Compare commits
44 Commits
v0.1.119
...
0db752b6ed
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0db752b6ed | ||
| d7f33aec85 | |||
| fb13d499e7 | |||
| ab2fd80497 | |||
| 71cba01d09 | |||
|
|
2ae6306c82 | ||
|
|
c336e68347 | ||
|
|
bab3024a7d | ||
|
|
5d56c2cb04 | ||
|
|
2d81c3b588 | ||
|
|
c28000a396 | ||
|
|
53c66c29cd | ||
|
|
b67a7a6941 | ||
|
|
2c829792f4 | ||
|
|
12fdaa7e25 | ||
| 41f39f62a1 | |||
| 675009ca4f | |||
| 124c4ef949 | |||
| d45a524d6b | |||
| a3be7882db | |||
| 92a3d90b29 | |||
| bd7bbcb65d | |||
| 9cf03586b1 | |||
| 629fb6e680 | |||
| 706a82375e | |||
| 515de87fbf | |||
| 5e13d1ca4d | |||
| 772d6ab447 | |||
|
|
5d9e6b329f | ||
|
|
8f1c87e6e5 | ||
|
|
b0cc66724b | ||
|
|
974c988fc0 | ||
|
|
d44ef4a13f | ||
| eb300ed36d | |||
| de5bae9791 | |||
| 38854d33c6 | |||
| 4f91b7ac83 | |||
| 415148de88 | |||
| 973aabe927 | |||
| 023dd2e42e | |||
| ba22efa440 | |||
| e25dc5675a | |||
| 74fd34d608 | |||
| 89e5f2c202 |
@@ -1,110 +1,34 @@
|
|||||||
# Ente Cloudron App Build and Installation Instructions
|
# Ente Cloudron – Quick Guide
|
||||||
|
|
||||||
This document provides detailed instructions for building and installing the Ente Cloudron app, an open-source, end-to-end encrypted photo storage and authentication solution.
|
## Build
|
||||||
|
```bash
|
||||||
|
git clone https://github.com/andreasdueren/ente-cloudron.git
|
||||||
|
cd ente-cloudron
|
||||||
|
|
||||||
## Prerequisites
|
cloudron build \
|
||||||
|
--set-build-service builder.docker.due.ren \
|
||||||
|
--build-service-token e3265de06b1d0e7bb38400539012a8433a74c2c96a17955e \
|
||||||
|
--set-repository andreasdueren/ente-cloudron \
|
||||||
|
--tag 0.4.5
|
||||||
|
```
|
||||||
|
|
||||||
- **Cloudron CLI**: Ensure the Cloudron CLI is installed and configured on your system. Refer to [Cloudron CLI Documentation](https://docs.cloudron.io/packaging/cli/) for setup instructions.
|
## Install
|
||||||
- **Docker**: Required for local testing or custom builds if needed.
|
```bash
|
||||||
- **Git**: To clone or manage the repository.
|
cloudron install \
|
||||||
- **Repository Access**: Ensure you have access to the Ente Cloudron repository at `andreasdueren/ente-cloudron`.
|
--location ente.due.ren \
|
||||||
- **Build Service Token**: A token for the Cloudron build service is required (provided in the command below).
|
--image andreasdueren/ente-cloudron:0.4.5
|
||||||
|
```
|
||||||
|
|
||||||
## Build Commands
|
## After Install
|
||||||
|
1. **S3** – In Cloudron File Manager open `/app/data/config/s3.env`, fill in your endpoint/region/bucket/access/secret, then restart the app from the dashboard.
|
||||||
|
2. **Subdomains** – In the Cloudron *Domains* tab add aliases for `auth.<app-domain>`, `accounts.<app-domain>`, `cast.<app-domain>`, `albums.<app-domain>` and `family.<app-domain>`. Create matching DNS records pointing at the primary domain (for example, if the app is `ente.cloudron.io`, add `auth.ente.cloudron.io`, `accounts.ente.cloudron.io`, etc. → `ente.cloudron.io`).
|
||||||
|
|
||||||
1. **Clone the Repository** (if not already done):
|
Once DNS propagates, use the dedicated hosts:
|
||||||
```bash
|
- `https://<app-host>` (the hostname you chose during install, main UI & uploads)
|
||||||
git clone https://github.com/andreasdueren/ente-cloudron.git
|
- `https://accounts.<app-domain>`
|
||||||
cd ente-cloudron
|
- `https://auth.<app-domain>`
|
||||||
```
|
- `https://cast.<app-domain>`
|
||||||
|
- `https://albums.<app-domain>`
|
||||||
|
- `https://family.<app-domain>`
|
||||||
|
|
||||||
2. **Build the App Using Cloudron Build Service**:
|
Check `cloudron logs --app ente.due.ren -f` or `/app/data/logs/startup.log` if anything looks off.
|
||||||
Use the provided build service and token to build the app. Replace `<version>` with the desired version tag (e.g., `0.1.0` or as per `CloudronManifest.json`).
|
|
||||||
```bash
|
|
||||||
cloudron build --set-build-service builder.docker.due.ren --build-service-token e3265de06b1d0e7bb38400539012a8433a74c2c96a17955e --set-repository andreasdueren/ente-cloudron --tag 1.0.1
|
|
||||||
```
|
|
||||||
**Note**: The build process should complete within a reasonable time. Monitor the output for any errors.
|
|
||||||
|
|
||||||
## Installation Commands
|
|
||||||
|
|
||||||
1. **Install the App on Cloudron**:
|
|
||||||
After a successful build, install the app on your Cloudron instance at the desired location (e.g., `ente.due.ren`).
|
|
||||||
```bash
|
|
||||||
cloudron install --location ente.due.ren --image andreasdueren/ente-cloudron:1.0.1
|
|
||||||
```
|
|
||||||
**Important**: Do not wait more than 30 seconds for feedback after running the install command. If there's an error, the process may hang, and you should terminate it to troubleshoot.
|
|
||||||
**Note**: Always uninstall and reinstall during development rather than updating an existing app to ensure a clean setup.
|
|
||||||
|
|
||||||
## Testing Procedures
|
|
||||||
|
|
||||||
1. **Verify Installation**:
|
|
||||||
- Access the app at `https://ente.due.ren` (or your configured domain).
|
|
||||||
- Ensure the Ente web interfaces (Photos, Accounts, Auth, Cast) load correctly.
|
|
||||||
|
|
||||||
2. **Check S3 Configuration**:
|
|
||||||
- Confirm that S3 environment variables are set in Cloudron app settings under the 'Environment Variables' section.
|
|
||||||
- Variables to check: `APP_S3_ENABLED`, `APP_S3_ENDPOINT`, `APP_S3_ACCESS_KEY_ID`, `APP_S3_SECRET_ACCESS_KEY`, `APP_S3_BUCKET`.
|
|
||||||
|
|
||||||
3. **Monitor Logs for Errors**:
|
|
||||||
- Use the Cloudron CLI to view logs:
|
|
||||||
```bash
|
|
||||||
cloudron logs --app ente.due.ren -f
|
|
||||||
```
|
|
||||||
- Alternatively, shell into the app for detailed log inspection:
|
|
||||||
```bash
|
|
||||||
cloudron exec --app ente.due.ren
|
|
||||||
tail -f /app/data/logs/*
|
|
||||||
```
|
|
||||||
- Look for S3 connection errors or other issues.
|
|
||||||
|
|
||||||
## Deployment Steps
|
|
||||||
|
|
||||||
1. **Post-Installation Configuration**:
|
|
||||||
- If S3 is not working, update the environment variables in Cloudron app settings and restart the app:
|
|
||||||
```bash
|
|
||||||
cloudron restart --app ente.due.ren
|
|
||||||
```
|
|
||||||
|
|
||||||
2. **User Authentication**:
|
|
||||||
- Ente uses its own authentication system. Ensure user registration and login work as expected.
|
|
||||||
- If OIDC integration is desired in the future, it can be configured using Cloudron's OIDC variables (`CLOUDRON_OIDC_IDENTIFIER`, `CLOUDRON_OIDC_CLIENT_ID`, `CLOUDRON_OIDC_CLIENT_SECRET`).
|
|
||||||
|
|
||||||
## Troubleshooting Common Issues
|
|
||||||
|
|
||||||
- **S3 Configuration Errors**:
|
|
||||||
- **Symptom**: App falls back to local storage or logs show S3 connection failures.
|
|
||||||
- **Solution**: Verify S3 environment variables in Cloudron settings. Test connectivity manually using AWS CLI (`aws s3 ls s3://<bucket> --endpoint-url <endpoint>`).
|
|
||||||
|
|
||||||
- **Build Failures**:
|
|
||||||
- **Symptom**: Build command errors out or hangs.
|
|
||||||
- **Solution**: Check network connectivity to the build service, ensure the token is correct, and review build logs for specific errors.
|
|
||||||
|
|
||||||
- **Installation Hangs**:
|
|
||||||
- **Symptom**: Install command does not complete within 30 seconds.
|
|
||||||
- **Solution**: Terminate the command and check Cloudron logs for errors (`cloudron logs --app ente.due.ren`). Reinstall if necessary.
|
|
||||||
|
|
||||||
- **App Not Starting**:
|
|
||||||
- **Symptom**: App shows as 'Stopped' or inaccessible after install.
|
|
||||||
- **Solution**: Check logs for startup errors (`cloudron logs --app ente.due.ren`). Ensure database connectivity and correct configuration.
|
|
||||||
|
|
||||||
## Configuration Examples
|
|
||||||
|
|
||||||
- **S3 Environment Variables** in Cloudron settings:
|
|
||||||
```
|
|
||||||
APP_S3_ENABLED=true
|
|
||||||
APP_S3_ENDPOINT=s3.amazonaws.com
|
|
||||||
APP_S3_ACCESS_KEY_ID=your_access_key
|
|
||||||
APP_S3_SECRET_ACCESS_KEY=your_secret_key
|
|
||||||
APP_S3_BUCKET=your_bucket_name
|
|
||||||
```
|
|
||||||
|
|
||||||
## Additional Resources
|
|
||||||
|
|
||||||
- **Cloudron Documentation**:
|
|
||||||
- [CLI](https://docs.cloudron.io/packaging/cli/)
|
|
||||||
- [Packaging Tutorial](https://docs.cloudron.io/packaging/tutorial/)
|
|
||||||
- [Manifest Reference](https://docs.cloudron.io/packaging/manifest/)
|
|
||||||
- [Addons Guide](https://docs.cloudron.io/packaging/addons/)
|
|
||||||
- [Cheat Sheet](https://docs.cloudron.io/packaging/cheat-sheet/)
|
|
||||||
|
|
||||||
For further assistance, contact the Ente team at `contact@ente.io` or refer to the GitHub repository at [https://github.com/ente-io/ente](https://github.com/ente-io/ente).
|
|
||||||
|
|||||||
33
CHANGELOG.md
33
CHANGELOG.md
@@ -1,5 +1,38 @@
|
|||||||
# Changelog
|
# Changelog
|
||||||
|
|
||||||
|
## 0.4.5 (2025-10-30)
|
||||||
|
|
||||||
|
* Serve photos UI on the primary hostname and mount other apps on `accounts/auth/cast/albums/family.<app-domain>`
|
||||||
|
* Enable multiDomain in the manifest so aliases can be set in Cloudron UI
|
||||||
|
* Simplified documentation for S3 setup and alias domains
|
||||||
|
* Fix CORS responses for auth subdomains and forward real client IPs from Cloudron proxy
|
||||||
|
* Remove unsupported Caddy `trusted_proxies` stanza while continuing to trust Cloudron-provided `X-Forwarded-For` headers for accurate logging
|
||||||
|
* Set CORS headers via reverse proxy response rewrites so cross-subdomain logins work reliably
|
||||||
|
|
||||||
|
## 0.4.4 (2025-10-30)
|
||||||
|
|
||||||
|
* Restore Cloudflare R2 path-style URLs and simplify to a single hot-storage data center
|
||||||
|
* Serve the frontend apps on dedicated subdomains (photos/accounts/auth/cast/albums/family)
|
||||||
|
* Startup script now regenerates Caddy and Museum configs for the new host layout
|
||||||
|
* Added post-install checklist entries and updated docs for required DNS records
|
||||||
|
|
||||||
|
## 0.4.3 (2025-10-29)
|
||||||
|
|
||||||
|
* Always regenerate Museum configuration on startup to pick up S3 credential changes
|
||||||
|
* Enables seamless workflow: add S3 credentials to /app/data/config/s3.env and restart
|
||||||
|
* Fixes issue where S3 configuration changes required manual intervention
|
||||||
|
|
||||||
|
## 0.4.2 (2025-10-29)
|
||||||
|
|
||||||
|
* Use SMTPS (port 2465) with TLS encryption for email delivery
|
||||||
|
* Fixes email sending with requiresValidCertificate flag on Cloudron 9
|
||||||
|
|
||||||
|
## 0.4.1 (2025-10-23)
|
||||||
|
|
||||||
|
* Fix email sending for user registration by enabling TLS certificate validation in sendmail addon
|
||||||
|
* Add requiresValidCertificate flag to sendmail configuration to ensure proper SMTP authentication with Go applications
|
||||||
|
* Note: Requires Cloudron 9 or later for requiresValidCertificate support
|
||||||
|
|
||||||
## 1.0.0 (2024-06-01)
|
## 1.0.0 (2024-06-01)
|
||||||
|
|
||||||
* Initial release of Ente for Cloudron
|
* Initial release of Ente for Cloudron
|
||||||
|
|||||||
@@ -1,38 +1,42 @@
|
|||||||
{
|
{
|
||||||
"id": "io.ente.cloudronapp",
|
"id": "io.ente.cloudronapp",
|
||||||
"title": "Ente",
|
"title": "Ente",
|
||||||
"author": "Ente Authors",
|
"author": "Ente Development Team",
|
||||||
"description": "file://DESCRIPTION.md",
|
"description": "file://DESCRIPTION.md",
|
||||||
"changelog": "file://CHANGELOG.md",
|
"changelog": "file://CHANGELOG.md",
|
||||||
"contactEmail": "contact@ente.io",
|
"contactEmail": "contact@ente.io",
|
||||||
"tagline": "Open Source End-to-End Encrypted Photos & Authentication",
|
"website": "https://ente.io",
|
||||||
"upstreamVersion": "1.0.0",
|
"tagline": "Open source, end-to-end encrypted photo backup",
|
||||||
"version": "0.1.119",
|
"version": "0.4.5",
|
||||||
"healthCheckPath": "/ping",
|
"upstreamVersion": "git-main",
|
||||||
|
"healthCheckPath": "/health",
|
||||||
"httpPort": 3080,
|
"httpPort": 3080,
|
||||||
"memoryLimit": 1073741824,
|
"memoryLimit": 1610612736,
|
||||||
|
"postInstallMessage": "file://POSTINSTALL.md",
|
||||||
|
"multiDomain": true,
|
||||||
"addons": {
|
"addons": {
|
||||||
"localstorage": {},
|
"localstorage": {},
|
||||||
"postgresql": {},
|
"postgresql": {},
|
||||||
"email": {},
|
|
||||||
"sendmail": {
|
"sendmail": {
|
||||||
"supportsDisplayName": true
|
"supportsDisplayName": true,
|
||||||
|
"requiresValidCertificate": true
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"checklist": {
|
"checklist": {
|
||||||
"create-permanent-admin": {
|
"configure-object-storage": {
|
||||||
"message": "Required: S3 Storage Configuration!"
|
"message": "Configure your S3-compatible storage in /app/data/config/s3.env before first use."
|
||||||
|
},
|
||||||
|
"configure-subdomains": {
|
||||||
|
"message": "Create DNS records and add Cloudron aliases for accounts., auth., cast., albums. and family. (using the base domain of this app)."
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|
||||||
"icon": "file://logo.png",
|
"icon": "file://logo.png",
|
||||||
"tags": [
|
"tags": [
|
||||||
"photos",
|
"photos",
|
||||||
"authentication",
|
"encryption",
|
||||||
"e2ee",
|
"backup",
|
||||||
"encryption"
|
"self-hosting"
|
||||||
],
|
],
|
||||||
"manifestVersion": 2,
|
"manifestVersion": 2,
|
||||||
"minBoxVersion": "8.1.0",
|
"minBoxVersion": "8.1.0"
|
||||||
"website": "https://ente.io"
|
|
||||||
}
|
}
|
||||||
|
|||||||
245
Dockerfile
245
Dockerfile
@@ -1,175 +1,114 @@
|
|||||||
# Build Museum server from source
|
# syntax=docker/dockerfile:1
|
||||||
|
|
||||||
|
ARG ENTE_GIT_REF=main
|
||||||
|
|
||||||
|
FROM debian:bookworm AS ente-source
|
||||||
|
ARG ENTE_GIT_REF
|
||||||
|
RUN apt-get update && \
|
||||||
|
apt-get install -y --no-install-recommends ca-certificates git && \
|
||||||
|
git clone --depth=1 --branch "${ENTE_GIT_REF}" https://github.com/ente-io/ente.git /src && \
|
||||||
|
rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
FROM golang:1.24-bookworm AS museum-builder
|
FROM golang:1.24-bookworm AS museum-builder
|
||||||
|
COPY --from=ente-source /src /ente
|
||||||
WORKDIR /ente
|
|
||||||
|
|
||||||
# Clone the repository for server building
|
|
||||||
RUN apt-get update && apt-get install -y git libsodium-dev && \
|
|
||||||
git clone --depth=1 https://github.com/ente-io/ente.git . && \
|
|
||||||
apt-get clean && apt-get autoremove && \
|
|
||||||
rm -rf /var/cache/apt /var/lib/apt/lists
|
|
||||||
|
|
||||||
# Build the Museum server
|
|
||||||
WORKDIR /ente/server
|
WORKDIR /ente/server
|
||||||
RUN go mod download && \
|
RUN apt-get update && \
|
||||||
CGO_ENABLED=1 GOOS=linux go build -a -o museum ./cmd/museum
|
apt-get install -y --no-install-recommends build-essential pkg-config libsodium-dev && \
|
||||||
|
rm -rf /var/lib/apt/lists/*
|
||||||
FROM node:20-bookworm-slim as web-builder
|
RUN mkdir -p /build/museum && \
|
||||||
|
CGO_ENABLED=1 GOOS=linux go build -o /build/museum/museum ./cmd/museum && \
|
||||||
WORKDIR /ente
|
for dir in migrations web-templates mail-templates assets; do \
|
||||||
|
rm -rf "/build/museum/$dir"; \
|
||||||
# Clone the repository for web app building
|
if [ -d "$dir" ]; then \
|
||||||
RUN apt-get update && apt-get install -y git && \
|
cp -r "$dir" "/build/museum/$dir"; \
|
||||||
git clone --depth=1 https://github.com/ente-io/ente.git . && \
|
|
||||||
apt-get clean && apt-get autoremove && \
|
|
||||||
rm -rf /var/cache/apt /var/lib/apt/lists
|
|
||||||
|
|
||||||
# Will help default to yarn version 1.22.22
|
|
||||||
RUN corepack enable
|
|
||||||
|
|
||||||
# Set environment variables for web app build - use relative endpoint
|
|
||||||
ENV NEXT_PUBLIC_ENTE_ENDPOINT="/api"
|
|
||||||
RUN echo "Building with relative NEXT_PUBLIC_ENTE_ENDPOINT=/api for self-hosted deployment"
|
|
||||||
|
|
||||||
# Debugging the repository structure
|
|
||||||
RUN find . -type d -maxdepth 3 | sort
|
|
||||||
|
|
||||||
# Check if web directory exists with apps subdirectory
|
|
||||||
RUN mkdir -p /build/web/photos /build/web/accounts /build/web/auth /build/web/cast && \
|
|
||||||
if [ -d "web" ] && [ -d "web/apps" ]; then \
|
|
||||||
echo "Found web/apps directory, building web apps"; \
|
|
||||||
cd web && \
|
|
||||||
yarn cache clean && \
|
|
||||||
yarn install --network-timeout 1000000000 && \
|
|
||||||
yarn build:photos && \
|
|
||||||
yarn build:accounts && \
|
|
||||||
yarn build:auth && \
|
|
||||||
yarn build:cast && \
|
|
||||||
if [ -d "apps/photos/out" ]; then \
|
|
||||||
cp -r apps/photos/out/* /build/web/photos/; \
|
|
||||||
fi && \
|
|
||||||
if [ -d "apps/accounts/out" ]; then \
|
|
||||||
cp -r apps/accounts/out/* /build/web/accounts/; \
|
|
||||||
fi && \
|
|
||||||
if [ -d "apps/auth/out" ]; then \
|
|
||||||
cp -r apps/auth/out/* /build/web/auth/; \
|
|
||||||
fi && \
|
|
||||||
if [ -d "apps/cast/out" ]; then \
|
|
||||||
cp -r apps/cast/out/* /build/web/cast/; \
|
|
||||||
fi; \
|
|
||||||
elif [ -d "web" ]; then \
|
|
||||||
echo "Found web directory, looking for alternative structure"; \
|
|
||||||
find web -type d | grep -v node_modules | sort; \
|
|
||||||
if [ -d "web/photos" ]; then \
|
|
||||||
echo "Building photos app"; \
|
|
||||||
cd web/photos && yarn install && yarn build && \
|
|
||||||
if [ -d "out" ]; then cp -r out/* /build/web/photos/; fi; \
|
|
||||||
fi; \
|
|
||||||
if [ -d "web/accounts" ]; then \
|
|
||||||
echo "Building accounts app"; \
|
|
||||||
cd web/accounts && yarn install && yarn build && \
|
|
||||||
if [ -d "out" ]; then cp -r out/* /build/web/accounts/; fi; \
|
|
||||||
fi; \
|
|
||||||
if [ -d "web/auth" ]; then \
|
|
||||||
echo "Building auth app"; \
|
|
||||||
cd web/auth && yarn install && yarn build && \
|
|
||||||
if [ -d "out" ]; then cp -r out/* /build/web/auth/; fi; \
|
|
||||||
fi; \
|
|
||||||
if [ -d "web/cast" ]; then \
|
|
||||||
echo "Building cast app"; \
|
|
||||||
cd web/cast && yarn install && yarn build && \
|
|
||||||
if [ -d "out" ]; then cp -r out/* /build/web/cast/; fi; \
|
|
||||||
fi; \
|
|
||||||
else \
|
else \
|
||||||
echo "Web directory not found, creating placeholder web pages"; \
|
mkdir -p "/build/museum/$dir"; \
|
||||||
# Create placeholder HTML files for each app \
|
fi; \
|
||||||
mkdir -p /build/web/photos /build/web/accounts /build/web/auth /build/web/cast; \
|
done
|
||||||
echo "<html><body><h1>Ente Photos</h1><p>Web app not available. Please check the build logs.</p></body></html>" > /build/web/photos/index.html; \
|
|
||||||
echo "<html><body><h1>Ente Accounts</h1><p>Web app not available. Please check the build logs.</p></body></html>" > /build/web/accounts/index.html; \
|
FROM golang:1.24-bookworm AS cli-builder
|
||||||
echo "<html><body><h1>Ente Auth</h1><p>Web app not available. Please check the build logs.</p></body></html>" > /build/web/auth/index.html; \
|
COPY --from=ente-source /src /ente
|
||||||
echo "<html><body><h1>Ente Cast</h1><p>Web app not available. Please check the build logs.</p></body></html>" > /build/web/cast/index.html; \
|
WORKDIR /ente/cli
|
||||||
fi
|
RUN go build -o /build/ente .
|
||||||
|
|
||||||
|
FROM node:20-bookworm-slim AS web-builder
|
||||||
|
ENV NEXT_PUBLIC_ENTE_ENDPOINT=ENTE_API_ORIGIN_PLACEHOLDER
|
||||||
|
ENV NEXT_PUBLIC_ENTE_ALBUMS_ENDPOINT=https://albums.localhost.invalid
|
||||||
|
COPY --from=ente-source /src /ente
|
||||||
|
WORKDIR /ente/web
|
||||||
|
RUN apt-get update && \
|
||||||
|
apt-get install -y --no-install-recommends build-essential python3 && \
|
||||||
|
rm -rf /var/lib/apt/lists/*
|
||||||
|
RUN corepack enable
|
||||||
|
RUN yarn install --network-timeout 1000000
|
||||||
|
RUN mkdir -p /build/web/photos /build/web/accounts /build/web/auth /build/web/cast /build/web/albums /build/web/family
|
||||||
|
RUN set -e; \
|
||||||
|
yarn build:photos; \
|
||||||
|
yarn build:accounts; \
|
||||||
|
yarn build:auth; \
|
||||||
|
yarn build:cast
|
||||||
|
RUN if [ -d "apps" ]; then \
|
||||||
|
for app in photos accounts auth cast; do \
|
||||||
|
if [ -d "apps/${app}/out" ]; then \
|
||||||
|
rm -rf "/build/web/${app}"; \
|
||||||
|
mkdir -p "/build/web/${app}"; \
|
||||||
|
cp -r "apps/${app}/out/." "/build/web/${app}/"; \
|
||||||
|
else \
|
||||||
|
printf 'Missing build output for %s\n' "${app}"; \
|
||||||
|
printf '<html><body><h1>Ente %s</h1><p>Build output missing.</p></body></html>\n' "${app}" > "/build/web/${app}/index.html"; \
|
||||||
|
fi; \
|
||||||
|
done; \
|
||||||
|
else \
|
||||||
|
for app in photos accounts auth cast; do \
|
||||||
|
printf '<html><body><h1>Ente %s</h1><p>Build output missing.</p></body></html>\n' "${app}" > "/build/web/${app}/index.html"; \
|
||||||
|
done; \
|
||||||
|
fi && \
|
||||||
|
rm -rf /build/web/albums /build/web/family && \
|
||||||
|
cp -r /build/web/photos /build/web/albums && \
|
||||||
|
cp -r /build/web/photos /build/web/family
|
||||||
|
|
||||||
FROM cloudron/base:5.0.0@sha256:04fd70dbd8ad6149c19de39e35718e024417c3e01dc9c6637eaf4a41ec4e596c
|
FROM cloudron/base:5.0.0@sha256:04fd70dbd8ad6149c19de39e35718e024417c3e01dc9c6637eaf4a41ec4e596c
|
||||||
|
|
||||||
# Install necessary packages and Caddy webserver
|
ENV APP_DIR=/app/code \
|
||||||
|
DATA_DIR=/app/data \
|
||||||
|
HOME=/app/data/home
|
||||||
|
|
||||||
RUN apt-get update && \
|
RUN apt-get update && \
|
||||||
apt-get install -y curl git nodejs npm libsodium23 libsodium-dev pkg-config postgresql-client && \
|
apt-get install -y --no-install-recommends ca-certificates curl jq libsodium23 pkg-config postgresql-client caddy openssl && \
|
||||||
npm install -g yarn serve && \
|
rm -rf /var/lib/apt/lists/*
|
||||||
# Install Caddy for web server
|
|
||||||
apt-get install -y debian-keyring debian-archive-keyring apt-transport-https && \
|
|
||||||
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key' | gpg --dearmor -o /usr/share/keyrings/caddy-stable-archive-keyring.gpg && \
|
|
||||||
curl -1sLf 'https://dl.cloudsmith.io/public/caddy/stable/debian.deb.txt' | tee /etc/apt/sources.list.d/caddy-stable.list && \
|
|
||||||
apt-get update && \
|
|
||||||
apt-get install -y caddy && \
|
|
||||||
apt-get clean && apt-get autoremove && \
|
|
||||||
rm -rf /var/cache/apt /var/lib/apt/lists
|
|
||||||
|
|
||||||
# Install Go 1.24.1
|
RUN mkdir -p /app/pkg /app/web "$HOME" && chown -R cloudron:cloudron /app /app/web "$HOME"
|
||||||
RUN curl -L https://go.dev/dl/go1.24.1.linux-amd64.tar.gz -o go.tar.gz && \
|
|
||||||
rm -rf /usr/local/go && \
|
|
||||||
tar -C /usr/local -xzf go.tar.gz && \
|
|
||||||
rm go.tar.gz && \
|
|
||||||
ln -sf /usr/local/go/bin/go /usr/local/bin/go && \
|
|
||||||
ln -sf /usr/local/go/bin/gofmt /usr/local/bin/gofmt
|
|
||||||
|
|
||||||
# Set up directory structure
|
COPY --from=ente-source /src ${APP_DIR}
|
||||||
RUN mkdir -p /app/code /app/data/config /app/data/caddy /app/web
|
RUN rm -rf ${APP_DIR}/.git
|
||||||
|
|
||||||
WORKDIR /app/code
|
RUN mkdir -p /app/museum-bin
|
||||||
|
COPY --from=museum-builder /build/museum/museum /app/museum-bin/museum
|
||||||
|
COPY --from=museum-builder /build/museum/migrations ${APP_DIR}/server/migrations
|
||||||
|
COPY --from=museum-builder /build/museum/web-templates ${APP_DIR}/server/web-templates
|
||||||
|
COPY --from=museum-builder /build/museum/mail-templates ${APP_DIR}/server/mail-templates
|
||||||
|
COPY --from=museum-builder /build/museum/assets ${APP_DIR}/server/assets
|
||||||
|
RUN chmod +x /app/museum-bin/museum
|
||||||
|
|
||||||
# Clone the ente repository during build (for the Museum server)
|
COPY --from=cli-builder /build/ente /app/code/ente
|
||||||
RUN git clone --depth=1 https://github.com/ente-io/ente.git . && \
|
RUN ln -sf /app/code/ente /usr/local/bin/ente && chmod +x /app/code/ente
|
||||||
sed -i 's/go 1.23/go 1.24/' server/go.mod && \
|
|
||||||
mkdir -p /app/data/go && \
|
|
||||||
cp -r server/go.mod server/go.sum /app/data/go/ && \
|
|
||||||
chmod 777 /app/data/go/go.mod /app/data/go/go.sum
|
|
||||||
|
|
||||||
# Pre-download Go dependencies
|
|
||||||
RUN cd server && \
|
|
||||||
export GOMODCACHE="/app/data/go/pkg/mod" && \
|
|
||||||
export GOFLAGS="-modfile=/app/data/go/go.mod -mod=mod" && \
|
|
||||||
export GOTOOLCHAIN=local && \
|
|
||||||
export GO111MODULE=on && \
|
|
||||||
export GOSUMDB=off && \
|
|
||||||
mkdir -p /app/data/go/pkg/mod && \
|
|
||||||
chmod -R 777 /app/data/go && \
|
|
||||||
go mod download
|
|
||||||
|
|
||||||
# Set Go environment variables
|
|
||||||
ENV GOTOOLCHAIN=local
|
|
||||||
ENV GO111MODULE=on
|
|
||||||
ENV GOFLAGS="-modfile=/app/data/go/go.mod -mod=mod"
|
|
||||||
ENV PATH="/usr/local/go/bin:${PATH}"
|
|
||||||
ENV GOSUMDB=off
|
|
||||||
ENV GOMODCACHE="/app/data/go/pkg/mod"
|
|
||||||
|
|
||||||
# Copy the web app built files from the first stage
|
|
||||||
COPY --from=web-builder /build/web/photos /app/web/photos
|
COPY --from=web-builder /build/web/photos /app/web/photos
|
||||||
COPY --from=web-builder /build/web/accounts /app/web/accounts
|
COPY --from=web-builder /build/web/accounts /app/web/accounts
|
||||||
COPY --from=web-builder /build/web/auth /app/web/auth
|
COPY --from=web-builder /build/web/auth /app/web/auth
|
||||||
COPY --from=web-builder /build/web/cast /app/web/cast
|
COPY --from=web-builder /build/web/cast /app/web/cast
|
||||||
|
COPY --from=web-builder /build/web/albums /app/web/albums
|
||||||
|
COPY --from=web-builder /build/web/family /app/web/family
|
||||||
|
|
||||||
# Copy Museum server binary from builder stage to app directory (not data volume)
|
COPY start.sh /app/pkg/start.sh
|
||||||
RUN mkdir -p /app/museum-bin
|
COPY admin-helper.sh /app/pkg/admin-helper.sh
|
||||||
COPY --from=museum-builder /ente/server/museum /app/museum-bin/museum
|
COPY admin-helper-direct.sh /app/pkg/admin-helper-direct.sh
|
||||||
RUN chmod +x /app/museum-bin/museum
|
|
||||||
|
|
||||||
# Copy configuration and startup scripts
|
|
||||||
ADD start.sh /app/pkg/
|
|
||||||
ADD config.template.yaml /app/pkg/
|
|
||||||
ADD otp-email-monitor.js /app/pkg/
|
|
||||||
ADD package.json /app/pkg/
|
|
||||||
ADD admin-helper.sh /app/pkg/
|
|
||||||
ADD admin-helper-direct.sh /app/pkg/
|
|
||||||
|
|
||||||
# Set proper permissions
|
|
||||||
RUN chmod +x /app/pkg/start.sh /app/pkg/admin-helper.sh /app/pkg/admin-helper-direct.sh
|
RUN chmod +x /app/pkg/start.sh /app/pkg/admin-helper.sh /app/pkg/admin-helper-direct.sh
|
||||||
|
RUN ln -s /app/data/cli-data /cli-data && \
|
||||||
|
rm -rf /home/cloudron && \
|
||||||
|
ln -s /app/data/home /home/cloudron
|
||||||
|
|
||||||
# Expose the web port (Cloudron expects port 3080)
|
EXPOSE 3080 8080
|
||||||
EXPOSE 3080
|
|
||||||
# Also expose API port
|
|
||||||
EXPOSE 8080
|
|
||||||
|
|
||||||
# Start the application
|
|
||||||
CMD ["/app/pkg/start.sh"]
|
CMD ["/app/pkg/start.sh"]
|
||||||
|
|||||||
@@ -1,21 +1,52 @@
|
|||||||
Your Ente installation is almost ready!
|
Your Ente installation is almost ready!
|
||||||
|
|
||||||
## Required: S3 Storage Configuration
|
## Required: External Object Storage
|
||||||
|
|
||||||
Before you can use Ente, you need to configure an S3-compatible storage service:
|
Before using Ente, configure an S3-compatible object storage provider:
|
||||||
|
|
||||||
1. Go to your Cloudron dashboard
|
1. Open the Cloudron dashboard and select your Ente app.
|
||||||
2. Click on your Ente app
|
2. Launch the web terminal.
|
||||||
3. Click on "Terminal"
|
3. Edit `/app/data/config/s3.env` and provide values for **all** required keys:
|
||||||
4. Edit the S3 configuration file:
|
```bash
|
||||||
```
|
|
||||||
nano /app/data/config/s3.env
|
nano /app/data/config/s3.env
|
||||||
```
|
```
|
||||||
5. Uncomment the variables you need and fill in your S3 credentials (AWS S3, MinIO, DigitalOcean Spaces, etc.)
|
4. Save the file and restart the app from the Cloudron dashboard.
|
||||||
6. Save the file and restart your Ente app from the Cloudron dashboard
|
|
||||||
|
|
||||||
## Next Steps
|
Supported variables:
|
||||||
|
- `S3_ENDPOINT` (e.g. `https://<account>.r2.cloudflarestorage.com`)
|
||||||
|
- `S3_REGION`
|
||||||
|
- `S3_BUCKET`
|
||||||
|
- `S3_ACCESS_KEY`
|
||||||
|
- `S3_SECRET_KEY`
|
||||||
|
- `S3_PREFIX` (optional path prefix)
|
||||||
|
|
||||||
1. Once S3 is configured, visit your app URL to create an admin account
|
## Required: DNS Subdomains
|
||||||
2. Configure your mobile apps to use your custom self-hosted server (Settings → Advanced → Custom Server)
|
|
||||||
3. Enjoy your private, end-to-end encrypted photo storage!
|
Ente now serves supporting apps on dedicated hosts. Create DNS records (CNAME or A) and add matching alias domains in Cloudron for:
|
||||||
|
|
||||||
|
- `auth.<app-domain>`
|
||||||
|
- `accounts.<app-domain>`
|
||||||
|
- `cast.<app-domain>`
|
||||||
|
- `albums.<app-domain>`
|
||||||
|
- `family.<app-domain>`
|
||||||
|
|
||||||
|
For example, if you installed the app at `ente.cloudron.io`, create records for `auth.ente.cloudron.io`, `accounts.ente.cloudron.io`, etc., all pointing to `ente.cloudron.io`, then add each hostname as an alias in the Cloudron dashboard.
|
||||||
|
|
||||||
|
## Administration
|
||||||
|
|
||||||
|
- Use the bundled CLI from the Cloudron web terminal (CLI state lives in `/app/data/cli-data`):
|
||||||
|
```bash
|
||||||
|
cloudron exec --app ente.cloudron.io -- sudo -u cloudron ente --help
|
||||||
|
|
||||||
|
# Whitelist an administrator
|
||||||
|
cloudron exec --app ente.cloudron.io -- sudo -u cloudron ente admin user whitelist --email admin@example.com
|
||||||
|
|
||||||
|
# Increase a user’s storage allocation (in GB)
|
||||||
|
cloudron exec --app ente.cloudron.io -- sudo -u cloudron ente admin user quota set --email user@example.com --storage-gb 500
|
||||||
|
```
|
||||||
|
See the upstream admin guides for further context: [user administration](https://ente.io/help/self-hosting/administration/users) and [CLI reference](https://ente.io/help/self-hosting/administration/cli).
|
||||||
|
|
||||||
|
Logs are streamed to the Cloudron dashboard. For deeper inspection use:
|
||||||
|
```bash
|
||||||
|
cloudron logs --app <location> -f
|
||||||
|
```
|
||||||
|
|||||||
55
README.md
55
README.md
@@ -9,28 +9,6 @@ This repository contains the Cloudron packaging for [Ente](https://ente.io), an
|
|||||||
- Configured to use Cloudron's mail service for sending emails
|
- Configured to use Cloudron's mail service for sending emails
|
||||||
- Easy to deploy and manage through the Cloudron interface
|
- Easy to deploy and manage through the Cloudron interface
|
||||||
|
|
||||||
## Requirements
|
|
||||||
|
|
||||||
### Browser Compatibility
|
|
||||||
|
|
||||||
Ente uses modern web technologies for its end-to-end encryption:
|
|
||||||
|
|
||||||
- **WebAssembly**: Required for cryptographic operations
|
|
||||||
- **IndexedDB**: Required for client-side data storage
|
|
||||||
|
|
||||||
Most modern browsers support these features, but they may be blocked by:
|
|
||||||
- Browser privacy settings
|
|
||||||
- Content Security Policies
|
|
||||||
- Certain browser extensions
|
|
||||||
|
|
||||||
This package includes custom Caddy configuration with appropriate security headers to ensure these features work correctly.
|
|
||||||
|
|
||||||
### S3-Compatible Storage
|
|
||||||
|
|
||||||
Ente requires an S3-compatible object storage service. You can use:
|
|
||||||
- Cloudron's built-in object storage
|
|
||||||
- External services like AWS S3, Wasabi, or MinIO
|
|
||||||
|
|
||||||
## Building and Installing
|
## Building and Installing
|
||||||
|
|
||||||
### Option 1: Build and Install Manually
|
### Option 1: Build and Install Manually
|
||||||
@@ -73,23 +51,28 @@ The app is configured automatically using Cloudron's environment variables for:
|
|||||||
- SMTP mail service
|
- SMTP mail service
|
||||||
- App origin URL
|
- App origin URL
|
||||||
|
|
||||||
### Additional Configuration
|
### Cloudron Admin Notes
|
||||||
|
|
||||||
The package includes several enhancements to ensure proper functionality:
|
After installing on Cloudron remember to:
|
||||||
|
|
||||||
1. **Security Headers**: Custom Content-Security-Policy headers that allow WebAssembly and IndexedDB
|
1. Open the File Manager for the app, edit `/app/data/config/s3.env` with your object storage endpoint/keys, and restart the app.
|
||||||
2. **API Configuration**: Dynamic runtime configuration to ensure the frontend connects to the correct API endpoint
|
2. Add alias domains for `auth.<app-domain>`, `accounts.<app-domain>`, `cast.<app-domain>`, `albums.<app-domain>` and `family.<app-domain>` in the Cloudron **Domains** tab. Create matching DNS records pointing to the primary hostname (for example, if you installed at `ente.cloudron.io`, add `auth.ente.cloudron.io`, `accounts.ente.cloudron.io`, etc.).
|
||||||
3. **CORS Headers**: Proper CORS configuration for API access
|
3. Use the bundled Ente CLI for admin tasks via `cloudron exec --app <location> -- sudo -u cloudron ente --help`. The CLI stores its state in `/app/data/cli-data` (exposed inside the container at `/cli-data`) and already trusts your app’s API endpoint. Typical workflows:
|
||||||
|
```bash
|
||||||
|
# Whitelist an administrator (see https://ente.io/help/self-hosting/administration/users )
|
||||||
|
cloudron exec --app ente.cloudron.io -- sudo -u cloudron ente admin user whitelist --email admin@example.com
|
||||||
|
|
||||||
You need to manually set up and configure:
|
# Increase a user’s storage quota (see https://ente.io/help/self-hosting/administration/cli )
|
||||||
|
cloudron exec --app ente.cloudron.io -- sudo -u cloudron ente admin user quota set --email user@example.com --storage-gb 500
|
||||||
|
```
|
||||||
|
|
||||||
- S3-compatible object storage
|
The main photos UI continues to live on the hostname you selected during installation.
|
||||||
|
|
||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
### Web Client
|
### Web Client
|
||||||
|
|
||||||
After installation, you can access the Ente web client at your app's URL. Create an admin account on first use.
|
After installation, you can access the Ente web client at your app's URL. Create the first user and whitelist them as an administrator using the CLI if desired.
|
||||||
|
|
||||||
### Mobile Apps
|
### Mobile Apps
|
||||||
|
|
||||||
@@ -107,18 +90,6 @@ To update to a newer version:
|
|||||||
cloudron update --app ente.yourdomain.com
|
cloudron update --app ente.yourdomain.com
|
||||||
```
|
```
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
### Common Issues
|
|
||||||
|
|
||||||
1. **"Failed to fetch" errors**: Check if your browser is blocking API requests to your domain
|
|
||||||
2. **WebAssembly errors**: Ensure your browser supports and allows WebAssembly (try using Chrome or Firefox)
|
|
||||||
3. **IndexedDB errors**: Make sure your browser allows IndexedDB (not in private/incognito mode)
|
|
||||||
|
|
||||||
For issues specific to the Cloudron packaging, please open an issue in this repository.
|
|
||||||
|
|
||||||
For issues with Ente itself, please refer to the [main Ente repository](https://github.com/ente-io/ente).
|
|
||||||
|
|
||||||
## License
|
## License
|
||||||
|
|
||||||
This Cloudron package is licensed under the same license as Ente (Apache 2.0).
|
This Cloudron package is licensed under the same license as Ente (Apache 2.0).
|
||||||
@@ -2,7 +2,7 @@
|
|||||||
# Ente Admin Helper Script for Cloudron
|
# Ente Admin Helper Script for Cloudron
|
||||||
# This script simplifies admin operations in the Cloudron terminal
|
# This script simplifies admin operations in the Cloudron terminal
|
||||||
|
|
||||||
MUSEUM_BIN="/app/data/ente/server/museum"
|
MUSEUM_BIN="/app/museum-bin/museum"
|
||||||
|
|
||||||
# Check if museum binary exists
|
# Check if museum binary exists
|
||||||
if [ ! -f "$MUSEUM_BIN" ]; then
|
if [ ! -f "$MUSEUM_BIN" ]; then
|
||||||
@@ -26,7 +26,7 @@ update_subscription() {
|
|||||||
echo "Storage: ${storage_gb}GB"
|
echo "Storage: ${storage_gb}GB"
|
||||||
echo "Valid for: ${valid_days} days"
|
echo "Valid for: ${valid_days} days"
|
||||||
|
|
||||||
cd /app/data/ente/server
|
cd /app/data/museum
|
||||||
|
|
||||||
# Use environment variables for database connection
|
# Use environment variables for database connection
|
||||||
export DB_HOST="$CLOUDRON_POSTGRESQL_HOST"
|
export DB_HOST="$CLOUDRON_POSTGRESQL_HOST"
|
||||||
@@ -48,14 +48,14 @@ get_user_details() {
|
|||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
cd /app/data/ente/server
|
cd /app/data/museum
|
||||||
|
|
||||||
"$MUSEUM_BIN" admin get-user-details --user "$user_email"
|
"$MUSEUM_BIN" admin get-user-details --user "$user_email"
|
||||||
}
|
}
|
||||||
|
|
||||||
# Function to list all users
|
# Function to list all users
|
||||||
list_users() {
|
list_users() {
|
||||||
cd /app/data/ente/server
|
cd /app/data/museum
|
||||||
|
|
||||||
# Connect to PostgreSQL and list users
|
# Connect to PostgreSQL and list users
|
||||||
PGPASSWORD="$CLOUDRON_POSTGRESQL_PASSWORD" psql \
|
PGPASSWORD="$CLOUDRON_POSTGRESQL_PASSWORD" psql \
|
||||||
|
|||||||
@@ -18,16 +18,20 @@ database:
|
|||||||
maxIdleConns: 25
|
maxIdleConns: 25
|
||||||
connMaxLifetime: "1h"
|
connMaxLifetime: "1h"
|
||||||
|
|
||||||
storage:
|
s3:
|
||||||
type: "s3"
|
are_local_buckets: false
|
||||||
s3:
|
use_path_style_urls: true
|
||||||
|
hot_storage:
|
||||||
|
primary: b2-eu-cen
|
||||||
|
secondary: b2-eu-cen
|
||||||
|
derived-storage: b2-eu-cen
|
||||||
|
b2-eu-cen:
|
||||||
endpoint: "%%S3_ENDPOINT%%"
|
endpoint: "%%S3_ENDPOINT%%"
|
||||||
region: "%%S3_REGION%%"
|
region: "%%S3_REGION%%"
|
||||||
bucket: "%%S3_BUCKET%%"
|
bucket: "%%S3_BUCKET%%"
|
||||||
accessKey: "%%S3_ACCESS_KEY%%"
|
key: "%%S3_ACCESS_KEY%%"
|
||||||
secretKey: "%%S3_SECRET_KEY%%"
|
secret: "%%S3_SECRET_KEY%%"
|
||||||
prefix: "%%S3_PREFIX%%"
|
path_prefix: "%%S3_PREFIX%%"
|
||||||
forcePathStyle: true
|
|
||||||
|
|
||||||
email:
|
email:
|
||||||
smtp:
|
smtp:
|
||||||
|
|||||||
Reference in New Issue
Block a user