Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 29 additions & 10 deletions .docker/app/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,12 +1,32 @@
ARG NEXTCLOUD_VERSION=stable-fpm
ARG NEXTCLOUD_BASE_IMAGE=nextcloud:stable-fpm
ARG NEXTCLOUD_SOURCE=release

FROM nextcloud:${NEXTCLOUD_VERSION}
FROM mlocati/php-extension-installer:2.12.0 AS php-extension-installer

FROM ${NEXTCLOUD_BASE_IMAGE} AS release

FROM ${NEXTCLOUD_BASE_IMAGE} AS daily
ARG NEXTCLOUD_DAILY_URL
RUN set -eux; \
test -n "${NEXTCLOUD_DAILY_URL}"; \
archive_name="$(basename "${NEXTCLOUD_DAILY_URL}")"; \
curl -fsSL "${NEXTCLOUD_DAILY_URL}" -o "/tmp/${archive_name}"; \
curl -fsSL "${NEXTCLOUD_DAILY_URL}.sha512" -o "/tmp/${archive_name}.sha512"; \
expected_sha512="$(awk -v archive="${archive_name}" '$2 == archive { print $1; exit }' "/tmp/${archive_name}.sha512")"; \
test -n "${expected_sha512}"; \
echo "${expected_sha512} /tmp/${archive_name}" | sha512sum -c -; \
rm -rf /usr/src/nextcloud; \
tar -xjf "/tmp/${archive_name}" -C /usr/src/; \
rm -f "/tmp/${archive_name}" "/tmp/${archive_name}.sha512"; \
rm -rf /usr/src/nextcloud/updater; \
mkdir -p /usr/src/nextcloud/data /usr/src/nextcloud/custom_apps; \
chmod +x /usr/src/nextcloud/occ

FROM ${NEXTCLOUD_SOURCE} AS runtime

RUN apt-get update \
&& apt-get install -y \
gzip \
&& apt-get install -y --no-install-recommends \
locales \
postgresql-client \
poppler-utils \
&& sed -i -e 's/# en_US.UTF-8 UTF-8/en_US.UTF-8 UTF-8/' /etc/locale.gen \
&& locale-gen \
Expand All @@ -16,10 +36,9 @@ ENV LANG=en_US.UTF-8
ENV LANGUAGE=en_US:en
ENV LC_ALL=en_US.UTF-8

ADD https://github.com/mlocati/docker-php-extension-installer/releases/latest/download/install-php-extensions /usr/local/bin/
RUN chmod uga+x /usr/local/bin/install-php-extensions && sync \
&& install-php-extensions \
bz2 \
imagick
COPY --from=php-extension-installer /usr/bin/install-php-extensions /usr/local/bin/install-php-extensions
RUN install-php-extensions \
bz2 \
&& rm /usr/local/bin/install-php-extensions

COPY config/php.ini /usr/local/etc/php/conf.d/
40 changes: 0 additions & 40 deletions .docker/app/Dockerfile.35

This file was deleted.

3 changes: 0 additions & 3 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,6 @@ LETSENCRYPT_EMAIL=
TZ=

POSTGRES_PASSWORD=
NEXTCLOUD_BACKUP_DIR=/backups
NEXTCLOUD_UPGRADE_MIN_FREE_MB=2048

NEXTCLOUD_ADMIN_USER=
NEXTCLOUD_ADMIN_PASSWORD=

Expand Down
7 changes: 4 additions & 3 deletions .github/actions/build-and-scan/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ runs:
platforms: linux/amd64
load: true
build-args: |
NEXTCLOUD_VERSION=${{ inputs.nextcloud_version }}
NEXTCLOUD_BASE_IMAGE=nextcloud:${{ inputs.nextcloud_version }}
tags: scan/app:amd64
cache-from: type=gha
cache-to: type=gha,mode=max
Expand All @@ -42,7 +42,7 @@ runs:
platforms: linux/arm64
load: true
build-args: |
NEXTCLOUD_VERSION=${{ inputs.nextcloud_version }}
NEXTCLOUD_BASE_IMAGE=nextcloud:${{ inputs.nextcloud_version }}
tags: scan/app:arm64
cache-from: type=gha
cache-to: type=gha,mode=max
Expand Down Expand Up @@ -70,7 +70,8 @@ runs:
- name: Install Trivy
uses: aquasecurity/setup-trivy@81e514348e19b6112ce2a7e3ecbafe19c1e1f567 # v0.3.1
with:
version: v0.74.0
# renovate: datasource=github-releases depName=aquasecurity/trivy
version: v0.75.0
cache: true

- name: Scan runtime images
Expand Down
23 changes: 23 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
version: 2

updates:
- package-ecosystem: docker
directory: /.docker/app
schedule:
interval: weekly
cooldown:
default-days: 7

- package-ecosystem: docker
directory: /.docker/web
schedule:
interval: weekly
cooldown:
default-days: 7

- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
cooldown:
default-days: 7
52 changes: 0 additions & 52 deletions .github/workflows/nextcloud-35-development.yml

This file was deleted.

97 changes: 97 additions & 0 deletions .github/workflows/nextcloud-development.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,97 @@
name: Validate Nextcloud master image

on:
pull_request:
branches:
- main
paths:
- '.docker/app/**'
- 'tests/app-image.bats'
- 'scripts/scan-images.sh'
- 'trivy.yaml'
- '.github/workflows/nextcloud-development.yml'
push:
branches:
- main
paths:
- '.docker/app/**'
- 'tests/app-image.bats'
- 'scripts/scan-images.sh'
- 'trivy.yaml'
- '.github/workflows/nextcloud-development.yml'
workflow_dispatch:

permissions:
contents: read

concurrency:
group: nextcloud-master-validation-${{ github.ref }}
cancel-in-progress: true

jobs:
validate:
name: master-fpm / linux/${{ matrix.arch }}
runs-on: ubuntu-latest

strategy:
fail-fast: false
matrix:
arch:
- amd64
- arm64

steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up QEMU
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3
with:
platforms: arm64

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3

- name: Setup Bats
uses: bats-core/bats-action@77d6fb60505b4d0d1d73e48bd035b55074bbfb43 # 4.0.0
with:
support-install: false
assert-install: false
detik-install: false
file-install: false

- name: Build Nextcloud master app image
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
with:
context: .docker/app
platforms: linux/${{ matrix.arch }}
load: true
build-args: |
NEXTCLOUD_BASE_IMAGE=nextcloud:stable-fpm
NEXTCLOUD_SOURCE=daily
NEXTCLOUD_DAILY_URL=https://download.nextcloud.com/server/daily/latest-master.tar.bz2
tags: scan/master:${{ matrix.arch }}
cache-from: type=gha,scope=master-${{ matrix.arch }}
cache-to: type=gha,mode=max,scope=master-${{ matrix.arch }}

- name: Install Trivy
uses: aquasecurity/setup-trivy@81e514348e19b6112ce2a7e3ecbafe19c1e1f567 # v0.3.1
with:
# renovate: datasource=github-releases depName=aquasecurity/trivy
version: v0.75.0
cache: true

- name: Scan Nextcloud master app image
shell: bash
env:
ARCH: ${{ matrix.arch }}
run: |
bash scripts/scan-images.sh "app@linux/${ARCH}=scan/master:${ARCH}"

- name: Runtime acceptance
shell: bash
env:
APP_IMAGE: scan/master:${{ matrix.arch }}
run: bats tests/app-image.bats
11 changes: 4 additions & 7 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ COMPOSE ?= docker compose
GARAGES3_COMPOSE_FILE ?= docker-compose-garages3.yml
APP_TEST_IMAGE ?= nextcloud-app:acceptance

.PHONY: up-garages3 down-garages3 bootstrap-garages3 garage-status-garages3 start-garages3 wait-nextcloud-garages3 setup-garages3 test-hooks test-scan-images test-ncdd test-app-image test-current-app-image scan-images
.PHONY: up-garages3 down-garages3 bootstrap-garages3 garage-status-garages3 start-garages3 wait-nextcloud-garages3 setup-garages3 test-scan-images test-ncdd test-app-image test-current-app-image scan-images

up-garages3:
$(COMPOSE) -f $(GARAGES3_COMPOSE_FILE) up -d garage
Expand All @@ -27,9 +27,6 @@ setup-garages3:
$(MAKE) start-garages3
$(MAKE) wait-nextcloud-garages3

test-hooks:
bash tests/test-hooks.sh

test-scan-images:
bash tests/test-scan-images.sh

Expand All @@ -45,17 +42,17 @@ test-current-app-image:
version="$$(sed -n 's/^NEXTCLOUD_VERSION=//p' .env.example | head -n 1)"; \
test -n "$$version" || { echo 'NEXTCLOUD_VERSION is missing from .env.example' >&2; exit 1; }; \
docker buildx build --platform linux/amd64 --load --tag "$(APP_TEST_IMAGE)" \
--build-arg "NEXTCLOUD_VERSION=$$version" --file .docker/app/Dockerfile .docker/app; \
--build-arg "NEXTCLOUD_BASE_IMAGE=nextcloud:$version" --file .docker/app/Dockerfile .docker/app; \
$(MAKE) test-app-image APP_IMAGE="$(APP_TEST_IMAGE)"

scan-images:
@set -e; \
version="$$(sed -n 's/^NEXTCLOUD_VERSION=//p' .env.example | head -n 1)"; \
test -n "$$version" || { echo 'NEXTCLOUD_VERSION is missing from .env.example' >&2; exit 1; }; \
docker buildx build --platform linux/amd64 --load --tag nextcloud-app:scan-amd64 \
--build-arg "NEXTCLOUD_VERSION=$$version" --file .docker/app/Dockerfile .docker/app; \
--build-arg "NEXTCLOUD_BASE_IMAGE=nextcloud:$version" --file .docker/app/Dockerfile .docker/app; \
docker buildx build --platform linux/arm64 --load --tag nextcloud-app:scan-arm64 \
--build-arg "NEXTCLOUD_VERSION=$$version" --file .docker/app/Dockerfile .docker/app; \
--build-arg "NEXTCLOUD_BASE_IMAGE=nextcloud:$version" --file .docker/app/Dockerfile .docker/app; \
docker buildx build --platform linux/amd64 --load --tag nextcloud-web:scan-amd64 \
--file .docker/web/Dockerfile .docker/web; \
docker buildx build --platform linux/arm64 --load --tag nextcloud-web:scan-arm64 \
Expand Down
39 changes: 0 additions & 39 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,6 @@ Languages avaliable: [pt-BR](docs/README_ptBR.md)
- [After setup](#after-setup)
- [Custom setup](#custom-setup)
- [Customize docker-compose content](#customize-docker-compose-content)
- [Nextcloud upgrade hooks](#nextcloud-upgrade-hooks)
- [PHP](#php)
- [Run Nextcloud](#run-nextcloud)
- [Use a specific version of Nextcloud](#use-a-specific-version-of-nextcloud)
Expand Down Expand Up @@ -128,44 +127,6 @@ You can do this using environments and creating a file called `docker-compose.ov

The main compose files now include a `redis` service by default. This keeps the stack self-contained for Nextcloud installations that already use Redis in `config.php` and avoids depending on a host-specific external network.

### Nextcloud upgrade hooks

This repository mounts the official Nextcloud Docker hook directories so you can extend install and upgrade flows without touching the image entrypoint.

The `app` service uses these mounts:

```yaml
services:
app:
volumes:
- ./volumes/nextcloud:/var/www/html
- ./backups:/backups
- ./app-hooks/pre-installation:/docker-entrypoint-hooks.d/pre-installation
- ./app-hooks/post-installation:/docker-entrypoint-hooks.d/post-installation
- ./app-hooks/pre-upgrade:/docker-entrypoint-hooks.d/pre-upgrade
- ./app-hooks/post-upgrade:/docker-entrypoint-hooks.d/post-upgrade
- ./app-hooks/before-starting:/docker-entrypoint-hooks.d/before-starting
```

The upgrade hooks behave like this:

- `pre-upgrade`: turns maintenance mode on
- `pre-upgrade`: saves the active app list to `/backups/app_list.old`
- `pre-upgrade`: checks free disk space on the Nextcloud volume and the backup volume
- `pre-upgrade`: creates a compressed PostgreSQL dump at `/backups/nextcloud-db.sql.gz`, replacing the previous dump
- `post-upgrade`: saves the new app list to `/backups/app_list.new` and prints a diff when possible
- `post-upgrade`: runs the extra `occ` commands needed after a major upgrade
- `post-upgrade`: turns maintenance mode off at the end

The following variables control the safety check and backup location:

- `NEXTCLOUD_BACKUP_DIR`, defaulting to `/backups`
- `NEXTCLOUD_UPGRADE_MIN_FREE_MB`, defaulting to `2048`

Both upgrade hooks use `NEXTCLOUD_BACKUP_DIR` for the app list files and the database dump.

This repository includes the `./backups` directory so Docker does not create it as a root-owned host path on a fresh checkout. It must still be writable by `www-data` inside the container. The recommended host-side ownership is `www-data:www-data` with mode `0755`.

### Garage S3 primary storage

Use `docker-compose-garages3.yml` when you want Nextcloud to store files in a Garage S3 bucket instead of the local `data/` directory.
Expand Down
Loading
Loading