Compare commits

..
Author SHA1 Message Date
stevensting 8d46dd808e Merge branch 'main' into trusted-domains 2026-08-27 10:51:22 +00:00
stevensting 0b58b1ef85 fix wrong commit 2026-08-27 12:47:56 +02:00
stevensting 166394587d add documentation, fix review findings 2026-08-27 12:44:10 +02:00
stevensting fc72b033b8 adapt env sample 2026-08-25 15:06:17 +02:00
stevensting 6cc3e151c1 fix trusted domains 2026-08-25 14:59:44 +02:00
15 changed files with 30 additions and 175 deletions
+3 -12
View File
@@ -6,6 +6,8 @@ ENABLE_BACKUPS=true
DOMAIN=nextcloud.example.com
## Domain aliases
#EXTRA_DOMAINS=', `www.nextcloud.example.com`'
# space separated list of trusted domains, only evaluated on first startup
#EXTRA_DOMAINS_TRUSTED=cloud.coquest.coop
LETS_ENCRYPT_ENV=production
COMPOSE_FILE="compose.yml"
@@ -69,11 +71,6 @@ DEFAULT_QUOTA="10 GB"
# APPS="$APPS onlyoffice"
# SECRET_ONLYOFFICE_JWT_VERSION=v1
# COMPOSE_FILE="$COMPOSE_FILE:compose.eurooffice.yml"
# EUROOFFICE_URL=https://euro-office.example.com
# APPS="$APPS eurooffice"
# SECRET_EURO_JWT_VERSION=v1
# COMPOSE_FILE="$COMPOSE_FILE:compose.bbb.yml"
# BBB_URL=https://talk.example.org/bigbluebutton/ # trailing slash!
# SECRET_BBB_SECRET_VERSION=v1
@@ -84,14 +81,11 @@ DEFAULT_QUOTA="10 GB"
# COMPOSE_FILE="$COMPOSE_FILE:compose.authentik.yml"
# APPS="$APPS sociallogin"
# AUTHENTIK_USER_PREFIX=authentik
# AUTHENTIK_DOMAIN=authentik.example.com
# SECRET_AUTHENTIK_SECRET_VERSION=v1
# SECRET_AUTHENTIK_ID_VERSION=v1
# Only change this if you've configured your authentik instance to use a non-default user prefix.
# If you're unsure, this should match the redirect_uri in authentik's nextcloud provider.
# AUTHENTIK_USER_PREFIX=authentik
#COMPOSE_FILE="$COMPOSE_FILE:compose.fulltextsearch.yml"
#SECRET_ELASTICSEARCH_PASSWORD_VERSION=v1
@@ -115,6 +109,3 @@ DEFAULT_QUOTA="10 GB"
#HSTS_ENABLED=1
# Uncomment this line to add the `preload` part
#HSTS_PRELOAD=1
# Metrics
# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
+1 -35
View File
@@ -38,7 +38,7 @@ In order to meet these responsibilities each maintainer:
## Release cadence
The intent is to **track Nextcloud's own release schedule** rather than invent
our own. In practice this means the following regarding new **nextcloud** releases:
our own. In practice this means:
- **Patch releases (e.g. `32.0.x`)**: published to this recipe shortly after
upstream, ideally within 1 week. `chore(deps)` opens the PRs; a maintainer
@@ -63,40 +63,6 @@ our own. In practice this means the following regarding new **nextcloud** releas
- **Co-installed components** (Talk HPB, OnlyOffice, Whiteboard, etc.) are
bumped alongside or shortly after the matching Nextcloud release.
## Semver versioning within this recipe
The recipe version itself is updated according to the following semver
rules, following
[How are recipes versioned](https://docs.coopcloud.tech/maintainers/handbook/#how-are-recipes-versioned):
These describe the minimum required bump for a given kind of change.
The actual impact of any change (an image update or, e.g. a compose or config change)
should always be considered, and the recipe version can always be bumped higher
than the guideline below to match the impact of the change.
- For updates of the image in the app container (nextcloud), we match the
recipe version bump to at least the image version bump.
- Other containers in this recipe are considered dependencies of the app container
unless they expose additional functionality directly.
- For image updates of dependency containers, we judge the recipe version bump
from the perspective of the app itself, but a minor or major update of a
dependent container is always reflected by at least a minor recipe version bump
to indicate a substantial update under the hood.
Temporary exception:
- In the past, there have been issues with upgrades from database containers
(before the `pgautoupgrade` image and `MARIADB_AUTO_UPGRADE` setting).
We continue treating a major update of a database container (postgresql, mariadb)
as a major recipe bump until that database has had two consecutive major upgrades
with no issues reported, building trust in its automatic upgrade.
Once that trust is established for a given database, we continue with the
default guidelines above.
WARNING:
When moving to a new major version of a dependency, the maintainer needs to make
sure that the version is supported!
Example: in June 2026, MariaDB got updated to version 12, but nextcloud suggests
only up to version 11.8 for best performance.
## Pull Requests
A pull request can be merged once it is approved by at least one maintainer.
+15 -44
View File
@@ -5,7 +5,7 @@
Fully automated luxury Nextcloud via docker-swarm.
<!-- metadata -->
* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti), [@javielico](https://git.coopcloud.tech/javielico), Local-IT: [@moritz](https://git.coopcloud.tech/moritz), [@msimon](https://git.coopcloud.tech/simon), [@carla](https://git.coopcloud.tech/carla)
* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti), [@javielico](https://git.coopcloud.tech/javielico)
* **Category**: Apps
* **Status**: 5
* **Image**: [`nextcloud`](https://hub.docker.com/_/nextcloud), 4, upstream
@@ -24,6 +24,20 @@ Fully automated luxury Nextcloud via docker-swarm.
* `abra app secret generate -a <app-name>`
* `abra app deploy <app-name>`
### Accessing nextcloud from multiple domains
If you want to access the nextcloud instance from multiple domains, add the additional domains by using both env vars:
```
EXTRA_DOMAINS=', `nextcloud.example2.com`' # comma separated, for traefik
EXTRA_DOMAINS_TRUSTED=nextcloud.example2.com # space separated, for nextcloud
```
`EXTRA_DOMAINS_TRUSTED` is only evaluated by nextcloud on the first install. If you want to add domains later, you need to run this command additionally:
```
abra app cmd nextcloud.example.com app run_occ '"config:system:set trusted_domains <index> --value="nextcloud.example2.com""'
```
The indices 0 and 1 are taken, start with 2 for the first extra domain.
### Onlyoffice Integration
First, install onlyoffice following the instructions in the
@@ -44,34 +58,6 @@ Then set the onlyoffice JWT secret from the onlyoffice installation:
* `abra app secret insert <app-name> onlyoffice_jwt v1 <jwt_secret>`
* `abra app cmd <app-name> app install_onlyoffice`
### Euro-Office Integration
First, deploy the [Euro-Office Recipe](https://recipes.coopcloud.tech/euro-office),
and keep its JWT secret. Then configure your nextcloud instance with:
`abra app config <app-name>`
Configure the following envs with the URL of the euro-office service:
```
COMPOSE_FILE="$COMPOSE_FILE:compose.eurooffice.yml"
EUROOFFICE_URL=https://euro-office.example.com
SECRET_EURO_JWT_VERSION=v1
```
Then set the euro-office JWT secret from the euro-office installation:
`abra app secret insert <app-name> euro_jwt v1 <jwt_secret>`
Now make sure that your nextcloud recipe is correctly deployed.
If it's a fresh install, deploy it, if Euro-Office is added after
the install, force-deploy it to update the configuration variables:
`abra app deploy -f <app-name>`
Once that is up and running, install the eurooffice plugin for nextcloud:
`abra app cmd <app-name> app install_eurooffice`
### BBB Integration
`abra app config <app-name>`
@@ -157,21 +143,6 @@ To disable dashboard app (since it is so corporate):
- Configure a `defaultapp` in your `config.php` or use [apporder](https://apps.nextcloud.com/apps/apporder)
## Metrics
Since Version 33, Nextcloud offers a /metrics endpoint (see [here](https://docs.nextcloud.com/server/stable/admin_manual/configuration_monitoring/index.html)).
Its configured via alloys label-based auto-discovery provided by the updated
[monitoring-stack](https://git.coopcloud.tech/coop-cloud/monitoring-ng).
To enable, uncomment
```
COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
```
and run `configure_metrics`:
```
abra app cmd <domain> app configure_metrics
```
## Upgrading Nextcloud
Upgrading Nextcloud can be a hair raising experiance. They
+1 -12
View File
@@ -1,7 +1,7 @@
#!/bin/bash
export FPM_TUNE_VERSION=v5
export NGINX_CONF_VERSION=v9
export NGINX_CONF_VERSION=v8
export MY_CNF_VERSION=v6
export ENTRYPOINT_VERSION=v3
export ENTRYPOINT_WHITEBOARD_VERSION=v1
@@ -84,19 +84,12 @@ install_onlyoffice() {
set_app_config onlyoffice customizationForcesave true
}
install_eurooffice() {
install_apps eurooffice
set_app_config eurooffice DocumentServerUrl "$EUROOFFICE_URL"
set_app_config eurooffice jwt_secret "$(cat /run/secrets/euro_jwt)"
}
install_collabora() {
install_apps richdocuments
set_app_config richdocuments wopi_url "$COLLABORA_URL"
# important for security reaosns
# https://docs.nextcloud.com/server/latest/admin_manual/office/configuration.html#wopi-settings
set_app_config richdocuments wopi_allowlist "$COLLABORA_ALLOWLIST"
run_occ "richdocuments:activate-config"
}
install_whiteboard() {
@@ -202,10 +195,6 @@ upgrade_mariadb() {
mariadb-upgrade -p`cat /run/secrets/db_root_password`
}
configure_metrics() {
run_occ "config:system:set openmetrics_allowed_clients 0 --value='10.0.0.0/8'"
}
# Checks whether this instance looks ready to update to the next Nextcloud
# major version.
#
-13
View File
@@ -1,13 +0,0 @@
version: "3.8"
services:
app:
secrets:
- euro_jwt
environment:
- EUROOFFICE_URL
secrets:
euro_jwt:
external: true
name: ${STACK_NAME}_euro_jwt_${SECRET_EURO_JWT_VERSION}
+2 -2
View File
@@ -2,7 +2,7 @@ version: "3.8"
services:
elasticsearch:
image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.22"
image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.20"
environment:
- cluster.name=docker-cluster
- bootstrap.memory_lock=true
@@ -29,7 +29,7 @@ services:
mode: 0600
searchindexer:
image: nextcloud:34.0.4-fpm
image: nextcloud:33.0.8-fpm
volumes:
- nextcloud:/var/www/html/
- nextapps:/var/www/html/custom_apps:cached
-1
View File
@@ -17,7 +17,6 @@ services:
- MYSQL_ROOT_PASSWORD_FILE=/run/secrets/db_root_password
- MAX_DB_CONNECTIONS=${MAX_DB_CONNECTIONS:-100}
- INNODB_BUFFER_POOL_SIZE=${INNODB_BUFFER_POOL_SIZE:-1G}"
- MARIADB_AUTO_UPGRADE=1
configs:
- source: my_tune
target: /etc/mysql/conf.d/my-tune.cnf
-8
View File
@@ -1,8 +0,0 @@
version: "3.8"
services:
web:
environment:
- METRICS_ENABLED=true
deploy:
labels:
- "prometheus.io/scrape=true"
-13
View File
@@ -13,19 +13,6 @@ services:
- MAIL_FROM_ADDRESS
- MAIL_DOMAIN
cron:
secrets:
- smtp_password
environment:
- SMTP_AUTHTYPE
- SMTP_HOST
- SMTP_SECURE
- SMTP_NAME
- SMTP_PORT
- SMTP_PASSWORD_FILE=/run/secrets/smtp_password
- MAIL_FROM_ADDRESS
- MAIL_DOMAIN
secrets:
smtp_password:
external: true
+1 -1
View File
@@ -6,7 +6,7 @@ services:
- whiteboard_jwt
whiteboard:
image: ghcr.io/nextcloud-releases/whiteboard:v2.0.0
image: ghcr.io/nextcloud-releases/whiteboard:v1.5.9
deploy:
labels:
- traefik.enable=true
+6 -6
View File
@@ -1,7 +1,7 @@
version: "3.8"
services:
web:
image: nginx:1.31.6
image: nginx:1.31.3
depends_on:
- app
configs:
@@ -48,7 +48,7 @@ services:
start_period: 5m
app:
image: nextcloud:34.0.4-fpm
image: nextcloud:33.0.8-fpm
depends_on:
- db
configs:
@@ -70,7 +70,7 @@ services:
- STACK_NAME
- NEXTCLOUD_ADMIN_USER=${ADMIN_USER}
- NEXTCLOUD_ADMIN_PASSWORD_FILE=/run/secrets/admin_password
- NEXTCLOUD_TRUSTED_DOMAINS=${DOMAIN}
- NEXTCLOUD_TRUSTED_DOMAINS=${DOMAIN} ${EXTRA_DOMAINS_TRUSTED}
- TRUSTED_PROXIES=10.0.0.0/8
- REDIS_HOST=cache
- OVERWRITEPROTOCOL=https
@@ -95,7 +95,7 @@ services:
failure_action: rollback
order: start-first
labels:
- "coop-cloud.${STACK_NAME}.version=14.5.0+33.0.9-fpm"
- "coop-cloud.${STACK_NAME}.version=14.1.1+33.0.8-fpm"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
- "backupbot.backup.volumes.redis=false"
@@ -109,7 +109,7 @@ services:
start_period: 15m
cron:
image: nextcloud:34.0.4-fpm
image: nextcloud:33.0.8-fpm
volumes:
- nextcloud:/var/www/html/
- nextapps:/var/www/html/custom_apps:cached
@@ -125,7 +125,7 @@ services:
cache:
image: redis:8.10.2-alpine
image: redis:8.8.1-alpine
networks:
- internal
volumes:
-11
View File
@@ -184,16 +184,5 @@ http {
location / {
try_files $uri $uri/ /index.php$request_uri;
}
{{ if env "METRICS_ENABLED" }}
location = /metrics {
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root/index.php;
fastcgi_param SCRIPT_NAME /index.php;
fastcgi_param REQUEST_URI /metrics;
fastcgi_param HTTP_HOST {{ env "DOMAIN" }};
fastcgi_pass php-handler;
}
{{ end }}
}
}
-1
View File
@@ -1 +0,0 @@
add option to scrape native /metrics endpoint via alloys auto-discovery
-14
View File
@@ -1,14 +0,0 @@
Upgrades Nextcloud from 33.0.9 to 34 (major version upgrade).
IMPORTANT:
- Do not skip major versions: your instance must be on the latest 33.x before
upgrading to 34. If you are on an older 33.x, deploy 33.0.9 first.
- Use `check_major_upgrade` (`abra app cmd <app-name> app check_major_upgrade`)
to check whether an instance is ready to upgrade to the next Nextcloud
major version.
- Nextcloud does NOT support downgrades. Take a backup before deploying.
- After deploying, check the logs and run any pending repair/upgrade steps:
`abra app cmd <app> app run_occ '"app:update --all"'`
- Review app (plug-in) compatibility with Nextcloud 34 before upgrading; some
apps may need to be updated or temporarily disabled.
- This release has support for Euro-Office, see the README.md for instructions
+1 -2
View File
@@ -5,6 +5,5 @@
],
"extends": [
"config:base"
],
"reviewers": ["moritz","simon","carla"]
]
}