Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Announcements
  3. What's coming in 6.0 (take 2)

What's coming in 6.0 (take 2)

Scheduled Pinned Locked Moved Announcements
142 Posts 22 Posters 70.3k Views 24 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jimcavoliJ jimcavoli

    @moocloud_matt yeah, there's currently a box level NGINx proxy - my idea is to replace that with a very hand-wavy something else which may be capable of shimming authentication for those things that just don't have it inbuilt (Kong) or if we go a different route on that sort of thing, we could use Traefik or similar at that layer. I think the use cases are intriguing enough to at least try the Kong route and fall back to something like Traefik if need be

    MooCloud_MattM Offline
    MooCloud_MattM Offline
    MooCloud_Matt
    wrote on last edited by
    #87

    @jimcavoli
    for adding .htpasswd support ? or what kind of auth are you talking about?

    Matteo. R.
    Founder and Tech-Support Manager.
    MooCloud MSP
    Swiss Managed Service Provider

    jimcavoliJ 1 Reply Last reply
    0
    • MooCloud_MattM MooCloud_Matt

      @jimcavoli
      for adding .htpasswd support ? or what kind of auth are you talking about?

      jimcavoliJ Offline
      jimcavoliJ Offline
      jimcavoli
      App Dev
      wrote on last edited by
      #88

      @moocloud_matt Kong is a pretty expansive topic on its own, but the idea would be with it in charge of ingress/routing, you could have a simple add-on config that would take care of enabling a plugin like https://docs.konghq.com/hub/kong-inc/ldap-auth/ on the route to a particular app, so you could have HTTP basic auth, but completely backed by the full Cloudron user store for any app that doesn't have its own scheme, providing clean headers that could be easily handled by that app's eb server or whatever

      MooCloud_MattM 1 Reply Last reply
      0
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #89

        Kong is indeed a separate complex topic. I think for the moment, if we had some template that people can quickly copy over to the app to get auth screen/login, it will help already. @nebulon do we have such a template already ? (like the one we use for our internal apps).

        1 Reply Last reply
        1
        • jimcavoliJ jimcavoli

          @moocloud_matt Kong is a pretty expansive topic on its own, but the idea would be with it in charge of ingress/routing, you could have a simple add-on config that would take care of enabling a plugin like https://docs.konghq.com/hub/kong-inc/ldap-auth/ on the route to a particular app, so you could have HTTP basic auth, but completely backed by the full Cloudron user store for any app that doesn't have its own scheme, providing clean headers that could be easily handled by that app's eb server or whatever

          MooCloud_MattM Offline
          MooCloud_MattM Offline
          MooCloud_Matt
          wrote on last edited by MooCloud_Matt
          #90

          @jimcavoli
          i think that's possible with nginx too, the ldap backend for auth.
          Custom Template for nginx config, will be the best i think, especially for performance optimization.

          But this Kong proxy is interesting i will ask to my team, if they have use it.

          Matteo. R.
          Founder and Tech-Support Manager.
          MooCloud MSP
          Swiss Managed Service Provider

          LonkleL 1 Reply Last reply
          0
          • nebulonN Away
            nebulonN Away
            nebulon
            Staff
            wrote on last edited by
            #91

            @girish said in What's coming in 6.0 (take 2):

            Kong is indeed a separate complex topic. I think for the moment, if we had some template that people can quickly copy over to the app to get auth screen/login, it will help already. @nebulon do we have such a template already ? (like the one we use for our internal apps).

            Yes in various shapes, but all nodejs based. This would be trivial to add, however if many of those apps are just apache+php does it make sense to add supervisor+nodejs+someproxy to those apps just for a login screen?

            1 Reply Last reply
            0
            • avatar1024A Offline
              avatar1024A Offline
              avatar1024
              wrote on last edited by
              #92

              @girish quick question in the mailbox sharing feature. If you make it so that a single inbox can have multiple owners (great feature btw), do you think it would then be possible to have the option to set a group as the owner so the mailbox ownership gets dynamically updated with changes in group membership? Thanks

              girishG avatar1024A 2 Replies Last reply
              2
              • avatar1024A avatar1024

                @girish quick question in the mailbox sharing feature. If you make it so that a single inbox can have multiple owners (great feature btw), do you think it would then be possible to have the option to set a group as the owner so the mailbox ownership gets dynamically updated with changes in group membership? Thanks

                girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by
                #93

                @avatar1024 Yes, that's the idea. The ownership will be dynamic.

                That said, the initial outlook for the feature is not looking so good. There are two issues that need to be sorted out (suggestions/ideas welcome):

                • Apps like SOGo show the "display name" of the user in the main UI. With a shared mailbox, it's not clear where this name should come from. With a single user, we give SOGo, the user's name. With multiple users, it's not clear what this should be.

                • The authentication (from a user's point of view) is a bit confusing. Or maybe it's not, I would welcome some feedback here. You have to authenticate with the user's username/password but use the shared mailbox as the mailbox name. In some ways, this is the case already, when you use a different mailbox name with a different username.

                avatar1024A ei8fdbE 2 Replies Last reply
                1
                • girishG girish

                  @avatar1024 Yes, that's the idea. The ownership will be dynamic.

                  That said, the initial outlook for the feature is not looking so good. There are two issues that need to be sorted out (suggestions/ideas welcome):

                  • Apps like SOGo show the "display name" of the user in the main UI. With a shared mailbox, it's not clear where this name should come from. With a single user, we give SOGo, the user's name. With multiple users, it's not clear what this should be.

                  • The authentication (from a user's point of view) is a bit confusing. Or maybe it's not, I would welcome some feedback here. You have to authenticate with the user's username/password but use the shared mailbox as the mailbox name. In some ways, this is the case already, when you use a different mailbox name with a different username.

                  avatar1024A Offline
                  avatar1024A Offline
                  avatar1024
                  wrote on last edited by avatar1024
                  #94

                  @girish thanks for the reply.

                  Perhaps there are a few things I do not understand about the technical implementation of such a feature but I will still try to give my opinion. As you describe in the first post on this thread the idea is, rather that a "shared mailbox" as such, to have a single mailbox with multiple owners, so:

                  • for point 1) I suppose you mean that the name of the "owner" is fed to the app when the owner is assigned to the mailbox rather than when the user logs in? If so, would it possible to feed the name of the user that logs in into that (which will be recognised through its unique pair of credential: mailbox name + its unique password). If not then I'd say, as a first implementation of this feature (which could be improved later), then the name of the mailbox (as in the prefix before the @) should be fed to the app as the Display Name, when more than one owner are set to that mailbox

                  • for point 2, then yes, as you say the username (for login) should just remain the full mailbox email address (just that in the case of a shared one, one username will but associated to multiple passwords as valid login credentials).

                  1 Reply Last reply
                  1
                  • avatar1024A avatar1024

                    @girish quick question in the mailbox sharing feature. If you make it so that a single inbox can have multiple owners (great feature btw), do you think it would then be possible to have the option to set a group as the owner so the mailbox ownership gets dynamically updated with changes in group membership? Thanks

                    avatar1024A Offline
                    avatar1024A Offline
                    avatar1024
                    wrote on last edited by avatar1024
                    #95

                    @girish Or as I suggested in my previous post, if we could assign a "group" as the owner of a mailbox, then group name could be fed as the Display Name (for point 1) and you potentially use the group name for the login username (for point 2).

                    @avatar1024 said in What's coming in 6.0 (take 2):

                    ...be possible to have the option to set a group as the owner...

                    girishG 1 Reply Last reply
                    2
                    • avatar1024A avatar1024

                      @girish Or as I suggested in my previous post, if we could assign a "group" as the owner of a mailbox, then group name could be fed as the Display Name (for point 1) and you potentially use the group name for the login username (for point 2).

                      @avatar1024 said in What's coming in 6.0 (take 2):

                      ...be possible to have the option to set a group as the owner...

                      girishG Offline
                      girishG Offline
                      girish
                      Staff
                      wrote on last edited by
                      #96

                      @avatar1024 said in What's coming in 6.0 (take 2):

                      @girish Or as I suggested in my previous post, if we could assign a "group" as the owner of a mailbox, then group name could be fed as the Display Name (for point 1) and you potentially use the group name for the login username (for point 2).

                      Making shared mailbox feature work only with groups is an excellent idea! I have to try this out and get back on how well this works.

                      avatar1024A 1 Reply Last reply
                      4
                      • MooCloud_MattM MooCloud_Matt

                        @jimcavoli
                        i think that's possible with nginx too, the ldap backend for auth.
                        Custom Template for nginx config, will be the best i think, especially for performance optimization.

                        But this Kong proxy is interesting i will ask to my team, if they have use it.

                        LonkleL Offline
                        LonkleL Offline
                        Lonkle
                        wrote on last edited by
                        #97

                        @moocloud_matt said in What's coming in 6.0 (take 2):

                        @jimcavoli
                        i think that's possible with nginx too, the ldap backend for auth.
                        Custom Template for nginx config, will be the best i think, especially for performance optimization.

                        But this Kong proxy is interesting i will ask to my team, if they have use it.

                        Should we branch this topic off into its own thread about centralized authentication? It seems like an important aspect to discuss but this thread is about 6.0, which this couldn't be a part of, right? This would be further down the road? @girish @nebulon

                        1 Reply Last reply
                        2
                        • girishG girish

                          @avatar1024 said in What's coming in 6.0 (take 2):

                          @girish Or as I suggested in my previous post, if we could assign a "group" as the owner of a mailbox, then group name could be fed as the Display Name (for point 1) and you potentially use the group name for the login username (for point 2).

                          Making shared mailbox feature work only with groups is an excellent idea! I have to try this out and get back on how well this works.

                          avatar1024A Offline
                          avatar1024A Offline
                          avatar1024
                          wrote on last edited by
                          #98

                          @girish Glad it was at least a useful suggestion. Let's see if it works in practice 🙂

                          girishG 1 Reply Last reply
                          1
                          • avatar1024A avatar1024

                            @girish Glad it was at least a useful suggestion. Let's see if it works in practice 🙂

                            girishG Offline
                            girishG Offline
                            girish
                            Staff
                            wrote on last edited by
                            #99

                            @avatar1024 That worked out quite nicely. You can now select a group as owner of a mailbox. founders and sales-team are groups in the screenshot below.

                            583602c4-1c06-46ee-ab8b-693fcea05b35-image.png

                            marcusquinnM ? 2 Replies Last reply
                            8
                            • girishG girish

                              @avatar1024 That worked out quite nicely. You can now select a group as owner of a mailbox. founders and sales-team are groups in the screenshot below.

                              583602c4-1c06-46ee-ab8b-693fcea05b35-image.png

                              marcusquinnM Offline
                              marcusquinnM Offline
                              marcusquinn
                              wrote on last edited by
                              #100

                              @girish Will each person's password work for IMAP/SMTP? (users in the group)

                              Web Design https://www.evergreen.je
                              Development https://brandlight.org
                              Life https://marcusquinn.com

                              girishG 1 Reply Last reply
                              0
                              • marcusquinnM marcusquinn

                                @girish Will each person's password work for IMAP/SMTP? (users in the group)

                                girishG Offline
                                girishG Offline
                                girish
                                Staff
                                wrote on last edited by
                                #101

                                @marcusquinn Yes, that's the idea. Each user can use their own password for sending/receiving with same mailbox.

                                1 Reply Last reply
                                5
                                • girishG girish

                                  @avatar1024 That worked out quite nicely. You can now select a group as owner of a mailbox. founders and sales-team are groups in the screenshot below.

                                  583602c4-1c06-46ee-ab8b-693fcea05b35-image.png

                                  ? Offline
                                  ? Offline
                                  A Former User
                                  wrote on last edited by
                                  #102

                                  @girish Just a suggestion, but IMO it should have two dropdowns like the access section for apps. One for users and one for groups. Unsure of the implementation details but that just stood out to me.

                                  girishG 2 Replies Last reply
                                  0
                                  • ? A Former User

                                    @girish Just a suggestion, but IMO it should have two dropdowns like the access section for apps. One for users and one for groups. Unsure of the implementation details but that just stood out to me.

                                    girishG Offline
                                    girishG Offline
                                    girish
                                    Staff
                                    wrote on last edited by
                                    #103

                                    @atrilahiji Currently, one can only choose a user or a group. This was just the initial UI anyway for testing the backend. I think we probably need select box with groups like

                                    cd45a8f6-3b3f-41d0-b79a-49c2550f6a9d-image.png

                                    marcusquinnM 1 Reply Last reply
                                    1
                                    • girishG girish

                                      @atrilahiji Currently, one can only choose a user or a group. This was just the initial UI anyway for testing the backend. I think we probably need select box with groups like

                                      cd45a8f6-3b3f-41d0-b79a-49c2550f6a9d-image.png

                                      marcusquinnM Offline
                                      marcusquinnM Offline
                                      marcusquinn
                                      wrote on last edited by
                                      #104

                                      @girish makes sense. Be good as an input-select box, so you can partial-type what you're looking for in the case of long lists.

                                      Web Design https://www.evergreen.je
                                      Development https://brandlight.org
                                      Life https://marcusquinn.com

                                      1 Reply Last reply
                                      0
                                      • ? A Former User

                                        @girish Just a suggestion, but IMO it should have two dropdowns like the access section for apps. One for users and one for groups. Unsure of the implementation details but that just stood out to me.

                                        girishG Offline
                                        girishG Offline
                                        girish
                                        Staff
                                        wrote on last edited by
                                        #105

                                        @atrilahiji That was easy.

                                        7e27d6d6-5aa3-4bee-8cc2-25c50438e725-image.png

                                        @marcusquinn Yes, it's searchable like the one in user's/group's view. The search only appears with more than 5 users.

                                        1 Reply Last reply
                                        8
                                        • girishG girish

                                          Some updates on volume management. There is now a volume view.

                                          51ffb468-f11f-41cf-813f-c36e10ae0e3c-image.png

                                          You add a host path as a volume and give it a name. This is most likely some EBS/external hard disk/Block Storage. There is also the file manager integration (the button next to the delete button).

                                          You can then go to the app view and mount these volumes into the apps. There is a new Storage section.

                                          88466958-b414-40ae-bff6-32edf6dac6bc-image.png

                                          There is a section overload in the app configure view 🙂 We are looking to reducing the list of sections in the left pane. It's making things hard to find.

                                          ei8fdbE Offline
                                          ei8fdbE Offline
                                          ei8fdb
                                          wrote on last edited by
                                          #106

                                          @girish said in What's coming in 6.0 (take 2):

                                          There is a section overload in the app configure view We are looking to reducing the list of sections in the left pane. It's making things hard to find.

                                          Hi @girish I'd like to help with this if you're interested.

                                          girishG 1 Reply Last reply
                                          2
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search