FILE, IT WILL BE OVERWRITTEN !!
; please make changes in the /nextcloud-entrypoint.sh script
[global]
daemonize = no
[www]
access.log = /tmp/fpm-access.log
listen = ${NEXTCLOUD_FPM_SOCK:-/tmp/docker/nextcloud-fpm.sock}
listen.owner = ${TARGET_UID}
listen.group = ${TARGET_UID}
; Restricting socket to owner and group only
listen.mode = 0660
user = ${TARGET_UID}
group = ${TARGET_UID}
pm.max_children = 50
pm.start_servers = 10
pm.min_spare_servers = 5
pm.max_spare_servers = 15
pm.max_requests = 1000
EOF
# replace "www-data" with numeric $PUID in /entrypoint.sh
sed -i "s/www-data/abc/g" /entrypoint.sh
# execute the patched entrypoint with all args
exec /entrypoint.sh php-fpm

View File

@@ -1,36 +1,58 @@
#!/bin/sh #!/bin/sh
NC_PATH="/var/www/html" # env exports
CONFIG="$NC_PATH/config/config.php" export NEXTCLOUD_URL="${NEXTCLOUD_URL:-$OVERWRITECLIURL}"
NOTIFY_BIN="$NC_PATH/apps/notify_push/bin/x86_64/notify_push" export REDIS_URL="redis+unix://${REDIS_HOST}"
SOCKET_PATH="${SOCKET_PATH:-/tmp/docker/notify_push.sock}" export DATABASE_URL="mysql://${MARIADB_USER}:${MARIADB_PASSWORD}@localhost/${MARIADB_DATABASE}?socket=${MARIADB_HOST}"
export DATABASE_PREFIX="oc_"
# Clean shutdown handler # Clean shutdown handler
cleanup() { cleanup() {
echo "[*] Stopping notify_push..." echo "[*] Stopping notify_push..."
kill -TERM "$NOTIFY_PID" 2>/dev/null && echo "[*] notify push stopped.." || echo "Unable to Kill Notify Push.." kill -TERM "$NOTIFY_PID" 2>/dev/null && echo "[] notify push stopped.." || echo "Unable to Kill Notify Push.."
echo "[*] Bye" echo "[] Bye..."
} }
trap 'cleanup' TERM INT trap 'cleanup' TERM INT
echo "[*] Checking Nextcloud Host Presence..."
while ! curl -s --fail --max-time 15 "$NEXTCLOUD_URL/status.php" >/dev/null; do
echo "[*] Waiting for Nextcloud to start..."
sleep 5
done
echo "[✓] Nextcloud Host is UP and Serving."
echo "[*] Ensuring notify_push app is installed and enabled..." echo "[*] Ensuring notify_push app is installed and enabled..."
php occ app:install notify_push || true php occ app:install notify_push || true
php occ app:enable notify_push || true php occ app:enable notify_push || true
echo "[*] Starting notify_push binary..." echo "[*] Starting notify_push binary..."
"$NOTIFY_BIN" "$CONFIG" & /var/www/html/custom_apps/notify_push/bin/x86_64/notify_push &
NOTIFY_PID=$! NOTIFY_PID=$!
# Wait for the socket to appear, max 30 seconds # Posix compliance check to ensure notify_push is running
i=0 if kill -0 "$PID" 2>/dev/null; then
while [ $i -lt 6 ]; do echo "[✓] Notify Push is UP and running."
else
echo "[X] Notify Push is not Running!! Exiting.."
exit 1
fi
# Wait for the socket to active and respond, max 30 seconds
i=1
while [ $i -le 6 ]; do
if [ -S "$SOCKET_PATH" ]; then
echo "[*] Socket file exists, testing HTTP response..."
if curl -s --max-time 5 --unix-socket "$SOCKET_PATH" http://localhost/ -o /dev/null; then
echo "[*] Running occ notify_push:setup"
php occ notify_push:setup "${NEXTCLOUD_URL}/push" || true
break
else
echo "[!] Socket exists, but no HTTP response yet"
fi
fi
echo "[*] Waiting 5 seconds for notify_push to be ready... (try $i/6)" echo "[*] Waiting 5 seconds for notify_push to be ready... (try $i/6)"
sleep 5 sleep 5
if [ -S "$SOCKET_PATH" ]; then
echo "[*] Socket found, running occ notify_push:setup"
php occ notify_push:setup "${NEXTCLOUD_URL}/push" || true
break
fi
: $((i += 1)) : $((i += 1))
done done

View File

@@ -3,38 +3,28 @@ Description=Nextcloud Container
Requires=nextcloud_db.service nextcloud_valkey.service Requires=nextcloud_db.service nextcloud_valkey.service
After=nextcloud_db.service nextcloud_valkey.service After=nextcloud_db.service nextcloud_valkey.service
AssertPathIsDirectory=%h/podman/nextcloud
AssertPathIsDirectory=%h/podman/nextcloud/html
AssertPathIsDirectory=%h/nextcloud
[Container] [Container]
Pod=nextcloud.pod Pod=nextcloud.pod
ContainerName=nextcloud ContainerName=nextcloud
Image=docker.io/library/nextcloud:fpm-alpine Image=docker.io/library/nextcloud:fpm-alpine
Entrypoint=/nextcloud-entrypoint.sh
# Enable auto-update container # Enable auto-update container
AutoUpdate=registry AutoUpdate=registry
Environment=TZ=${TZ} # DB credentials (only required when setting up first time)
# Redis Credentials
Environment=REDIS_HOST=/tmp/docker/valkey.sock
# DB credentials
Environment=MYSQL_PASSWORD=${MARIADB_PASSWORD} Environment=MYSQL_PASSWORD=${MARIADB_PASSWORD}
Environment=MYSQL_DATABASE=${MARIADB_DATABASE} Environment=MYSQL_DATABASE=${MARIADB_DATABASE}
Environment=MYSQL_USER=${MARIADB_USER} Environment=MYSQL_USER=${MARIADB_USER}
Environment=MYSQL_HOST=localhost:/tmp/docker/mysqld.sock Environment=MYSQL_HOST=localhost:${MARIADB_HOST}
# PHP Optimizations # env file
Environment=PHP_MEMORY_LIMIT=2G EnvironmentFile=./.env
Environment=PHP_UPLOAD_LIMIT=100G
Environment=PHP_OPCACHE_MEMORY_CONSUMPTION=256
Volume=%h/podman/nextcloud/html:/var/www/html Volume=%h/podman/nextcloud/html:/var/www/html
Volume=%h/nextcloud:/var/www/html/data Volume=%h/nextcloud:/var/www/html/data
Volume=./zz-docker.conf:/usr/local/etc/php-fpm.d/zz-docker.conf
Volume=${EXTERNAL_DIR}:${EXTERNAL_DIR} Volume=${EXTERNAL_DIR}:${EXTERNAL_DIR}
Volume=./nextcloud-entrypoint.sh:/nextcloud-entrypoint.sh
[Service] [Service]
# pass this to autofill above variables # pass this to autofill above variables

View File

@@ -5,12 +5,19 @@ Description=Nextcloud DB Container
Pod=nextcloud.pod Pod=nextcloud.pod
ContainerName=nextcloud_db ContainerName=nextcloud_db
Image=docker.io/library/mariadb:lts Image=docker.io/library/mariadb:lts
Exec='--transaction-isolation=READ-COMMITTED' '--log-bin=binlog' '--binlog-format=ROW' '--socket=/tmp/docker/mysqld.sock' '--skip-networking' Exec=--transaction-isolation=READ-COMMITTED --log-bin=binlog --binlog-format=ROW --socket=${MARIADB_HOST} --skip-networking
# Enable auto-update container # Enable auto-update container
AutoUpdate=registry AutoUpdate=registry
# pass this to attach it to container
EnvironmentFile=./.env # Timezone
Environment=TZ=${TZ}
# DB credentials
Environment=MARIADB_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD}
Environment=MARIADB_PASSWORD=${MARIADB_PASSWORD}
Environment=MARIADB_DATABASE=${MARIADB_DATABASE}
Environment=MARIADB_USER=${MARIADB_USER}
Volume=%h/podman/nextcloud/db:/var/lib/mysql Volume=%h/podman/nextcloud/db:/var/lib/mysql

View File

@@ -14,11 +14,24 @@ Group=1000
# Enable auto-update container # Enable auto-update container
AutoUpdate=registry AutoUpdate=registry
# Timezone
Environment=TZ=${TZ} Environment=TZ=${TZ}
# Nextcloud Notify Push socket # Nextcloud variables
Environment=SOCKET_PATH=${SOCKET_PATH} Environment=SOCKET_PATH=${SOCKET_PATH}
Environment=NEXTCLOUD_URL=${NEXTCLOUD_URL} Environment=OVERWRITECLIURL=${OVERWRITECLIURL}
Environment=OVERWRITEPROTOCOL=${OVERWRITEPROTOCOL}
Environment=TRUSTED_PROXIES=${TRUSTED_PROXIES}
# DB credentials
Environment=MARIADB_PASSWORD=${MARIADB_PASSWORD}
Environment=MARIADB_DATABASE=${MARIADB_DATABASE}
Environment=MARIADB_USER=${MARIADB_USER}
Environment=MARIADB_HOST=${MARIADB_HOST}
# Redis
Environment=REDIS_HOST=${REDIS_HOST}
Environment=REDIS_HOST_PORT=${REDIS_HOST_PORT}
Volume=%h/podman/nextcloud/html:/var/www/html Volume=%h/podman/nextcloud/html:/var/www/html
Volume=./nextcloud-notify-push-entrypoint.sh:/nextcloud-notify-push-entrypoint.sh Volume=./nextcloud-notify-push-entrypoint.sh:/nextcloud-notify-push-entrypoint.sh

View File

@@ -5,12 +5,13 @@ Description=Nextcloud Valkey Container
Pod=nextcloud.pod Pod=nextcloud.pod
ContainerName=nextcloud_valkey ContainerName=nextcloud_valkey
Image=ghcr.io/valkey-io/valkey:alpine Image=ghcr.io/valkey-io/valkey:alpine
Exec=--port 0 --unixsocket /tmp/docker/valkey.sock --unixsocketperm 777 Exec=--port 0 --unixsocket ${REDIS_HOST} --unixsocketperm 777
# Enable auto-update container # Enable auto-update container
AutoUpdate=registry AutoUpdate=registry
# pass this to attach it to container
EnvironmentFile=./.env # Timezone
Environment=TZ=${TZ}
Volume=%h/podman/nextcloud/valkey:/data Volume=%h/podman/nextcloud/valkey:/data

View File

@@ -1,20 +0,0 @@
[global]
daemonize = no
[www]
access.log = /tmp/fpm-access.log
listen = /tmp/docker/nextcloud-fpm.sock
listen.owner = 1000
listen.group = 1000
listen.mode = 0777
user = 1000
group = 1000
pm.max_children = 50
pm.start_servers = 10
pm.min_spare_servers = 5
pm.max_spare_servers = 15
pm.max_requests = 1000

17
vaultwarden/env.example Normal file
View File

@@ -0,0 +1,17 @@
# base config
DOMAIN=https://vw.example.com
SIGNUPS_ALLOWED=false
INVITATIONS_ALLOWED=false
# smtp config
SMTP_HOST=smtp.example.com
SMTP_FROM=mail@example.com
SMTP_FROM_NAME=Vaultwarden
SMTP_USERNAME=username
SMTP_PASSWORD=
SMTP_TIMEOUT=15
SMTP_SECURITY=force_tls
SMTP_PORT=465
# rocket http configuration
ROCKET_PORT=7777

View File

@@ -0,0 +1,22 @@
[Unit]
Description=VaultWarden Container
[Container]
ContainerName=vaultwarden
Image=ghcr.io/dani-garcia/vaultwarden:alpine
# Enable auto-update container
AutoUpdate=registry
EnvironmentFile=./.env
Network=host
Volume=%h/podman/vaultwarden:/data
[Service]
EnvironmentFile=%h/.config/containers/systemd/vaultwarden/.env
Restart=always
TimeoutStartSec=300
[Install]
WantedBy=default.target