Repository navigation
Conversation
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
vitormattos
left a comment
There was a problem hiding this comment.
Thanks for investigating the fresh-clone startup problems. The issues identified in this PR are valid, but I think we should revise the solution before merging.
The main goal of this repository is straightforward: a developer should be able to start the complete LibreSign SaaS environment, including the site, WordPress, Nextcloud, and their integrations, with a single make up command.
Since the nextcloud-development submodule was last updated, NCDD has introduced improvements that make part of the implementation proposed here unnecessary.
1. Update the NCDD submodule
The current submodule is pinned to commit 56660f4 from August 2026.
Since then, NCDD has introduced:
- A shared reverse proxy managed by
proxy-coordinator. - Canonical Nextcloud URLs configured through
NEXTCLOUD_HOSTandNEXTCLOUD_PROTOCOL. - Automatic configuration of
trusted_domains,overwritehost, andoverwriteprotocol. - Internal Docker network routing to the shared proxy.
- An updated startup lifecycle.
References:
- https://github.com/LibreCodeCoop/nextcloud-docker-development/blob/main/docs/advanced-setup.md
- LibreCodeCoop/nextcloud-docker-development#152
- LibreCodeCoop/nextcloud-docker-development#153
Please update the submodule to a tested revision and adapt the SaaS startup commands to the current NCDD interfaces.
Keep the submodule pinned to an explicit commit.
2. Remove the unnecessary Nextcloud networking workaround
The newly introduced docker-compose.nextcloud.override.yml publishes an additional nginx port through the Docker host gateway.
This workaround targets the older NCDD architecture. The current implementation uses a shared proxy and supports container access through Docker network aliases.
Please:
- Remove
docker-compose.nextcloud.override.yml. - Remove
DOCKER_HOST_GATEWAY_IPand the related gateway detection logic. - Use the existing NCDD proxy mechanisms for WordPress → Nextcloud communication.
- Review
_connect-networksand remove or adjust the manual network connection if it is no longer necessary.
There is an additional issue to resolve: the SaaS WordPress Compose override currently publishes host port 80, which conflicts with the port used by the NCDD shared proxy.
Please find the simplest configuration that allows WordPress, the site, and Nextcloud to coexist without conflicting host ports.
We do not need to introduce another reverse proxy or redesign the entire SaaS networking architecture. We only need the existing components to communicate reliably.
3. Reuse the canonical Nextcloud configuration
The new _set-trusted-domains target should not be necessary.
NCDD already configures the canonical hostname, trusted domains, and overwrite settings.
Please remove this target and avoid reading config/config.php directly from the Makefile.
Review NEXTCLOUD_LOCAL_URL, NEXTCLOUD_BASE_URL, and NEXTCLOUD_HTTP_PORT so that SaaS does not maintain unnecessary or conflicting Nextcloud URL configuration.
The WordPress integration should receive the correct Nextcloud URL derived from the NCDD configuration.
Since NCDD uses HTTPS by default, also verify that WordPress can reach the shared proxy with proper TLS certificate validation. We should not disable certificate verification to make the integration work.
4. Adjust only the affected Makefile targets
Please review the existing Nextcloud startup and integration targets against the updated NCDD.
In particular:
_refresh-nextcloud-images_start-nextcloud_wait-nextcloud_connect-networks_setup-apps_provision-user
Prefer the standard NCDD Compose lifecycle rather than maintaining an explicit list of infrastructure services that may become outdated.
Keep the responsibility boundaries clear:
- NCDD manages the Nextcloud runtime, proxy, networking, and canonical URL configuration.
- SaaS manages the integration between the site, WordPress, and Nextcloud, including application-specific setup and provisioning.
Preserve the existing make up, make down, and component-specific commands.
Do not refactor unrelated functionality.
5. Preserve the valid fixes and address startup failures
The env UID=... fix is valid and should stay.
The mysql → database service rename is also valid, although the startup command should be reconsidered based on the current NCDD lifecycle.
One additional problem was identified in the PR description: woocommerce-nextcloud-admin-group-manager cannot be activated because of a WordPress version incompatibility, and the failure is currently ignored.
Since this plugin is part of the SaaS integration, please verify its actual compatibility and fix the underlying issue. Do not bypass plugin version requirements or silently ignore activation failures.
The same principle applies to required provisioning steps: make up should not report success if an essential integration failed.
Keep this review limited to errors that affect the expected startup and integration behavior.
6. Add focused regression tests
The original problem was discovered when running make up on a fresh clone. We should prevent that regression from returning.
Please add automated coverage for the relevant startup and integration behavior.
At minimum, verify:
- The Compose configuration is valid with the updated NCDD.
- The required services start successfully.
- WordPress can reach Nextcloud through the configured hostname and protocol.
- An authenticated Nextcloud API request succeeds.
- Required applications and plugins are enabled.
- Running the setup again does not break existing configuration.
Keep tests proportional to this change. Prefer lightweight checks where possible and a focused Docker integration test for the actual connectivity.
There is no need to introduce a new testing framework or adopt NCDD's dev-worker functionality solely for this PR.
Expected outcome
The revised PR should:
- Update NCDD to a tested revision.
- Remove the unnecessary nginx override and host gateway workaround.
- Reuse NCDD's existing proxy and canonical URL configuration.
- Resolve the WordPress/Nextcloud networking and compatibility problems.
- Simplify the affected Makefile targets without expanding their responsibilities.
- Preserve the valid
UIDand database service fixes. - Ensure
make upstarts a functional environment and reports meaningful failures. - Include focused automated regression coverage.
The objective is to make use of improvements already available in NCDD, not to introduce new infrastructure functionality into SaaS.
Please keep the changes focused on making the existing single-command startup reliable. Any unrelated improvements can be handled in separate issues.
On a fresh clone of
main,make upfails for the site and Nextcloud stacks, and the WordPress → Nextcloud integration cannot reach Nextcloud.Changes
SITE_COMPOSEnow usesenv UID=... docker compose .... In bash, which is/bin/shon Fedora,UIDis readonly, soUID=... docker composefailed withUID: readonly variable.mysqlwas renamed todatabasein_refresh-nextcloud-imagesand_start-nextcloud. Thenextcloud-developmentbump in 7f556a7 renamed the service, which made the Makefile fail withno such service: mysql.127.0.0.1(IP_BIND), so WordPress could no longer reach Nextcloud throughhost.docker.internal.docker-compose.nextcloud.override.ymlnow also publishes the Nextcloud nginx port on the Docker host gateway address (DOCKER_HOST_GATEWAY_IP), which the Makefile detects from thebridgenetwork. Nextcloud stays off the LAN, andIP_BINDfrom.envis still honored._set-trusted-domainsstep adds the host fromNEXTCLOUD_LOCAL_URLto Nextcloud'strusted_domains, at the next free index and only if it is missing. Without it, requests from WordPress gotTrusted domain error.NEXTCLOUD_LOCAL_URLnow defaults tohttp://host.docker.internal:$(NEXTCLOUD_HTTP_PORT).Validation
Tested with
make upon a fresh clone (Fedora 44, bash 5.3)::80), the site (:8081) and Nextcloud (:8082) all respond 200.wordpress_login_backend,admin_group_managerandgroupquotaare enabled, and theadmlibrecodegroup is created.host.docker.internal:8082returns 200, including an authenticated OCS call.127.0.0.1and the Docker gateway (172.17.0.1); neither is reachable on the LAN IP._set-trusted-domainskeeps existing entries, including when the indexes have gaps (e.g. 0 and 2), does not add duplicates when run again, and picks up a customNEXTCLOUD_LOCAL_URL.Notes
woocommerce-nextcloud-admin-group-managerrequires WordPress 7.0, butwordpress-docker:latestships 6.9.4, so the plugin is not activated.make upignores this error.