Merge branch 'main' into fix-dockerlint

Signed-off-by: Zoey <zoey@z0ey.de>
This commit is contained in:
Zoey
2026-08-22 11:20:59 +02:00
committed by GitHub
55 changed files with 311 additions and 85 deletions
+1
View File
@@ -8,6 +8,7 @@
## Summary
- [ ] The PR was tested and verified that it works locally
- [ ] Or will be tested after merge on a dedicated test instance (available for maintainers)
- [ ] [Sign-off message](https://github.com/src-d/guide/blob/master/developer-community/fix-DCO.md) is added to all commits
- [ ] Tests (playwright if possible) are included
- [ ] Screenshots before/after for front-end changes
+1 -1
View File
@@ -36,7 +36,7 @@ jobs:
line-length: warning
- name: Install the latest version of uv
uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
uses: astral-sh/setup-uv@ae62891fec2bb8e7d6c99fc78c9fec3a63790f8d # v10.0.0
- name: Check GitHub actions
run: uvx zizmor --min-severity medium .github/workflows/*.yml
+7 -2
View File
@@ -13,6 +13,7 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Run nextcloud-update script
id: nextcloud_update
run: |
# Inspired by https://github.com/nextcloud/docker/blob/master/update.sh
@@ -77,6 +78,7 @@ jobs:
if [ -n "$NCVERSION" ]; then
sed -i "s|^ENV NEXTCLOUD_VERSION.*|ENV NEXTCLOUD_VERSION=$NCVERSION|" ./Containers/nextcloud/Dockerfile
fi
echo "nc_version=$NCVERSION" >> "$GITHUB_OUTPUT"
- name: Create Pull Request
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v7
@@ -84,8 +86,11 @@ jobs:
token: ${{ secrets.GITHUB_TOKEN }}
commit-message: nextcloud-update automated change
signoff: true
title: Nextcloud dependency update
body: Automated Nextcloud container update
title: Nextcloud dependency update to ${{ steps.nextcloud_update.outputs.nc_version }}
body: |
Automated Nextcloud container update to version ${{ steps.nextcloud_update.outputs.nc_version }}.
See the [Nextcloud Server ${{ steps.nextcloud_update.outputs.nc_version }} release notes](https://github.com/nextcloud/server/releases/tag/v${{ steps.nextcloud_update.outputs.nc_version }}) for details.
labels: dependencies, 3. to review
milestone: next
branch: nextcloud-container-update
+1 -1
View File
@@ -29,7 +29,7 @@ jobs:
signoff: true
title: Helm Chart updates
body: Automated Helm Chart updates for the yaml files. It can be merged if it looks good at any time which will automatically trigger a new release of the helm chart.
labels: dependencies, 3. to review
labels: 3. to review
milestone: next
branch: aio-helm-update
token: ${{ secrets.GITHUB_TOKEN }}
+8 -3
View File
@@ -12,6 +12,7 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Run watchtower-container-update
id: watchtower_update
run: |
# Watchtower
watchtower_version="$(
@@ -24,15 +25,19 @@ jobs:
watchtower_commit_hash="$(git ls-remote https://github.com/nicholas-fedor/watchtower $watchtower_version | sed 's/refs.*//')"
sed -i "s|^ENV WATCHTOWER_COMMIT_HASH.*$|ENV WATCHTOWER_COMMIT_HASH=$watchtower_commit_hash|" ./Containers/watchtower/Dockerfile
sed -i "s|\$WATCHTOWER_COMMIT_HASH.*$|\$WATCHTOWER_COMMIT_HASH # $watchtower_version|" ./Containers/watchtower/Dockerfile
echo "watchtower_version=$watchtower_version" >> "$GITHUB_OUTPUT"
- name: Create Pull Request
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v7
with:
token: ${{ secrets.GITHUB_TOKEN }}
commit-message: watchtower-update automated change
signoff: true
title: watchtower container update
body: Automated watchtower container update
title: watchtower container update to ${{ steps.watchtower_update.outputs.watchtower_version }}
body: |
Automated watchtower container update to version ${{ steps.watchtower_update.outputs.watchtower_version }}.
See the [Watchtower ${{ steps.watchtower_update.outputs.watchtower_version }} release notes](https://github.com/nicholas-fedor/watchtower/releases/tag/${{ steps.watchtower_update.outputs.watchtower_version }}) for details.
labels: dependencies, 3. to review
milestone: next
branch: watchtower-container-update
+1 -1
View File
@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:latest
# From a file located probably somewhere here: https://github.com/CollaboraOnline/online/blob/master/docker/from-packages/Dockerfile
FROM collabora/code:26.04.2.4.1
FROM collabora/code:26.04.2.1.1
USER root:root
ARG DEBIAN_FRONTEND=noninteractive
+1 -1
View File
@@ -1,5 +1,5 @@
# syntax=docker/dockerfile:latest
FROM ghcr.io/euro-office/documentserver:v9.3.2
FROM ghcr.io/euro-office/documentserver:v9.3.3
# USER root is probably used
+1 -1
View File
@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:latest
# Probably from here https://github.com/elastic/dockerfiles/blob/9.3/elasticsearch/Dockerfile
FROM elasticsearch:9.4.4
FROM elasticsearch:9.5.1
USER root:root
+1 -1
View File
@@ -1,5 +1,5 @@
# syntax=docker/dockerfile:latest
FROM ghcr.io/nextcloud/nextcloud-appapi-harp:v0.4.3
FROM ghcr.io/nextcloud/nextcloud-appapi-harp:v0.4.4
# USER root is probably used
+1 -1
View File
@@ -1,5 +1,5 @@
# syntax=docker/dockerfile:latest
FROM golang:1.26.5-alpine3.24 AS go
FROM golang:1.26.6-alpine3.24 AS go
ENV IMAGINARY_HASH=6a274b488759a896aff02f52afee6e50b5e3a3ee
+1 -1
View File
@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:latest
# Docker CLI is a requirement
FROM docker:29.7.0-cli AS docker
FROM docker:29.7.2-cli AS docker
ARG CADDY_REMOTE_HOST_HASH=e80a9931765a8dbcbb47db415863387f0df0e1b3
+1 -1
View File
@@ -8,7 +8,7 @@ ENV SOURCE_LOCATION=/usr/src/nextcloud
ENV REDIS_DB_INDEX=0
# AIO settings start # Do not remove or change this line!
ENV NEXTCLOUD_VERSION=33.0.7
ENV NEXTCLOUD_VERSION=33.0.8
# Required to stop hadolint from complaining about potentially sensitive data in an environment variable.
# It might be a good idea to reconsider using and env var for this at one point,
# but the actual value here is just a dummy and not relevant, so we silence the warning for now.
+1
View File
@@ -31,6 +31,7 @@ stdout_logfile_maxbytes=0
stderr_logfile=/dev/stderr
stderr_logfile_maxbytes=0
command=php /var/www/html/occ taskprocessing:worker --timeout 300
autorestart=true
user=www-data
[program:run-exec-commands]
+1 -1
View File
@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:latest
# From https://github.com/docker-library/postgres/blob/master/18/alpine3.24/Dockerfile
FROM postgres:18.4-alpine
FROM postgres:18.6-alpine
ENV PGDATA=/var/lib/postgresql/data
+1 -1
View File
@@ -1,5 +1,5 @@
# syntax=docker/dockerfile:latest
FROM python:3.14.6-alpine3.24
FROM python:3.14.7-alpine3.24
COPY --chmod=775 start.sh /start.sh
COPY --chmod=775 healthcheck.sh /healthcheck.sh
+1 -1
View File
@@ -1,5 +1,5 @@
# syntax=docker/dockerfile:latest
FROM nats:2.14.4-scratch AS nats
FROM nats:2.14.5-scratch AS nats
FROM eturnal/eturnal:1.12.2-alpine AS eturnal
FROM strukturag/nextcloud-spreed-signaling:2.1.1 AS signaling
FROM alpine:3.24.1 AS janus
+3 -3
View File
@@ -1,13 +1,13 @@
# syntax=docker/dockerfile:latest
FROM golang:1.26.5-alpine3.24 AS go
FROM golang:1.26.6-alpine3.24 AS go
ENV WATCHTOWER_COMMIT_HASH=e48a0307b9cab185e08f6f8453ee62f937f43a06
ENV WATCHTOWER_COMMIT_HASH=dcc6e4acd3bd798c46b21bb4e70870f2dca6675d
RUN set -ex; \
apk upgrade --no-cache -a; \
apk add --no-cache \
build-base; \
go install github.com/nicholas-fedor/watchtower@$WATCHTOWER_COMMIT_HASH # v1.20.2
go install github.com/nicholas-fedor/watchtower@$WATCHTOWER_COMMIT_HASH # v1.20.3
FROM alpine:3.24.1
+3 -1
View File
@@ -21,6 +21,7 @@
"APACHE_PORT=%APACHE_PORT%",
"APACHE_IP_BINDING=%APACHE_IP_BINDING%",
"NEXTCLOUD_EXPORTER_CADDY_PASSWORD=%NEXTCLOUD_EXPORTER_CADDY_PASSWORD%",
"NEXTCLOUD_GLANCES_CADDY_PASSWORD=%NEXTCLOUD_GLANCES_CADDY_PASSWORD%",
"DESEC_TOKEN=%DESEC_TOKEN%"
],
"volumes": [
@@ -36,7 +37,8 @@
}
],
"secrets": [
"NEXTCLOUD_EXPORTER_CADDY_PASSWORD"
"NEXTCLOUD_EXPORTER_CADDY_PASSWORD",
"NEXTCLOUD_GLANCES_CADDY_PASSWORD"
],
"aio_variables": [
"apache_ip_binding=@INTERNAL",
+4 -3
View File
@@ -5,11 +5,11 @@ This container bundles [caddy](https://caddyserver.com/) and auto-configures it
> [!Caution]
> - This container is incompatible with the [npmplus](https://github.com/nextcloud/all-in-one/tree/main/community-containers/npmplus) community container. So make sure that you do not enable both at the same time!
> - Make sure that no other service is using port 443/tcp on your host as otherwise the containers will fail to start. You can check this with `sudo netstat -tulpn | grep 443` before installing this container
> - the default `admin` user needs to be present, i.e. it can not be deleted because caddy configuration can be done there.
> - the default `admin` Nextcloud user needs to be present, i.e. it can not be deleted because caddy configuration can be done there.
## Supported community containers
This container configures subdomains for a number of community containers.
This container creates Let's Encrypt certificates for subdomains of `your-nc-domain.com` for a number of community containers.
> [!Important]
> You need to set the correct DNS records for this to work
@@ -23,6 +23,7 @@ This container configures subdomains for a number of community containers.
| Container | Subdomain | Geoblocking | IP Allow List | Authentication |
|---------------------------------------------------------------------------------------------------------------------|----------------------------------|-------------|---------------|----------------|
| [azuracast](https://github.com/nextcloud/all-in-one/tree/main/community-containers/azuracast) | `radio.your-nc-domain.com` | ✅ | | |
| [glances](https://github.com/nextcloud/all-in-one/tree/main/community-containers/glances) | `glances.your-nc-domain.com` | ✅ | | ✅ |
| [jellyfin](https://github.com/nextcloud/all-in-one/tree/main/community-containers/jellyfin) | `media.your-nc-domain.com` | ✅ | | |
| [joplin-server](https://github.com/nextcloud/all-in-one/tree/main/community-containers/joplin-server) | `joplin.your-nc-domain.com` | ✅ | | |
| [lldap](https://github.com/nextcloud/all-in-one/tree/main/community-containers/lldap) | `ldap.your-nc-domain.com` | ✅ | ✅ | |
@@ -35,7 +36,7 @@ This container configures subdomains for a number of community containers.
## Geoblocking
- After the container was started the first time, log in as default `admin` user. You should see a new `nextcloud-aio-caddy` folder and inside there an `allowed-countries.txt` file
- After the container was started the first time, log in in Nextcloud as default `admin` user. You should see a new `nextcloud-aio-caddy` folder in the files app and inside there an `allowed-countries.txt` file
- In there you can adjust the allowed country codes for caddy by adding them to the first line, e.g. `IT FR` would allow access from italy and france.
- Additionally, in order to activate this config, you need to get an account at https://dev.maxmind.com/geoip/geolite2-free-geolocation-data
- download the `GeoLite2-Country.mmdb` from there and upload it with this exact name into the `nextcloud-aio-caddy` folder.
+5 -1
View File
@@ -30,9 +30,13 @@
"environment": [
"GLANCES_OPT=-w"
],
"ui_secret": "NEXTCLOUD_GLANCES_CADDY_PASSWORD",
"secrets": [
"NEXTCLOUD_GLANCES_CADDY_PASSWORD"
],
"backup_volumes": [
"nextcloud_aio_glances"
]
}
]
}
}
+1
View File
@@ -6,6 +6,7 @@ This container starts [Glances](https://nicolargo.github.io/glances/), a web-bas
### Notes
- After adding and starting the container, you can directly visit http://ip.address.of.server:61208/ and access your new Glances instance!
- if you are using caddy community container, this will be available at `https://glances.your-server.com`, For security reasons, a password will be generated and shown in the AIO interface (if you click on showing the secret for glances). Use `glances` as user name.
- It is recommended to start this container only in home networks, because there is no built-in authentication. But you can do a http-auth with your proxy.
- In order to access your Glances outside the local network, you have to set up your own reverse proxy. You can set up a reverse proxy following [these instructions](https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md).
- The data of Glances will be automatically included in AIO's backup solution!
+8 -6
View File
@@ -1,22 +1,24 @@
> [!CAUTION]
> Be aware that the mail server is the most difficult service to deploy.
>
> Be aware that the mail server is the most challenging service to deploy.
>
> Do not use this feature as a main mail server or without a redundancy system and without knowledge.
## Stalwart mail server
This container bundles the [Stalwart](https://stalw.art/) mail server and auto-configures it for you.
This container bundles the [Stalwart](https://stalw.art/) mail server and autoconfigures it for you.
### Notes
Documentation is available on the container repository.
This documentation is regularly updated and is intended to be as simple and detailed as possible.
Thanks for all your feedback!
- See https://github.com/docjyJ/aio-stalwart#getting-started for getting start with this container.
- See https://github.com/winterrific/aio-stalwart#getting-started for getting start with this container.
- See https://stalw.art/docs/faq for further faq and docs on the project
- See https://github.com/nextcloud/all-in-one/tree/main/community-containers#community-containers how to add it to the AIO stack
### Repository
https://github.com/docjyj/aio-stalwart
https://github.com/winterrific/aio-stalwart
### Maintainer
https://github.com/docjyj
https://github.com/winterrific
Created by https://github.com/docjyj
+2 -2
View File
@@ -4,8 +4,8 @@
"container_name": "nextcloud-aio-stalwart",
"display_name": "Stalwart",
"documentation": "https://github.com/nextcloud/all-in-one/tree/main/community-containers/stalwart",
"image": "ghcr.io/docjyj/aio-stalwart",
"image_tag": "v3",
"image": "ghcr.io/winterrific/aio-stalwart",
"image_tag": "v0",
"internal_port": "10003",
"restart": "unless-stopped",
"ports": [
+41
View File
@@ -19,6 +19,9 @@ services:
nextcloud-aio-whiteboard:
condition: service_started
required: false
nextcloud-aio-harp:
condition: service_started
required: false
nextcloud-aio-nextcloud:
condition: service_started
required: false
@@ -50,6 +53,7 @@ services:
- APACHE_MAX_TIME=${NEXTCLOUD_MAX_TIME}
- NOTIFY_PUSH_HOST=nextcloud-aio-notify-push
- WHITEBOARD_HOST=nextcloud-aio-whiteboard
- HARP_HOST=nextcloud-aio-harp
volumes:
- nextcloud_aio_nextcloud:/var/www/html:ro
- nextcloud_aio_apache:/mnt/data:rw
@@ -193,6 +197,8 @@ services:
- IMAGINARY_SECRET
- WHITEBOARD_SECRET
- WHITEBOARD_ENABLED
- HARP_ENABLED
- HP_SHARED_KEY
stop_grace_period: 600s
restart: unless-stopped
shm_size: 134217728
@@ -434,6 +440,7 @@ services:
- JWT_SECRET=${EUROOFFICE_SECRET}
volumes:
- nextcloud_aio_eurooffice:/var/lib/euro-office:rw
- nextcloud_aio_eurooffice_data:/var/www/euro-office/Data:rw
restart: unless-stopped
profiles:
- eurooffice
@@ -504,6 +511,36 @@ services:
cap_drop:
- NET_RAW
nextcloud-aio-harp:
image: ghcr.io/nextcloud-releases/aio-harp:latest
init: true
expose:
- "8780"
healthcheck:
start_period: 0s
test: /healthcheck.sh
interval: 10s
timeout: 10s
start_interval: 5s
retries: 9
environment:
- HP_SHARED_KEY
- NC_INSTANCE_URL=https://${NC_DOMAIN}
- HP_FRP_DISABLE_TLS=true
- TZ=${TIMEZONE}
volumes:
- ${WATCHTOWER_DOCKER_SOCKET_PATH}:/var/run/docker.sock:ro
- nextcloud_aio_harp:/certs:rw
restart: unless-stopped
read_only: true
tmpfs:
- /tmp
- /run/harp
cap_drop:
- NET_RAW
profiles:
- harp
nextcloud-aio-whiteboard:
image: ghcr.io/nextcloud-releases/aio-whiteboard:latest
user: "65534"
@@ -549,6 +586,10 @@ volumes:
name: nextcloud_aio_elasticsearch
nextcloud_aio_eurooffice:
name: nextcloud_aio_eurooffice
nextcloud_aio_eurooffice_data:
name: nextcloud_aio_eurooffice_data
nextcloud_aio_harp:
name: nextcloud_aio_harp
nextcloud_aio_nextcloud:
name: nextcloud_aio_nextcloud
nextcloud_aio_onlyoffice:
+3
View File
@@ -1,6 +1,7 @@
DATABASE_PASSWORD= # TODO! This needs to be a unique and good password!
EUROOFFICE_SECRET= # TODO! This needs to be a unique and good password!
FULLTEXTSEARCH_PASSWORD= # TODO! This needs to be a unique and good password!
HP_SHARED_KEY= # TODO! This needs to be a unique and good password!
IMAGINARY_SECRET= # TODO! This needs to be a unique and good password!
NC_DOMAIN=yourdomain.com # TODO! Needs to be changed to the domain that you want to use for Nextcloud.
NEXTCLOUD_PASSWORD= # TODO! This is the password of the initially created Nextcloud admin with username "admin".
@@ -17,6 +18,7 @@ CLAMAV_ENABLED="no" # Setting this to "yes" (with quotes) enables the o
COLLABORA_ENABLED="no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
EUROOFFICE_ENABLED="no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
FULLTEXTSEARCH_ENABLED="no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
HARP_ENABLED="no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
IMAGINARY_ENABLED="no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
ONLYOFFICE_ENABLED="no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
TALK_ENABLED="no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
@@ -43,3 +45,4 @@ NEXTCLOUD_UPLOAD_LIMIT=16G # This allows to change the upload limit of
REMOVE_DISABLED_APPS=yes # Setting this to no keep Nextcloud apps that are disabled via their switch and not uninstall them if they should be installed in Nextcloud.
TALK_PORT=3478 # This allows to adjust the port that the talk container is using. It should be set to something higher than 1024! Otherwise it might not work!
UPDATE_NEXTCLOUD_APPS="no" # When setting to "yes" (with quotes), it will automatically update all installed Nextcloud apps upon container startup on saturdays.
WATCHTOWER_DOCKER_SOCKET_PATH=/var/run/docker.sock # This can be changed depending on where the docker socket is located on your host
-1
View File
@@ -45,7 +45,6 @@ sed -i 's|- ip_binding: |- |' containers.yml
sed -i '/AIO_TOKEN/d' containers.yml
sed -i '/AIO_URL/d' containers.yml
sed -i '/DOCKER_SOCKET_PROXY_ENABLED/d' containers.yml
sed -i '/HP_SHARED_KEY/d' containers.yml
sed -i '/ADDITIONAL_TRUSTED_PROXY/d' containers.yml
sed -i '/TURN_DOMAIN/d' containers.yml
sed -i '/NC_AIO_VERSION/d' containers.yml
+1 -1
View File
@@ -1,6 +1,6 @@
name: nextcloud-aio-helm-chart
description: A generated Helm Chart for Nextcloud AIO from Skippbox Kompose
version: 13.4.1
version: 13.5.2
apiVersion: v2
keywords:
- latest
@@ -51,6 +51,8 @@ spec:
value: nextcloud-aio-collabora
- name: EUROOFFICE_HOST
value: nextcloud-aio-eurooffice
- name: HARP_HOST
value: nextcloud-aio-harp
- name: NC_DOMAIN
value: "{{ .Values.NC_DOMAIN }}"
- name: NEXTCLOUD_HOST
@@ -65,7 +67,7 @@ spec:
value: "{{ .Values.TIMEZONE }}"
- name: WHITEBOARD_HOST
value: nextcloud-aio-whiteboard
image: ghcr.io/nextcloud-releases/aio-apache:20260805_083533
image: ghcr.io/nextcloud-releases/aio-apache:20260817_082005
readinessProbe:
exec:
command:
@@ -36,7 +36,7 @@ spec:
{{- end }}
initContainers:
- name: init-subpath
image: ghcr.io/nextcloud-releases/aio-alpine:20260805_083533
image: ghcr.io/nextcloud-releases/aio-alpine:20260817_082005
command:
- mkdir
- "-p"
@@ -61,7 +61,7 @@ spec:
value: "{{ .Values.NEXTCLOUD_UPLOAD_LIMIT }}"
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-clamav:20260805_083533
image: ghcr.io/nextcloud-releases/aio-clamav:20260817_082005
readinessProbe:
exec:
command:
@@ -37,7 +37,7 @@ spec:
value: --o:ssl.enable=false --o:ssl.termination=true --o:logging.disable_server_audit=true --o:welcome.enable=false --o:fetch_update_check=0 --o:allow_update_popup=false --o:remote_font_config.url=https://{{ .Values.NC_DOMAIN }}/apps/richdocuments/settings/fonts.json --o:net.post_allow.host[0]=.+
- name: server_name
value: "{{ .Values.NC_DOMAIN }}"
image: ghcr.io/nextcloud-releases/aio-collabora:20260805_083533
image: ghcr.io/nextcloud-releases/aio-collabora:20260817_082005
readinessProbe:
exec:
command:
@@ -35,7 +35,7 @@ spec:
{{- end }}
initContainers:
- name: init-subpath
image: ghcr.io/nextcloud-releases/aio-alpine:20260805_083533
image: ghcr.io/nextcloud-releases/aio-alpine:20260817_082005
command:
- mkdir
- "-p"
@@ -66,7 +66,7 @@ spec:
value: nextcloud
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-postgresql:20260805_083533
image: ghcr.io/nextcloud-releases/aio-postgresql:20260817_082005
readinessProbe:
exec:
command:
@@ -0,0 +1,18 @@
{{- if eq .Values.EUROOFFICE_ENABLED "yes" }}
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
labels:
io.kompose.service: nextcloud-aio-eurooffice-data
name: nextcloud-aio-eurooffice-data
namespace: "{{ .Values.NAMESPACE }}"
spec:
{{- if .Values.STORAGE_CLASS }}
storageClassName: {{ .Values.STORAGE_CLASS }}
{{- end }}
accessModes:
- ReadWriteOnce
resources:
requests:
storage: {{ .Values.EUROOFFICE_DATA_STORAGE_SIZE }}
{{- end }}
@@ -24,12 +24,15 @@ spec:
spec:
initContainers:
- name: init-volumes
image: ghcr.io/nextcloud-releases/aio-alpine:20260805_083533
image: ghcr.io/nextcloud-releases/aio-alpine:20260817_082005
command:
- chmod
- "777"
- /nextcloud-aio-eurooffice
- /nextcloud-aio-eurooffice-data
volumeMounts:
- name: nextcloud-aio-eurooffice-data
mountPath: /nextcloud-aio-eurooffice-data
- name: nextcloud-aio-eurooffice
mountPath: /nextcloud-aio-eurooffice
containers:
@@ -46,7 +49,7 @@ spec:
value: "{{ .Values.AIO_LOG_LEVEL }}"
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-eurooffice:20260805_083533
image: ghcr.io/nextcloud-releases/aio-eurooffice:20260817_082005
readinessProbe:
exec:
command:
@@ -70,8 +73,13 @@ spec:
volumeMounts:
- mountPath: /var/lib/euro-office
name: nextcloud-aio-eurooffice
- mountPath: /var/www/euro-office/Data
name: nextcloud-aio-eurooffice-data
volumes:
- name: nextcloud-aio-eurooffice
persistentVolumeClaim:
claimName: nextcloud-aio-eurooffice
- name: nextcloud-aio-eurooffice-data
persistentVolumeClaim:
claimName: nextcloud-aio-eurooffice-data
{{- end }}
@@ -24,7 +24,7 @@ spec:
spec:
initContainers:
- name: init-volumes
image: ghcr.io/nextcloud-releases/aio-alpine:20260805_083533
image: ghcr.io/nextcloud-releases/aio-alpine:20260817_082005
command:
- chmod
- "777"
@@ -64,7 +64,7 @@ spec:
value: "false"
- name: xpack.security.transport.ssl.enabled
value: "false"
image: ghcr.io/nextcloud-releases/aio-fulltextsearch:20260805_083533
image: ghcr.io/nextcloud-releases/aio-fulltextsearch:20260817_082005
readinessProbe:
exec:
command:
@@ -0,0 +1,74 @@
{{- if eq .Values.HARP_ENABLED "yes" }}
apiVersion: apps/v1
kind: Deployment
metadata:
annotations:
kompose.version: 1.38.0 (a8f5d1cbd)
labels:
io.kompose.service: nextcloud-aio-harp
name: nextcloud-aio-harp
namespace: "{{ .Values.NAMESPACE }}"
spec:
replicas: 1
selector:
matchLabels:
io.kompose.service: nextcloud-aio-harp
strategy:
type: Recreate
template:
metadata:
annotations:
kompose.version: 1.38.0 (a8f5d1cbd)
labels:
io.kompose.service: nextcloud-aio-harp
spec:
{{- if .Values.HARP_SERVICE_ACCOUNT_NAME }}
serviceAccountName: "{{ .Values.HARP_SERVICE_ACCOUNT_NAME }}"
{{- end }}
containers:
- env:
- name: HP_K8S_ENABLED
value: "true"
- name: HP_K8S_NAMESPACE
value: "{{ .Values.HARP_K8S_NAMESPACE }}"
- name: HP_K8S_STORAGE_CLASS
value: "{{ .Values.HARP_K8S_STORAGE_CLASS }}"
- name: HP_K8S_DEFAULT_STORAGE_SIZE
value: "{{ .Values.HARP_K8S_DEFAULT_STORAGE_SIZE }}"
- name: HP_K8S_HOST_ALIASES
value: "{{ .Values.HARP_K8S_HOST_ALIASES }}"
- name: HP_FRP_DISABLE_TLS
value: "true"
- name: HP_SHARED_KEY
value: "{{ .Values.HP_SHARED_KEY }}"
- name: NC_INSTANCE_URL
value: https://{{ .Values.NC_DOMAIN }}
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-harp:20260817_082005
readinessProbe:
exec:
command:
- /healthcheck.sh
failureThreshold: 9
periodSeconds: 10
timeoutSeconds: 10
livenessProbe:
exec:
command:
- /healthcheck.sh
failureThreshold: 9
periodSeconds: 10
timeoutSeconds: 10
name: nextcloud-aio-harp
ports:
- containerPort: 8780
protocol: TCP
volumeMounts:
- mountPath: /certs
name: nextcloud-aio-harp
volumes:
- name: nextcloud-aio-harp
persistentVolumeClaim:
claimName: nextcloud-aio-harp
{{- end }}
@@ -0,0 +1,18 @@
{{- if eq .Values.HARP_ENABLED "yes" }}
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
labels:
io.kompose.service: nextcloud-aio-harp
name: nextcloud-aio-harp
namespace: "{{ .Values.NAMESPACE }}"
spec:
{{- if .Values.STORAGE_CLASS }}
storageClassName: {{ .Values.STORAGE_CLASS }}
{{- end }}
accessModes:
- ReadWriteOnce
resources:
requests:
storage: {{ .Values.HARP_STORAGE_SIZE }}
{{- end }}
@@ -0,0 +1,19 @@
{{- if eq .Values.HARP_ENABLED "yes" }}
apiVersion: v1
kind: Service
metadata:
annotations:
kompose.version: 1.38.0 (a8f5d1cbd)
labels:
io.kompose.service: nextcloud-aio-harp
name: nextcloud-aio-harp
namespace: "{{ .Values.NAMESPACE }}"
spec:
ipFamilyPolicy: PreferDualStack
ports:
- name: "8780"
port: 8780
targetPort: 8780
selector:
io.kompose.service: nextcloud-aio-harp
{{- end }}
@@ -40,7 +40,7 @@ spec:
value: "{{ .Values.IMAGINARY_SECRET }}"
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-imaginary:20260805_083533
image: ghcr.io/nextcloud-releases/aio-imaginary:20260817_082005
readinessProbe:
exec:
command:
@@ -38,7 +38,7 @@ spec:
# AIO settings start # Do not remove or change this line!
initContainers:
- name: init-volumes
image: ghcr.io/nextcloud-releases/aio-alpine:20260805_083533
image: ghcr.io/nextcloud-releases/aio-alpine:20260817_082005
command:
- chmod
- "777"
@@ -126,6 +126,10 @@ spec:
value: http
- name: FULLTEXTSEARCH_USER
value: elastic
- name: HARP_ENABLED
value: "{{ .Values.HARP_ENABLED }}"
- name: HP_SHARED_KEY
value: "{{ .Values.HP_SHARED_KEY }}"
- name: IMAGINARY_ENABLED
value: "{{ .Values.IMAGINARY_ENABLED }}"
- name: IMAGINARY_HOST
@@ -198,7 +202,7 @@ spec:
value: "{{ .Values.WHITEBOARD_ENABLED }}"
- name: WHITEBOARD_SECRET
value: "{{ .Values.WHITEBOARD_SECRET }}"
image: ghcr.io/nextcloud-releases/aio-nextcloud:20260805_083533
image: ghcr.io/nextcloud-releases/aio-nextcloud:20260817_082005
{{- if eq (.Values.RPSS_ENABLED | default "no") "yes" }} # AIO-config - do not change this comment!
securityContext:
# The items below only work in container context
@@ -41,7 +41,7 @@ spec:
value: nextcloud-aio-nextcloud
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-notify-push:20260805_083533
image: ghcr.io/nextcloud-releases/aio-notify-push:20260817_082005
readinessProbe:
exec:
command:
@@ -24,7 +24,7 @@ spec:
spec:
initContainers:
- name: init-volumes
image: ghcr.io/nextcloud-releases/aio-alpine:20260805_083533
image: ghcr.io/nextcloud-releases/aio-alpine:20260817_082005
command:
- chmod
- "777"
@@ -46,7 +46,7 @@ spec:
value: "{{ .Values.AIO_LOG_LEVEL }}"
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-onlyoffice:20260805_083533
image: ghcr.io/nextcloud-releases/aio-onlyoffice:20260817_082005
readinessProbe:
exec:
command:
@@ -41,7 +41,7 @@ spec:
value: "{{ .Values.REDIS_PASSWORD }}"
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-redis:20260805_083533
image: ghcr.io/nextcloud-releases/aio-redis:20260817_082005
readinessProbe:
exec:
command:
@@ -56,7 +56,7 @@ spec:
value: "{{ .Values.TURN_SECRET }}"
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-talk:20260805_083533
image: ghcr.io/nextcloud-releases/aio-talk:20260817_082005
readinessProbe:
exec:
command:
@@ -46,7 +46,7 @@ spec:
value: "{{ .Values.RECORDING_SECRET }}"
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-talk-recording:20260805_083533
image: ghcr.io/nextcloud-releases/aio-talk-recording:20260817_082005
readinessProbe:
exec:
command:
@@ -52,7 +52,7 @@ spec:
value: redis
- name: TZ
value: "{{ .Values.TIMEZONE }}"
image: ghcr.io/nextcloud-releases/aio-whiteboard:20260805_083533
image: ghcr.io/nextcloud-releases/aio-whiteboard:20260817_082005
readinessProbe:
exec:
command:
+7
View File
@@ -475,6 +475,7 @@ MAIL_DOMAIN: # (not set by default): Set a different domain for the emai
TALK_MAX_STREAM_BITRATE: "1048576" # This allows to adjust the max stream bitrate of the talk hpb
TALK_MAX_SCREEN_BITRATE: "2097152" # This allows to adjust the max stream bitrate of the talk hpb
HARP_K8S_NAMESPACE: nextcloud-exapps # The Kubernetes namespace that HaRP deploys ExApps (AppAPI apps) into. The namespace must already exist and the HaRP service account must be allowed to manage resources in it.
# HP_SHARED_KEY: # This allows to set the shared key for HaRP which is getting set at the very top of this values.yaml file.
HARP_K8S_STORAGE_CLASS: # The storage class that HaRP uses for ExApp persistent volume claims. Leave empty to use the cluster's default storage class.
HARP_K8S_DEFAULT_STORAGE_SIZE: 10Gi # The default size of the persistent volume claims that HaRP creates for ExApps.
HARP_K8S_HOST_ALIASES: # Optional. Additional host aliases that HaRP sets on the ExApp pods so that they can resolve the configured hostnames. Use a comma-separated list of hostname:ip pairs, e.g. 'nextcloud.example.com:10.0.0.5,collabora.example.com:10.0.0.6'. Leave empty to not set any host aliases.
@@ -509,6 +510,12 @@ find ./ -name "*nextcloud-aio-elasticsearch-persistentvolumeclaim.yaml" -exec se
# shellcheck disable=SC1083
find ./ -name "*nextcloud-aio-elasticsearch-persistentvolumeclaim.yaml" -exec sed -i "$ a {{- end }}" \{} \;
# Additional case for Eurooffice-data
# shellcheck disable=SC1083
find ./ -name "*nextcloud-aio-eurooffice-data-persistentvolumeclaim.yaml" -exec sed -i "1i\\{{- if eq .Values.EUROOFFICE_ENABLED \"yes\" }}" \{} \;
# shellcheck disable=SC1083
find ./ -name "*nextcloud-aio-eurooffice-data-persistentvolumeclaim.yaml" -exec sed -i "$ a {{- end }}" \{} \;
cat << EOL > /tmp/security.conf
# The items below only work in container context
allowPrivilegeEscalation: false
+10
View File
@@ -1,6 +1,7 @@
DATABASE_PASSWORD: # TODO! This needs to be a unique and good password!
EUROOFFICE_SECRET: # TODO! This needs to be a unique and good password!
FULLTEXTSEARCH_PASSWORD: # TODO! This needs to be a unique and good password!
HP_SHARED_KEY: # TODO! This needs to be a unique and good password!
IMAGINARY_SECRET: # TODO! This needs to be a unique and good password!
NC_DOMAIN: yourdomain.com # TODO! Needs to be changed to the domain that you want to use for Nextcloud.
NEXTCLOUD_PASSWORD: # TODO! This is the password of the initially created Nextcloud admin with username admin.
@@ -17,6 +18,7 @@ CLAMAV_ENABLED: "no" # Setting this to "yes" (with quotes) enables the
COLLABORA_ENABLED: "no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
EUROOFFICE_ENABLED: "no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
FULLTEXTSEARCH_ENABLED: "no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
HARP_ENABLED: "no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
IMAGINARY_ENABLED: "no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
ONLYOFFICE_ENABLED: "no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
TALK_ENABLED: "no" # Setting this to "yes" (with quotes) enables the option in Nextcloud automatically.
@@ -49,6 +51,8 @@ DATABASE_STORAGE_SIZE: 1Gi # You can change the size of the database volum
DATABASE_DUMP_STORAGE_SIZE: 1Gi # You can change the size of the database-dump volume that default to 1Gi with this value
ELASTICSEARCH_STORAGE_SIZE: 1Gi # You can change the size of the elasticsearch volume that default to 1Gi with this value
EUROOFFICE_STORAGE_SIZE: 1Gi # You can change the size of the eurooffice volume that default to 1Gi with this value
EUROOFFICE_DATA_STORAGE_SIZE: 1Gi # You can change the size of the eurooffice-data volume that default to 1Gi with this value
HARP_STORAGE_SIZE: 1Gi # You can change the size of the harp volume that default to 1Gi with this value
NEXTCLOUD_STORAGE_SIZE: 5Gi # You can change the size of the nextcloud volume that default to 1Gi with this value
NEXTCLOUD_DATA_STORAGE_SIZE: 5Gi # You can change the size of the nextcloud-data volume that default to 1Gi with this value
NEXTCLOUD_TRUSTED_CACERTS_STORAGE_SIZE: 1Gi # You can change the size of the nextcloud-trusted-cacerts volume that default to 1Gi with this value
@@ -77,3 +81,9 @@ MAIL_FROM_ADDRESS: # (not set by default): Set the local-part for the 'f
MAIL_DOMAIN: # (not set by default): Set a different domain for the emails than the domain where Nextcloud is installed.
TALK_MAX_STREAM_BITRATE: "1048576" # This allows to adjust the max stream bitrate of the talk hpb
TALK_MAX_SCREEN_BITRATE: "2097152" # This allows to adjust the max stream bitrate of the talk hpb
HARP_K8S_NAMESPACE: nextcloud-exapps # The Kubernetes namespace that HaRP deploys ExApps (AppAPI apps) into. The namespace must already exist and the HaRP service account must be allowed to manage resources in it.
# HP_SHARED_KEY: # This allows to set the shared key for HaRP which is getting set at the very top of this values.yaml file.
HARP_K8S_STORAGE_CLASS: # The storage class that HaRP uses for ExApp persistent volume claims. Leave empty to use the cluster's default storage class.
HARP_K8S_DEFAULT_STORAGE_SIZE: 10Gi # The default size of the persistent volume claims that HaRP creates for ExApps.
HARP_K8S_HOST_ALIASES: # Optional. Additional host aliases that HaRP sets on the ExApp pods so that they can resolve the configured hostnames. Use a comma-separated list of hostname:ip pairs, e.g. 'nextcloud.example.com:10.0.0.5,collabora.example.com:10.0.0.6'. Leave empty to not set any host aliases.
HARP_SERVICE_ACCOUNT_NAME: # The name of the Kubernetes service account that is mounted into the HaRP pod and used to authenticate against the Kubernetes API. You need to create this service account yourself and grant it permission to manage resources (deployments, services, persistent volume claims, …) in the HARP_K8S_NAMESPACE namespace via a Role/RoleBinding. Leave empty to use the namespace's "default" service account.
+13 -13
View File
@@ -64,21 +64,21 @@
},
{
"name": "guzzlehttp/guzzle",
"version": "7.15.2",
"version": "7.15.3",
"source": {
"type": "git",
"url": "https://github.com/guzzle/guzzle.git",
"reference": "744101956d78b7c1384d0cbf379db13e859167bf"
"reference": "ae311b8f045ea93ce7b1c9cdb7cec06c53f944bc"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/guzzle/guzzle/zipball/744101956d78b7c1384d0cbf379db13e859167bf",
"reference": "744101956d78b7c1384d0cbf379db13e859167bf",
"url": "https://api.github.com/repos/guzzle/guzzle/zipball/ae311b8f045ea93ce7b1c9cdb7cec06c53f944bc",
"reference": "ae311b8f045ea93ce7b1c9cdb7cec06c53f944bc",
"shasum": ""
},
"require": {
"ext-json": "*",
"guzzlehttp/promises": "^2.5.1",
"guzzlehttp/promises": "^2.5.2",
"guzzlehttp/psr7": "^2.13",
"php": "^7.2.5 || ^8.0",
"psr/http-client": "^1.0",
@@ -172,7 +172,7 @@
],
"support": {
"issues": "https://github.com/guzzle/guzzle/issues",
"source": "https://github.com/guzzle/guzzle/tree/7.15.2"
"source": "https://github.com/guzzle/guzzle/tree/7.15.3"
},
"funding": [
{
@@ -188,20 +188,20 @@
"type": "tidelift"
}
],
"time": "2026-07-26T23:23:20+00:00"
"time": "2026-08-05T19:48:21+00:00"
},
{
"name": "guzzlehttp/promises",
"version": "2.5.1",
"version": "2.5.2",
"source": {
"type": "git",
"url": "https://github.com/guzzle/promises.git",
"reference": "9ad1e4fc607446a055b95870c7f668e93b5cff29"
"reference": "2823687acff28b2dbe67b2508a6b300e2c3fa4ce"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/guzzle/promises/zipball/9ad1e4fc607446a055b95870c7f668e93b5cff29",
"reference": "9ad1e4fc607446a055b95870c7f668e93b5cff29",
"url": "https://api.github.com/repos/guzzle/promises/zipball/2823687acff28b2dbe67b2508a6b300e2c3fa4ce",
"reference": "2823687acff28b2dbe67b2508a6b300e2c3fa4ce",
"shasum": ""
},
"require": {
@@ -256,7 +256,7 @@
],
"support": {
"issues": "https://github.com/guzzle/promises/issues",
"source": "https://github.com/guzzle/promises/tree/2.5.1"
"source": "https://github.com/guzzle/promises/tree/2.5.2"
},
"funding": [
{
@@ -272,7 +272,7 @@
"type": "tidelift"
}
],
"time": "2026-07-08T15:48:39+00:00"
"time": "2026-08-05T19:30:54+00:00"
},
{
"name": "guzzlehttp/psr7",
-3
View File
@@ -802,9 +802,6 @@
"writeable": true
}
],
"backup_volumes": [
"nextcloud_aio_eurooffice_data"
],
"secrets": [
"EUROOFFICE_SECRET"
],
+1 -1
View File
@@ -21,6 +21,6 @@ $nextcloudContainer = $containerDefinitionFetcher->GetContainerById($id);
$isNextcloudImageOutdated = $dockerActionManager->isNextcloudImageOutdated();
if ($isNextcloudImageOutdated === true) {
$dockerActionManager->sendNotification($nextcloudContainer, 'AIO is outdated!', 'Please open the AIO interface or ask an administrator to update it. If you do not want to do it manually each time, you can enable the daily backup feature from the AIO interface which automatically updates all containers.', '/notify-all.sh');
$dockerActionManager->sendNotification($nextcloudContainer, 'AIO is outdated!', 'Please open the AIO interface to update it. If you do not want to do it manually each time, you can enable the daily backup feature from the AIO interface which automatically updates all containers.');
}
+1 -1
View File
@@ -1 +1 @@
13.4.1
13.6.0
+2 -2
View File
@@ -59,14 +59,14 @@ services:
- local-code
desec-mock:
image: docker.io/library/node:26@sha256:c31fbcbf4a7e94a36accd38fdf69882fdf7685039dcd41412245d3d1065c5cbc
image: docker.io/library/node:26@sha256:bde0dae02f2b12d2bce5ee72b2432f0e511767b7b2dc4dd3b064df11ae422fee
volumes:
- ..:/app/php
working_dir: /app
command: node php/tests/desec-mock.mjs 8090 2>&1
npm-installer:
image: docker.io/library/node:26@sha256:c31fbcbf4a7e94a36accd38fdf69882fdf7685039dcd41412245d3d1065c5cbc
image: docker.io/library/node:26@sha256:bde0dae02f2b12d2bce5ee72b2432f0e511767b7b2dc4dd3b064df11ae422fee
volumes:
- ..:/app
working_dir: /app/tests
+1 -1
View File
@@ -36,7 +36,7 @@ run_tests() {
exitcode=$?
if test $exitcode -gt 0; then
for container in nextcloud-aio-{mastercontainer,borgbackup,desec-mock}; do
if docker container list --format="{{ .Names }}" | grep -q "$container"; then
if docker container list -a --format="{{ .Names }}" | grep -q "$container"; then
echo -e "\n 📣 Log output from container ${container}:\n"
docker logs "$container"
fi
+1 -1
View File
@@ -1314,7 +1314,7 @@ What are the requirements?
This project values stability over new features. That means that when a new major Nextcloud update gets introduced, we will wait at least until the first patch release, e.g. `24.0.1` is out before upgrading to it. Also we will wait with the upgrade until all important apps are compatible with the new major version. Minor or patch releases for Nextcloud and all dependencies as well as all containers will be updated to new versions as soon as possible but we try to give all updates first a good test round before pushing them. That means that it can take around 2 weeks before new updates reach the `latest` channel. If you want to help testing, you can switch to the `beta` channel by following [this documentation](#how-to-switch-the-channel) which will also give you the updates earlier.
### How often are update notifications sent?
AIO ships its own update notifications implementation. It checks if container updates are available. If so, it sends a notification with the title `Container updates available!` on saturdays to Nextcloud users that are part of the `admin` group. If the Nextcloud container image should be older than 90 days (~3 months) and thus badly outdated, AIO sends a notification to all Nextcloud users with the title `AIO is outdated!`. Thus admins should make sure to update the container images at least once every 3 months in order to make sure that the instance gets all security bugfixes as soon as possible.
AIO ships its own update notifications implementation. It checks if container updates are available. If so, it sends a notification with the title `Container updates available!` on saturdays to Nextcloud users that are part of the `admin` group. If the Nextcloud container image should be older than 90 days (~3 months) and thus badly outdated, AIO sends a notification to Nextcloud users that are part of the `admin` group with the title `AIO is outdated!` every day. Thus admins should make sure to update the container images at least once every 3 months in order to make sure that the instance gets all security bugfixes as soon as possible.
### Huge docker logs
If you should run into issues with huge docker logs, you can adjust the log size by following https://docs.docker.com/config/containers/logging/local/#usage. You can additionally reduce the verbosity of the included AIO containers by setting `AIO_LOG_LEVEL=error` on the mastercontainer. By default, AIO keeps the existing component-specific log defaults, so this should usually not be needed.
+12 -8
View File
@@ -214,7 +214,6 @@ Add this as a new Apache site config:
<VirtualHost *:443>
ServerName <your-nc-domain>
# Reverse proxy based on https://httpd.apache.org/docs/current/mod/mod_proxy_wstunnel.html
RewriteEngine On
ProxyPreserveHost On
RequestHeader set X-Real-IP %{REMOTE_ADDR}s
@@ -223,13 +222,8 @@ Add this as a new Apache site config:
AllowEncodedSlashes NoDecode
# Adjust the two lines below to match APACHE_PORT and APACHE_IP_BINDING. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md#adapting-the-sample-web-server-configurations-below
ProxyPass / http://localhost:11000/ nocanon
ProxyPass / http://localhost:11000/ nocanon upgrade=websocket
ProxyPassReverse / http://localhost:11000/
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteCond %{THE_REQUEST} "^[a-zA-Z]+ /(.*) HTTP/\d+(\.\d+)?$"
RewriteRule .? "ws://localhost:11000/%1" [P,L,UnsafeAllow3F] # Adjust to match APACHE_PORT and APACHE_IP_BINDING. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md#adapting-the-sample-web-server-configurations-below
# Enable h2, h2c and http1.1
Protocols h2 h2c http/1.1
@@ -270,7 +264,17 @@ Add this as a new Apache site config:
⚠️ **Please note:** Look into [this](#adapting-the-sample-web-server-configurations-below) to adapt the above example configuration.
To make the config work you can run the following command:
`sudo a2enmod rewrite proxy proxy_http proxy_wstunnel ssl headers http2`
`sudo a2enmod rewrite proxy proxy_http ssl headers http2`
The `upgrade=websocket` parameter requires Apache 2.4.47 or later. On older versions, replace it with the following block, which needs `proxy_wstunnel` enabled additionally:
```
RewriteEngine On
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteCond %{THE_REQUEST} "^[a-zA-Z]+ /(.*) HTTP/\d+(\.\d+)?$"
RewriteRule .? "ws://localhost:11000/%1" [P,L,NE,UnsafeAllow3F] # Adjust to match APACHE_PORT and APACHE_IP_BINDING. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md#adapting-the-sample-web-server-configurations-below
```
</details>