* Add AzuraCast community container Signed-off-by: Nicolas Binette <biguenique@nuee.cc> * Update Caddy readme to mention AzuraCast Signed-off-by: Nicolas Binette <biguenique@nuee.cc> * azuracast: consolidate storage/* volumes into single storage volume Replace seven granular mounts under /var/azuracast/storage with a single nextcloud_aio_azuracast_storage volume, matching AzuraCast's official docker-compose layout. Remove nextcloud_aio_azuracast_uploads from backup_volumes (media files are captured via stations and AzuraCast's own backup archives in /var/azuracast/backups). Signed-off-by: Nicolas Binette <biguenique@nuee.cc> * azuracast: change HTTP/HTTPS ports to 10080/10443, expose on host Use ports recommended by AzuraCast docs for reverse proxy deployments. Expose port 10080 (HTTP) with %APACHE_IP_BINDING% following the vaultwarden pattern, and port 10443 (HTTPS) on all interfaces for direct access. Update readme accordingly. Signed-off-by: Nicolas Binette <biguenique@nuee.cc> * azuracast: replace shared volume with %NEXTCLOUD_MOUNT%, document filesystem sharing Replace the named volume nextcloud_aio_azuracast_shared with the AIO-native %NEXTCLOUD_MOUNT% mechanism. The volume is silently skipped if NEXTCLOUD_MOUNT is not configured in AIO. Update readme.md: - Document NEXTCLOUD_MOUNT as the advanced file sharing approach, with setup instructions and a comparison to the SFTP approach - Clarify default access behavior: files (mode 644) are world-readable by both processes; some AzuraCast directories (mode 700) require intervention - Document POSIX ACL commands for unlocking read-only or bidirectional access on specific paths, with a note that they must be re-run after structural changes by AzuraCast - Minor wording and formatting improvements throughout Tested on a live AzuraCast instance: rename and bidirectional move confirmed working after ACL application; containers start correctly without UMASK override. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Signed-off-by: Nicolas Binette <biguenique@nuee.cc> * Update community-containers/azuracast/azuracast.json Do not expose internal HTTP port 10080 on host. Co-authored-by: Simon L. <szaimen@e.mail.de> Signed-off-by: Nicolas Binette <biguenique@nuee.cc> * azuracast: add to community containers overview diagram Add AzuraCast entry to the Media group of the mermaid overview diagram in community-containers/readme.md, as requested by szaimen. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Signed-off-by: Nicolas Binette <biguenique@nuee.cc> * fix the json Signed-off-by: Simon L. <szaimen@e.mail.de> * Apply suggestion from @szaimen Signed-off-by: Simon L. <szaimen@e.mail.de> * Apply suggestion from @szaimen Signed-off-by: Simon L. <szaimen@e.mail.de> --------- Signed-off-by: Nicolas Binette <biguenique@nuee.cc> Signed-off-by: Simon L. <szaimen@e.mail.de> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Simon L. <szaimen@e.mail.de>
AzuraCast
This container bundles AzuraCast, an open-source web radio management suite, and integrates it with Nextcloud AIO.
Notes
- To access AzuraCast from outside your local network, use the Caddy community container, which will automatically configure
radio.$NC_DOMAINto reverse-proxy the AzuraCast interface. Make sure to pointradio.your-nc-domain.comto your server using an A or CNAME record before starting. - The AzuraCast web interface is then available at
https://radio.your-nc-domain.com. On first start, you will be directed to/setup/registerto create the admin account. - Radio streaming ports (8000–8046) cover up to 5 stations that are exposed directly on the host without reverse-proxy.
- SFTP access is available on port 2022.
- AzuraCast's data (stations, database, backups) is automatically included in AIO's BorgBackup solution.
- Updater: The standard AzuraCast
updatercontainer is omitted — updates are managed through AIO's standard container update mechanism (pulling the newghcr.io/azuracast/azuracast:stableimage). - AzuraCast uses port 10080 (HTTP) and 10443 (HTTPS), following the ports recommended by AzuraCast for reverse proxy deployments. Both ports are exposed directly on the host. The recommended way to access the web interface is via
https://radio.your-nc-domain.comthrough the Caddy community container. Direct HTTPS access is also available athttps://yourserver:10443(self-signed certificate — browser warning expected). - Custom domains can be configured using caddy
Recommended settings after first login
On first access, AzuraCast will prompt you to create an admin account, then redirect to a System Settings page. The following settings are recommended when running behind the Caddy community container:
Settings tab:
- Site Base URL: Set to
https://radio.your-nc-domain.com - Use Web Proxy for Radio: Enable — all radio traffic is routed securely through Caddy
- Use High-Performance Now Playing Updates: Enable — activates WebSocket, SSE, and static JSON updates for metadata (fully supported by Caddy)
Security & Privacy tab:
- Always Use HTTPS: Enable
- IP Address Source: Select
Reverse Proxy (X-Forwarded-For)
Services tab:
- LetsEncrypt: Leave empty — TLS certificates are handled by Caddy
Streaming ports
The following ports are exposed for up to 5 radio stations (3 ports per station: stream, remote DJ, legacy SHOUTcast):
| Station | Stream | Remote DJ | SHOUTcast |
|---|---|---|---|
| 1 | 8000 | 8005 | 8006 |
| 2 | 8010 | 8015 | 8016 |
| 3 | 8020 | 8025 | 8026 |
| 4 | 8030 | 8035 | 8036 |
| 5 | 8040 | 8045 | 8046 |
Listeners and live source (remote DJs) can connect to these ports directly. Ports are assigned sequentially to new stations, but can be configured manually in /admin/stations.
By enabling Web Proxy for Radio (recommended settings), you can create an unlimited number of stations without direct port access. Assign the available ports to stations that actually need them.
Known limitations
- The
updatercontainer from the standard AzuraCast docker-compose is not included (requires Docker socket access, incompatible with AIO's security model). - The
shoutcast2,stereo_tool,rsas, andgeoliteoptional install directories are part of the unifiedstoragevolume. The corresponding features (SHOUTcast 2, Stereo Tool, RSAS, GeoLite2 geolocation) must be installed and activated manually from within AzuraCast after the container is running.
Nextcloud file integration
By default, AzuraCast runs in an isolated container: Nextcloud files are not accessible from within AzuraCast, and AzuraCast media files are not browsable in Nextcloud.
Nextcloud External Storage via SFTP
AzuraCast includes a built-in SFTP server (SFTPGo) on port 2022. SFTP users are managed per-station in AzuraCast under Media → SFTP Users. This lets each station operator define their own Nextcloud External Storage mount with their own credentials, without any host-level configuration.
In Nextcloud, add an External Storage mount of type SFTP with the following parameters:
| Field | Value |
|---|---|
| Host | nextcloud-aio-azuracast (within the Docker network) or your external domain/IP |
| Port | 2022 |
| Username / Password | As configured in AzuraCast's SFTP user settings |
| Root | Leave empty or set to the station's media subfolder |
Note: Do not use
localhostas the host — within the Nextcloud container,localhostrefers to Nextcloud itself, not AzuraCast. Use the container namenextcloud-aio-azuracastor your server's domain name instead.
This approach supports per-station access control, works with both local and remote AzuraCast instances, and media files remain covered by AIO's BorgBackup solution.
Advanced: shared filesystem via NEXTCLOUD_MOUNT
NEXTCLOUD_MOUNT is an AIO setting that exposes an arbitrary host directory to the Nextcloud container, enabling Nextcloud External Storage mounts on the host filesystem. When set, the same path is automatically mounted in AzuraCast at the same location, giving both processes direct access to the same files — with significantly better performance than SFTP when managing large media libraries.
To set this up:
- Set
NEXTCLOUD_MOUNTto a host directory path in AIO settings (e.g./data/media). - In AzuraCast, configure a station to use a subdirectory of that path as its media storage (e.g.
/data/media/stations/mystation/media). - In Nextcloud, optionally add a Local External Storage mount pointing to the same path to browse and manage the files from Nextcloud.
If NEXTCLOUD_MOUNT is not configured in AIO, this volume is silently skipped and AzuraCast starts normally.
Note: Files in the shared directory are not included in AIO's BorgBackup. Back up this directory separately if needed.
Default access
Both processes run as different users — Nextcloud as www-data (UID 33) and AzuraCast as azuracast (UID 1000) — with no group membership in common.
- Files created by either process (mode
644) are readable by the other as world-readable, but cannot be modified. - Directories created by Nextcloud (mode
755) are browsable by AzuraCast. - Some AzuraCast directories are created with mode
700(user-created subdirectories). These cannot be listed or entered by Nextcloud without intervention.
Unlocking access
The following commands are run on the host. To grant access to a specific path — for example, after creating a new station — run:
# Install ACL tools if not already present (Debian/Ubuntu)
sudo apt install acl
# Read-only access for Nextcloud to an AzuraCast directory
sudo setfacl -R -m u:33:rX /data/media/stations/mystation/
# Bidirectional read/write access
sudo setfacl -R -m u:33:rwX,u:1000:rwX /data/media/stations/mystation/
sudo setfacl -R -d -m u:33:rwX,u:1000:rwX /data/media/stations/mystation/
Note: These commands apply to the current directory tree. They need to be re-run when AzuraCast creates new subdirectories within the affected path.
Repository
https://github.com/AzuraCast/AzuraCast