Skip to content

feat(images): replace version-specific app image foundation - #67

Merged
vitormattos merged 13 commits into
mainfrom
feat/generic-app-image-foundation
Oct 8, 2026
Merged

vitormattos merged 13 commits into
mainfrom
feat/generic-app-image-foundation

Conversation

@vitormattos

@vitormattos vitormattos commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Closes #66.
Closes #57.
Blocks reconstruction of #62.
Part of #47.

This PR removes the Nextcloud-major-specific app image path and replaces it with one generic app Dockerfile.

What changes:

  • .docker/app/Dockerfile now supports explicit release and daily source modes;
  • the base runtime is configurable independently from the Nextcloud server payload;
  • daily archives are verified against upstream SHA-512 before extraction;
  • the PHP extension installer is consumed as a Docker build dependency and tracked for updates;
  • the existing Compose environment keeps NEXTCLOUD_VERSION as its user-facing setting and maps it to the generic base image;
  • .docker/app/Dockerfile.35 is removed;
  • the old Nextcloud-35 publication workflow is removed;
  • a new validation-only workflow builds Nextcloud Server master from the same Dockerfile for amd64 and arm64, scans both images, and runs the same Bats runtime acceptance gate introduced by Add runtime acceptance tests for the Nextcloud app image #49.

Intentionally not included:

  • no :master-fpm publication yet;
  • no new stable/full-version tagging workflow;
  • no second Compose stack;
  • no Redis/web integration expansion.

The final development publication workflow should be rebuilt only after this foundation is merged.

Follow-up architecture review:

  • replaced the Dockerfile shell branch with explicit Docker build stages for release and daily sources;
  • consume mlocati/php-extension-installer as a Docker dependency instead of maintaining a version/checksum pair in shell;
  • separated dependency ownership: Dependabot manages Docker and GitHub Actions, while Renovate is restricted to explicit custom values such as the Trivy binary version;
  • kept Trivy explicitly versioned because setup-trivy caching requires a concrete version; updated it to v0.75.0.

Upgrade lifecycle review:

  • removed repository-specific pre/post-upgrade hooks entirely;
  • removed database backup policy from the Nextcloud app lifecycle;
  • removed the dedicated backup mount and upgrade-backup environment variables;
  • removed postgresql-client and gzip from the app image because they existed only for the deleted database dump hook;
  • kept LibreSign runtime requirements such as Poppler, UTF-8 locale support, and PHP bz2;
  • fixed the Garage Compose path to use the generic app-image build argument as well.

Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
@vitormattos
vitormattos merged commit 57b3d82 into main Oct 8, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant