Nothing was group-restricted, so customers saw Dashboard, Photos, Office
and the rest, plus Nextcloud's first-run and promo apps.
- Disable for everyone: firstrunwizard, recommendations, related_resources,
weather_status, survey_client, support, app_api, contactsinteraction,
photos. A refused disable now fails the play (occ exits 0 on "can't be
disabled").
- Restrict dashboard and office to staff. defaultapp=dashboard,files so
staff land on the dashboard and customers fall through to Files.
- libresign groups_request_sign pinned to staff and asserted in verify.
LibreSign itself is deliberately NOT group-restricted: that also blocks
anonymous requests and would break public signing links.
- profile.enabled=false; lookup_server="" (lookup_server_connector
can't be disabled).
- README: what customers can open.
Checked as a probe customer: apps=files,activity,libresign,text,viewer,
lands in Files, can't request signatures; staff land on Dashboard.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Customers are admin-created accounts in per-customer groups. They should
read what staff share with them and nothing else. Checked against a test
customer in the UI, and by running the sharee and contacts-menu search
services as that user.
- shareapi_exclude_groups=allow, list [admin]: only staff can share. Exclude
mode ("yes") only disables sharing for users whose groups are ALL
excluded, so it never catches a customer in their own group.
- User/group autocomplete off. By default a customer typing "bas" found the
owner's account. Staff share by exact group name; LibreSign signers are
found by email.
- New shares default to View only (shareapi_default_permissions=1).
- files default_quota 0 B, so customers get no personal storage. Staff in
cloud_debyltech_staff_users are exempted (skipped if not yet created).
- No "Leon Green" sample contact in new address books.
- The verify script fails the deploy if any isolation setting drifts.
- README: staff and customer onboarding checklist.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Enable LibreSign's email identify method (click-to-sign, no account
creation), remove the stamp background and collect signer metadata.
On Skudak these were only ever set in the admin UI. Without the email
method a fresh instance answers "No signers." for any outside address.
The verify script now asserts it.
- Store add_footer=true explicitly. The code already defaults to it, but
the 14.2 admin page shows unset as unchecked.
- trusted_proxies = the container's own address, read per deploy. Behind
rootless port forwarding every request arrives from it, so without this
X-Forwarded-For was ignored and every client shared one IP for
brute-force throttling.
- maintenance_window_start and default_phone_region, which clears the setup
warnings.
- Mail declares color-scheme "light only" so Apple Mail's dark mode doesn't
repaint the white ground and bury the black wordmark (asserted in verify).
- Idempotency: redis image fully qualified (docker.io/library/...), the
debyltechmail copy owned by the mapped www-data uid, and theming
compared before setting.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A de Byl Technologies LLC Nextcloud cloned from the Skudak instance:
LibreSign signing for people without an account, registration off
(admin-created accounts only), no Group Folders. DNS is a terraform-managed
ALIAS to fulfillr.debyltech.com.
- containers/debyltech/cloud.yml: nextcloud/mariadb/redis on port 8091.
It installs unattended on the first deploy, sends mail through SES as
noreply@debyltech.com, and re-asserts the Skudak LibreSign settings.
- files/debyltechmail: skudakmail rebranded, with a new black-and-white
wordmark and white web-UI logos.
- LibreSign is pinned to 14.2.2 from the GitHub release (sha256-checked)
rather than `occ app:install`. The app store served a same-day 14.2.3
whose tarball has no binary-signature metadata. 14.2.x also doesn't
create its own download dirs, so they're pre-created.
- The backup runs nightly at 04:15 to TrueNAS /mnt/glacier/debyltechcloud and
reaches personal iDrive via the "iDrive E2 Backup" task; the TrueNAS side
excludes /debyltechcloud/_backup/config/**.
- Fix the libresign:configure:check gate in both instances: '\berror\b'
becomes a backspace in Jinja and never matched, so a check reporting three
errors passed clean. Now '\\berror\\b'.
- vault: cloud_debyltech_* secrets.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>