Files
docudjeex/content/en/3.serveex/6.cloud/2.nextcloud.md
T

6.6 KiB
Raw Blame History

title, description
title description
Nextcloud Install Nextcloud to self-host your files, photos, and calendar, a privacy-friendly alternative to Google Drive, OneDrive, and iCloud.

:ellipsis{left=0px width=40rem top=10rem blur=140px zIndex=60}

Nextcloud

::note 🎯 Goals: Install Nextcloud to manage your photos and files across all your devices. ::

Nextcloud is a self-hosted solution that allows you to access and synchronize your data across all your devices. It also includes collaboration features, calendar, and more. Its a great alternative to services like Google Drive, iCloud, or OneDrive.

Picture

Installation

::note

We'll be using the Docker image maintained by LinuxServer.io ::

::file-tree

tree: /: - docker: - nextcloud: - config/ - data/ - compose.yaml - .env

::

Open Dockge, click on compose, name the stack nextcloud and paste the following:

---
services:
  nextcloud:
    image: lscr.io/linuxserver/nextcloud:latest
    container_name: nextcloud
    environment:
      - PUID=${PUID}
      - PGID=${GUID}
      - TZ=Etc/UTC
    volumes:
      - /docker/nextcloud/config:/config
      - /docker/nextcloud/data:/data
    ports:
      - ${PORT}:443
    restart: unless-stopped

::note

If youre using a NAS or network-shared drive via Samba, replace /docker/nextcloud/data with the path to your shared folder. ::

Find your PUID and GUID by running the following command:

id username

Then fill out the .env file with your preferred port and the values found above, for example:

PUID=1000
GUID=1000
PORT=4545

Deploy the stack and visit http://yourserverip:4545 to complete the setup.

::caution

If it fails: check your firewall rules. ::

Exposing Nextcloud with Swag

The goal of this setup is to access Nextcloud remotely from all your devices. Well use Swag to expose the app.

::note

We assume you have a subdomain nextcloud.yourdomain.com with a CNAME pointing to yourdomain.com in your DNS zone. And unless youre using Cloudflare Zero Trust, port 443 on your router must be forwarded to port 443 on your server using NAT rules. ::

In Dockge, go to your SWAG stack and edit the compose to add Nextcloud's network:

---
services:
  swag:
     container_name: # ...
      # ... 
     networks:               
      # ...           
      - nextcloud            
    
networks:                    
  # ...
  nextcloud:                 
    name: nextcloud_default  
    external: true           

::note

We assume the Nextcloud network is named nextcloud_default. You can confirm connectivity by visiting the SWAG dashboard at http://yourserverip:81. ::

Redeploy the stack and wait for SWAG to become fully operational.

In Nextclouds files, edit the config.php file:

::tip{icon=""} Tip: You can use File Browser Quantum to navigate and edit files instead of using terminal commands. ::

sudo nano /docker/nextcloud/config/www/nextcloud/config/config.php

Paste the following before the final );:

'trusted_proxies' => [gethostbyname('swag')],
'overwrite.cli.url' => 'https://nextcloud.example.com/',
'overwritehost' => 'nextcloud.example.com',
'overwriteprotocol' => 'https',

Also add your domain in the array section. It should look like this:

array (
   0 => '192.168.0.1:444', # This line may differ, dont change it!
   1 => 'nextcloud.yourdomain.com', # Add your domain here
),

Press :kbd{value="Ctrl+O"}, then :kbd{value="Enter"} to save, and :kbd{value="Ctrl+X"} to exit.

In Swags folders, create the file nextcloud.subdomain.conf:

sudo nano /docker/swag/config/nginx/proxy-confs/nextcloud.subdomain.conf

Paste the following:

## Version 2024/04/25
server {
    listen 443 ssl;
    listen [::]:443 ssl;

    server_name nextcloud.*;

    include /config/nginx/ssl.conf;

    client_max_body_size 0;

    location / {
        include /config/nginx/proxy.conf;
        include /config/nginx/resolver.conf;
        set $upstream_app nextcloud;
        set $upstream_port 443;
        set $upstream_proto https;
        proxy_pass $upstream_proto://$upstream_app:$upstream_port;

        # Hide proxy response headers from Nextcloud that conflict with ssl.conf
        proxy_hide_header Referrer-Policy;
        proxy_hide_header X-Content-Type-Options;
        proxy_hide_header X-Frame-Options;
        proxy_hide_header X-XSS-Protection;

        # Disable proxy buffering
        proxy_buffering off;
    }
}

Press :kbd{value="Ctrl+O"}, then :kbd{value="Enter"} to save, and :kbd{value="Ctrl+X"} to exit.

Thats it! Youve exposed Nextcloud! Dont forget to install the desktop and mobile apps.

Protecting Nextcloud with Pocket ID

Nextcloud can also delegate login to an OIDC provider instead of (or alongside) its own accounts.

::steps{level="3"}

Install the OpenID Connect app

In Nextcloud, go to Apps > Integration and install OpenID Connect user backend (user_oidc).

Register Nextcloud as an OIDC client

Register an OIDC client in Pocket ID named Nextcloud, with this callback URL:

https://nextcloud.yourdomain.com/apps/user_oidc/code

Add the provider in Nextcloud

In Nextcloud, go to Administration > OpenID Connect, click the + button, and fill in:

Field Value
Identifier PocketID
Client ID The client ID copied from Pocket ID
Client secret The client secret copied from Pocket ID
Discovery endpoint Pocket ID's OIDC discovery URL
Scope openid email profile groups

Done !

::

::tip{icon=""} You can use Authentik instead of Pocket ID:

  1. In Authentik, create an application and an OAuth2/OpenID Connect provider named Nextcloud, with a redirect URI (type Strict) of https://nextcloud.yourdomain.com/apps/user_oidc/code.
  2. Note the provider's Client ID, Client Secret, and Slug.
  3. In Nextcloud's OpenID Connect settings, set the Discovery endpoint to https://authentik.yourdomain.com/application/o/<slug>/.well-known/openid-configuration, then fill in the Client ID and Client Secret. ::