Skip to content

Latest commit

 

History

140 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Katta Compose

Compose

Katta: transform your S3 storage into a secure, team-friendly workspace with client-side encryption.

Docker Compose environment to run Katta Server with Keycloak, PostgreSQL and MinIO.

Usage

docker compose --profile demo up --wait
docker compose --profile demo down

Tip

Open Katta Web at http://hub.localhost:8280 and log in with username admin and password admin.

Warning

This environment is for development, testing and demos only. It uses well-known passwords and client secrets, a committed TLS key for Keycloak, and runs Keycloak and Katta Server in development mode.

Profiles

Profile Description
local Katta Server, Keycloak, PostgreSQL and MinIO.
demo Same as local, and creates storage profiles for MinIO with static and STS storage access in Katta Server.
hybrid Katta Server and PostgreSQL only, using an existing Keycloak and MinIO configured in the env file.

Configuration

All variables are set in .env, which Compose loads automatically. To provide your own values, pass a complete copy with --env-file, which replaces .env.

Variable Default Description
KATTA_CHART oci://ghcr.io/shift7-ch/katta-helm/katta-server Helm chart of Katta Server to render the Keycloak realm from. See Keycloak Realm.
KATTA_CHART_VERSION ^1 Version or version range of the Helm chart. Keep at the version of KATTA_SERVER_IMAGE. Leave empty for the latest version.
SETUP_DIR ./setup Directory with the MinIO policies, using the layout of setup.
KATTA_SERVER_IMAGE ghcr.io/shift7-ch/katta-server:latest Image to build Katta Server from.
HUB_INITIAL_LICENSE, HUB_INITIAL_ID License of Katta Server. .env sets a test license.
CSP_CONNECT_SRC_EXTRA Additional connect-src sources for the Content-Security-Policy header of Katta Server, such as the S3 and STS endpoints of storage profiles.

Relative paths resolve against the directory containing compose.yaml. Use absolute paths to provide setup files from another project.

Keycloak Realm

The service keycloak-realm renders the realm with helm template from the realm template _realm.tpl of the Katta Server Helm chart from katta-helm using the variables of the env file, and Keycloak imports it on start. There is no realm file in this project. To render the realm from a local checkout of katta-helm instead, mount it into keycloak-realm with a Compose override file and set KATTA_CHART to the mount path.

After the import, the service keycloak-allow-http sets sslRequired to NONE for the master and the Katta realm, so that Keycloak accepts plain HTTP requests from the host. The realm does not enable direct access grants. The demo profile creates the storage profiles with the service account of client cryptomatorhub-system.

Changing Variables of a Running Environment

Compose resolves variables when it creates a container, so docker compose restart keeps the previous values. For example, after changing CSP_CONNECT_SRC_EXTRA, recreate only Katta Server with the profile the environment was started with:

docker compose --profile demo up -d --no-deps hub

To verify the Content-Security-Policy header, run:

curl -sI http://hub.localhost:8280/ | grep -i content-security-policy

Provisioned Users

User Password Description
admin admin Katta administrator and Keycloak realm administrator.
minioadmin minioadmin MinIO root user.
testuser top-secret MinIO user for static storage access.

The realm also contains the service account of the cryptomatorhub-system client used by Katta Server.

Endpoints

Component URL Discovery
Katta Web http://hub.localhost:8280
Katta API http://hub.localhost:8280 http://hub.localhost:8280/api/config
Keycloak http://keycloak.localhost:8380 http://keycloak.localhost:8380/realms/cryptomator/.well-known/openid-configuration
MinIO Console http://minio.localhost:9101
MinIO S3 API http://minio.localhost:9100

The hostnames are subdomains of localhost, which resolve to the loopback address on the host as specified in RFC 6761, and to the containers through network aliases inside the Docker network. Therefore, the same URLs work in the browser on the host and in the containers, such as for the issuer of tokens. Browsers and recent versions of curl resolve subdomains of localhost without DNS, but the system resolver of macOS does not. For other clients on the host, add the hostnames to /etc/hosts:

127.0.0.1 hub.localhost keycloak.localhost minio.localhost

Tip

To access with Katta Desktop over plain HTTP (no HTTPS/TLS required) in a development or test environment, install the Katta Server (HTTP) connection profile from Preferences → Profiles.

MinIO STS Setup

To configure MinIO for STS storage access with the local profile, use the setup minio command of the Katta Admin CLI:

katta setup minio --hubUrl http://hub.localhost:8280 --endpointUrl http://minio.localhost:9100 --accessKey=minioadmin --secretKey=minioadmin

Contents

Path Description
compose.yaml Services for Katta Server, Keycloak, PostgreSQL and MinIO.
.env Variables for running all services locally.
hub Image for Katta Server.
minio Image for MinIO.
minio-setup Image for the jobs configuring and tracing MinIO.
keycloak Self-signed certificate for HTTPS of Keycloak. For development only.
setup Default MinIO policies.

License

Licensed under the GNU Affero General Public License v3.0.

About

Docker Compose environment for Katta Server with Keycloak, PostgreSQL and MinIO

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors

Languages