From 1d3af8edfbd42b2bfd5e1ea4e0812b1d2afacb5b Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Mon, 5 Oct 2026 21:17:31 +0200 Subject: [PATCH] R-776: nextcloud sees each visitor behind the tunnel (trusted docker networks; 9202 checklist 3.6 re-measure owed) Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- templates/nextcloud/docker-compose.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/templates/nextcloud/docker-compose.yml b/templates/nextcloud/docker-compose.yml index 5990547..3c28816 100644 --- a/templates/nextcloud/docker-compose.yml +++ b/templates/nextcloud/docker-compose.yml @@ -32,6 +32,10 @@ services: - NEXTCLOUD_TRUSTED_DOMAINS=${SUBDOMAIN}.${DOMAIN} nextcloud - OVERWRITEPROTOCOL=https - OVERWRITEHOST=${SUBDOMAIN}.${DOMAIN} + # R-776 (R-753, controller >= 0.286.0): the image's reverse-proxy.config.php turns this into trusted_proxies; Nextcloud + # then reads X-Forwarded-For from the RIGHT, so its brute-force throttle keys on each VISITOR instead of one bucket + # for the whole tunnel. 9202 re-measure owed (checklist 3.6). + - TRUSTED_PROXIES=172.16.0.0/12 - REDIS_HOST=nextcloud-redis # App-email (managed relay). Injected by the controller only when app-email is on (global + per-app); # empty SMTP_HOST keeps Nextcloud mail disabled. Nextcloud uses the plaintext :2526 listener