Compare commits

...
Author SHA1 Message Date
ineiti 931b403f3e Fixing Typo
@simon - I suppose it's a type to have `@msimon` - or is this on purpose?
2026-09-28 19:20:15 +00:00
Amras a3959eb859 [doc] warning for AUTHENTIK_USER_PREFIX
[Discussion here](#106)
2026-09-25 09:22:22 +00:00
moritz 41e3e2bb33 chore: publish 14.5.0+33.0.9-fpm release
continuous-integration/drone/tag Build is passing
2026-09-24 15:01:40 +02:00
moritz 1af9dc1ace chore: publish 14.4.0+33.0.9-fpm release
continuous-integration/drone/tag Build is passing
2026-09-24 15:00:49 +02:00
moritz 2071a7dc2f fix new collabora installation by activating the config 2026-09-24 14:59:26 +02:00
renovate-bot b3c7aef2a9 chore(deps): update docker.elastic.co/elasticsearch/elasticsearch docker tag to v8.19.22 2026-09-23 09:17:13 +00:00
moritz 70f8ab4b56 chore: publish 14.3.0+33.0.9-fpm release
continuous-integration/drone/tag Build is passing
2026-09-22 11:14:32 +02:00
renovate-bot 0ba186b408 chore(deps): update ghcr.io/nextcloud-releases/whiteboard docker tag to v2 2026-09-22 08:52:22 +00:00
renovate-bot 445715e409 chore(deps): update redis docker tag to v8.10.2 2026-09-21 19:18:40 +00:00
simon e715938ebb chore: publish 14.2.0+33.0.9-fpm release
continuous-integration/drone/tag Build is passing
2026-09-21 17:03:43 +02:00
simon 12109fb122 Merge branch 'main' into nextcloud-metrics 2026-09-21 14:56:01 +00:00
simon 5b393d6194 use port 80 for metrics 2026-09-21 13:04:28 +02:00
simon 2a2357142e replace sidecar metrics exporter with native metrics endpoint 2026-09-17 17:53:16 +02:00
simon f9203e5d7f docs: format readme 2026-09-17 15:24:48 +02:00
Linus Gasser d811dfa1cb Add warning about major dependency version updates 2026-09-16 20:33:31 +02:00
Linus Gasser ea487f93dd Details about semver of the recipe
Spell out how we update the release versions of the recipe, specifically
wrt dependencies.
Based on the text of @dannygroenewegen.
2026-09-16 20:33:31 +02:00
renovate-bot 1a43b8fe4f chore(deps): update nginx docker tag to v1.31.6 2026-09-15 23:21:13 +00:00
simon 768531d1a2 Merge branch 'nextcloud-metrics' of ssh://git.coopcloud.tech:2222/coop-cloud/nextcloud into nextcloud-metrics 2026-09-14 18:12:22 +02:00
simon 1d6ec8cf38 add nextcloud metrics exporter 2026-09-14 18:08:09 +02:00
Linus Gasser 131054d234 chore: publish 14.1.2+33.0.9-fpm release
continuous-integration/drone/tag Build is passing
2026-09-12 10:48:38 +01:00
renovate-bot 785931c0de chore(deps): update nextcloud docker tag to v33.0.9 2026-09-12 02:26:35 +00:00
renovate-bot a7f5ec8506 chore(deps): update docker.elastic.co/elasticsearch/elasticsearch docker tag to v8.19.21 2026-09-10 08:16:50 +00:00
moritz 5990c68f23 fix(cron): parsing smtp settings from envs 2026-09-09 17:43:19 +02:00
Linus Gasser fb511d8d07 Set MARIADB_AUTO_UPGRADE=1
This will automatically upgrade the tables to the latest version of mariadb.
2026-09-08 08:17:42 +00:00
carla d019c23843 fixes copy paste 2026-09-07 08:57:08 +00:00
carla 59beed36a7 adds LIT to reviewers 2026-09-07 08:57:08 +00:00
carla d3afccfca9 adds Local IT to maintainers 2026-09-07 08:57:08 +00:00
renovate-bot 257a7ac3a1 chore(deps): update nginx docker tag to v1.31.5 2026-09-02 23:18:10 +00:00
simon d2560c9304 add option to expose metrics via nextcloud-exporter
continuous-integration/drone/pr Build is failing
2026-09-02 11:34:45 +02:00
renovate-bot 364e3088f7 chore(deps): update redis docker tag to v8.10.1 2026-08-28 15:47:54 +00:00
renovate-bot d40797dbda chore(deps): update nginx docker tag to v1.31.4 2026-08-19 20:18:48 +00:00
13 changed files with 108 additions and 13 deletions
+7 -1
View File
@@ -79,11 +79,14 @@ DEFAULT_QUOTA="10 GB"
# COMPOSE_FILE="$COMPOSE_FILE:compose.authentik.yml"
# APPS="$APPS sociallogin"
# AUTHENTIK_USER_PREFIX=authentik
# AUTHENTIK_DOMAIN=authentik.example.com
# SECRET_AUTHENTIK_SECRET_VERSION=v1
# SECRET_AUTHENTIK_ID_VERSION=v1
# Only change this if you've configured your authentik instance to use a non-default user prefix.
# If you're unsure, this should match the redirect_uri in authentik's nextcloud provider.
# AUTHENTIK_USER_PREFIX=authentik
#COMPOSE_FILE="$COMPOSE_FILE:compose.fulltextsearch.yml"
#SECRET_ELASTICSEARCH_PASSWORD_VERSION=v1
@@ -107,3 +110,6 @@ DEFAULT_QUOTA="10 GB"
#HSTS_ENABLED=1
# Uncomment this line to add the `preload` part
#HSTS_PRELOAD=1
# Metrics
# COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
+35 -1
View File
@@ -38,7 +38,7 @@ In order to meet these responsibilities each maintainer:
## Release cadence
The intent is to **track Nextcloud's own release schedule** rather than invent
our own. In practice this means:
our own. In practice this means the following regarding new **nextcloud** releases:
- **Patch releases (e.g. `32.0.x`)**: published to this recipe shortly after
upstream, ideally within 1 week. `chore(deps)` opens the PRs; a maintainer
@@ -63,6 +63,40 @@ our own. In practice this means:
- **Co-installed components** (Talk HPB, OnlyOffice, Whiteboard, etc.) are
bumped alongside or shortly after the matching Nextcloud release.
## Semver versioning within this recipe
The recipe version itself is updated according to the following semver
rules, following
[How are recipes versioned](https://docs.coopcloud.tech/maintainers/handbook/#how-are-recipes-versioned):
These describe the minimum required bump for a given kind of change.
The actual impact of any change (an image update or, e.g. a compose or config change)
should always be considered, and the recipe version can always be bumped higher
than the guideline below to match the impact of the change.
- For updates of the image in the app container (nextcloud), we match the
recipe version bump to at least the image version bump.
- Other containers in this recipe are considered dependencies of the app container
unless they expose additional functionality directly.
- For image updates of dependency containers, we judge the recipe version bump
from the perspective of the app itself, but a minor or major update of a
dependent container is always reflected by at least a minor recipe version bump
to indicate a substantial update under the hood.
Temporary exception:
- In the past, there have been issues with upgrades from database containers
(before the `pgautoupgrade` image and `MARIADB_AUTO_UPGRADE` setting).
We continue treating a major update of a database container (postgresql, mariadb)
as a major recipe bump until that database has had two consecutive major upgrades
with no issues reported, building trust in its automatic upgrade.
Once that trust is established for a given database, we continue with the
default guidelines above.
WARNING:
When moving to a new major version of a dependency, the maintainer needs to make
sure that the version is supported!
Example: in June 2026, MariaDB got updated to version 12, but nextcloud suggests
only up to version 11.8 for best performance.
## Pull Requests
A pull request can be merged once it is approved by at least one maintainer.
+16 -1
View File
@@ -5,7 +5,7 @@
Fully automated luxury Nextcloud via docker-swarm.
<!-- metadata -->
* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti), [@javielico](https://git.coopcloud.tech/javielico)
* **Maintainer**: [@dannygroenewegen](https://git.coopcloud.tech/dannygroenewegen), [@ineiti](https://git.coopcloud.tech/ineiti), [@javielico](https://git.coopcloud.tech/javielico), Local-IT: [@moritz](https://git.coopcloud.tech/moritz), [@simon](https://git.coopcloud.tech/simon), [@carla](https://git.coopcloud.tech/carla)
* **Category**: Apps
* **Status**: 5
* **Image**: [`nextcloud`](https://hub.docker.com/_/nextcloud), 4, upstream
@@ -129,6 +129,21 @@ To disable dashboard app (since it is so corporate):
- Configure a `defaultapp` in your `config.php` or use [apporder](https://apps.nextcloud.com/apps/apporder)
## Metrics
Since Version 33, Nextcloud offers a /metrics endpoint (see [here](https://docs.nextcloud.com/server/stable/admin_manual/configuration_monitoring/index.html)).
Its configured via alloys label-based auto-discovery provided by the updated
[monitoring-stack](https://git.coopcloud.tech/coop-cloud/monitoring-ng).
To enable, uncomment
```
COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
```
and run `configure_metrics`:
```
abra app cmd <domain> app configure_metrics
```
## Upgrading Nextcloud
Upgrading Nextcloud can be a hair raising experiance. They
+6 -1
View File
@@ -1,7 +1,7 @@
#!/bin/bash
export FPM_TUNE_VERSION=v5
export NGINX_CONF_VERSION=v8
export NGINX_CONF_VERSION=v9
export MY_CNF_VERSION=v6
export ENTRYPOINT_VERSION=v3
export ENTRYPOINT_WHITEBOARD_VERSION=v1
@@ -90,6 +90,7 @@ install_collabora() {
# important for security reaosns
# https://docs.nextcloud.com/server/latest/admin_manual/office/configuration.html#wopi-settings
set_app_config richdocuments wopi_allowlist "$COLLABORA_ALLOWLIST"
run_occ "richdocuments:activate-config"
}
install_whiteboard() {
@@ -195,6 +196,10 @@ upgrade_mariadb() {
mariadb-upgrade -p`cat /run/secrets/db_root_password`
}
configure_metrics() {
run_occ "config:system:set openmetrics_allowed_clients 0 --value='10.0.0.0/8'"
}
# Checks whether this instance looks ready to update to the next Nextcloud
# major version.
#
+2 -2
View File
@@ -2,7 +2,7 @@ version: "3.8"
services:
elasticsearch:
image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.20"
image: "docker.elastic.co/elasticsearch/elasticsearch:8.19.22"
environment:
- cluster.name=docker-cluster
- bootstrap.memory_lock=true
@@ -29,7 +29,7 @@ services:
mode: 0600
searchindexer:
image: nextcloud:33.0.8-fpm
image: nextcloud:33.0.9-fpm
volumes:
- nextcloud:/var/www/html/
- nextapps:/var/www/html/custom_apps:cached
+1
View File
@@ -17,6 +17,7 @@ services:
- MYSQL_ROOT_PASSWORD_FILE=/run/secrets/db_root_password
- MAX_DB_CONNECTIONS=${MAX_DB_CONNECTIONS:-100}
- INNODB_BUFFER_POOL_SIZE=${INNODB_BUFFER_POOL_SIZE:-1G}"
- MARIADB_AUTO_UPGRADE=1
configs:
- source: my_tune
target: /etc/mysql/conf.d/my-tune.cnf
+8
View File
@@ -0,0 +1,8 @@
version: "3.8"
services:
web:
environment:
- METRICS_ENABLED=true
deploy:
labels:
- "prometheus.io/scrape=true"
+13
View File
@@ -13,6 +13,19 @@ services:
- MAIL_FROM_ADDRESS
- MAIL_DOMAIN
cron:
secrets:
- smtp_password
environment:
- SMTP_AUTHTYPE
- SMTP_HOST
- SMTP_SECURE
- SMTP_NAME
- SMTP_PORT
- SMTP_PASSWORD_FILE=/run/secrets/smtp_password
- MAIL_FROM_ADDRESS
- MAIL_DOMAIN
secrets:
smtp_password:
external: true
+1 -1
View File
@@ -6,7 +6,7 @@ services:
- whiteboard_jwt
whiteboard:
image: ghcr.io/nextcloud-releases/whiteboard:v1.5.9
image: ghcr.io/nextcloud-releases/whiteboard:v2.0.0
deploy:
labels:
- traefik.enable=true
+5 -5
View File
@@ -1,7 +1,7 @@
version: "3.8"
services:
web:
image: nginx:1.31.3
image: nginx:1.31.6
depends_on:
- app
configs:
@@ -48,7 +48,7 @@ services:
start_period: 5m
app:
image: nextcloud:33.0.8-fpm
image: nextcloud:33.0.9-fpm
depends_on:
- db
configs:
@@ -95,7 +95,7 @@ services:
failure_action: rollback
order: start-first
labels:
- "coop-cloud.${STACK_NAME}.version=14.1.1+33.0.8-fpm"
- "coop-cloud.${STACK_NAME}.version=14.5.0+33.0.9-fpm"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
- "backupbot.backup.volumes.redis=false"
@@ -109,7 +109,7 @@ services:
start_period: 15m
cron:
image: nextcloud:33.0.8-fpm
image: nextcloud:33.0.9-fpm
volumes:
- nextcloud:/var/www/html/
- nextapps:/var/www/html/custom_apps:cached
@@ -125,7 +125,7 @@ services:
cache:
image: redis:8.8.1-alpine
image: redis:8.10.2-alpine
networks:
- internal
volumes:
+11
View File
@@ -184,5 +184,16 @@ http {
location / {
try_files $uri $uri/ /index.php$request_uri;
}
{{ if env "METRICS_ENABLED" }}
location = /metrics {
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root/index.php;
fastcgi_param SCRIPT_NAME /index.php;
fastcgi_param REQUEST_URI /metrics;
fastcgi_param HTTP_HOST {{ env "DOMAIN" }};
fastcgi_pass php-handler;
}
{{ end }}
}
}
+1
View File
@@ -0,0 +1 @@
add option to scrape native /metrics endpoint via alloys auto-discovery
+2 -1
View File
@@ -5,5 +5,6 @@
],
"extends": [
"config:base"
]
],
"reviewers": ["moritz","simon","carla"]
}