Skip to content

fix: start the stack from a fresh clone - #24

Open
YvesCesar wants to merge 2 commits into
mainfrom
fix/makefile-fresh-clone
Open

YvesCesar wants to merge 2 commits into
mainfrom
fix/makefile-fresh-clone

Conversation

@YvesCesar

@YvesCesar YvesCesar commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

On a fresh clone of main, make up fails for the site and Nextcloud stacks, and the WordPress → Nextcloud integration cannot reach Nextcloud.

Changes

  • Site: SITE_COMPOSE now uses env UID=... docker compose .... In bash, which is /bin/sh on Fedora, UID is readonly, so UID=... docker compose failed with UID: readonly variable.
  • Nextcloud services: mysql was renamed to database in _refresh-nextcloud-images and _start-nextcloud. The nextcloud-development bump in 7f556a7 renamed the service, which made the Makefile fail with no such service: mysql.
  • Nextcloud reachable from WordPress: the same bump made ports bind to 127.0.0.1 (IP_BIND), so WordPress could no longer reach Nextcloud through host.docker.internal. docker-compose.nextcloud.override.yml now also publishes the Nextcloud nginx port on the Docker host gateway address (DOCKER_HOST_GATEWAY_IP), which the Makefile detects from the bridge network. Nextcloud stays off the LAN, and IP_BIND from .env is still honored.
  • Trusted domain: a new _set-trusted-domains step adds the host from NEXTCLOUD_LOCAL_URL to Nextcloud's trusted_domains, at the next free index and only if it is missing. Without it, requests from WordPress got Trusted domain error. NEXTCLOUD_LOCAL_URL now defaults to http://host.docker.internal:$(NEXTCLOUD_HTTP_PORT).

Validation

Tested with make up on a fresh clone (Fedora 44, bash 5.3):

  • WordPress (:80), the site (:8081) and Nextcloud (:8082) all respond 200.
  • wordpress_login_backend, admin_group_manager and groupquota are enabled, and the admlibrecode group is created.
  • From the WordPress container, host.docker.internal:8082 returns 200, including an authenticated OCS call.
  • Nextcloud and its database only listen on 127.0.0.1 and the Docker gateway (172.17.0.1); neither is reachable on the LAN IP.
  • _set-trusted-domains keeps existing entries, including when the indexes have gaps (e.g. 0 and 2), does not add duplicates when run again, and picks up a custom NEXTCLOUD_LOCAL_URL.

Notes

  • Not fixed here: woocommerce-nextcloud-admin-group-manager requires WordPress 7.0, but wordpress-docker:latest ships 6.9.4, so the plugin is not activated. make up ignores this error.

Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
@YvesCesar
YvesCesar requested a review from vitormattos October 5, 2026 22:05

@vitormattos vitormattos left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for investigating the fresh-clone startup problems. The issues identified in this PR are valid, but I think we should revise the solution before merging.

The main goal of this repository is straightforward: a developer should be able to start the complete LibreSign SaaS environment, including the site, WordPress, Nextcloud, and their integrations, with a single make up command.

Since the nextcloud-development submodule was last updated, NCDD has introduced improvements that make part of the implementation proposed here unnecessary.

1. Update the NCDD submodule

The current submodule is pinned to commit 56660f4 from August 2026.

Since then, NCDD has introduced:

  • A shared reverse proxy managed by proxy-coordinator.
  • Canonical Nextcloud URLs configured through NEXTCLOUD_HOST and NEXTCLOUD_PROTOCOL.
  • Automatic configuration of trusted_domains, overwritehost, and overwriteprotocol.
  • Internal Docker network routing to the shared proxy.
  • An updated startup lifecycle.

References:

Please update the submodule to a tested revision and adapt the SaaS startup commands to the current NCDD interfaces.

Keep the submodule pinned to an explicit commit.

2. Remove the unnecessary Nextcloud networking workaround

The newly introduced docker-compose.nextcloud.override.yml publishes an additional nginx port through the Docker host gateway.

This workaround targets the older NCDD architecture. The current implementation uses a shared proxy and supports container access through Docker network aliases.

Please:

  • Remove docker-compose.nextcloud.override.yml.
  • Remove DOCKER_HOST_GATEWAY_IP and the related gateway detection logic.
  • Use the existing NCDD proxy mechanisms for WordPress → Nextcloud communication.
  • Review _connect-networks and remove or adjust the manual network connection if it is no longer necessary.

There is an additional issue to resolve: the SaaS WordPress Compose override currently publishes host port 80, which conflicts with the port used by the NCDD shared proxy.

Please find the simplest configuration that allows WordPress, the site, and Nextcloud to coexist without conflicting host ports.

We do not need to introduce another reverse proxy or redesign the entire SaaS networking architecture. We only need the existing components to communicate reliably.

3. Reuse the canonical Nextcloud configuration

The new _set-trusted-domains target should not be necessary.

NCDD already configures the canonical hostname, trusted domains, and overwrite settings.

Please remove this target and avoid reading config/config.php directly from the Makefile.

Review NEXTCLOUD_LOCAL_URL, NEXTCLOUD_BASE_URL, and NEXTCLOUD_HTTP_PORT so that SaaS does not maintain unnecessary or conflicting Nextcloud URL configuration.

The WordPress integration should receive the correct Nextcloud URL derived from the NCDD configuration.

Since NCDD uses HTTPS by default, also verify that WordPress can reach the shared proxy with proper TLS certificate validation. We should not disable certificate verification to make the integration work.

4. Adjust only the affected Makefile targets

Please review the existing Nextcloud startup and integration targets against the updated NCDD.

In particular:

  • _refresh-nextcloud-images
  • _start-nextcloud
  • _wait-nextcloud
  • _connect-networks
  • _setup-apps
  • _provision-user

Prefer the standard NCDD Compose lifecycle rather than maintaining an explicit list of infrastructure services that may become outdated.

Keep the responsibility boundaries clear:

  • NCDD manages the Nextcloud runtime, proxy, networking, and canonical URL configuration.
  • SaaS manages the integration between the site, WordPress, and Nextcloud, including application-specific setup and provisioning.

Preserve the existing make up, make down, and component-specific commands.

Do not refactor unrelated functionality.

5. Preserve the valid fixes and address startup failures

The env UID=... fix is valid and should stay.

The mysql → database service rename is also valid, although the startup command should be reconsidered based on the current NCDD lifecycle.

One additional problem was identified in the PR description: woocommerce-nextcloud-admin-group-manager cannot be activated because of a WordPress version incompatibility, and the failure is currently ignored.

Since this plugin is part of the SaaS integration, please verify its actual compatibility and fix the underlying issue. Do not bypass plugin version requirements or silently ignore activation failures.

The same principle applies to required provisioning steps: make up should not report success if an essential integration failed.

Keep this review limited to errors that affect the expected startup and integration behavior.

6. Add focused regression tests

The original problem was discovered when running make up on a fresh clone. We should prevent that regression from returning.

Please add automated coverage for the relevant startup and integration behavior.

At minimum, verify:

  1. The Compose configuration is valid with the updated NCDD.
  2. The required services start successfully.
  3. WordPress can reach Nextcloud through the configured hostname and protocol.
  4. An authenticated Nextcloud API request succeeds.
  5. Required applications and plugins are enabled.
  6. Running the setup again does not break existing configuration.

Keep tests proportional to this change. Prefer lightweight checks where possible and a focused Docker integration test for the actual connectivity.

There is no need to introduce a new testing framework or adopt NCDD's dev-worker functionality solely for this PR.

Expected outcome

The revised PR should:

  • Update NCDD to a tested revision.
  • Remove the unnecessary nginx override and host gateway workaround.
  • Reuse NCDD's existing proxy and canonical URL configuration.
  • Resolve the WordPress/Nextcloud networking and compatibility problems.
  • Simplify the affected Makefile targets without expanding their responsibilities.
  • Preserve the valid UID and database service fixes.
  • Ensure make up starts a functional environment and reports meaningful failures.
  • Include focused automated regression coverage.

The objective is to make use of improvements already available in NCDD, not to introduce new infrastructure functionality into SaaS.

Please keep the changes focused on making the existing single-command startup reliable. Any unrelated improvements can be handled in separate issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants