Files
nextcloud/Containers/mastercontainer
Pablo Zmdl 93cf3d3931 Two factor authentication for both login variants
This adds optional two factor authentication based on shared
TOTP-secrets to both login variants (password and AIO token
authentication).

The 2FA can be enabled as soon as the containers are running in a
section below the backup configuration. As long as it is not enabled,
the AIO UI shows a warning at the top, and inside the Nextcloud a
notification is shown to all Nextcloud admins, strongly recommending to
enable it. The Nextcloud admin notification is sent via the
mastercontainer's `cron.sh`, thus will be renewed whenever it is
dismissed.

In order to show the notices, this PR includes a notification system for
the AIO UI, providing two variants: notices, and warnings. Notices have
a green background and border and vanish after 5 seconds. Warnings have
a orange-leaning yellow background and border and don't vanish (and
can't be dismissed manually, neither).

Another visual improvement is highlighted section headlines: If the URL
hash matches an `h2` element's ID, the `h2` is highlighted and if the
`h2` is followed by a `detail` element, that `detail` is opened. If
effect, browsing to `#two-factor-auth` jumps to the section, which is
highlighted and opened already (as shown in the second screenshot
below).

Signed-off-by: Pablo Zmdl <pablo@nextcloud.com>
AI-assistant: Claude Opus 4.8
2026-08-20 16:33:29 +02:00
..
2026-08-02 17:32:32 +02:00

Nextcloud All-in-One mastercontainer

This folder contains the OCI/Docker container definition, along with associated resources and configuration files, for building the mastercontainer as part of the Nextcloud All-in-One project. This container hosts the Nextcloud AIO interface1 , and a dedicated PHP environment for it (which is completely independent of the Nextcloud Server).

Overview

The mastercontainer acts as the central orchestration service for the deployment and management of all other containers in the Nextcloud All-in-One stack. It hosts:

  • A dedicated PHP SAPI/backend (php-fpm) for AIO itself (not Nextcloud Server)
  • A Caddy server enabling self-signed HTTPS access to the AIO frontend on port 8080/tcp.
  • A Caddy server enabling trusted HTTPS access to the AIO frontend on port 8443/tcp.
    • Caddy will automatically issue a Let's Encrypt issued certificate if port 80 and 8443 is open/forwarded and a domain pointer is in place; then, simply open the Nextcloud AIO interface using the domain (https://your-domain-that-points-to-this-server.tld:8443). The Let's Encrypt certificate request will use an ACME HTTP-01 challenge.
  • Miscellaneous support services specific to AIO (backup management, health checks, etc.)

Key Responsibilities

  • Orchestrates the deployment and lifecycle of all Nextcloud service containers
  • Handles initial setup and container configuration
  • Coordinates image updates
  • Monitors general system health

It triggers the initial installation and ensures the smooth operation of the Nextcloud All-in-One stack.

Contents

  • Dockerfile: Instructions for building the mastercontainer image.
  • Entrypoint script: The start.sh script is used for container initialization and runtime configuration before starting supervisord.
  • Nextcloud All-in-One Controller App: The core AIO orchestrator that handles configuration and settings for the containers.
  • Supervisor: The supervisord.conf file defines the long-running services hosted within the container (php-fpm, cron, etc.)

Usage

This container should be used as the trigger image when deploying the Nextcloud All-in-One stack in a Docker or other OCI-compliant container environment. For detailed deployment instructions, refer to the project documentation.

Contributing

Contributions are welcome! Please follow the Nextcloud project's guidelines and submit pull requests or issues via the main repository.

License

This folder and its contents are licensed under the GNU AGPLv3, in line with the rest of Nextcloud All-in-One.


  1. The Nextcloud All-in-One interface allows users to install, configure, and manage their Nextcloud instance and related containers via a secure web interface and API. It automates and simplifies complex tasks such as container orchestration, backups, updates, and service management for users deploying Nextcloud in Docker environments. ↩︎