From e7532f652277504071a5de445dccc5b8b00a5431 Mon Sep 17 00:00:00 2001 From: nold Date: Fri, 21 Jun 2024 08:32:52 +0200 Subject: [PATCH] update(nextcloud): upstream chart 5.0.0 --- projects/nextcloud/project.yaml | 9 +++------ projects/nextcloud/values/nextcloud.yaml | 25 ++++++++++++++++++++++++ 2 files changed, 28 insertions(+), 6 deletions(-) diff --git a/projects/nextcloud/project.yaml b/projects/nextcloud/project.yaml index 6c68a15e..eb061d03 100644 --- a/projects/nextcloud/project.yaml +++ b/projects/nextcloud/project.yaml @@ -11,12 +11,9 @@ config: apps: - name: nextcloud - #repoURL: https://nextcloud.github.io/helm - #chart: nextcloud - #targetRevision: 3.1.0 - repoURL: https://github.com/Nold360/nextcloud-helm - targetRevision: f/multifix - path: charts/nextcloud + repoURL: https://nextcloud.github.io/helm + chart: nextcloud + targetRevision: 5.0.0 secrets: - name: nextcloud-user keys: diff --git a/projects/nextcloud/values/nextcloud.yaml b/projects/nextcloud/values/nextcloud.yaml index 62c169a1..c3053377 100644 --- a/projects/nextcloud/values/nextcloud.yaml +++ b/projects/nextcloud/values/nextcloud.yaml @@ -80,6 +80,31 @@ ingress: external-dns.alpha.kubernetes.io/target: gnu.one external-dns.alpha.kubernetes.io/cloudflare-proxied: "false" + nginx.ingress.kubernetes.io/server-snippet: |- + server_tokens off; + proxy_hide_header X-Powered-By; + rewrite ^/.well-known/webfinger /index.php/.well-known/webfinger last; + rewrite ^/.well-known/nodeinfo /index.php/.well-known/nodeinfo last; + rewrite ^/.well-known/host-meta /public.php?service=host-meta last; + rewrite ^/.well-known/host-meta.json /public.php?service=host-meta-json; + location = /.well-known/carddav { + return 301 $scheme://$host/remote.php/dav; + } + location = /.well-known/caldav { + return 301 $scheme://$host/remote.php/dav; + } + location = /robots.txt { + allow all; + log_not_found off; + access_log off; + } + location ~ ^/(?:build|tests|config|lib|3rdparty|templates|data)/ { + deny all; + } + location ~ ^/(?:autotest|occ|issue|indie|db_|console) { + deny all; + } + tls: - secretName: nextcloud-tls hosts: