From 1d9c844cadd15ced4bc2451b4142bff75c8c0d1b Mon Sep 17 00:00:00 2001 From: Danny Groenewegen Date: Sun, 2 Aug 2026 17:02:40 +0200 Subject: [PATCH 01/45] fix: remove -c max_connections flag from postgres command to fix pgautoupgrade The pgautoupgrade switch from 13.1.0+32.0.11-fpm was released untested and had a bug: the db service's `-c max_connections=...` command breaks pgautoupgrade, failing with `initdb: invalid option -- 'c'`. See pgautoupgrade/docker-pgautoupgrade#148 --- compose.postgres.yml | 3 ++- compose.yml | 2 +- release/next | 2 ++ 3 files changed, 5 insertions(+), 2 deletions(-) create mode 100644 release/next diff --git a/compose.postgres.yml b/compose.postgres.yml index cee110c..777f9df 100644 --- a/compose.postgres.yml +++ b/compose.postgres.yml @@ -11,7 +11,8 @@ services: db: image: "pgautoupgrade/pgautoupgrade:14-debian" - command: -c "max_connections=${MAX_DB_CONNECTIONS:-100}" + #setting max_connections with -c breaks pgautoupgrade + #command: -c "max_connections=${MAX_DB_CONNECTIONS:-100}" volumes: - "postgres:/var/lib/postgresql/data" networks: diff --git a/compose.yml b/compose.yml index 55cb91c..d974851 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=13.1.1+32.0.12-fpm" + - "coop-cloud.${STACK_NAME}.version=13.1.1+32.0.13-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" diff --git a/release/next b/release/next new file mode 100644 index 0000000..d71cfdc --- /dev/null +++ b/release/next @@ -0,0 +1,2 @@ +Important: +The pgautoupgrade switch from 13.1.0+32.0.11-fpm was released untested and had a bug: the db service's `-c max_connections=...` command breaks pgautoupgrade, failing with `initdb: invalid option -- 'c'`. If your db got stuck mid-upgrade on 13.1.0-13.1.4 with that error: restore the old data dir and remove the upgrade lock file. Then redeploy this version. From 3be4c3aa4a458da9a1bc31b4219689aec6c39f66 Mon Sep 17 00:00:00 2001 From: Danny Groenewegen Date: Sun, 2 Aug 2026 17:13:45 +0200 Subject: [PATCH 02/45] chore: publish 13.1.5+32.0.13-fpm release --- compose.yml | 2 +- release/{next => 13.1.5+32.0.13-fpm} | 0 2 files changed, 1 insertion(+), 1 deletion(-) rename release/{next => 13.1.5+32.0.13-fpm} (100%) diff --git a/compose.yml b/compose.yml index d974851..990d4b7 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=13.1.1+32.0.13-fpm" + - "coop-cloud.${STACK_NAME}.version=13.1.5+32.0.13-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" diff --git a/release/next b/release/13.1.5+32.0.13-fpm similarity index 100% rename from release/next rename to release/13.1.5+32.0.13-fpm From f9e57d1ec17e6e7846025a228160f6ed1e2261e6 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Sat, 8 Aug 2026 10:47:50 +0200 Subject: [PATCH 03/45] Last release for nextcloud-32 --- compose.fulltextsearch.yml | 2 +- compose.yml | 4 ++-- release/13.2.0+32-fpm | 1 + 3 files changed, 4 insertions(+), 3 deletions(-) create mode 100644 release/13.2.0+32-fpm diff --git a/compose.fulltextsearch.yml b/compose.fulltextsearch.yml index f6cd53d..bc85ca6 100644 --- a/compose.fulltextsearch.yml +++ b/compose.fulltextsearch.yml @@ -29,7 +29,7 @@ services: mode: 0600 searchindexer: - image: nextcloud:32.0.13-fpm + image: nextcloud:32-fpm volumes: - nextcloud:/var/www/html/ - nextapps:/var/www/html/custom_apps:cached diff --git a/compose.yml b/compose.yml index 990d4b7..4bb9666 100644 --- a/compose.yml +++ b/compose.yml @@ -48,7 +48,7 @@ services: start_period: 5m app: - image: nextcloud:32.0.13-fpm + image: nextcloud:32-fpm depends_on: - db configs: @@ -109,7 +109,7 @@ services: start_period: 15m cron: - image: nextcloud:32.0.13-fpm + image: nextcloud:32-fpm volumes: - nextcloud:/var/www/html/ - nextapps:/var/www/html/custom_apps:cached diff --git a/release/13.2.0+32-fpm b/release/13.2.0+32-fpm new file mode 100644 index 0000000..6fcc63a --- /dev/null +++ b/release/13.2.0+32-fpm @@ -0,0 +1 @@ +Last release for nextcloud-32, pointing to the latest version of nextcloud-32. From abd102e3a8aa5023e2f27155614af8aeab2d668e Mon Sep 17 00:00:00 2001 From: Danny Groenewegen Date: Sat, 8 Aug 2026 13:04:12 +0200 Subject: [PATCH 04/45] fix: align nginx_conf config name with its compose key Name dropped the _conf suffix, so abra's live-vs-desired lookup (keyed by compose config name) never matched and always showed nginx_conf as (new) on deploy, even when unchanged. --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 4bb9666..99626ae 100644 --- a/compose.yml +++ b/compose.yml @@ -154,7 +154,7 @@ volumes: configs: nginx_conf: - name: ${STACK_NAME}_nginx_${NGINX_CONF_VERSION} + name: ${STACK_NAME}_nginx_conf_${NGINX_CONF_VERSION} file: nginx.conf.tmpl template_driver: golang fpm_tune: From 14ec244f97cdb18f6f5fc1fa863d770dc74b959b Mon Sep 17 00:00:00 2001 From: Danny Groenewegen Date: Sun, 9 Aug 2026 20:48:18 +0200 Subject: [PATCH 05/45] fix: use pgautoupgrade's default healthcheck --- compose.postgres.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/compose.postgres.yml b/compose.postgres.yml index 777f9df..c3f071b 100644 --- a/compose.postgres.yml +++ b/compose.postgres.yml @@ -23,11 +23,11 @@ services: POSTGRES_DB: nextcloud secrets: - db_password - healthcheck: - test: ["CMD-SHELL", "pg_isready", "-U", "nextcloud"] - interval: 10s - timeout: 5s - retries: 5 + # The pgautoupgrade image already ships its own HEALTHCHECK. + # This runs pg_isready but also takes into accounts if pg_upgrade is being run. + # No need to override it here. + # healthcheck: + # test: ["CMD", "/usr/local/bin/pgautoupgrade-healthcheck.sh"] deploy: labels: backupbot.backup.pre-hook: "/pg_backup.sh backup" From 5d923d343f8cc45315d23254f98aeae73d8208e8 Mon Sep 17 00:00:00 2001 From: Danny Groenewegen Date: Sun, 9 Aug 2026 20:52:28 +0200 Subject: [PATCH 06/45] chore: publish 13.2.0+32-fpm release --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 99626ae..c596243 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=13.1.5+32.0.13-fpm" + - "coop-cloud.${STACK_NAME}.version=13.2.0+32-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" From 2fb279d96abcb173e699859e31a64fcabe530b12 Mon Sep 17 00:00:00 2001 From: Danny Groenewegen Date: Sun, 9 Aug 2026 22:03:22 +0200 Subject: [PATCH 07/45] feat: add check_major_upgrade abra.sh function to check readiness for the next major Checks version skip, pending DB upgrade, occ update:check status, and non-shipped app compatibility (with an apps.nextcloud.com fallback lookup) to verify if it looks safe to upgrade to the next Nextcloud major version. --- README.md | 44 +++++++++++++- abra.sh | 159 ++++++++++++++++++++++++++++++++++++++++++++++++++- release/next | 1 + 3 files changed, 201 insertions(+), 3 deletions(-) create mode 100644 release/next diff --git a/README.md b/README.md index dd86ffa..e0466f8 100644 --- a/README.md +++ b/README.md @@ -130,9 +130,49 @@ To disable dashboard app (since it is so corporate): - Configure a `defaultapp` in your `config.php` or use [apporder](https://apps.nextcloud.com/apps/apporder) ## Upgrading Nextcloud -Upgrading Nextcloud can be a hair raising experiance. They [don't support downgrading](https://docs.nextcloud.com/server/latest/admin_manual/maintenance/upgrade.html) even for minor versions. -Many of us have found that jumping major versions when upgrading is also a bad idea. We have however found that it's ok to skip minor version upgrades and go to the last minor version before a major version (e.g. 24.0.0 to 24.9.9 before going to 25.0.0). To extra cautious just upgrade one release at a time. Read the release notes and check your logs. +Upgrading Nextcloud can be a hair raising experiance. They +[don't support downgrading](https://docs.nextcloud.com/server/latest/admin_manual/maintenance/upgrade.html) +even for minor versions. + +### Upgrade path + +Many of us have found that jumping major versions when upgrading is a bad idea. +We have however found that it's ok to skip minor version upgrades and go to the +last minor version before a major version (e.g. 24.0.0 to 24.9.9 before going to +25.0.0). To be extra cautious just upgrade one release at a time. Read the +release notes and check your logs. + +### Checking upgrade readiness + +Before upgrading to a new major, check whether the instance (and its enabled +apps) look ready: + +`abra app cmd app check_major_upgrade` + +This checks that you're not skipping a major version, that there's no pending DB +upgrade left over from a previous update, and that every enabled non-shipped app +declares support for the target major (falling back to an apps.nextcloud.com +lookup to see if an app update would fix it). Shipped apps (`files`, `settings`, +etc.) are skipped since they come bundled and are upgraded within the Docker +image. Pass an explicit target major as the first argument (e.g. +`check_major_upgrade 33`) to check readiness for a specific major, or it +defaults to current major + 1. This is a sanity check, not a guarantee. Still +read Nextcloud's release notes for any +[critical changes between major versions](https://docs.nextcloud.com/server/stable/admin_manual/release_notes/index.html#critical-changes). + +### Staying on an old major version + +If you're not able to move to a new major version yet (e.g. because of app +incompatibility), note that (starting from v32) before we release a recipe +container a new major Nextcloud version, we also publish one more release of the +previous major that points its image at the floating `nextcloud:XX-fpm` tag +(e.g. `nextcloud:32-fpm`) instead of a pinned patch version. Deploying that +release is less predictable: every redeploy pulls whatever the latest `32-fpm` +build happens to be at that moment, rather than a fixed, reproducible version. +But it means you keep getting security patches for the old major if you can't +move to the next major. See [MAINTENANCE.md](./MAINTENANCE.md#release-cadence) +for how this fits into our release process. ## Upgrading Nextcloud apps (plug-ins) diff --git a/abra.sh b/abra.sh index af39f71..f201ab7 100644 --- a/abra.sh +++ b/abra.sh @@ -10,7 +10,8 @@ export CRONTAB_VERSION=v1 export PG_BACKUP_VERSION=v2 run_occ() { - su -p www-data -s /bin/sh -c "/var/www/html/occ $@" + # NOTE: uses $* (not $@) so this still works when called with multiple args as seperate words. + su -p www-data -s /bin/sh -c "/var/www/html/occ $*" } install_apps() { @@ -193,3 +194,159 @@ set_windowsfriendly_filenames() { upgrade_mariadb() { mariadb-upgrade -p`cat /run/secrets/db_root_password` } + +# Checks whether this instance looks ready to update to the next Nextcloud +# major version. +# +# Usage: +# abra app cmd app check_major_upgrade +# abra app cmd app check_major_upgrade 33 # check readiness for a specific target +# +# What it checks: +# - current version is exactly one major behind the target +# - no pending DB upgrade from a previous, unfinished update +# - whether a newer release is available on the current major +# (recommended before upgradeing to the next major) +# - every enabled, non-shipped app's compatibility with the target major +# - for apps that don't, whether apps.nextcloud.com already has a newer +# release that does +# +# It does NOT check every precondition, always read the release notes +# from Nextcloud too. +check_major_upgrade() { + target_major=$1 + + echo "=== Nextcloud major upgrade readiness check ===" + + status_json=$(run_occ status --output=json 2>/dev/null) + if [ -z "$status_json" ]; then + echo "[FAIL] Could not read 'occ status' - is Nextcloud installed and reachable?" + return 1 + fi + + current_version=$(echo "$status_json" | php -r '$d=json_decode(stream_get_contents(STDIN),true); echo $d["versionstring"] ?? "";') + current_major=${current_version%%.*} + needs_db_upgrade=$(echo "$status_json" | php -r '$d=json_decode(stream_get_contents(STDIN),true); echo ($d["needsDbUpgrade"] ?? false) ? "true" : "false";') + + if [ -z "$current_major" ]; then + echo "[FAIL] Could not determine the current Nextcloud version from 'occ status'." + return 1 + fi + + if [ -z "$target_major" ]; then + target_major=$((current_major + 1)) + fi + + echo "Current version: $current_version" + echo "Target major version: $target_major" + + ok=true + + if [ "$target_major" -le "$current_major" ]; then + echo "[FAIL] Target major ($target_major) is not newer than the current major ($current_major)." + ok=false + elif [ "$target_major" -gt "$((current_major + 1))" ]; then + echo "[FAIL] Cannot skip major versions. Upgrade to $((current_major + 1)) first." + ok=false + fi + + if [ "$needs_db_upgrade" = "true" ]; then + echo "[FAIL] A pending database upgrade was detected. Run 'occ upgrade' for the current version first." + ok=false + fi + + echo + echo "--- occ update:check ---" + update_check_output=$(run_occ "update:check" 2>&1) + if [ -z "$update_check_output" ]; then + echo "[WARN] 'occ update:check' produced no output, could not verify." + elif echo "$update_check_output" | grep -q "Everything up to date"; then + echo "[OK] Everything up to date." + else + available_version=$(echo "$update_check_output" | grep -oE 'Nextcloud [0-9]+\.[0-9]+\.[0-9]+(\.[0-9]+)?' | head -n1 | awk '{print $2}') + available_major=${available_version%%.*} + if [ -z "$available_major" ]; then + echo "[WARN] Could not parse 'occ update:check' output to determine the available version." + elif [ "$available_major" = "$current_major" ]; then + echo "[WARN] $available_version is available on the current major. Recommended to update to that before upgrading to $target_major." + else + echo "[OK] Already on the latest release of major $current_major (next available update is $available_version)." + fi + fi + echo + + echo "--- Non-shipped app compatibility with Nextcloud $target_major ---" + echo "(shipped apps are skipped, they come bundled with the docker image)" + apps_json=$(run_occ "app:list --shipped=false --enabled --output=json" 2>/dev/null) + + if [ -z "$apps_json" ]; then + echo "[WARN] 'occ app:list' returned no output, could not check non-shipped app compatibility." + enabled_apps="" + else + apps_json_valid=$(echo "$apps_json" | php -r '$d=json_decode(stream_get_contents(STDIN),true); echo (json_last_error() === JSON_ERROR_NONE && is_array($d)) ? "1" : "0";') + if [ "$apps_json_valid" != "1" ]; then + echo "[WARN] Could not parse 'occ app:list' output, could not check non-shipped app compatibility." + enabled_apps="" + else + enabled_apps=$(echo "$apps_json" | php -r '$d=json_decode(stream_get_contents(STDIN),true); foreach(array_keys($d["enabled"] ?? []) as $a) echo $a."\n";') + if [ -z "$enabled_apps" ]; then + echo "No non-shipped apps are enabled - nothing to check here." + fi + fi + fi + + compatible_apps="" + compatible_apps_fetched=0 + + for app in $enabled_apps; do + info_file=$(find /var/www/html/apps /var/www/html/custom_apps -maxdepth 3 -type f -ipath "*/$app/appinfo/info.xml" 2>/dev/null | head -n1) + + if [ -z "$info_file" ]; then + echo "[WARN] $app: could not locate appinfo/info.xml, skipping" + continue + fi + + max_version=$(php -r ' + $x = @simplexml_load_file($argv[1]); + $dep = $x ? ($x->dependencies->nextcloud ?? null) : null; + echo $dep !== null ? (string)$dep["max-version"] : ""; + ' "$info_file") + + if [ -z "$max_version" ]; then + echo "[WARN] $app: no max-version declared in info.xml, assume compatible but verify manually" + continue + fi + + if [ "${max_version%%.*}" -ge "$target_major" ] 2>/dev/null; then + echo "[OK] $app: installed version supports up to Nextcloud $max_version" + continue + fi + + echo "[INFO] $app: installed version only supports up to Nextcloud $max_version" + + if [ "$compatible_apps_fetched" != "1" ]; then + compatible_apps_fetched=1 + compatible_apps=$(curl -fsSL --max-time 30 "https://apps.nextcloud.com/api/v1/platform/${target_major}.0.0/apps.json" 2>/dev/null \ + | php -r '$d=json_decode(stream_get_contents(STDIN),true); if(is_array($d)) foreach($d as $a) echo $a["id"]."\n";') + fi + + if [ -z "$compatible_apps" ]; then + echo "[FAIL] $app: could not reach apps.nextcloud.com to check for a newer compatible release, verify manually" + ok=false + elif echo "$compatible_apps" | grep -qxF "$app"; then + echo "[WARN] $app: apps.nextcloud.com has a release that supports $target_major. It may not update until Nextcloud is upgraded, occ upgrade will try to update it automatically" + else + echo "[FAIL] $app: no apps.nextcloud.com release supports $target_major yet, it will be disabled during the upgrade" + ok=false + fi + done + + echo + if [ "$ok" = true ]; then + echo "=== READY: no blocking issues found for upgrade to major $target_major ===" + return 0 + else + echo "=== NOT READY: resolve the [FAIL] items above before running the upgrade ===" + return 1 + fi +} diff --git a/release/next b/release/next new file mode 100644 index 0000000..4c2a64c --- /dev/null +++ b/release/next @@ -0,0 +1 @@ +Added `check_major_upgrade` (`abra app cmd app check_major_upgrade`) to check whether an instance is ready to upgrade to the next Nextcloud major version. From 0998a98df5e3eb76c6efb35fe4645508e5b44690 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Sat, 8 Aug 2026 10:50:51 +0200 Subject: [PATCH 08/45] Updating to nextcloud 33.0.7 --- compose.fulltextsearch.yml | 2 +- compose.yml | 6 +++--- release/next | 14 +++++++++++++- 3 files changed, 17 insertions(+), 5 deletions(-) diff --git a/compose.fulltextsearch.yml b/compose.fulltextsearch.yml index bc85ca6..ef47b35 100644 --- a/compose.fulltextsearch.yml +++ b/compose.fulltextsearch.yml @@ -29,7 +29,7 @@ services: mode: 0600 searchindexer: - image: nextcloud:32-fpm + image: nextcloud:33.0.7-fpm volumes: - nextcloud:/var/www/html/ - nextapps:/var/www/html/custom_apps:cached diff --git a/compose.yml b/compose.yml index c596243..fb59d60 100644 --- a/compose.yml +++ b/compose.yml @@ -48,7 +48,7 @@ services: start_period: 5m app: - image: nextcloud:32-fpm + image: nextcloud:33.0.7-fpm depends_on: - db configs: @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=13.2.0+32-fpm" + - "coop-cloud.${STACK_NAME}.version=14.0.0+33.0.7-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" @@ -109,7 +109,7 @@ services: start_period: 15m cron: - image: nextcloud:32-fpm + image: nextcloud:33.0.7-fpm volumes: - nextcloud:/var/www/html/ - nextapps:/var/www/html/custom_apps:cached diff --git a/release/next b/release/next index 4c2a64c..7a815a2 100644 --- a/release/next +++ b/release/next @@ -1 +1,13 @@ -Added `check_major_upgrade` (`abra app cmd app check_major_upgrade`) to check whether an instance is ready to upgrade to the next Nextcloud major version. +Upgrades Nextcloud from 32.0.13 to 33 (major version upgrade). + +IMPORTANT: +- Nextcloud does NOT support downgrades. Take a backup before deploying. +- Do not skip major versions: your instance must be on the latest 32.x before + upgrading to 33. If you are on an older 32.x, deploy 32.0.13 first. +- After deploying, check the logs and run any pending repair/upgrade steps: + `abra app cmd app run_occ '"app:update --all"'` +- Review app (plug-in) compatibility with Nextcloud 33 before upgrading; some + apps may need to be updated or temporarily disabled. +- Added `check_major_upgrade` (`abra app cmd app check_major_upgrade`) + to check whether an instance is ready to upgrade to the next Nextcloud + major version. From 080fedc4b6237df471c2d21084f80db85c428995 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Tue, 11 Aug 2026 21:59:03 +0200 Subject: [PATCH 09/45] Re-arrange notes --- release/next | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/release/next b/release/next index 7a815a2..e104a8f 100644 --- a/release/next +++ b/release/next @@ -1,13 +1,13 @@ Upgrades Nextcloud from 32.0.13 to 33 (major version upgrade). IMPORTANT: -- Nextcloud does NOT support downgrades. Take a backup before deploying. - Do not skip major versions: your instance must be on the latest 32.x before upgrading to 33. If you are on an older 32.x, deploy 32.0.13 first. +- Added `check_major_upgrade` (`abra app cmd app check_major_upgrade`) + to check whether an instance is ready to upgrade to the next Nextcloud + major version. +- Nextcloud does NOT support downgrades. Take a backup before deploying. - After deploying, check the logs and run any pending repair/upgrade steps: `abra app cmd app run_occ '"app:update --all"'` - Review app (plug-in) compatibility with Nextcloud 33 before upgrading; some apps may need to be updated or temporarily disabled. -- Added `check_major_upgrade` (`abra app cmd app check_major_upgrade`) - to check whether an instance is ready to upgrade to the next Nextcloud - major version. From 2e0a4cf928462b9d1a4368a22a5b0663c8b59a55 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Tue, 11 Aug 2026 22:17:39 +0200 Subject: [PATCH 10/45] chore: publish 14.0.0+33.0.7-fpm release --- release/{next => 14.0.0+33.0.7-fpm} | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename release/{next => 14.0.0+33.0.7-fpm} (100%) diff --git a/release/next b/release/14.0.0+33.0.7-fpm similarity index 100% rename from release/next rename to release/14.0.0+33.0.7-fpm From 533f4bf66c0f6abfe82a23ca35ae965a61c9c066 Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Tue, 11 Aug 2026 14:16:53 +0000 Subject: [PATCH 11/45] chore(deps): update docker.elastic.co/elasticsearch/elasticsearch docker tag to v8.19.20 --- compose.fulltextsearch.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.fulltextsearch.yml b/compose.fulltextsearch.yml index ef47b35..341c592 100644 --- a/compose.fulltextsearch.yml +++ b/compose.fulltextsearch.yml @@ -2,7 +2,7 @@ version: "3.8" services: elasticsearch: - image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.19" + image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.20" environment: - cluster.name=docker-cluster - bootstrap.memory_lock=true From 2b23d5f6541fc007580f0fdef2b0690a2da4a676 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Tue, 11 Aug 2026 22:20:41 +0200 Subject: [PATCH 12/45] chore: publish 14.0.1+33.0.7-fpm release --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index fb59d60..2554d2b 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=14.0.0+33.0.7-fpm" + - "coop-cloud.${STACK_NAME}.version=14.0.1+33.0.7-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" From c0683807bb43381e68b6d4a2b424d9201e023314 Mon Sep 17 00:00:00 2001 From: Javielico <103+javielico@noreply.git.coopcloud.tech> Date: Mon, 10 Aug 2026 19:12:08 +0000 Subject: [PATCH 13/45] Adding myself as maintainer --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index e0466f8..8de10a1 100644 --- a/README.md +++ b/README.md @@ -5,7 +5,7 @@ Fully automated luxury Nextcloud via docker-swarm. -* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti) +* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti), [@javielico](https://git.coopcloud.tech/javielico) * **Category**: Apps * **Status**: 5 * **Image**: [`nextcloud`](https://hub.docker.com/_/nextcloud), 4, upstream From bac93fd4a5c37a32c112ac6ffb93b5bd30fdd4f6 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Tue, 11 Aug 2026 22:20:41 +0200 Subject: [PATCH 14/45] Update to postgresql-17 --- compose.postgres.yml | 2 +- release/next | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) create mode 100644 release/next diff --git a/compose.postgres.yml b/compose.postgres.yml index c3f071b..b9c581a 100644 --- a/compose.postgres.yml +++ b/compose.postgres.yml @@ -10,7 +10,7 @@ services: - NEXTCLOUD_UPDATE=1 db: - image: "pgautoupgrade/pgautoupgrade:14-debian" + image: "pgautoupgrade/pgautoupgrade:17-debian" #setting max_connections with -c breaks pgautoupgrade #command: -c "max_connections=${MAX_DB_CONNECTIONS:-100}" volumes: diff --git a/release/next b/release/next new file mode 100644 index 0000000..10a29c1 --- /dev/null +++ b/release/next @@ -0,0 +1 @@ +Update pgautoupgrade to postgresql v17 \ No newline at end of file From 72562871ea818e736cd833a3a8c42a18a476bee5 Mon Sep 17 00:00:00 2001 From: Danny Groenewegen Date: Thu, 13 Aug 2026 12:20:17 +0200 Subject: [PATCH 15/45] chore: publish 14.1.0+33.0.7-fpm release --- compose.yml | 2 +- release/{next => 14.1.0+33.0.7-fpm} | 0 2 files changed, 1 insertion(+), 1 deletion(-) rename release/{next => 14.1.0+33.0.7-fpm} (100%) diff --git a/compose.yml b/compose.yml index 2554d2b..bf89823 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=14.0.1+33.0.7-fpm" + - "coop-cloud.${STACK_NAME}.version=14.1.0+33.0.7-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" diff --git a/release/next b/release/14.1.0+33.0.7-fpm similarity index 100% rename from release/next rename to release/14.1.0+33.0.7-fpm From fd01844b8fae85458d724fc7b19c6002da69c314 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Fri, 14 Aug 2026 11:19:19 +0200 Subject: [PATCH 16/45] Update to latest version --- compose.fulltextsearch.yml | 2 +- compose.yml | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/compose.fulltextsearch.yml b/compose.fulltextsearch.yml index 341c592..1e19d42 100644 --- a/compose.fulltextsearch.yml +++ b/compose.fulltextsearch.yml @@ -29,7 +29,7 @@ services: mode: 0600 searchindexer: - image: nextcloud:33.0.7-fpm + image: nextcloud:33.0.8-fpm volumes: - nextcloud:/var/www/html/ - nextapps:/var/www/html/custom_apps:cached diff --git a/compose.yml b/compose.yml index bf89823..b3b296b 100644 --- a/compose.yml +++ b/compose.yml @@ -48,7 +48,7 @@ services: start_period: 5m app: - image: nextcloud:33.0.7-fpm + image: nextcloud:33.0.8-fpm depends_on: - db configs: @@ -109,7 +109,7 @@ services: start_period: 15m cron: - image: nextcloud:33.0.7-fpm + image: nextcloud:33.0.8-fpm volumes: - nextcloud:/var/www/html/ - nextapps:/var/www/html/custom_apps:cached From 65e13ff3f30bae7fa3f1d730da8b3b6d5dabb9b0 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Fri, 14 Aug 2026 12:47:36 +0200 Subject: [PATCH 17/45] chore: publish 14.1.1+33.0.8-fpm release --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index b3b296b..46de6f4 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=14.1.0+33.0.7-fpm" + - "coop-cloud.${STACK_NAME}.version=14.1.1+33.0.8-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" From d40797dbda6d9b1c898237ee1a33242b2e4efb14 Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Wed, 19 Aug 2026 20:18:48 +0000 Subject: [PATCH 18/45] chore(deps): update nginx docker tag to v1.31.4 --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 46de6f4..c225f42 100644 --- a/compose.yml +++ b/compose.yml @@ -1,7 +1,7 @@ version: "3.8" services: web: - image: nginx:1.31.3 + image: nginx:1.31.4 depends_on: - app configs: From 364e3088f78d10333b9e449bf5ac7a77a5bb8050 Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Thu, 20 Aug 2026 17:25:39 +0000 Subject: [PATCH 19/45] chore(deps): update redis docker tag to v8.10.1 --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index c225f42..244c2ff 100644 --- a/compose.yml +++ b/compose.yml @@ -125,7 +125,7 @@ services: cache: - image: redis:8.8.1-alpine + image: redis:8.10.1-alpine networks: - internal volumes: From d2560c930495f92f04339c78ed41d88aca4bc00a Mon Sep 17 00:00:00 2001 From: Simon Date: Wed, 2 Sep 2026 11:34:45 +0200 Subject: [PATCH 20/45] add option to expose metrics via nextcloud-exporter --- .env.sample | 4 ++++ README.md | 11 +++++++++++ abra.sh | 4 ++++ compose.metrics.yml | 22 ++++++++++++++++++++++ 4 files changed, 41 insertions(+) create mode 100644 compose.metrics.yml diff --git a/.env.sample b/.env.sample index 3e84dc5..3180442 100644 --- a/.env.sample +++ b/.env.sample @@ -107,3 +107,7 @@ DEFAULT_QUOTA="10 GB" #HSTS_ENABLED=1 # Uncomment this line to add the `preload` part #HSTS_PRELOAD=1 + +# Metrics +# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" +# SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex \ No newline at end of file diff --git a/README.md b/README.md index b317d3e..03cd758 100644 --- a/README.md +++ b/README.md @@ -128,6 +128,17 @@ To disable dashboard app (since it is so corporate): - Configure a `defaultapp` in your `config.php` or use [apporder](https://apps.nextcloud.com/apps/apporder) +## Metrics + +There is a [metrics exporter](https://github.com/xperimental/nextcloud-exporter) that can be run as sidecar container, also part of the nextcloud helm charts. Its configured via alloys label-based auto-discovery provided by the updated [monitoring-stack](https://git.coopcloud.tech/coop-cloud/monitoring-ng) +To enable, uncomment +``` +COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" +SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex +``` +then generate the secret with abra and run +`abra app cmd app set_metrics_token` + ## Upgrading Nextcloud Upgrading Nextcloud can be a hair raising experiance. They [don't support downgrading](https://docs.nextcloud.com/server/latest/admin_manual/maintenance/upgrade.html) even for minor versions. diff --git a/abra.sh b/abra.sh index af39f71..1ab8570 100644 --- a/abra.sh +++ b/abra.sh @@ -193,3 +193,7 @@ set_windowsfriendly_filenames() { upgrade_mariadb() { mariadb-upgrade -p`cat /run/secrets/db_root_password` } + +set_metrics_token() { + run_occ "config:app:set serverinfo token --value '$(cat /run/secrets/metrics_token)'" +} \ No newline at end of file diff --git a/compose.metrics.yml b/compose.metrics.yml new file mode 100644 index 0000000..b0befdf --- /dev/null +++ b/compose.metrics.yml @@ -0,0 +1,22 @@ +version: "3.8" +services: + app: + secrets: + - metrics_token + metrics: + image: xperimental/nextcloud-exporter:0.9.0 + environment: + - NEXTCLOUD_SERVER=https://$DOMAIN + - NEXTCLOUD_AUTH_TOKEN=@/run/secrets/metrics_token + secrets: + - metrics_token + networks: + - proxy + deploy: + labels: + - "prometheus.io/scrape=true" + - "prometheus.io/port=9205" +secrets: + metrics_token: + external: true + name: ${STACK_NAME}_metrics_token_${SECRET_METRICS_TOKEN_VERSION} \ No newline at end of file From 257a7ac3a1d5895ac6662a334fe5c378068efb3b Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Wed, 2 Sep 2026 23:18:10 +0000 Subject: [PATCH 21/45] chore(deps): update nginx docker tag to v1.31.5 --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 244c2ff..975c5d2 100644 --- a/compose.yml +++ b/compose.yml @@ -1,7 +1,7 @@ version: "3.8" services: web: - image: nginx:1.31.4 + image: nginx:1.31.5 depends_on: - app configs: From d3afccfca903b6005d22170c0170ddc0300c14ca Mon Sep 17 00:00:00 2001 From: carla Date: Wed, 26 Aug 2026 13:27:31 +0200 Subject: [PATCH 22/45] adds Local IT to maintainers --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 8de10a1..897cc0c 100644 --- a/README.md +++ b/README.md @@ -5,7 +5,7 @@ Fully automated luxury Nextcloud via docker-swarm. -* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti), [@javielico](https://git.coopcloud.tech/javielico) +* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti), [@javielico](https://git.coopcloud.tech/javielico), Local-IT: [@moritz](https://git.coopcloud.tech/moritz), [@msimon](https://git.coopcloud.tech/simon), [@carla](https://git.coopcloud.tech/carla) * **Category**: Apps * **Status**: 5 * **Image**: [`nextcloud`](https://hub.docker.com/_/nextcloud), 4, upstream From 59beed36a758fae53609fc5b06e397899afc21d5 Mon Sep 17 00:00:00 2001 From: carla Date: Fri, 28 Aug 2026 08:44:30 +0200 Subject: [PATCH 23/45] adds LIT to reviewers --- renovate.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/renovate.json b/renovate.json index 341a7ea..5523195 100644 --- a/renovate.json +++ b/renovate.json @@ -5,5 +5,6 @@ ], "extends": [ "config:base" - ] + ], + "reviewers": ["fauno","moritz","simon","carla"] } From d019c23843e4aad42bd057eeff81f60ecbf00170 Mon Sep 17 00:00:00 2001 From: carla Date: Fri, 28 Aug 2026 09:21:26 +0200 Subject: [PATCH 24/45] fixes copy paste --- renovate.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/renovate.json b/renovate.json index 5523195..f0bec03 100644 --- a/renovate.json +++ b/renovate.json @@ -6,5 +6,5 @@ "extends": [ "config:base" ], - "reviewers": ["fauno","moritz","simon","carla"] + "reviewers": ["moritz","simon","carla"] } From fb511d8d075cd1b5cd0b71fa7e73f5c90b7e93f6 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Fri, 28 Aug 2026 16:52:48 +0200 Subject: [PATCH 25/45] Set MARIADB_AUTO_UPGRADE=1 This will automatically upgrade the tables to the latest version of mariadb. --- compose.mariadb.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/compose.mariadb.yml b/compose.mariadb.yml index 94557af..d972845 100644 --- a/compose.mariadb.yml +++ b/compose.mariadb.yml @@ -17,6 +17,7 @@ services: - MYSQL_ROOT_PASSWORD_FILE=/run/secrets/db_root_password - MAX_DB_CONNECTIONS=${MAX_DB_CONNECTIONS:-100} - INNODB_BUFFER_POOL_SIZE=${INNODB_BUFFER_POOL_SIZE:-1G}" + - MARIADB_AUTO_UPGRADE=1 configs: - source: my_tune target: /etc/mysql/conf.d/my-tune.cnf From 5990c68f23aa2ebc2476b50029059ae543206c72 Mon Sep 17 00:00:00 2001 From: Moritz Date: Wed, 9 Sep 2026 17:43:19 +0200 Subject: [PATCH 26/45] fix(cron): parsing smtp settings from envs --- compose.smtp.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/compose.smtp.yml b/compose.smtp.yml index cd7436b..8696718 100644 --- a/compose.smtp.yml +++ b/compose.smtp.yml @@ -13,6 +13,19 @@ services: - MAIL_FROM_ADDRESS - MAIL_DOMAIN + cron: + secrets: + - smtp_password + environment: + - SMTP_AUTHTYPE + - SMTP_HOST + - SMTP_SECURE + - SMTP_NAME + - SMTP_PORT + - SMTP_PASSWORD_FILE=/run/secrets/smtp_password + - MAIL_FROM_ADDRESS + - MAIL_DOMAIN + secrets: smtp_password: external: true From a7f5ec8506dc9f7e9a8d42f7476cff8b6dc59f6f Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Tue, 8 Sep 2026 18:29:26 +0000 Subject: [PATCH 27/45] chore(deps): update docker.elastic.co/elasticsearch/elasticsearch docker tag to v8.19.21 --- compose.fulltextsearch.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.fulltextsearch.yml b/compose.fulltextsearch.yml index 1e19d42..8980a56 100644 --- a/compose.fulltextsearch.yml +++ b/compose.fulltextsearch.yml @@ -2,7 +2,7 @@ version: "3.8" services: elasticsearch: - image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.20" + image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.21" environment: - cluster.name=docker-cluster - bootstrap.memory_lock=true From 785931c0dea1491a0ee3959b0d7948873ad9ad8c Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Sat, 12 Sep 2026 02:26:35 +0000 Subject: [PATCH 28/45] chore(deps): update nextcloud docker tag to v33.0.9 --- compose.fulltextsearch.yml | 2 +- compose.yml | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/compose.fulltextsearch.yml b/compose.fulltextsearch.yml index 8980a56..3f39fae 100644 --- a/compose.fulltextsearch.yml +++ b/compose.fulltextsearch.yml @@ -29,7 +29,7 @@ services: mode: 0600 searchindexer: - image: nextcloud:33.0.8-fpm + image: nextcloud:33.0.9-fpm volumes: - nextcloud:/var/www/html/ - nextapps:/var/www/html/custom_apps:cached diff --git a/compose.yml b/compose.yml index 975c5d2..22902b4 100644 --- a/compose.yml +++ b/compose.yml @@ -48,7 +48,7 @@ services: start_period: 5m app: - image: nextcloud:33.0.8-fpm + image: nextcloud:33.0.9-fpm depends_on: - db configs: @@ -109,7 +109,7 @@ services: start_period: 15m cron: - image: nextcloud:33.0.8-fpm + image: nextcloud:33.0.9-fpm volumes: - nextcloud:/var/www/html/ - nextapps:/var/www/html/custom_apps:cached From 131054d23440e1191cdcd19d49c6cff1eb29e2c2 Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Sat, 12 Sep 2026 10:48:38 +0100 Subject: [PATCH 29/45] chore: publish 14.1.2+33.0.9-fpm release --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 22902b4..2191009 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=14.1.1+33.0.8-fpm" + - "coop-cloud.${STACK_NAME}.version=14.1.2+33.0.9-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" From 1d6ec8cf38e77c84cb5d8c450d08bbe18b7e86c5 Mon Sep 17 00:00:00 2001 From: Simon Date: Mon, 14 Sep 2026 18:08:09 +0200 Subject: [PATCH 30/45] add nextcloud metrics exporter --- .env.sample | 4 ++++ README.md | 11 +++++++++++ abra.sh | 4 ++++ compose.metrics.yml | 22 ++++++++++++++++++++++ 4 files changed, 41 insertions(+) create mode 100644 compose.metrics.yml diff --git a/.env.sample b/.env.sample index 3e84dc5..3180442 100644 --- a/.env.sample +++ b/.env.sample @@ -107,3 +107,7 @@ DEFAULT_QUOTA="10 GB" #HSTS_ENABLED=1 # Uncomment this line to add the `preload` part #HSTS_PRELOAD=1 + +# Metrics +# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" +# SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex \ No newline at end of file diff --git a/README.md b/README.md index 897cc0c..7fae4f8 100644 --- a/README.md +++ b/README.md @@ -129,6 +129,17 @@ To disable dashboard app (since it is so corporate): - Configure a `defaultapp` in your `config.php` or use [apporder](https://apps.nextcloud.com/apps/apporder) +## Metrics + +There is a [metrics exporter](https://github.com/xperimental/nextcloud-exporter) that can be run as sidecar container, also part of the nextcloud helm charts. Its configured via alloys label-based auto-discovery provided by the updated [monitoring-stack](https://git.coopcloud.tech/coop-cloud/monitoring-ng) +To enable, uncomment +``` +COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" +SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex +``` +then generate the secret with abra and run +`abra app cmd app set_metrics_token` + ## Upgrading Nextcloud Upgrading Nextcloud can be a hair raising experiance. They diff --git a/abra.sh b/abra.sh index f201ab7..fa4c797 100644 --- a/abra.sh +++ b/abra.sh @@ -350,3 +350,7 @@ check_major_upgrade() { return 1 fi } + +set_metrics_token() { + run_occ "config:app:set serverinfo token --value '$(cat /run/secrets/metrics_token)'" +} \ No newline at end of file diff --git a/compose.metrics.yml b/compose.metrics.yml new file mode 100644 index 0000000..b0befdf --- /dev/null +++ b/compose.metrics.yml @@ -0,0 +1,22 @@ +version: "3.8" +services: + app: + secrets: + - metrics_token + metrics: + image: xperimental/nextcloud-exporter:0.9.0 + environment: + - NEXTCLOUD_SERVER=https://$DOMAIN + - NEXTCLOUD_AUTH_TOKEN=@/run/secrets/metrics_token + secrets: + - metrics_token + networks: + - proxy + deploy: + labels: + - "prometheus.io/scrape=true" + - "prometheus.io/port=9205" +secrets: + metrics_token: + external: true + name: ${STACK_NAME}_metrics_token_${SECRET_METRICS_TOKEN_VERSION} \ No newline at end of file From 1a43b8fe4fae6d7a1cfc2dbf1d0167a086c5c35a Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Tue, 15 Sep 2026 23:21:13 +0000 Subject: [PATCH 31/45] chore(deps): update nginx docker tag to v1.31.6 --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 2191009..9b48f67 100644 --- a/compose.yml +++ b/compose.yml @@ -1,7 +1,7 @@ version: "3.8" services: web: - image: nginx:1.31.5 + image: nginx:1.31.6 depends_on: - app configs: From ea487f93dd27a26bda998073deae2a418b7881ab Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Fri, 28 Aug 2026 17:31:35 +0200 Subject: [PATCH 32/45] Details about semver of the recipe Spell out how we update the release versions of the recipe, specifically wrt dependencies. Based on the text of @dannygroenewegen. --- MAINTENANCE.md | 30 +++++++++++++++++++++++++++++- 1 file changed, 29 insertions(+), 1 deletion(-) diff --git a/MAINTENANCE.md b/MAINTENANCE.md index 9e0c683..77a4a5d 100644 --- a/MAINTENANCE.md +++ b/MAINTENANCE.md @@ -38,7 +38,7 @@ In order to meet these responsibilities each maintainer: ## Release cadence The intent is to **track Nextcloud's own release schedule** rather than invent -our own. In practice this means: +our own. In practice this means the following regarding new **nextcloud** releases: - **Patch releases (e.g. `32.0.x`)**: published to this recipe shortly after upstream, ideally within 1 week. `chore(deps)` opens the PRs; a maintainer @@ -63,6 +63,34 @@ our own. In practice this means: - **Co-installed components** (Talk HPB, OnlyOffice, Whiteboard, etc.) are bumped alongside or shortly after the matching Nextcloud release. +## Semver versioning within this recipe + +The recipe version itself is updated according to the following semver +rules, following +[How are recipes versioned](https://docs.coopcloud.tech/maintainers/handbook/#how-are-recipes-versioned): +These describe the minimum required bump for a given kind of change. +The actual impact of any change (an image update or, e.g. a compose or config change) +should always be considered, and the recipe version can always be bumped higher +than the guideline below to match the impact of the change. + +- For updates of the image in the app container (nextcloud), we match the + recipe version bump to at least the image version bump. +- Other containers in this recipe are considered dependencies of the app container + unless they expose additional functionality directly. +- For image updates of dependency containers, we judge the recipe version bump + from the perspective of the app itself, but a minor or major update of a + dependent container is always reflected by at least a minor recipe version bump + to indicate a substantial update under the hood. + +Temporary exception: +- In the past, there have been issues with upgrades from database containers + (before the `pgautoupgrade` image and `MARIADB_AUTO_UPGRADE` setting). + We continue treating a major update of a database container (postgresql, mariadb) + as a major recipe bump until that database has had two consecutive major upgrades + with no issues reported, building trust in its automatic upgrade. + Once that trust is established for a given database, we continue with the + default guidelines above. + ## Pull Requests A pull request can be merged once it is approved by at least one maintainer. From d811dfa1cb7f4e839b1f2e02475529447e9d5bdf Mon Sep 17 00:00:00 2001 From: Linus Gasser Date: Wed, 16 Sep 2026 20:32:52 +0200 Subject: [PATCH 33/45] Add warning about major dependency version updates --- MAINTENANCE.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/MAINTENANCE.md b/MAINTENANCE.md index 77a4a5d..d499d16 100644 --- a/MAINTENANCE.md +++ b/MAINTENANCE.md @@ -91,6 +91,12 @@ Temporary exception: Once that trust is established for a given database, we continue with the default guidelines above. +WARNING: +When moving to a new major version of a dependency, the maintainer needs to make +sure that the version is supported! +Example: in June 2026, MariaDB got updated to version 12, but nextcloud suggests +only up to version 11.8 for best performance. + ## Pull Requests A pull request can be merged once it is approved by at least one maintainer. From f9203e5d7fa75ffcc6f3dde604b7fe0c79dcce7f Mon Sep 17 00:00:00 2001 From: Simon Date: Thu, 17 Sep 2026 15:24:48 +0200 Subject: [PATCH 34/45] docs: format readme --- README.md | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 7fae4f8..d358e48 100644 --- a/README.md +++ b/README.md @@ -131,14 +131,21 @@ To disable dashboard app (since it is so corporate): ## Metrics -There is a [metrics exporter](https://github.com/xperimental/nextcloud-exporter) that can be run as sidecar container, also part of the nextcloud helm charts. Its configured via alloys label-based auto-discovery provided by the updated [monitoring-stack](https://git.coopcloud.tech/coop-cloud/monitoring-ng) +There is a [metrics exporter](https://github.com/xperimental/nextcloud-exporter) +that can be run as sidecar container, also part of the nextcloud helm charts. +Its configured via alloys label-based auto-discovery provided by the updated +[monitoring-stack](https://git.coopcloud.tech/coop-cloud/monitoring-ng). + To enable, uncomment ``` COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex ``` -then generate the secret with abra and run -`abra app cmd app set_metrics_token` +then generate the secret with abra and insert it via `set_metrics_token` +``` +abra app secret generate metrics_token +abra app cmd app set_metrics_token +``` ## Upgrading Nextcloud From 2a2357142e0a14234fa47220361060ed163e5aaa Mon Sep 17 00:00:00 2001 From: Simon Date: Thu, 17 Sep 2026 17:53:16 +0200 Subject: [PATCH 35/45] replace sidecar metrics exporter with native metrics endpoint --- .env.sample | 3 +-- README.md | 9 +++------ abra.sh | 6 +++--- compose.metrics.yml | 18 +++--------------- nginx.conf.tmpl | 19 +++++++++++++++++++ release/next | 1 + 6 files changed, 30 insertions(+), 26 deletions(-) create mode 100644 release/next diff --git a/.env.sample b/.env.sample index 3180442..ee2842c 100644 --- a/.env.sample +++ b/.env.sample @@ -109,5 +109,4 @@ DEFAULT_QUOTA="10 GB" #HSTS_PRELOAD=1 # Metrics -# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" -# SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex \ No newline at end of file +# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" \ No newline at end of file diff --git a/README.md b/README.md index d358e48..1ecd2ca 100644 --- a/README.md +++ b/README.md @@ -131,20 +131,17 @@ To disable dashboard app (since it is so corporate): ## Metrics -There is a [metrics exporter](https://github.com/xperimental/nextcloud-exporter) -that can be run as sidecar container, also part of the nextcloud helm charts. +Since Version 33, Nextcloud offers a /metrics endpoint (see [here](https://docs.nextcloud.com/server/stable/admin_manual/configuration_monitoring/index.html)). Its configured via alloys label-based auto-discovery provided by the updated [monitoring-stack](https://git.coopcloud.tech/coop-cloud/monitoring-ng). To enable, uncomment ``` COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" -SECRET_METRICS_TOKEN_VERSION=v1 # length=32 charset=hex ``` -then generate the secret with abra and insert it via `set_metrics_token` +and run `configure_metrics`: ``` -abra app secret generate metrics_token -abra app cmd app set_metrics_token +abra app cmd app configure_metrics ``` ## Upgrading Nextcloud diff --git a/abra.sh b/abra.sh index b31d401..0ee72ad 100644 --- a/abra.sh +++ b/abra.sh @@ -1,7 +1,7 @@ #!/bin/bash export FPM_TUNE_VERSION=v5 -export NGINX_CONF_VERSION=v8 +export NGINX_CONF_VERSION=v9 export MY_CNF_VERSION=v6 export ENTRYPOINT_VERSION=v3 export ENTRYPOINT_WHITEBOARD_VERSION=v1 @@ -195,8 +195,8 @@ upgrade_mariadb() { mariadb-upgrade -p`cat /run/secrets/db_root_password` } -set_metrics_token() { - run_occ "config:app:set serverinfo token --value '$(cat /run/secrets/metrics_token)'" +configure_metrics() { + run_occ "config:system:set openmetrics_allowed_clients 0 --value='10.0.0.0/8'" } # Checks whether this instance looks ready to update to the next Nextcloud diff --git a/compose.metrics.yml b/compose.metrics.yml index b0befdf..334720c 100644 --- a/compose.metrics.yml +++ b/compose.metrics.yml @@ -1,22 +1,10 @@ version: "3.8" services: - app: - secrets: - - metrics_token - metrics: - image: xperimental/nextcloud-exporter:0.9.0 + web: environment: - - NEXTCLOUD_SERVER=https://$DOMAIN - - NEXTCLOUD_AUTH_TOKEN=@/run/secrets/metrics_token - secrets: - - metrics_token - networks: - - proxy + - METRICS_ENABLED=true deploy: labels: - "prometheus.io/scrape=true" - "prometheus.io/port=9205" -secrets: - metrics_token: - external: true - name: ${STACK_NAME}_metrics_token_${SECRET_METRICS_TOKEN_VERSION} \ No newline at end of file + - "prometheus.io/path=/metrics" \ No newline at end of file diff --git a/nginx.conf.tmpl b/nginx.conf.tmpl index fc82a44..74f0777 100644 --- a/nginx.conf.tmpl +++ b/nginx.conf.tmpl @@ -185,4 +185,23 @@ http { try_files $uri $uri/ /index.php$request_uri; } } + + {{ if env "METRICS_ENABLED" }} + server { + listen 9205; + + location = /metrics { + include fastcgi_params; + fastcgi_param SCRIPT_FILENAME /var/www/html/index.php; + fastcgi_param SCRIPT_NAME /index.php; + fastcgi_param REQUEST_URI /metrics; + fastcgi_param HTTP_HOST {{ env "DOMAIN" }}; + fastcgi_pass php-handler; + } + + location / { + return 404; + } + } + {{ end }} } diff --git a/release/next b/release/next new file mode 100644 index 0000000..c4ede33 --- /dev/null +++ b/release/next @@ -0,0 +1 @@ +add option to scrape native /metrics endpoint via alloys auto-discovery \ No newline at end of file From 5b393d61943343450c53a0041ee1eb7bb343de64 Mon Sep 17 00:00:00 2001 From: Simon Date: Mon, 21 Sep 2026 13:04:28 +0200 Subject: [PATCH 36/45] use port 80 for metrics --- compose.metrics.yml | 4 +--- nginx.conf.tmpl | 14 +++----------- 2 files changed, 4 insertions(+), 14 deletions(-) diff --git a/compose.metrics.yml b/compose.metrics.yml index 334720c..e3ec36f 100644 --- a/compose.metrics.yml +++ b/compose.metrics.yml @@ -5,6 +5,4 @@ services: - METRICS_ENABLED=true deploy: labels: - - "prometheus.io/scrape=true" - - "prometheus.io/port=9205" - - "prometheus.io/path=/metrics" \ No newline at end of file + - "prometheus.io/scrape=true" \ No newline at end of file diff --git a/nginx.conf.tmpl b/nginx.conf.tmpl index 74f0777..0dc5503 100644 --- a/nginx.conf.tmpl +++ b/nginx.conf.tmpl @@ -184,24 +184,16 @@ http { location / { try_files $uri $uri/ /index.php$request_uri; } - } - - {{ if env "METRICS_ENABLED" }} - server { - listen 9205; + {{ if env "METRICS_ENABLED" }} location = /metrics { include fastcgi_params; - fastcgi_param SCRIPT_FILENAME /var/www/html/index.php; + fastcgi_param SCRIPT_FILENAME $document_root/index.php; fastcgi_param SCRIPT_NAME /index.php; fastcgi_param REQUEST_URI /metrics; fastcgi_param HTTP_HOST {{ env "DOMAIN" }}; fastcgi_pass php-handler; } - - location / { - return 404; - } + {{ end }} } - {{ end }} } From e715938ebb4fe4a1b4d320f458019e9c28f0db55 Mon Sep 17 00:00:00 2001 From: Simon Date: Mon, 21 Sep 2026 17:03:43 +0200 Subject: [PATCH 37/45] chore: publish 14.2.0+33.0.9-fpm release --- compose.yml | 2 +- release/{next => 14.2.0+33.0.9-fpm} | 0 2 files changed, 1 insertion(+), 1 deletion(-) rename release/{next => 14.2.0+33.0.9-fpm} (100%) diff --git a/compose.yml b/compose.yml index 9b48f67..37f25cb 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=14.1.2+33.0.9-fpm" + - "coop-cloud.${STACK_NAME}.version=14.2.0+33.0.9-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" diff --git a/release/next b/release/14.2.0+33.0.9-fpm similarity index 100% rename from release/next rename to release/14.2.0+33.0.9-fpm From 445715e409a2f1599697d4420b3da77aaae7318a Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Mon, 21 Sep 2026 19:18:40 +0000 Subject: [PATCH 38/45] chore(deps): update redis docker tag to v8.10.2 --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 37f25cb..2479ea9 100644 --- a/compose.yml +++ b/compose.yml @@ -125,7 +125,7 @@ services: cache: - image: redis:8.10.1-alpine + image: redis:8.10.2-alpine networks: - internal volumes: From 0ba186b408e24c7ca00b9dc040d85b4399a9c9bb Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Wed, 16 Sep 2026 10:18:39 +0000 Subject: [PATCH 39/45] chore(deps): update ghcr.io/nextcloud-releases/whiteboard docker tag to v2 --- compose.whiteboard.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.whiteboard.yml b/compose.whiteboard.yml index 302ea74..f22e7e4 100644 --- a/compose.whiteboard.yml +++ b/compose.whiteboard.yml @@ -6,7 +6,7 @@ services: - whiteboard_jwt whiteboard: - image: ghcr.io/nextcloud-releases/whiteboard:v1.5.9 + image: ghcr.io/nextcloud-releases/whiteboard:v2.0.0 deploy: labels: - traefik.enable=true From 70f8ab4b567dee3d5accc06bb838c1168b6a8af9 Mon Sep 17 00:00:00 2001 From: Moritz Date: Tue, 22 Sep 2026 11:14:32 +0200 Subject: [PATCH 40/45] chore: publish 14.3.0+33.0.9-fpm release --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 2479ea9..26d8e1d 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=14.2.0+33.0.9-fpm" + - "coop-cloud.${STACK_NAME}.version=14.3.0+33.0.9-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" From b3c7aef2a9ef553f6e7a73fe2ee8a11eec66e6eb Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Wed, 23 Sep 2026 09:17:13 +0000 Subject: [PATCH 41/45] chore(deps): update docker.elastic.co/elasticsearch/elasticsearch docker tag to v8.19.22 --- compose.fulltextsearch.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.fulltextsearch.yml b/compose.fulltextsearch.yml index 3f39fae..57addc2 100644 --- a/compose.fulltextsearch.yml +++ b/compose.fulltextsearch.yml @@ -2,7 +2,7 @@ version: "3.8" services: elasticsearch: - image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.21" + image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.22" environment: - cluster.name=docker-cluster - bootstrap.memory_lock=true From 2071a7dc2f1984873ecc8c1ddc9e83096e1a658c Mon Sep 17 00:00:00 2001 From: Moritz Date: Thu, 24 Sep 2026 14:59:26 +0200 Subject: [PATCH 42/45] fix new collabora installation by activating the config --- abra.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/abra.sh b/abra.sh index 0ee72ad..00dda1d 100644 --- a/abra.sh +++ b/abra.sh @@ -90,6 +90,7 @@ install_collabora() { # important for security reaosns # https://docs.nextcloud.com/server/latest/admin_manual/office/configuration.html#wopi-settings set_app_config richdocuments wopi_allowlist "$COLLABORA_ALLOWLIST" + run_occ "richdocuments:activate-config" } install_whiteboard() { From 1af9dc1aceb2769b30537cbcd6f6c3df23cf9823 Mon Sep 17 00:00:00 2001 From: Moritz Date: Thu, 24 Sep 2026 15:00:49 +0200 Subject: [PATCH 43/45] chore: publish 14.4.0+33.0.9-fpm release --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 26d8e1d..87c6ddb 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=14.3.0+33.0.9-fpm" + - "coop-cloud.${STACK_NAME}.version=14.4.0+33.0.9-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" From 41e3e2bb33bea00b755b148b5074c67bcb47fccd Mon Sep 17 00:00:00 2001 From: Moritz Date: Thu, 24 Sep 2026 15:01:40 +0200 Subject: [PATCH 44/45] chore: publish 14.5.0+33.0.9-fpm release --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 87c6ddb..583ad25 100644 --- a/compose.yml +++ b/compose.yml @@ -95,7 +95,7 @@ services: failure_action: rollback order: start-first labels: - - "coop-cloud.${STACK_NAME}.version=14.4.0+33.0.9-fpm" + - "coop-cloud.${STACK_NAME}.version=14.5.0+33.0.9-fpm" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup.volumes.redis=false" From a3959eb8593625e8ed92e8dea46cdc132c8716c0 Mon Sep 17 00:00:00 2001 From: Amras Date: Wed, 23 Sep 2026 13:18:05 +0200 Subject: [PATCH 45/45] [doc] warning for AUTHENTIK_USER_PREFIX [Discussion here](https://git.coopcloud.tech/coop-cloud/nextcloud/issues/106) --- .env.sample | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.env.sample b/.env.sample index ee2842c..4405472 100644 --- a/.env.sample +++ b/.env.sample @@ -79,11 +79,14 @@ DEFAULT_QUOTA="10 GB" # COMPOSE_FILE="$COMPOSE_FILE:compose.authentik.yml" # APPS="$APPS sociallogin" -# AUTHENTIK_USER_PREFIX=authentik # AUTHENTIK_DOMAIN=authentik.example.com # SECRET_AUTHENTIK_SECRET_VERSION=v1 # SECRET_AUTHENTIK_ID_VERSION=v1 +# Only change this if you've configured your authentik instance to use a non-default user prefix. +# If you're unsure, this should match the redirect_uri in authentik's nextcloud provider. +# AUTHENTIK_USER_PREFIX=authentik + #COMPOSE_FILE="$COMPOSE_FILE:compose.fulltextsearch.yml" #SECRET_ELASTICSEARCH_PASSWORD_VERSION=v1 @@ -109,4 +112,4 @@ DEFAULT_QUOTA="10 GB" #HSTS_PRELOAD=1 # Metrics -# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" \ No newline at end of file +# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"