From 3b59dfb1bcdc69b68d8706eceed1232693a7a298 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Thu, 1 Oct 2026 07:37:51 +0200 Subject: [PATCH] nextcloud: re-test of the same tag at a new digest (decision 52, R-740) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit STEP nextcloud: the superseded step {'nextcloud': 'nextcloud:34.0.4-apache', 'nextcloud-db': 'mariadb:12.3', 'nextcloud-redis': 'redis:7-alpine'} keeps its definition at steps/61e93c3e1a1806df.yml STEP nextcloud: … and its .felhom.yml at steps/61e93c3e1a1806df.felhom.yml WROTE nextcloud: RE-TEST {'nextcloud': 'nextcloud:34.0.4-apache', 'nextcloud-db': 'mariadb:12.3', 'nextcloud-redis': 'redis:7-alpine'} -> {'nextcloud': 'nextcloud:34.0.4-apache', 'nextcloud-db': 'mariadb:12.3', 'nextcloud-redis': 'redis:7-alpine'} peak 23.7% marks {'files_may_change': False, 'needs_person': None, 'memory_tight': False} digest {'nextcloud': 'sha256:a5ace30c695afe48c2c406e940ee7886a81e13fa382e57cd68b2416d1a66914c', 'nextcloud-db': 'sha256:805c8e104bd563d5bfa24fadd3f31cd419ea859cb5277f32b5dbf2db714f9ed1', 'nextcloud-redis': 'sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499'} -> {'nextcloud': 'sha256:37b109885aa3cba3e056362a899556a625c986f2c17cd2c0cc157d21c789f53b', 'nextcloud-db': 'sha256:805c8e104bd563d5bfa24fadd3f31cd419ea859cb5277f32b5dbf2db714f9ed1', 'nextcloud-redis': 'sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499'} Evidence: felhom.eu/documentation/audits/retest-2026-10/nextcloud --- templates/nextcloud/.felhom.yml | 3 +- .../steps/61e93c3e1a1806df.felhom.yml | 181 ++++++++++++++++++ .../nextcloud/steps/61e93c3e1a1806df.yml | 132 +++++++++++++ 3 files changed, 315 insertions(+), 1 deletion(-) create mode 100644 templates/nextcloud/steps/61e93c3e1a1806df.felhom.yml create mode 100644 templates/nextcloud/steps/61e93c3e1a1806df.yml diff --git a/templates/nextcloud/.felhom.yml b/templates/nextcloud/.felhom.yml index db73676..6438b85 100644 --- a/templates/nextcloud/.felhom.yml +++ b/templates/nextcloud/.felhom.yml @@ -10,7 +10,7 @@ subdomain: "cloud" slug: "nextcloud" # catalog_since: the date THIS repo last changed this app's pinned images. Any commit that # changes an image: line must set this to the same day (see CLAUDE.md). -catalog_since: "2026-09-23" +catalog_since: "2026-10-01" # --- Resource hints (displayed on deploy screen) --- resources: @@ -186,3 +186,4 @@ i18n: update_ladder: - {"from": {"nextcloud": "nextcloud:34.0.1-apache", "nextcloud-db": "mariadb:11.6", "nextcloud-redis": "redis:7-alpine"}, "to": {"nextcloud": "nextcloud:34.0.1-apache", "nextcloud-db": "mariadb:12.3", "nextcloud-redis": "redis:7-alpine"}, "digest": {"nextcloud": "sha256:b52f7bc0e496f227b0e85e3b88571a42c68b6245ccde29d577e733227715dcf5", "nextcloud-db": "sha256:805c8e104bd563d5bfa24fadd3f31cd419ea859cb5277f32b5dbf2db714f9ed1", "nextcloud-redis": "sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499"}, "verdict": "proven", "tested_at": "2026-09-21T19:37:10.235635+00:00", "harness_version": 1, "evidence": "felhom.eu/documentation/audits/update-night-2026-09-21/apps/nextcloud-engine-mariadb/verdict.json", "memory_peak_pct": null, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "backfilled": "2026-09-23", "note": "backfilled from catalog commit 39374d5; box walk only (harness v1, no memory watch); digest = what the registry served on 2026-09-23, not a measurement of the tested image; the commit cited no record — this one was named by the backfill because its from/to refs are the commit's and the commit describes the same walk"} - {"from": {"nextcloud": "nextcloud:34.0.1-apache", "nextcloud-db": "mariadb:12.3", "nextcloud-redis": "redis:7-alpine"}, "to": {"nextcloud": "nextcloud:34.0.4-apache", "nextcloud-db": "mariadb:12.3", "nextcloud-redis": "redis:7-alpine"}, "digest": {"nextcloud": "sha256:a5ace30c695afe48c2c406e940ee7886a81e13fa382e57cd68b2416d1a66914c", "nextcloud-db": "sha256:805c8e104bd563d5bfa24fadd3f31cd419ea859cb5277f32b5dbf2db714f9ed1", "nextcloud-redis": "sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499"}, "verdict": "proven", "tested_at": "2026-09-23T20:16:04Z", "harness_version": 3, "evidence": "felhom.eu/documentation/audits/night-2026-09-23/apps/nextcloud/bench/evidence/MV-nextcloud/verdict.json", "box_evidence": "felhom.eu/documentation/audits/night-2026-09-23/apps/nextcloud/verdict.json", "memory_peak_pct": 24.2, "marks": {"files_may_change": true, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 100.0} + - {"from": {"nextcloud": "nextcloud:34.0.4-apache", "nextcloud-db": "mariadb:12.3", "nextcloud-redis": "redis:7-alpine"}, "to": {"nextcloud": "nextcloud:34.0.4-apache", "nextcloud-db": "mariadb:12.3", "nextcloud-redis": "redis:7-alpine"}, "digest": {"nextcloud": "sha256:37b109885aa3cba3e056362a899556a625c986f2c17cd2c0cc157d21c789f53b", "nextcloud-db": "sha256:805c8e104bd563d5bfa24fadd3f31cd419ea859cb5277f32b5dbf2db714f9ed1", "nextcloud-redis": "sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499"}, "verdict": "proven", "tested_at": "2026-10-01T05:32:19Z", "harness_version": 4, "evidence": "felhom.eu/documentation/audits/retest-2026-10/nextcloud/bench", "box_evidence": "felhom.eu/documentation/audits/retest-2026-10/nextcloud/box", "memory_peak_pct": 23.7, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 36.7, "digest_from": {"nextcloud": "sha256:a5ace30c695afe48c2c406e940ee7886a81e13fa382e57cd68b2416d1a66914c", "nextcloud-db": "sha256:805c8e104bd563d5bfa24fadd3f31cd419ea859cb5277f32b5dbf2db714f9ed1", "nextcloud-redis": "sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499"}} diff --git a/templates/nextcloud/steps/61e93c3e1a1806df.felhom.yml b/templates/nextcloud/steps/61e93c3e1a1806df.felhom.yml new file mode 100644 index 0000000..f790078 --- /dev/null +++ b/templates/nextcloud/steps/61e93c3e1a1806df.felhom.yml @@ -0,0 +1,181 @@ +# ============================================================================= +# .felhom.yml - App metadata for felhom-controller +# ============================================================================= + +# --- Display info (shown on dashboard) --- +display_name: "Nextcloud" +description: "Saját felhő tárhely - Google Drive/Dropbox alternatíva" +category: "files" +subdomain: "cloud" +slug: "nextcloud" +# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that +# changes an image: line must set this to the same day (see CLAUDE.md). +catalog_since: "2026-09-23" + +# --- Resource hints (displayed on deploy screen) --- +resources: + mem_request: "256M" + mem_limit: "1024M" + pi_compatible: false + needs_hdd: true + +# --- Backup classification (referential coupling; see felhom.eu documentation/audits/SPIKE-backup-classification-2026-07-14.md) --- +backup: + hdd: + - path: appdata/nextcloud + class: mandatory # THE user files — oc_filecache/shares reference them + +# --- Deploy fields (first deployment only) --- +deploy_fields: + - env_var: DOMAIN + label: "Domain" + type: domain + description: "A szerver domain neve" + locked_after_deploy: true + + - env_var: SUBDOMAIN + label: "Aldomain" + type: subdomain + default: "cloud" + required: true + locked_after_deploy: true + description: "Az alkalmazás aldomainje" + + - env_var: DB_PASSWORD + label: "Adatbázis jelszó" + type: secret + generate: "password:24" + locked_after_deploy: true + + - env_var: MYSQL_ROOT_PASSWORD + label: "MariaDB root jelszó" + type: secret + generate: "password:24" + locked_after_deploy: true + + - env_var: NEXTCLOUD_ADMIN_USER + label: "Admin felhasználónév" + type: text + default: "admin" + locked_after_deploy: true + + - env_var: NEXTCLOUD_ADMIN_PASSWORD + label: "Admin jelszó" + type: password + generate: "password:16" + description: "Első bejelentkezéshez. Utána a webes felületen módosítható." + locked_after_deploy: false + + - env_var: HDD_PATH + label: "Adattárolási útvonal" + type: path + required: true + placeholder: "/mnt/felhom-drives/hdd_1" + description: "A külső merevlemez elérési útja" + locked_after_deploy: true + +# --- App info (info page content) --- +app_info: + tagline: "A saját Google Drive-od - fájlok, naptár, névjegyek egy helyen" + default_creds: "Az admin fiók adatait a telepítéskor adod meg" + docs_url: "https://docs.nextcloud.com/server/latest/user_manual/" + + use_cases: + - 'Fájlok szinkronizálása és megosztása eszközök között' + - 'Naptár és névjegyek szinkronizálás (CalDAV/CardDAV)' + - 'Dokumentumok közös szerkesztése (OnlyOffice integrációval)' + - 'Fotó és videó automatikus feltöltés telefonról' + - 'Alkalmazásbolt - kibővíthető funkciók (Notes, Tasks, Forms, stb.)' + + first_steps: + - 'Nyisd meg a cloud.DOMAIN címet a böngészőben' + - 'Jelentkezz be a telepítéskor megadott admin fiókkal' + - 'Telepítsd a Nextcloud asztali alkalmazást a számítógépedre' + - 'Telepítsd a Nextcloud mobil alkalmazást a telefonodra' + - 'Hívd meg a családtagokat felhasználói fiókok létrehozásával' + + prerequisites: + - 'Külső HDD szükséges a fájlok tárolásához' + - 'Legalább 1 GB szabad RAM (Nextcloud + MariaDB + Redis)' + - 'x86 processzor ajánlott a legjobb teljesítményhez' + +# --- Controller-side health probe --- +healthcheck: + checks: + - type: api + port: 80 + path: "/status.php" + expect: + status: 200 + body_contains: "installed" + +# --- After a load of kept data (`09` §3 decision 36; controller ≥ the kept-data release) --- +# „Use my kept data" / „Load" restores the database from a backup under the files kept on the drive. +# MEASURED 2026-09-25 on 9202 (audits/night-2026-09-26/E/E1-README.md Q2): a file written after the backup +# is on the drive and invisible to Nextcloud until its own rescan — 0.6 s for 130 files. Run once, logged. +# An older controller ignores the key. +after_load: + service: nextcloud + user: www-data + command: ["php", "occ", "files:scan", "--all"] + +# --- App-email mapping (apps → in-controller shim → hub → Resend) --- +# Nextcloud (Symfony Mailer) has no env to skip TLS cert verification and opportunistically STARTTLS-upgrades, +# so it can't use the self-signed :2525 listener → tls_mode=plaintext points it at :2526 (STARTTLS NOT +# advertised → no upgrade attempted; plaintext on the single-tenant app bridge — accepted posture). +# Nextcloud SPLITS the From into local-part + domain, so from_var=MAIL_FROM_ADDRESS (local) + +# from_domain_var=MAIL_DOMAIN → nextcloud@felhom.eu. No security_var (SMTP_SECURE stays empty = no TLS); +# SMTP_NAME/PASSWORD unset (no auth). The official image reads these via getenv() on every boot. +smtp_mapping: + tls_mode: plaintext + host_var: SMTP_HOST + port_var: SMTP_PORT + from_var: MAIL_FROM_ADDRESS + from_domain_var: MAIL_DOMAIN + from_local: nextcloud + +# --- English copy (localisation slice 5, R-560) -------------------------------------------- +# The Hungarian above is UNCHANGED. A box on English reads this block field by field; a missing +# field shows the Hungarian one; a controller older than 0.257.0 ignores the block entirely. +i18n: + en: + description: 'Your own cloud storage - a Google Drive/Dropbox alternative' + app_info: + tagline: 'Your own Google Drive - files, calendar and contacts in one place' + default_creds: 'You set the admin account details at install time' + use_cases: + - 'Sync and share files between your devices' + - 'Calendar and contact sync (CalDAV/CardDAV)' + - 'Work on a document together (with the OnlyOffice integration)' + - 'Photos and videos upload themselves from your phone' + - 'An app store - more features when you want them (Notes, Tasks, Forms and more)' + first_steps: + - 'Open cloud.DOMAIN in your browser' + - 'Sign in with the admin account you set at install time' + - 'Install the Nextcloud desktop app on your computer' + - 'Install the Nextcloud mobile app on your phone' + - 'Invite the household by creating an account for each of them' + prerequisites: + - 'An external hard drive is needed to keep the files on' + - 'At least 1 GB of free RAM (Nextcloud + MariaDB + Redis)' + - 'An x86 processor is recommended for the best speed' + deploy_fields: + - env_var: DOMAIN + label: 'Domain' + description: 'The server domain name' + - env_var: SUBDOMAIN + label: 'Subdomain' + description: 'The subdomain this app answers on' + - env_var: DB_PASSWORD + label: 'Database password' + - env_var: HDD_PATH + label: 'Data storage path' + description: 'The path to the external hard drive' + placeholder: '/mnt/felhom-drives/hdd_1' + - env_var: MYSQL_ROOT_PASSWORD + label: 'MariaDB root password' + - env_var: NEXTCLOUD_ADMIN_USER + label: 'Admin user name' + - env_var: NEXTCLOUD_ADMIN_PASSWORD + label: 'Admin password' + description: 'For the first sign-in. You can change it in the app afterwards.' diff --git a/templates/nextcloud/steps/61e93c3e1a1806df.yml b/templates/nextcloud/steps/61e93c3e1a1806df.yml new file mode 100644 index 0000000..5990547 --- /dev/null +++ b/templates/nextcloud/steps/61e93c3e1a1806df.yml @@ -0,0 +1,132 @@ +# Nextcloud - Saját felhő tárhely - Google Drive/Dropbox alternatíva +# Domain: ${SUBDOMAIN}.${DOMAIN} +# Database: mariadb +# RAM: ~256M (mem_limit: 1024M) | Pi-compatible: No +# +# Environment variables: +# DOMAIN - Your domain (e.g., demo-felhom.eu) +# DB_PASSWORD - Adatbázis jelszó (auto-generated) +# MYSQL_ROOT_PASSWORD- MariaDB root jelszó (auto-generated) +# NEXTCLOUD_ADMIN_USER- Admin felhasználónév +# NEXTCLOUD_ADMIN_PASSWORD- Admin jelszó (auto-generated) +# HDD_PATH - Adattárolási útvonal + +services: + nextcloud: + image: nextcloud:34.0.4-apache + container_name: nextcloud + restart: unless-stopped + depends_on: + nextcloud-db: + condition: service_healthy + nextcloud-redis: + condition: service_healthy + environment: + - TZ=Europe/Budapest + - MYSQL_DATABASE=nextcloud + - MYSQL_USER=nextcloud + - MYSQL_PASSWORD=${DB_PASSWORD} + - MYSQL_HOST=nextcloud-db + - NEXTCLOUD_ADMIN_USER=${NEXTCLOUD_ADMIN_USER:-admin} + - NEXTCLOUD_ADMIN_PASSWORD=${NEXTCLOUD_ADMIN_PASSWORD} + - NEXTCLOUD_TRUSTED_DOMAINS=${SUBDOMAIN}.${DOMAIN} nextcloud + - OVERWRITEPROTOCOL=https + - OVERWRITEHOST=${SUBDOMAIN}.${DOMAIN} + - REDIS_HOST=nextcloud-redis + # App-email (managed relay). Injected by the controller only when app-email is on (global + per-app); + # empty SMTP_HOST keeps Nextcloud mail disabled. Nextcloud uses the plaintext :2526 listener + # (tls_mode=plaintext, SMTP_SECURE empty = no TLS) — it can't skip the self-signed STARTTLS cert. + # From is split: MAIL_FROM_ADDRESS=nextcloud + MAIL_DOMAIN=felhom.eu. See .felhom.yml smtp_mapping. + - SMTP_HOST=${SMTP_HOST:-} + - SMTP_PORT=${SMTP_PORT:-25} + - SMTP_SECURE=${SMTP_SECURE:-} + - MAIL_FROM_ADDRESS=${MAIL_FROM_ADDRESS:-} + - MAIL_DOMAIN=${MAIL_DOMAIN:-} + volumes: + - nextcloud_html:/var/www/html + - ${HDD_PATH}/appdata/nextcloud:/var/www/html/data + networks: + - traefik-public + - nextcloud-internal + deploy: + resources: + limits: + memory: 1024M + healthcheck: + test: ["CMD", "curl", "-f", "http://127.0.0.1:80/status.php"] + interval: 30s + timeout: 5s + retries: 3 + start_period: 30s + labels: + - "traefik.enable=true" + - "traefik.http.routers.nextcloud.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" + - "traefik.http.routers.nextcloud.entrypoints=websecure" + - "traefik.http.routers.nextcloud.tls=true" + - "traefik.http.routers.nextcloud.tls.certresolver=letsencrypt" + - "traefik.http.services.nextcloud.loadbalancer.server.port=80" + - "traefik.http.middlewares.nextcloud-redirect.redirectregex.regex=/.well-known/(card|cal)dav" + - "traefik.http.middlewares.nextcloud-redirect.redirectregex.replacement=/remote.php/dav/" + - "traefik.http.routers.nextcloud.middlewares=nextcloud-redirect" + + nextcloud-db: + image: mariadb:12.3 + container_name: nextcloud-db + restart: unless-stopped + environment: + - MYSQL_ROOT_PASSWORD=${MYSQL_ROOT_PASSWORD} + - MYSQL_DATABASE=nextcloud + - MYSQL_USER=nextcloud + - MYSQL_PASSWORD=${DB_PASSWORD} + - TZ=Europe/Budapest + # MARIADB_AUTO_UPGRADE: on a MAJOR engine move the engine converts its own datadir (~7 s on a + # small DB, backs its system tables up first). Operator ruling 2026-09-13 on + # felhom.eu/documentation/audits/SPIKE-r459-mariadb-upgrade-2026-09-06.md. Inert until a + # major moves — and none may, until Slice 4 (R-448) ships: see CLAUDE.md, engine-major rule. + - MARIADB_AUTO_UPGRADE=1 + volumes: + - nextcloud_db_data:/var/lib/mysql + networks: + - nextcloud-internal + deploy: + resources: + limits: + memory: 512M + healthcheck: + test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"] + interval: 10s + timeout: 5s + retries: 5 + start_period: 20s + + nextcloud-redis: + image: redis:7-alpine + container_name: nextcloud-redis + restart: unless-stopped + command: redis-server --appendonly yes + environment: + - TZ=Europe/Budapest + volumes: + - nextcloud_redis_data:/data + networks: + - nextcloud-internal + deploy: + resources: + limits: + memory: 128M + healthcheck: + test: ["CMD", "redis-cli", "ping"] + interval: 10s + timeout: 5s + retries: 5 + start_period: 20s + +volumes: + nextcloud_db_data: + nextcloud_html: + nextcloud_redis_data: + +networks: + traefik-public: + external: true + nextcloud-internal: