Compare commits

..
Author SHA1 Message Date
brian.long d8b4c89fd0 Merge branch 'acs-aims' into acs-aims-enterprise 2023-11-01 14:30:10 -04:00
brian.long 48859f80ee fixed AIS URL 2023-11-01 14:28:26 -04:00
brian.long 6f1acad7b6 Merge branch 'acs-frontend' into acs-aims 2023-11-01 14:28:01 -04:00
brian.long aa2aceb8ed Merge branch 'acs-backend' into acs-frontend 2023-11-01 14:25:55 -04:00
brian.long faa633c46c Merge branch 'acs-lats' into acs-backend 2023-11-01 14:25:01 -04:00
brian.long 72026e2ad2 Merge branch 'acs-search' into acs-backend 2023-11-01 14:24:57 -04:00
brian.long ab44e01638 Merge branch 'acs' into acs-lats 2023-11-01 14:23:23 -04:00
brian.long b3c89aa9ce Merge branch 'acs' into acs-search 2023-11-01 14:23:12 -04:00
brian.long fbda2bcdde configure CORS in ACS 2023-11-01 14:21:02 -04:00
brian.long d7c7ba0c69 Merge branch 'acs-aims' into acs-aims-enterprise 2023-11-01 10:42:32 -04:00
brian.long a6797d5550 Merge branch 'aims' into acs-aims 2023-11-01 10:36:24 -04:00
brian.long b211d1ea8a fix well-known reporting 2023-11-01 10:35:56 -04:00
brian.long 2aa2cf6f64 Merge branch 'acs-backend' into acs-frontend 2023-10-26 14:35:58 -04:00
brian.long 0b18c583da Merge branch 'acs-lats' into acs-backend 2023-10-26 14:29:07 -04:00
brian.long 40dd43068d Merge branch 'acs-search' into acs-backend 2023-10-26 14:29:04 -04:00
brian.long 231f11ea05 Merge branch 'acs' into acs-lats 2023-10-26 14:28:24 -04:00
brian.long bae1c47984 Merge branch 'acs' into acs-search 2023-10-26 14:27:39 -04:00
brian.long 3581872511 Merge branch 'acs-aims' into acs-aims-enterprise 2023-10-26 14:25:22 -04:00
brian.long bcf68b4027 Merge branch 'aims' into acs-aims 2023-10-26 14:24:54 -04:00
brian.long 885e53df2a Merge branch 'acs' into acs-aims 2023-10-26 14:24:38 -04:00
brian.long f456bb7ea9 removed mem_limit from proxy 2023-10-26 14:15:11 -04:00
brian.long df452d73a0 removed mem_limit from proxy 2023-10-26 14:13:48 -04:00
brian.long 9a0a428bbd Merge branch 'acs-frontend-enterprise' into acs-aims-enterprise 2023-10-25 22:31:26 -04:00
brian.long 1732253d8f Merge branch 'acs-aims' into acs-aims-enterprise 2023-10-25 22:30:39 -04:00
brian.long 350380fb3d Merge branch 'acs-frontend' into acs-aims 2023-10-25 22:29:48 -04:00
brian.long 9427e0e1cb Merge branch 'aims' into acs-aims 2023-10-25 22:29:17 -04:00
brian.long 51e5b376c1 Merge branch 'acs-adw-base' into acs-frontend-enterprise 2023-10-25 22:13:57 -04:00
brian.long 37ec00fd9d Merge branch 'acs-backend-enterprise' into acs-frontend-enterprise 2023-10-25 22:13:38 -04:00
brian.long 3a967c28d6 Merge branch 'acs-frontend' into acs-frontend-enterprise 2023-10-25 22:12:12 -04:00
brian.long df81075066 Merge branch 'acs-backend' into acs-frontend 2023-10-25 22:09:59 -04:00
brian.long 890f8ac11a Merge branch 'acs-share-base' into acs-frontend 2023-10-25 22:09:09 -04:00
brian.long 1f1e10cd9c Merge branch 'acs-sync-base' into acs-backend-enterprise 2023-10-25 21:53:02 -04:00
brian.long 3202dc9e51 Merge branch 'acs-search' into acs-backend-enterprise 2023-10-25 21:52:34 -04:00
brian.long aa6c6e54b6 Merge branch 'acs-ats-enterprise' into acs-backend-enterprise 2023-10-25 21:51:52 -04:00
brian.long f5b11e4a48 Merge branch 'acs-ats-base' into acs-ats-enterprise 2023-10-25 21:50:29 -04:00
brian.long a52eb3403f Merge branch 'acs-enterprise' into acs-ats-enterprise 2023-10-25 21:49:34 -04:00
brian.long 38b5f8dc36 Merge branch 'acs' into acs-enterprise 2023-10-25 21:47:34 -04:00
brian.long 664a47f49c Merge branch 'acs-lats' into acs-backend 2023-10-25 21:45:51 -04:00
brian.long 020c4822fd Merge branch 'acs-search' into acs-backend 2023-10-25 21:45:36 -04:00
brian.long 105b34664a Merge branch 'acs-lats-base' into acs-lats 2023-10-25 21:43:40 -04:00
brian.long 59c87eb302 added solr health check 2023-10-25 20:37:32 -04:00
brian.long 8c875fe850 Merge branch 'acs-search-base' into acs-search 2023-10-25 20:30:58 -04:00
brian.long c3880ac43d ADW v4.1.0 2023-10-25 20:28:03 -04:00
brian.long a1bd61bdde Merge branch 'acs-base' into acs-adw-base 2023-10-25 20:27:33 -04:00
brian.long b17f702f05 Merge branch 'acs-base' into acs-ats-base 2023-10-25 20:26:08 -04:00
brian.long c3f695ae8b Merge branch 'ats-base' into acs-ats-base 2023-10-25 20:25:48 -04:00
brian.long 415994f1f3 ATE AIO v4.0.0 2023-10-25 20:23:36 -04:00
brian.long 9a93ec369c Merge branch 'acs-base' into acs-lats-base 2023-10-25 20:23:20 -04:00
brian.long 81ca2ed038 ACS search 2.0.8.2 2023-10-25 20:21:21 -04:00
brian.long 51b777c0c5 Merge branch 'acs-base' into acs-search-base 2023-10-25 20:19:55 -04:00
brian.long 23b3057329 ACS share v7.4.1.2 2023-10-25 20:19:43 -04:00
brian.long b009fa9219 Merge branch 'acs-base' into acs-share-base 2023-10-25 20:17:55 -04:00
brian.long f5c4b00a02 ACS sync v3.9.0 2023-10-25 20:17:44 -04:00
brian.long 9e4577222b Merge branch 'acs-base' into acs-sync-base 2023-10-25 20:16:30 -04:00
brian.long ef221d9c7a Merge branch 'acs-base' into acs 2023-10-25 20:11:38 -04:00
brian.long 57af0a20b1 ACS v7.4.1.1 2023-10-25 20:11:15 -04:00
brian.long 76e4287aa1 Merge branch 'proxy' into acs-base 2023-10-25 20:08:28 -04:00
brian.long 9afc703a2c AIS v1.8.0.1 2023-10-25 20:02:33 -04:00
brian.long 416fe88c6b Merge branch 'proxy' into aims 2023-10-25 18:27:08 -04:00
brian.long 2b14374993 updated ATS versions 2023-10-25 18:25:49 -04:00
brian.long a4cfbd0b14 Merge branch 'base' into ats-base 2023-10-25 18:18:30 -04:00
brian.long 241a3e47ea Merge branch 'base' into proxy 2023-10-25 18:07:00 -04:00
brian.long c2a9679ede update comment 2023-10-25 18:05:39 -04:00
brian.long 5109b34641 Merge branch 'acs-aims' into acs-aims-enterprise 2022-11-01 17:52:08 -04:00
brian.long cd1d2e08b7 Merge branch 'acs-frontend-enterprise' into acs-aims-enterprise 2022-11-01 17:51:14 -04:00
brian.long 9114da403b Merge branch 'aims' into acs-aims 2022-11-01 17:47:43 -04:00
brian.long 8e6eb7ae72 Merge branch 'acs-frontend' into acs-aims 2022-11-01 17:47:14 -04:00
brian.long ff3554c0ce parameterized AIS version 2022-11-01 17:45:46 -04:00
brian.long cc77feb9b6 Merge branch 'proxy' into aims 2022-11-01 17:44:59 -04:00
brian.long 117982a0ac Merge branch 'acs-backend-enterprise' into acs-frontend-enterprise 2022-11-01 16:53:55 -04:00
brian.long f139716d25 Merge branch 'acs-ats-enterprise' into acs-backend-enterprise 2022-11-01 16:52:44 -04:00
brian.long 49d2647ab6 Merge branch 'acs-ats-base' into acs-ats-enterprise 2022-11-01 16:52:20 -04:00
brian.long 04b394c31c Merge branch 'ats-base' into acs-ats-base 2022-11-01 16:51:54 -04:00
brian.long fbbed5946f fixed ASFS docker image path 2022-11-01 16:51:30 -04:00
brian.long 450fb7c769 Merge branch 'acs-adw-base' into acs-frontend-enterprise 2022-11-01 16:40:30 -04:00
brian.long db0da17798 Merge branch 'acs-backend-enterprise' into acs-frontend-enterprise 2022-11-01 16:39:53 -04:00
brian.long 693aa9e4bf Merge branch 'acs-frontend' into acs-frontend-enterprise 2022-11-01 16:37:49 -04:00
brian.long 8bc64cd881 Merge branch 'acs-search' into acs-backend-enterprise 2022-11-01 16:34:46 -04:00
brian.long 9f0f5868bd Merge branch 'acs-sync-base' into acs-backend-enterprise 2022-11-01 16:33:37 -04:00
brian.long 9b3ed9fbbd Merge branch 'acs-ats-enterprise' into acs-backend-enterprise 2022-11-01 16:31:02 -04:00
brian.long 3283969431 Merge branch 'acs-ats-base' into acs-ats-enterprise 2022-11-01 16:29:43 -04:00
brian.long bc91054eeb Merge branch 'acs-enterprise' into acs-ats-enterprise 2022-11-01 16:28:26 -04:00
brian.long 8fd11ed1d6 Merge branch 'acs' into acs-enterprise 2022-11-01 16:26:33 -04:00
brian.long 7fd04f30f3 Merge branch 'acs-share-base' into acs-frontend 2022-11-01 16:23:43 -04:00
brian.long 226a2d05e2 Merge branch 'acs-backend' into acs-frontend 2022-11-01 16:22:46 -04:00
brian.long c60e224a14 Merge branch 'acs-lats' into acs-backend 2022-11-01 16:17:27 -04:00
brian.long fc74faf57a Merge branch 'acs-search' into acs-backend 2022-11-01 16:16:59 -04:00
brian.long da933f2aa7 Merge branch 'acs' into acs-lats 2022-11-01 16:15:28 -04:00
brian.long 10aa561c52 Merge branch 'acs-lats-base' into acs-lats 2022-11-01 16:11:15 -04:00
brian.long 2dc64b23e4 parameterized LATS version 2022-11-01 16:09:56 -04:00
brian.long e9186dec84 Merge branch 'acs-base' into acs-lats-base 2022-11-01 16:08:01 -04:00
brian.long d556040909 Merge branch 'acs' into acs-search 2022-11-01 16:05:53 -04:00
brian.long 64f85da579 Merge branch 'acs-search-base' into acs-search 2022-11-01 16:04:44 -04:00
brian.long 7113aa012f parameterized the ADW version 2022-11-01 15:36:33 -04:00
brian.long d4426fe373 Merge branch 'acs-base' into acs-adw-base 2022-11-01 15:32:54 -04:00
brian.long 831f1cb4f0 Merge branch 'acs-base' into acs-ats-base 2022-11-01 15:32:08 -04:00
brian.long 0e5181d12a Merge branch 'ats-base' into acs-ats-base 2022-11-01 15:30:48 -04:00
brian.long f569d712e1 parameterize Docker image versions 2022-11-01 15:30:07 -04:00
brian.long ffac352049 Merge branch 'base' into ats-base 2022-11-01 15:11:57 -04:00
brian.long 9899d03da9 parameterized ASIE version; enabled secret comms 2022-11-01 15:07:51 -04:00
brian.long 5b4069427e Merge branch 'acs-base' into acs-search-base 2022-11-01 15:04:21 -04:00
brian.long fcd1262721 parameterized ACS share version 2022-11-01 15:03:04 -04:00
brian.long d7de714eeb Merge branch 'acs-base' into acs-share-base 2022-11-01 15:01:38 -04:00
brian.long b3a9145dd6 parameterized sync service version 2022-11-01 15:00:53 -04:00
brian.long 08ce9f6cc8 Merge branch 'acs-base' into acs-sync-base 2022-11-01 14:57:20 -04:00
brian.long 7511eba729 added memory limit 2022-11-01 14:54:47 -04:00
brian.long 173de2375e Merge branch 'acs-base' into acs 2022-11-01 14:52:59 -04:00
brian.long 8e3301877a parameterized docker image tags 2022-11-01 14:51:11 -04:00
brian.long 8b4e45c2e2 Merge branch 'proxy' into acs-base 2022-11-01 14:49:06 -04:00
brian.long 9e1a819e8b Merge branch 'base' into proxy 2022-11-01 14:48:11 -04:00
brian.long 10e7f81163 advancing to docker v3 2022-11-01 14:46:58 -04:00
brian.long 481e1bb38d Merge branch 'acs-base' into acs 2022-11-01 14:22:57 -04:00
brian.long 29f254a68e updated to ACS v7.3.0 2022-11-01 14:19:58 -04:00
5 changed files with 239 additions and 186 deletions
+12
View File
@@ -7,3 +7,15 @@ PROXY_PORT=8080
IDENTITY_SERVICE_PROTOCOL=http
IDENTITY_SERVICE_HOST=auth.example.org
IDENTITY_SERVICE_PORT=8080
ACS_TAG=7.4.1.1
ATR_TAG=3.0.0
ATE_AIO_TAG=4.0.0
ASFS_TAG=3.0.0
AIS_TAG=1.8.0.1
AAMQ_TAG=latest
POSTGRES_TAG=13
ASIE_TAG=2.0.8.2
ACS_SHARE_TAG=7.4.1.2
ALF_SYNC_SERV_TAG=3.9.0
ADW_TAG=4.1.0
+52 -164
View File
@@ -1,22 +1,32 @@
# Sourced from https://github.com/Alfresco/acs-deployment/blob/4.0.3/docker-compose/docker-compose.yml
# Originally sourced from https://github.com/Alfresco/acs-deployment/blob/4.0.3/docker-compose/docker-compose.yml
#
# Using version 2 as 3 does not support resource constraint options (cpu_*, mem_* limits) for non swarm mode in Compose
version: "2.1"
version: "3"
services:
platform:
image: quay.io/alfresco/alfresco-governance-repository-enterprise:V3.4-latest
mem_limit: 2g
image: quay.io/alfresco/alfresco-content-repository:${ACS_TAG}
environment:
JAVA_TOOL_OPTIONS: "
-Dencryption.keystore.type=JCEKS
-Dencryption.cipherAlgorithm=DESede/CBC/PKCS5Padding
-Dencryption.keyAlgorithm=DESede
-Dencryption.keystore.location=/usr/local/tomcat/shared/classes/alfresco/extension/keystore/keystore
-Dmetadata-keystore.password=mp6yc0UD9e
-Dmetadata-keystore.aliases=metadata
-Dmetadata-keystore.metadata.password=oKIWzVdEdA
-Dmetadata-keystore.metadata.algorithm=DESede
"
JAVA_OPTS: "
-Xms512m -Xmx1g
-Ddb.driver=org.postgresql.Driver
-Ddb.username=alfresco
-Ddb.password=alfresco
-Ddb.url=jdbc:postgresql://postgres-acs:5432/alfresco
-Dindex.subsystem.name=solr6
-Dsolr.host=search
-Dsolr.port=8983
-Dsolr.secureComms=none
-Dsolr.secureComms=secret
-Dsolr.sharedSecret=alfresco-secret
-Dshare.host=${PROXY_HOST}
-Dshare.port=${PROXY_PORT}
-Dshare.protocol=${PROXY_PROTOCOL}
@@ -26,32 +36,22 @@ services:
-Daos.baseUrlOverwrite=${PROXY_PROTOCOL}://${PROXY_HOST}:${PROXY_PORT}/alfresco/aos
-Dmessaging.broker.url=\"failover:(nio://activemq:61616)?timeout=3000&jms.useCompression=true\"
-Ddeployment.method=DOCKER_COMPOSE
-DlocalTransform.core-aio.url=http://transform-core-aio:8090/
-Dalfresco-pdf-renderer.url=http://transform-core-aio:8090/
-Djodconverter.url=http://transform-core-aio:8090/
-Dimg.url=http://transform-core-aio:8090/
-Dtika.url=http://transform-core-aio:8090/
-Dtransform.misc.url=http://transform-core-aio:8090/
-Dcsrf.filter.enabled=false
-XX:MinRAMPercentage=50 -XX:MaxRAMPercentage=80
-Dcors.enabled=true
-Dcors.allowed.origins=http://localhost:4200,http://localhost:8080,${PROXY_PROTOCOL}://${PROXY_HOST}
-Dtransform.service.enabled=true
-Dlocal.transform.service.enabled=false
-Dtransform.service.url=http://transform-router:8095
-Dsfs.url=http://shared-file-store:8099
-Dlocal.transform.service.enabled=true
-Dalfresco-pdf-renderer.url=http://transform-engine-aio:8090
-Djodconverter.url=http://transform-engine-aio:8090
-Dimg.url=http://transform-engine-aio:8090
-Dtika.url=http://transform-engine-aio:8090
-Dtransform.misc.url=http://transform-engine-aio:8090
-Ddsync.service.uris=${PROXY_PROTOCOL}://${PROXY_HOST}:${PROXY_PORT}/sync
-Dauthentication.chain=aims:identity-service,builtin:alfrescoNtlm
-Didentity-service.authentication.defaultAdministratorUserNames=admin.1
-Didentity-service.auth-server-url=${IDENTITY_SERVICE_PROTOCOL}://${IDENTITY_SERVICE_HOST}:${IDENTITY_SERVICE_PORT}/auth
-Didentity-service.auth-server-url=http://identity:8080/auth
-Dsystem.content.eagerOrphanCleanup=true
-Dsystem.content.orphanProtectDays=0
-Djodconverter.enabled=false
@@ -67,11 +67,9 @@ services:
condition: service_healthy
volumes:
- "$ALFRESCO_LICENSE_DIR/acs:/usr/local/tomcat/shared/classes/alfresco/extension/license:ro"
- acsbin-volume:/usr/local/tomcat/alf_data:rw
transform-router:
image: quay.io/alfresco/alfresco-transform-router:1.3.1
mem_limit: 128m
image: quay.io/alfresco/alfresco-transform-router:${ATR_TAG}
environment:
ACTIVEMQ_URL: "nio://activemq:61616"
CORE_AIO_URL : "http://transform-core-aio:8090"
@@ -81,8 +79,7 @@ services:
- shared-file-store
transform-core-aio:
image: alfresco/alfresco-transform-core-aio:2.3.6
mem_limit: 1g
image: alfresco/alfresco-transform-core-aio:${ATE_AIO_TAG}
environment:
ACTIVEMQ_URL: "nio://activemq:61616"
FILE_STORE_URL: "http://shared-file-store:8099/alfresco/api/-default-/private/sfs/versions/1/file"
@@ -91,14 +88,12 @@ services:
- shared-file-store
shared-file-store:
image: alfresco/alfresco-shared-file-store:0.10.0
mem_limit: 256m
image: quay.io/alfresco/alfresco-shared-file-store:${ASFS_TAG}
volumes:
- shared-file-store-volume:/tmp/Alfresco/sfs
share:
image: quay.io/alfresco/alfresco-governance-share-enterprise:V3.4-latest
mem_limit: 512m
image: alfresco/alfresco-share:${ACS_SHARE_TAG}
environment:
REPO_HOST: "platform"
CSRF_FILTER_REFERER: "${PROXY_PROTOCOL}://${PROXY_HOST}(:${PROXY_PORT})?/?.*"
@@ -123,40 +118,38 @@ services:
"
postgres-acs:
image: postgres:11.7
mem_limit: 128m
image: postgres:${POSTGRES_TAG}
environment:
- POSTGRES_PASSWORD=alfresco
- POSTGRES_USER=alfresco
- POSTGRES_DB=alfresco
POSTGRES_PASSWORD: alfresco
POSTGRES_USER: alfresco
POSTGRES_DB: alfresco
command: postgres -c max_connections=300 -c log_min_messages=LOG
volumes:
- acsdb-volume:/var/lib/postgresql/data:rw
search:
image: alfresco/alfresco-search-services:2.0.1
mem_limit: 1g
image: alfresco/alfresco-search-services:${ASIE_TAG}
environment:
- SOLR_ALFRESCO_HOST=platform
- SOLR_ALFRESCO_PORT=8080
- SOLR_SOLR_HOST=search
- SOLR_SOLR_PORT=8983
- SOLR_CREATE_ALFRESCO_DEFAULTS=alfresco,archive
- ALFRESCO_SECURE_COMMS=none
volumes:
- solrindex-volume:/opt/alfresco-search-services/data:rw
SOLR_ALFRESCO_HOST: platform
SOLR_SOLR_HOST: search
SOLR_CREATE_ALFRESCO_DEFAULTS: alfresco,archive
ALFRESCO_SECURE_COMMS: secret
JAVA_TOOL_OPTIONS: "
-Dalfresco.secureComms.secret=alfresco-secret
"
healthcheck:
test: "curl -fsS http://localhost:8983/solr"
activemq:
image: alfresco/alfresco-activemq:5.15.8
mem_limit: 512m
volumes:
- activemq-volume:/opt/activemq/data:rw
image: alfresco/alfresco-activemq:${AAMQ_TAG}
environment:
ACTIVEMQ_OPTS_MEMORY: -Xms64m -Xmx256m
ACTIVEMQ_ADMIN_LOGIN: alfresco
ACTIVEMQ_ADMIN_PASSWORD: alfresco
sync:
image: quay.io/alfresco/service-sync:3.3.3.1
mem_limit: 512m
image: quay.io/alfresco/service-sync:${ALF_SYNC_SERV_TAG}
environment:
JAVA_OPTS : "
-Xms64m -Xmx256m
-Dsql.db.driver=org.postgresql.Driver
-Dsql.db.url=jdbc:postgresql://postgres-acs:5432/alfresco
-Dsql.db.username=alfresco
@@ -165,7 +158,6 @@ services:
-Drepo.hostname=platform
-Drepo.port=8080
-Ddw.server.applicationConnectors[0].type=http
-XX:MinRAMPercentage=50 -XX:MaxRAMPercentage=80
-Didentity-service.auth-server-url=${IDENTITY_SERVICE_PROTOCOL}://${IDENTITY_SERVICE_HOST}:${IDENTITY_SERVICE_PORT}/auth
-Didentity-service.resource=acs-sync
"
@@ -174,16 +166,11 @@ services:
- activemq
digital-workspace:
image: quay.io/alfresco/alfresco-digital-workspace:2.0.0-adw
mem_limit: 128m
image: quay.io/alfresco/alfresco-digital-workspace:${ADW_TAG}
environment:
BASE_PATH: ./
APP_CONFIG_ECM_HOST: "${PROXY_PROTOCOL}://${PROXY_HOST}:${PROXY_PORT}"
APP_CONFIG_BPM_HOST: "${PROXY_PROTOCOL}://${PROXY_HOST}:${PROXY_PORT}"
APP_BASE_SHARE_URL: "${PROXY_PROTOCOL}://${PROXY_HOST}:${PROXY_PORT}/workspace/#/preview/s"
APP_CONFIG_PROVIDER: "ALL"
APP_CONFIG_PLUGIN_PROCESS_SERVICE: "true"
#APP_CONFIG_PLUGIN_PROCESS_AUTOMATION: "true"
APP_BASE_SHARE_URL: "${PROXY_PROTOCOL}://${PROXY_HOST}:${PROXY_PORT}/#/preview/s"
APP_CONFIG_AUTH_TYPE: OAUTH
APP_CONFIG_OAUTH2_HOST: "${IDENTITY_SERVICE_PROTOCOL}://${IDENTITY_SERVICE_HOST}:${IDENTITY_SERVICE_PORT}/auth/realms/alfresco"
APP_CONFIG_OAUTH2_CLIENTID: alfresco
@@ -191,90 +178,13 @@ services:
APP_CONFIG_OAUTH2_REDIRECT_LOGIN: "/workspace/"
APP_CONFIG_OAUTH2_REDIRECT_LOGOUT: "/workspace/logout"
activiti-app:
image: alfresco/process-services:1.11.1.1
mem_limit: 512m
environment:
ACTIVITI_DATASOURCE_USERNAME: alfresco
ACTIVITI_DATASOURCE_PASSWORD: alfresco
ACTIVITI_DATASOURCE_DRIVER: org.postgresql.Driver
ACTIVITI_HIBERNATE_DIALECT: org.hibernate.dialect.PostgreSQLDialect
ACTIVITI_DATASOURCE_URL: 'jdbc:postgresql://postgres-aps:5432/activiti?characterEncoding=UTF-8'
ACTIVITI_ES_SERVER_TYPE: rest
ACTIVITI_ES_REST_CLIENT_ADDRESS: search-aps
ACTIVITI_ES_REST_CLIENT_PORT: 9200
ACTIVITI_ES_REST_CLIENT_SCHEMA: http
IDENTITY_SERVICE_ENABLED: "true"
IDENTITY_SERVICE_AUTH: ${IDENTITY_SERVICE_PROTOCOL}://${IDENTITY_SERVICE_HOST}:${IDENTITY_SERVICE_PORT}/auth
IDENTITY_SERVICE_CONTENT_SSO_REDIRECT_URI: ${PROXY_PROTOCOL}://${PROXY_HOST}:${PROXY_PORT}/activiti-app/app/rest/integration/sso/confirm-auth-request
JAVA_OPTS: "-XX:MinRAMPercentage=50 -XX:MaxRAMPercentage=80"
depends_on:
- postgres-aps
volumes:
- "$ALFRESCO_LICENSE_DIR/aps:/root/.activiti/enterprise-license:ro"
- apsbin-volume:/var/lib/postgresql/data:rw
activiti-admin:
image: alfresco/process-services-admin:1.11.1.1
mem_limit: 256m
environment:
ACTIVITI_ADMIN_DATASOURCE_USERNAME: alfresco
ACTIVITI_ADMIN_DATASOURCE_PASSWORD: alfresco
ACTIVITI_ADMIN_DATASOURCE_DRIVER: org.postgresql.Driver
ACTIVITI_ADMIN_HIBERNATE_DIALECT: org.hibernate.dialect.PostgreSQLDialect
ACTIVITI_ADMIN_DATASOURCE_URL: 'jdbc:postgresql://postgres-aps-admin:5432/activiti-admin?characterEncoding=UTF-8'
ACTIVITI_ADMIN_REST_APP_HOST: http://activiti-app
ACTIVITI_ADMIN_REST_APP_PORT: 8080
JAVA_OPTS: "-XX:MinRAMPercentage=50 -XX:MaxRAMPercentage=80"
depends_on:
- postgres-aps-admin
- activiti-app
postgres-aps:
image: postgres:11.6
mem_limit: 128m
environment:
POSTGRES_DB: activiti
POSTGRES_USER: alfresco
POSTGRES_PASSWORD: alfresco
command: postgres -c max_connections=300 -c log_min_messages=LOG
volumes:
- apsdb-volume:/var/lib/postgresql/data:rw
postgres-aps-admin:
image: postgres:11.6
mem_limit: 128m
environment:
POSTGRES_DB: activiti-admin
POSTGRES_USER: alfresco
POSTGRES_PASSWORD: alfresco
command: postgres -c max_connections=50 -c log_min_messages=LOG
volumes:
- apsadmindb-volume:/var/lib/postgresql/data:rw
search-aps:
image: elasticsearch:7.6.0
mem_limit: 512m
environment:
discovery.type: single-node
ES_JAVA_OPTS: "-Xms128m -Xmx256m"
ulimits:
memlock:
soft: -1
hard: -1
depends_on:
- activiti-app
volumes:
- esindex-volume:/var/lib/postgresql/data:rw
identity:
image: alfresco/alfresco-identity-service:1.4.0
mem_limit: 512m
image: alfresco/alfresco-identity-service:${AIS_TAG}
user: jboss
environment:
KEYCLOAK_USER: admin
KEYCLOAK_PASSWORD: admin
KEYCLOAK_HOSTNAME: ${IDENTITY_SERVICE_HOST}
KEYCLOAK_FRONTEND_URL: ${IDENTITY_SERVICE_PROTOCOL}://${IDENTITY_SERVICE_HOST}:${IDENTITY_SERVICE_PORT}/auth
KEYCLOAK_IMPORT: /tmp/keycloak-alfresco-realm.json
KEYCLOAK_STATISTICS: enabled
networks:
@@ -289,12 +199,10 @@ services:
retries: 18
volumes:
- ./keycloak-alfresco-realm.json:/tmp/keycloak-alfresco-realm.json:ro
- keycloak-volume:/opt/jboss/keycloak/standalone/data:rw
proxy:
build: ./nginx-ingress
image: local/nginx-ingress:acs-sync-share-adw-aps-aims
mem_limit: 256m
image: local/nginx-ingress:acs-sync-share-adw-aims
ports:
- 8080:8080
depends_on:
@@ -302,8 +210,6 @@ services:
- sync
- share
- digital-workspace
- activiti-app
- activiti-admin
- identity
volumes:
@@ -311,21 +217,3 @@ volumes:
driver_opts:
type: tmpfs
device: tmpfs
acsbin-volume:
driver: local
acsdb-volume:
driver: local
activemq-volume:
driver: local
solrindex-volume:
driver: local
apsbin-volume:
driver: local
apsdb-volume:
driver: local
apsadmindb-volume:
driver: local
esindex-volume:
driver: local
keycloak-volume:
driver: local
-8
View File
@@ -16,14 +16,6 @@ if [[ $ADW_URL ]]; then
sed -i s%http:\/\/digital-workspace:8080%"$ADW_URL"%g /etc/nginx/nginx.conf
fi
if [[ $APS_APP_URL ]]; then
sed -i s%http:\/\/activiti-app:8080%"$APS_APP_URL"%g /etc/nginx/nginx.conf
fi
if [[ $APS_ADMIN_URL ]]; then
sed -i s%http:\/\/activiti-admin:8080%"$APS_ADMIN_URL"%g /etc/nginx/nginx.conf
fi
if [[ $AIMS_URL ]]; then
sed -i s%http:\/\/identity:8080%"$AIMS_URL"%g /etc/nginx/nginx.conf
fi
-14
View File
@@ -56,20 +56,6 @@ http {
proxy_pass http://sync:9090/alfresco/;
}
location /activiti-app/ {
proxy_pass http://activiti-app:8080;
# If using external proxy / load balancer (for initial redirect if no trailing slash)
absolute_redirect off;
}
location /activiti-admin/ {
proxy_pass http://activiti-admin:8080;
# If using external proxy / load balancer (for initial redirect if no trailing slash)
absolute_redirect off;
}
location /share/ {
proxy_pass http://share:8080;
}
+175
View File
@@ -0,0 +1,175 @@
<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- Note: A "Server" is not itself a "Container", so you may not
define subcomponents such as "Valves" at this level.
Documentation at /docs/config/server.html
-->
<Server port="8005" shutdown="SHUTDOWN">
<Listener className="org.apache.catalina.startup.VersionLoggerListener" logArgs="false" />
<!-- Security listener. Documentation at /docs/config/listeners.html
<Listener className="org.apache.catalina.security.SecurityListener" />
-->
<!-- APR library loader. Documentation at /docs/apr.html -->
<Listener className="org.apache.catalina.core.AprLifecycleListener" SSLEngine="on" />
<!-- Prevent memory leaks due to use of particular java/javax APIs-->
<Listener className="org.apache.catalina.core.JreMemoryLeakPreventionListener" />
<Listener className="org.apache.catalina.mbeans.GlobalResourcesLifecycleListener" />
<Listener className="org.apache.catalina.core.ThreadLocalLeakPreventionListener" />
<!-- Global JNDI resources
Documentation at /docs/jndi-resources-howto.html
-->
<GlobalNamingResources>
<!-- Editable user database that can also be used by
UserDatabaseRealm to authenticate users
-->
<Resource name="UserDatabase" auth="Container"
type="org.apache.catalina.UserDatabase"
description="User database that can be updated and saved"
factory="org.apache.catalina.users.MemoryUserDatabaseFactory"
pathname="conf/tomcat-users.xml" />
</GlobalNamingResources>
<!-- A "Service" is a collection of one or more "Connectors" that share
a single "Container" Note: A "Service" is not itself a "Container",
so you may not define subcomponents such as "Valves" at this level.
Documentation at /docs/config/service.html
-->
<Service name="Catalina">
<!--The connectors can use a shared executor, you can define one or more named thread pools-->
<!--
<Executor name="tomcatThreadPool" namePrefix="catalina-exec-"
maxThreads="150" minSpareThreads="4"/>
-->
<!-- A "Connector" represents an endpoint by which requests are received
and responses are returned. Documentation at :
Java HTTP Connector: /docs/config/http.html
Java AJP Connector: /docs/config/ajp.html
APR (HTTP/AJP) Connector: /docs/apr.html
Define a non-SSL/TLS HTTP/1.1 Connector on port 8080
-->
<Connector port="8080" protocol="HTTP/1.1"
Server=" "
connectionTimeout="20000"
redirectPort="8443"
proxyName="alfresco.inteligr8.com" proxyPort="443" />
<!-- A "Connector" using the shared thread pool-->
<!--
<Connector executor="tomcatThreadPool"
port="8080" protocol="HTTP/1.1"
connectionTimeout="20000"
redirectPort="8443"
proxyHost="alfresco.inteligr8.com" proxyPort="443" />
-->
<!-- Define an SSL/TLS HTTP/1.1 Connector on port 8443
This connector uses the NIO implementation. The default
SSLImplementation will depend on the presence of the APR/native
library and the useOpenSSL attribute of the AprLifecycleListener.
Either JSSE or OpenSSL style configuration may be used regardless of
the SSLImplementation selected. JSSE style configuration is used below.
-->
<!--
<Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150" SSLEnabled="true">
<SSLHostConfig>
<Certificate certificateKeystoreFile="conf/localhost-rsa.jks"
type="RSA" />
</SSLHostConfig>
</Connector>
-->
<!-- Define an SSL/TLS HTTP/1.1 Connector on port 8443 with HTTP/2
This connector uses the APR/native implementation which always uses
OpenSSL for TLS.
Either JSSE or OpenSSL style configuration may be used. OpenSSL style
configuration is used below.
-->
<!--
<Connector port="8443" protocol="org.apache.coyote.http11.Http11AprProtocol"
maxThreads="150" SSLEnabled="true" >
<UpgradeProtocol className="org.apache.coyote.http2.Http2Protocol" />
<SSLHostConfig>
<Certificate certificateKeyFile="conf/localhost-rsa-key.pem"
certificateFile="conf/localhost-rsa-cert.pem"
certificateChainFile="conf/localhost-rsa-chain.pem"
type="RSA" />
</SSLHostConfig>
</Connector>
-->
<!-- Define an AJP 1.3 Connector on port 8009 -->
<!--
<Connector protocol="AJP/1.3"
address="::1"
port="8009"
redirectPort="8443" />
-->
<!-- An Engine represents the entry point (within Catalina) that processes
every request. The Engine implementation for Tomcat stand alone
analyzes the HTTP headers included with the request, and passes them
on to the appropriate Host (virtual host).
Documentation at /docs/config/engine.html -->
<!-- You should set jvmRoute to support load-balancing via AJP ie :
<Engine name="Catalina" defaultHost="localhost" jvmRoute="jvm1">
-->
<Engine name="Catalina" defaultHost="localhost">
<!--For clustering, please take a look at documentation at:
/docs/cluster-howto.html (simple how to)
/docs/config/cluster.html (reference documentation) -->
<!--
<Cluster className="org.apache.catalina.ha.tcp.SimpleTcpCluster"/>
-->
<!-- Use the LockOutRealm to prevent attempts to guess user passwords
via a brute-force attack -->
<Realm className="org.apache.catalina.realm.LockOutRealm">
<!-- This Realm uses the UserDatabase configured in the global JNDI
resources under the key "UserDatabase". Any edits
that are performed against this UserDatabase are immediately
available for use by the Realm. -->
<Realm className="org.apache.catalina.realm.UserDatabaseRealm"
resourceName="UserDatabase"/>
</Realm>
<Host name="localhost" appBase="webapps"
unpackWARs="true" autoDeploy="true">
<!-- SingleSignOn valve, share authentication between web applications
Documentation at: /docs/config/valve.html -->
<!--
<Valve className="org.apache.catalina.authenticator.SingleSignOn" />
-->
<!-- Access log processes all example.
Documentation at: /docs/config/valve.html
Note: The pattern used is equivalent to using pattern="common" -->
<Valve className="org.apache.catalina.valves.AccessLogValve" directory="logs"
prefix="localhost_access_log" suffix=".txt"
pattern="%h %l %u %t &quot;%r&quot; %s %b" />
<Valve className="org.apache.catalina.valves.RemoteIpValve" />
</Host>
</Engine>
</Service>
</Server>