Files
app-catalog-felhom.eu/templates/nextcloud/.felhom.yml
T
admin 5d49a11b31
gates / gates (push) Successful in 2s
nextcloud: 34.0.1 -> 34.0.4 (proven on the bench AND on 9202, with its test record) — files_may_change
"Upgrading nextcloud from 34.0.1.2 ..." then the seeded user read back
through occ (a never-created uid reads absent on the same call). The
bench's drive tree changed under the app (its appdata), so the entry is
marked files_may_change: an automatic update needs a fresh copy of the
files (09 decision 13). Memory: nextcloud's own 7.9 % (cgroup 100 % =
file cache), db 24.2 %; 0 kills. Abort refuses ("the version of the data
is higher") — the undo, not the old image, is the way back. Box (9202):
done, read back, R-626 clean. 09 decision 21.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-23 22:19:19 +02:00

179 lines
9.0 KiB
YAML

# =============================================================================
# .felhom.yml - App metadata for felhom-controller
# =============================================================================
# --- Display info (shown on dashboard) ---
display_name: "Nextcloud"
description: "Saját felhő tárhely - Google Drive/Dropbox alternatíva"
category: "files"
subdomain: "cloud"
slug: "nextcloud"
# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that
# changes an image: line must set this to the same day (see CLAUDE.md).
catalog_since: "2026-09-23"
# --- Resource hints (displayed on deploy screen) ---
resources:
mem_request: "256M"
mem_limit: "1024M"
pi_compatible: false
needs_hdd: true
# --- Backup classification (referential coupling; see felhom.eu documentation/audits/SPIKE-backup-classification-2026-07-14.md) ---
backup:
hdd:
- path: appdata/nextcloud
class: mandatory # THE user files — oc_filecache/shares reference them
# --- Deploy fields (first deployment only) ---
deploy_fields:
- env_var: DOMAIN
label: "Domain"
type: domain
description: "A szerver domain neve"
locked_after_deploy: true
- env_var: SUBDOMAIN
label: "Aldomain"
type: subdomain
default: "cloud"
required: true
locked_after_deploy: true
description: "Az alkalmazás aldomainje"
- env_var: DB_PASSWORD
label: "Adatbázis jelszó"
type: secret
generate: "password:24"
locked_after_deploy: true
- env_var: MYSQL_ROOT_PASSWORD
label: "MariaDB root jelszó"
type: secret
generate: "password:24"
locked_after_deploy: true
- env_var: NEXTCLOUD_ADMIN_USER
label: "Admin felhasználónév"
type: text
default: "admin"
locked_after_deploy: true
- env_var: NEXTCLOUD_ADMIN_PASSWORD
label: "Admin jelszó"
type: password
generate: "password:16"
description: "Első bejelentkezéshez. Utána a webes felületen módosítható."
locked_after_deploy: false
- env_var: HDD_PATH
label: "Adattárolási útvonal"
type: path
required: true
placeholder: "/mnt/felhom-drives/hdd_1"
description: "A külső merevlemez elérési útja"
locked_after_deploy: true
# --- App info (info page content) ---
app_info:
tagline: "A saját Google Drive-od - fájlok, naptár, névjegyek egy helyen"
default_creds: "Az admin fiók adatait a telepítéskor adod meg"
docs_url: "https://docs.nextcloud.com/server/latest/user_manual/"
use_cases:
- 'Fájlok szinkronizálása és megosztása eszközök között'
- 'Naptár és névjegyek szinkronizálás (CalDAV/CardDAV)'
- 'Dokumentumok közös szerkesztése (OnlyOffice integrációval)'
- 'Fotó és videó automatikus feltöltés telefonról'
- 'Alkalmazásbolt - kibővíthető funkciók (Notes, Tasks, Forms, stb.)'
first_steps:
- 'Nyisd meg a cloud.DOMAIN címet a böngészőben'
- 'Jelentkezz be a telepítéskor megadott admin fiókkal'
- 'Telepítsd a Nextcloud asztali alkalmazást a számítógépedre'
- 'Telepítsd a Nextcloud mobil alkalmazást a telefonodra'
- 'Hívd meg a családtagokat felhasználói fiókok létrehozásával'
prerequisites:
- 'Külső HDD szükséges a fájlok tárolásához'
- 'Legalább 1 GB szabad RAM (Nextcloud + MariaDB + Redis)'
- 'x86 processzor ajánlott a legjobb teljesítményhez'
# --- Controller-side health probe ---
healthcheck:
checks:
- type: api
port: 80
path: "/status.php"
expect:
status: 200
body_contains: "installed"
# --- App-email mapping (apps → in-controller shim → hub → Resend) ---
# Nextcloud (Symfony Mailer) has no env to skip TLS cert verification and opportunistically STARTTLS-upgrades,
# so it can't use the self-signed :2525 listener → tls_mode=plaintext points it at :2526 (STARTTLS NOT
# advertised → no upgrade attempted; plaintext on the single-tenant app bridge — accepted posture).
# Nextcloud SPLITS the From into local-part + domain, so from_var=MAIL_FROM_ADDRESS (local) +
# from_domain_var=MAIL_DOMAIN → nextcloud@felhom.eu. No security_var (SMTP_SECURE stays empty = no TLS);
# SMTP_NAME/PASSWORD unset (no auth). The official image reads these via getenv() on every boot.
smtp_mapping:
tls_mode: plaintext
host_var: SMTP_HOST
port_var: SMTP_PORT
from_var: MAIL_FROM_ADDRESS
from_domain_var: MAIL_DOMAIN
from_local: nextcloud
# --- English copy (localisation slice 5, R-560) --------------------------------------------
# The Hungarian above is UNCHANGED. A box on English reads this block field by field; a missing
# field shows the Hungarian one; a controller older than 0.257.0 ignores the block entirely.
i18n:
en:
description: 'Your own cloud storage - a Google Drive/Dropbox alternative'
app_info:
tagline: 'Your own Google Drive - files, calendar and contacts in one place'
default_creds: 'You set the admin account details at install time'
use_cases:
- 'Sync and share files between your devices'
- 'Calendar and contact sync (CalDAV/CardDAV)'
- 'Work on a document together (with the OnlyOffice integration)'
- 'Photos and videos upload themselves from your phone'
- 'An app store - more features when you want them (Notes, Tasks, Forms and more)'
first_steps:
- 'Open cloud.DOMAIN in your browser'
- 'Sign in with the admin account you set at install time'
- 'Install the Nextcloud desktop app on your computer'
- 'Install the Nextcloud mobile app on your phone'
- 'Invite the household by creating an account for each of them'
prerequisites:
- 'An external hard drive is needed to keep the files on'
- 'At least 1 GB of free RAM (Nextcloud + MariaDB + Redis)'
- 'An x86 processor is recommended for the best speed'
deploy_fields:
- env_var: DOMAIN
label: 'Domain'
description: 'The server domain name'
- env_var: SUBDOMAIN
label: 'Subdomain'
description: 'The subdomain this app answers on'
- env_var: DB_PASSWORD
label: 'Database password'
- env_var: HDD_PATH
label: 'Data storage path'
description: 'The path to the external hard drive'
placeholder: '/mnt/felhom-drives/hdd_1'
- env_var: MYSQL_ROOT_PASSWORD
label: 'MariaDB root password'
- env_var: NEXTCLOUD_ADMIN_USER
label: 'Admin user name'
- env_var: NEXTCLOUD_ADMIN_PASSWORD
label: 'Admin password'
description: 'For the first sign-in. You can change it in the app afterwards.'
# update_ladder — the test record: one tested step per line, oldest first (JSON flow mappings,
# `09-update-architecture.md` §6.4 part 4). WRITTEN BY scripts/upgrade-test.py, never by hand;
# gated by scripts/check-test-record.py. An image: move without a proven entry here is refused.
update_ladder:
- {"from": {"nextcloud": "nextcloud:34.0.1-apache", "nextcloud-db": "mariadb:11.6", "nextcloud-redis": "redis:7-alpine"}, "to": {"nextcloud": "nextcloud:34.0.1-apache", "nextcloud-db": "mariadb:12.3", "nextcloud-redis": "redis:7-alpine"}, "digest": {"nextcloud": "sha256:b52f7bc0e496f227b0e85e3b88571a42c68b6245ccde29d577e733227715dcf5", "nextcloud-db": "sha256:805c8e104bd563d5bfa24fadd3f31cd419ea859cb5277f32b5dbf2db714f9ed1", "nextcloud-redis": "sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499"}, "verdict": "proven", "tested_at": "2026-09-21T19:37:10.235635+00:00", "harness_version": 1, "evidence": "felhom.eu/documentation/audits/update-night-2026-09-21/apps/nextcloud-engine-mariadb/verdict.json", "memory_peak_pct": null, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "backfilled": "2026-09-23", "note": "backfilled from catalog commit 39374d5; box walk only (harness v1, no memory watch); digest = what the registry served on 2026-09-23, not a measurement of the tested image; the commit cited no record — this one was named by the backfill because its from/to refs are the commit's and the commit describes the same walk"}
- {"from": {"nextcloud": "nextcloud:34.0.1-apache", "nextcloud-db": "mariadb:12.3", "nextcloud-redis": "redis:7-alpine"}, "to": {"nextcloud": "nextcloud:34.0.4-apache", "nextcloud-db": "mariadb:12.3", "nextcloud-redis": "redis:7-alpine"}, "digest": {"nextcloud": "sha256:a5ace30c695afe48c2c406e940ee7886a81e13fa382e57cd68b2416d1a66914c", "nextcloud-db": "sha256:805c8e104bd563d5bfa24fadd3f31cd419ea859cb5277f32b5dbf2db714f9ed1", "nextcloud-redis": "sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499"}, "verdict": "proven", "tested_at": "2026-09-23T20:16:04Z", "harness_version": 3, "evidence": "felhom.eu/documentation/audits/night-2026-09-23/apps/nextcloud/bench/evidence/MV-nextcloud/verdict.json", "box_evidence": "felhom.eu/documentation/audits/night-2026-09-23/apps/nextcloud/verdict.json", "memory_peak_pct": 24.2, "marks": {"files_may_change": true, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 100.0}