Nextcloud — Installation¶
Primary audience: TAPPaaS admin.
Prerequisites¶
- Authentik (
identity:identity) is installed. It is a required dependency, not an optional one: Nextcloud has no way to sign users in besides Authentik and the local emergency account.
To deviate from the defaults in
./nextcloud.json(target node, storage, zone/VLAN, sizing), copy the json to/home/tappaas/configand edit it before installing.
The public domain is derived as <vmname>.<domain> from the environment configuration — no proxyDomain is hardcoded in the module json.
Install¶
install-module.sh nextcloud
What happens automatically:
- The platform dependencies provision the VM, ship and rebuild
nextcloud.nixagainst the pinned nixpkgs revision, publish the reverse-proxy route, apply firewall rules, and add the VM to the platform's backup job. - On first boot, admin and database passwords are generated, PostgreSQL and Redis start, and Nextcloud installs itself non-interactively.
install.shreads the generated admin password off the VM, saves it to/home/tappaas/secrets/nextcloud.envon tappaas-cicd, and prints the admin login.
Post-install¶
Single sign-on (Authentik / user_oidc): nothing to do. The identity:identity service creates Nextcloud's application in Authentik, writes OIDC_CLIENT_ID, OIDC_CLIENT_SECRET and OIDC_DISCOVERY_URI to /etc/secrets/nextcloud.env on the VM, and restarts nextcloud-configure-oidc. The login page then goes straight to Authentik. Emergency bypass: a local account can still sign in at https://nextcloud.<domain>/login?direct=1.
Mail (system email): populate /etc/secrets/mail.env on the VM with SMTP_USER and SMTP_PASSWORD so Nextcloud can send its own outbound notifications (password resets, share emails).
Mail app — optional Microsoft 365 sign-in: create an Entra app registration with redirect URI https://<domain>/apps/mail/integration/microsoft-auth, delegated permissions offline_access, IMAP.AccessAsUser.All, SMTP.Send, and admin consent. Put MS_TENANT_ID, MS_CLIENT_ID and MS_CLIENT_SECRET into /home/tappaas/secrets/<vmname>-mail-microsoft.env on tappaas-cicd, then run update-module.sh nextcloud. The mailboxes involved must allow IMAP and authenticated SMTP in Exchange Online.
Document editing, Talk relay and Talk call scaling: none. Installing euro-office, coturn or nextcloud-hpb wires each connector in automatically via nextcloud:fileservice.
Public internet access (optional): Nextcloud is reachable only from internal zones by default. To publish it on the internet, set config["network:proxy"].proxyAllowedZones to ["internet"] in nextcloud.json and run update-module.sh nextcloud.
Verification¶
test-module.sh nextcloud
| Check | Expected |
|---|---|
| Web response | HTTP 200 or 3xx redirect |
installed flag in config.php | true, maintenance mode off |
| PostgreSQL and Redis services | active |
| No in-guest backup | /var/backup/nextcloud and the old backup timers gone (PBS takes the VM) |
| Secret file permissions | mode 0600 |
| Firewall ports | 22 and 80 open, 9980 closed |
OIDC app (user_oidc) | enabled |
onlyoffice connector | DocumentServerUrl matches the euro-office module's URL |
| Public domain | present in trusted_domains |
| Installed apps | at the version this module ships |
| User acceptance | sign in via web and the iOS/Android client, upload and download a file |
Troubleshooting¶
install-module.sh exits with a dependency error A required dependency is not installed (cluster:vm, templates:nixos, backup:vm, network:proxy, network:rules, identity:identity). Install the missing module first, then retry.
Nextcloud not reachable after first boot NixOS first-boot activation may still be running. Check from tappaas-cicd:
ssh tappaas@nextcloud.srv.internal "sudo journalctl -u phpfpm-nextcloud -n 30"
Wait a few minutes, then run test-module.sh nextcloud again.
Admin password unknown It is saved to /home/tappaas/secrets/nextcloud.env on tappaas-cicd at install time; the source of truth is /var/lib/nextcloud/admin-pass on the VM:
ssh tappaas@nextcloud.srv.internal "sudo cat /var/lib/nextcloud/admin-pass"
A user's apps keep asking them to log in again This happens after that user's Nextcloud user ID changes (for example, an auth-backend switch). Every Nextcloud app on every device must remove and re-add the account; the repeated failed logins in between can trigger brute-force throttling. Clear it for the user's address:
ssh tappaas@nextcloud.srv.internal "sudo nextcloud-occ security:bruteforce:reset <ip>"
For upgrades see UPGRADE.md.