Compare commits

..
Author SHA1 Message Date
brian.long 50ad4a380b Merge branch 'acs-base' into acs-ext-platform 2023-10-25 20:28:45 -04:00
brian.long 57af0a20b1 ACS v7.4.1.1 2023-10-25 20:11:15 -04:00
brian.long 76e4287aa1 Merge branch 'proxy' into acs-base 2023-10-25 20:08:28 -04:00
brian.long 1e1667c039 parameterize ACS version in Dockerfile 2022-11-01 16:00:54 -04:00
brian.long 6e6f38e9e4 Merge branch 'acs-base' into acs-ext-platform 2022-11-01 15:40:04 -04:00
brian.long 8e3301877a parameterized docker image tags 2022-11-01 14:51:11 -04:00
brian.long 8b4e45c2e2 Merge branch 'proxy' into acs-base 2022-11-01 14:49:06 -04:00
brian.long 29f254a68e updated to ACS v7.3.0 2022-11-01 14:19:58 -04:00
brian.long aeb3fe5b62 splitting share/platform module dirs 2021-04-23 08:37:03 -04:00
brian 228e930caa Merge branch 'acs-base' into acs-ext-platform 2021-04-02 09:13:13 -04:00
brian.long 6bce626075 Merge branch 'proxy' into acs-base 2021-04-02 08:42:43 -04:00
brian.long fa515e4984 Merge branch 'acs-base.proxy' into acs-ext-platform.acs-base 2021-01-06 16:07:52 -05:00
brian.long ebd6c503bd Merge branch 'proxy.base' into acs-base.proxy 2021-01-06 12:21:58 -05:00
brian.long 5a12f3a6e0 Merge branch 'acs-base.proxy' into acs-ext-platform.acs-base 2020-12-26 14:06:49 -05:00
brian.long 1d5624496d renamed proxy variables to match changes to proxy branch 2020-12-26 13:55:19 -05:00
brian.long 3a6b5c4850 Merge commit '817b062dfddd1035aa68554f55065c042607c482' into acs-base.proxy 2020-12-26 13:54:44 -05:00
brian.long c0c6dcd1ce remove share context; moving to acs-share-base 2020-12-26 13:51:23 -05:00
brian.long 3cb24f7587 added proxy config to platform 2020-12-26 11:18:58 -05:00
brian.long 6579a5a0c9 Merge branch 'proxy.base' into acs-base.proxy 2020-12-26 11:16:07 -05:00
brian.long 1ead7a8d16 added alf-specific variables back to docker-compose env in the right branch 2020-12-26 11:13:00 -05:00
brian.long 63aa212ccb Merge branch 'proxy.base' into acs-base.proxy 2020-12-26 11:11:48 -05:00
brian.long 6d396a640f added JDBC driver to base config 2020-12-26 11:06:07 -05:00
brian.long b6ff1bb4d2 Merge remote-tracking branch 'home/acs-ext-platform.acs-base' into acs-ext-platform.acs-base 2020-12-26 00:00:32 -05:00
brian.long 8467968c92 Merge branch 'acs-base.proxy' into acs-ext-platform.acs-base 2020-12-25 23:37:45 -05:00
brian.long 9720bd7fa6 Merge branch 'proxy.base' into acs-base.proxy 2020-12-25 23:08:53 -05:00
brian.long 32b8e047fb appending catalina.policy file for these external JARs 2020-12-25 15:16:36 -05:00
brian.long 119c6643bd refactored JAR ext loading 2020-12-25 14:41:51 -05:00
brian.long a30f423c44 enabled JAR extension loading 2020-12-25 14:32:20 -05:00
brian.long 4650110b96 fixed COPY for multiple AMPs 2020-12-21 14:28:20 -05:00
brian.long 24114c2604 initial platform extension framework 2020-12-17 19:25:31 -05:00
brian.long 46bbeeef30 fixed missed envvar 2020-12-17 16:29:36 -05:00
brian.long 6b0c103d75 added depends_on for proxy 2020-12-17 16:24:34 -05:00
brian.long faee3aaa48 Merge branch 'acs-proxy.proxy' into acs-base.acs-proxy 2020-12-17 16:20:23 -05:00
brian.long beb87dd97a Merge branch 'proxy.base' into acs-proxy.proxy 2020-12-17 16:20:12 -05:00
brian.long db6a1e148c Merge branch 'acs-proxy.proxy' into acs-base.acs-proxy 2020-12-17 16:16:57 -05:00
brian.long ab396f7656 changed version to 'acs' 2020-12-17 16:16:44 -05:00
brian.long b65d3d301f Merge branch 'acs-proxy.proxy' into acs-base.acs-proxy 2020-12-17 16:16:07 -05:00
brian.long 6332985ebd removed proxy 2020-12-17 16:09:48 -05:00
brian.long 010149e6b6 added platform config 2020-12-17 16:07:17 -05:00
brian.long 79a1644530 more corrections to service names and addressing additions 2020-12-17 12:46:24 -05:00
brian.long 5cfee3d18f updated service names 2020-12-17 12:31:55 -05:00
brian.long 6c665fab04 added depends_on for the alfresco service 2020-12-16 23:55:56 -05:00
brian.long 0f36dd1943 added minimum unconfigured ACS services to Docker Compose 2020-12-16 23:34:34 -05:00
9 changed files with 107 additions and 1 deletions
+7
View File
@@ -1,3 +1,10 @@
ALFRESCO_DIR=~/alfresco
ALFRESCO_LICENSE_DIR=~/alfresco/license
PROXY_PROTOCOL=http
PROXY_HOST=localhost
PROXY_PORT=8080
ACS_TAG=7.4.1.1
AAMQ_TAG=latest
POSTGRES_TAG=13
@@ -0,0 +1,17 @@
ARG ACS_TAG=inject-it
FROM alfresco/alfresco-content-repository-community:${ACS_TAG}
ARG USERNAME=alfresco
ARG TOMCAT_DIR=/usr/local/tomcat
USER root
COPY catalina.policy /tmp/catalina.policy.ext
COPY tomcat-platform-context.xml ${TOMCAT_DIR}/conf/Catalina/localhost/alfresco.xml
COPY *.amp ${TOMCAT_DIR}/amps/
RUN java -jar ${TOMCAT_DIR}/alfresco-mmt/alfresco-mmt*.jar install ${TOMCAT_DIR}/amps ${TOMCAT_DIR}/webapps/alfresco -nobackup -directory && \
mkdir -p ${TOMCAT_DIR}/modules/platform && \
cat /tmp/catalina.policy.ext >> ${TOMCAT_DIR}/conf/catalina.policy
USER ${USERNAME}
@@ -0,0 +1,3 @@
## Usage
Download all AMP files needed into this directory. All of them will be copied into a new Docker image and installed into the Alfresco Platform web application.
@@ -0,0 +1,4 @@
grant codeBase "file:${catalina.base}/modules/-" {
permission java.security.AllPermission;
};
@@ -0,0 +1,6 @@
<?xml version="1.0" encoding="utf-8" ?>
<Context>
<Resources>
<PreResources base="${catalina.base}/modules/platform" className="org.apache.catalina.webresources.DirResourceSet" webAppMount="/WEB-INF/lib" readOnly="true" />
</Resources>
</Context>
@@ -0,0 +1,3 @@
## Usage
Download all JAR module files needed into this directory. All of them will be dynamically loaded into the Docker container and loaded into the Alfresco Platform web application.
+40 -1
View File
@@ -3,8 +3,47 @@
version: "3"
services:
platform:
build:
context: ./alfresco-content-repository/docker
args:
ACS_TAG: ${ACS_TAG}
image: local/alfresco-content-repository:latest
environment:
JAVA_TOOL_OPTIONS: "
-Dencryption.keystore.type=JCEKS
-Dencryption.cipherAlgorithm=DESede/CBC/PKCS5Padding
-Dencryption.keyAlgorithm=DESede
-Dencryption.keystore.location=/usr/local/tomcat/shared/classes/alfresco/extension/keystore/keystore
-Dmetadata-keystore.password=mp6yc0UD9e
-Dmetadata-keystore.aliases=metadata
-Dmetadata-keystore.metadata.password=oKIWzVdEdA
-Dmetadata-keystore.metadata.algorithm=DESede"
JAVA_OPTS: "
-Ddb.driver=org.postgresql.Driver
-Ddb.url=jdbc:postgresql://postgres-acs:5432/alfresco
-Dalfresco.host=${PROXY_HOST}
-Dalfresco.port=${PROXY_PORT}
-Dalfresco.protocol=${PROXY_PROTOCOL}
-Dmessaging.broker.url=\"failover:(nio://activemq:61616)?timeout=3000&jms.useCompression=true\"
"
depends_on:
- postgres-acs
- activemq
volumes:
- "./alfresco-content-repository/modules:/usr/local/tomcat/modules/platform:ro"
postgres-acs:
image: postgres:${POSTGRES_TAG}
activemq:
image: alfresco/alfresco-activemq:${AAMQ_TAG}
proxy:
build: ./nginx-ingress
image: local/nginx-ingress:base
image: local/nginx-ingress:acs
ports:
- 8080:8080
depends_on:
- platform
+4
View File
@@ -1,5 +1,9 @@
#!/bin/sh
if [[ $ACS_PLATFORM_URL ]]; then
sed -i s%http:\/\/platform:8080%"$ACS_PLATFORM_URL"%g /etc/nginx/nginx.conf
fi
if [[ $ACCESS_LOG ]]; then
sed -i s%\#ENV_ACCESS_LOG%"access_log $ACCESS_LOG;"%g /etc/nginx/nginx.conf
fi
+23
View File
@@ -25,5 +25,28 @@ http {
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_pass_header Set-Cookie;
# Protect access to SOLR APIs
location ~ ^(/.*/service/api/solr/.*)$ {return 403;}
location ~ ^(/.*/s/api/solr/.*)$ {return 403;}
location ~ ^(/.*/wcservice/api/solr/.*)$ {return 403;}
location ~ ^(/.*/wcs/api/solr/.*)$ {return 403;}
location ~ ^(/.*/proxy/alfresco/api/solr/.*)$ {return 403 ;}
location ~ ^(/.*/-default-/proxy/alfresco/api/.*)$ {return 403;}
# Protect access to Prometheus endpoint
location ~ ^(/.*/s/prometheus)$ {return 403;}
location / {
proxy_pass http://platform:8080;
}
location /alfresco/ {
proxy_pass http://platform:8080;
# If using external proxy / load balancer (for initial redirect if no trailing slash)
absolute_redirect off;
}
}
}