mirror of
https://codeberg.org/icewind/haze.git
synced 2026-10-01 08:44:09 +02:00
feat(services): Add a service for the lookup server
Signed-off-by: Louis Chmn <louis@chmn.me>
This commit is contained in:
parent
7121474198
commit
46ea577dbd
3 changed files with 213 additions and 0 deletions
64
README.md
64
README.md
|
|
@ -85,6 +85,8 @@ Additionally, you can use the following options when starting an instance:
|
|||
- `saml`: set up authentik as a SAML IDP.
|
||||
- `oidc`: set up authentik as an OIDC IDP.
|
||||
- `scim`: set up authentik as a SCIM server.
|
||||
- `lookup`: set up a
|
||||
[lookup server](https://github.com/nextcloud/lookup-server).
|
||||
- `office`: set up a Nextcloud Office server.
|
||||
- `onlyoffice` setup an onlyoffice document server.
|
||||
- `push` set up [client push](https://github.com/nextcloud/notify_push).
|
||||
|
|
@ -293,6 +295,68 @@ name to allow for testing federation between instances. Alternatively, you can
|
|||
set up the haze proxy and the proxied domains to get https support between
|
||||
instances.
|
||||
|
||||
## Global scale
|
||||
|
||||
You can start a lookup-server service when starting an instance:
|
||||
|
||||
```bash
|
||||
haze start --name gs-master lookup
|
||||
```
|
||||
|
||||
The lookup server is then accessible by other instances at
|
||||
`http://haze-gs-master-lookup`.
|
||||
|
||||
The Nextcloud instance started with this command is already properly configured
|
||||
as master node.
|
||||
|
||||
For the slaves instance, here is a sane preset:
|
||||
|
||||
```toml
|
||||
[[preset]]
|
||||
name = "gs-slave"
|
||||
apps = ["globalsiteselector"]
|
||||
config = {
|
||||
"gs.enabled" = true,
|
||||
"gs.federation" = "global",
|
||||
"gss.jwt.key" = "random-key", # Matches the key set in the docker container of the lookup server.
|
||||
"gss.mode" = "slave",
|
||||
}
|
||||
```
|
||||
|
||||
You'll then have to manually point your slave instances to the lookup and master
|
||||
instances:
|
||||
|
||||
```bash
|
||||
haze start --name gs-slave1 gs-slave
|
||||
# Assuming that the master instance was started with `--name gs-master`.
|
||||
haze gs-slave1 occ config:system:set gss.master.url --value="http://haze-gs-master.haze.example.com"
|
||||
haze gs-slave1 occ config:system:set lookup_server --value="http://haze-gs-master-lookup"
|
||||
```
|
||||
|
||||
If you want to use the `ManualUserMapping` module, you'll have to set the
|
||||
following config on the master instance:
|
||||
|
||||
```bash
|
||||
haze gs-master occ config:system:set gss.user.discovery.module --value="\\OCA\\GlobalSiteSelector\\UserDiscoveryModules\\ManualUserMapping"
|
||||
haze gs-master occ config:system:set gss.discovery.manual.mapping.file --value="/shared/config/gs-user-mapping.json" # See the volume section below for how to mount this file into the container.
|
||||
haze gs-master occ config:system:set gss.discovery.manual.mapping.regex --type boolean --value=true
|
||||
```
|
||||
|
||||
```toml
|
||||
[[volume]] # Needed if you are using "ManualUserMapping" module.
|
||||
source = "/home/louis/.config/haze/config/gs-user-mapping.json"
|
||||
target = "/shared/config/gs-user-mapping.json"
|
||||
read_only = true
|
||||
```
|
||||
|
||||
You can test the connection between the instances and the lookup server by
|
||||
running the following command on the slave instance:
|
||||
|
||||
```bash
|
||||
haze gs-master occ globalsiteselector:discovery
|
||||
haze gs-slave1 occ globalsiteselector:discovery
|
||||
```
|
||||
|
||||
## Proxy
|
||||
|
||||
By default, instances can be accessed by their IP. In order to get more
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue