eec1228dc8
bookstack-db, kimai-db, nextcloud-db, romm-db each gain `MARIADB_AUTO_UPGRADE=1` in the db service's environment list. Operator ruling 2026-09-13 on the measurement in felhom.eu/documentation/audits/SPIKE-r459-mariadb-upgrade-2026-09-06.md: an unconverted datadir is stable but never heals; the conversion costs ~7 s and the engine backs its system tables up first. MARIADB_DISABLE_UPGRADE_BACKUP is deliberately left UNSET — that backup is the precaution. NO `image:` line changed, so `catalog_since` does NOT move — the CLAUDE.md rule ties it to an image change and this is not one. Do not "fix" that. The setting is inert until an engine major actually moves, and none may until Slice 4 (R-448) ships — see the engine-major rule in CLAUDE.md and scripts/check-engine-major.py (next commit). The eleven PostgreSQL templates are untouched: R-463 is a different engine and a different measurement. REUSE.md: one convention row for the MariaDB sidecar env, same commit. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
133 lines
4.5 KiB
YAML
133 lines
4.5 KiB
YAML
# Nextcloud - Saját felhő tárhely - Google Drive/Dropbox alternatíva
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: mariadb
|
|
# RAM: ~256M (mem_limit: 1024M) | Pi-compatible: No
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# DB_PASSWORD - Adatbázis jelszó (auto-generated)
|
|
# MYSQL_ROOT_PASSWORD- MariaDB root jelszó (auto-generated)
|
|
# NEXTCLOUD_ADMIN_USER- Admin felhasználónév
|
|
# NEXTCLOUD_ADMIN_PASSWORD- Admin jelszó (auto-generated)
|
|
# HDD_PATH - Adattárolási útvonal
|
|
|
|
services:
|
|
nextcloud:
|
|
image: nextcloud:34.0.1-apache
|
|
container_name: nextcloud
|
|
restart: unless-stopped
|
|
depends_on:
|
|
nextcloud-db:
|
|
condition: service_healthy
|
|
nextcloud-redis:
|
|
condition: service_healthy
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
- MYSQL_DATABASE=nextcloud
|
|
- MYSQL_USER=nextcloud
|
|
- MYSQL_PASSWORD=${DB_PASSWORD}
|
|
- MYSQL_HOST=nextcloud-db
|
|
- NEXTCLOUD_ADMIN_USER=${NEXTCLOUD_ADMIN_USER:-admin}
|
|
- NEXTCLOUD_ADMIN_PASSWORD=${NEXTCLOUD_ADMIN_PASSWORD}
|
|
- NEXTCLOUD_TRUSTED_DOMAINS=${SUBDOMAIN}.${DOMAIN} nextcloud
|
|
- OVERWRITEPROTOCOL=https
|
|
- OVERWRITEHOST=${SUBDOMAIN}.${DOMAIN}
|
|
- REDIS_HOST=nextcloud-redis
|
|
# App-email (managed relay). Injected by the controller only when app-email is on (global + per-app);
|
|
# empty SMTP_HOST keeps Nextcloud mail disabled. Nextcloud uses the plaintext :2526 listener
|
|
# (tls_mode=plaintext, SMTP_SECURE empty = no TLS) — it can't skip the self-signed STARTTLS cert.
|
|
# From is split: MAIL_FROM_ADDRESS=nextcloud + MAIL_DOMAIN=felhom.eu. See .felhom.yml smtp_mapping.
|
|
- SMTP_HOST=${SMTP_HOST:-}
|
|
- SMTP_PORT=${SMTP_PORT:-25}
|
|
- SMTP_SECURE=${SMTP_SECURE:-}
|
|
- MAIL_FROM_ADDRESS=${MAIL_FROM_ADDRESS:-}
|
|
- MAIL_DOMAIN=${MAIL_DOMAIN:-}
|
|
volumes:
|
|
- nextcloud_html:/var/www/html
|
|
- ${HDD_PATH}/appdata/nextcloud:/var/www/html/data
|
|
networks:
|
|
- traefik-public
|
|
- nextcloud-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 1024M
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-f", "http://127.0.0.1:80/status.php"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 30s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.nextcloud.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
- "traefik.http.routers.nextcloud.entrypoints=websecure"
|
|
- "traefik.http.routers.nextcloud.tls=true"
|
|
- "traefik.http.routers.nextcloud.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.nextcloud.loadbalancer.server.port=80"
|
|
- "traefik.http.middlewares.nextcloud-redirect.redirectregex.regex=/.well-known/(card|cal)dav"
|
|
- "traefik.http.middlewares.nextcloud-redirect.redirectregex.replacement=/remote.php/dav/"
|
|
- "traefik.http.routers.nextcloud.middlewares=nextcloud-redirect"
|
|
|
|
nextcloud-db:
|
|
image: mariadb:11.6
|
|
container_name: nextcloud-db
|
|
restart: unless-stopped
|
|
environment:
|
|
- MYSQL_ROOT_PASSWORD=${MYSQL_ROOT_PASSWORD}
|
|
- MYSQL_DATABASE=nextcloud
|
|
- MYSQL_USER=nextcloud
|
|
- MYSQL_PASSWORD=${DB_PASSWORD}
|
|
- TZ=Europe/Budapest
|
|
# MARIADB_AUTO_UPGRADE: on a MAJOR engine move the engine converts its own datadir (~7 s on a
|
|
# small DB, backs its system tables up first). Operator ruling 2026-09-13 on
|
|
# felhom.eu/documentation/audits/SPIKE-r459-mariadb-upgrade-2026-09-06.md. Inert until a
|
|
# major moves — and none may, until Slice 4 (R-448) ships: see CLAUDE.md, engine-major rule.
|
|
- MARIADB_AUTO_UPGRADE=1
|
|
volumes:
|
|
- nextcloud_db_data:/var/lib/mysql
|
|
networks:
|
|
- nextcloud-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 512M
|
|
healthcheck:
|
|
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 20s
|
|
|
|
nextcloud-redis:
|
|
image: redis:7-alpine
|
|
container_name: nextcloud-redis
|
|
restart: unless-stopped
|
|
command: redis-server --appendonly yes
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
volumes:
|
|
- nextcloud_redis_data:/data
|
|
networks:
|
|
- nextcloud-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 128M
|
|
healthcheck:
|
|
test: ["CMD", "redis-cli", "ping"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 20s
|
|
|
|
volumes:
|
|
nextcloud_db_data:
|
|
nextcloud_html:
|
|
nextcloud_redis_data:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|
|
nextcloud-internal:
|