roll back authentik login. removed and restore working state.
This commit is contained in:
@@ -1,194 +0,0 @@
|
||||
version: '3.8'
|
||||
|
||||
# Authentik - Identity Provider for SSO (Using Shared Infrastructure)
|
||||
# Phase 1: Foundation - Google OAuth Integration
|
||||
# Ports: 9000 (HTTP), 9443 (HTTPS)
|
||||
# GPU: No
|
||||
# Dependencies: postgres-shared, redis-shared
|
||||
|
||||
services:
|
||||
authentik-server:
|
||||
image: ghcr.io/goauthentik/server:latest
|
||||
container_name: authentik-server
|
||||
restart: unless-stopped
|
||||
command: server
|
||||
ports:
|
||||
- "9000:9000"
|
||||
# Port 9443 removed - use NPM for HTTPS termination
|
||||
environment:
|
||||
# Database configuration (shared PostgreSQL)
|
||||
AUTHENTIK_POSTGRESQL__HOST: postgres-shared
|
||||
AUTHENTIK_POSTGRESQL__PORT: 5432
|
||||
AUTHENTIK_POSTGRESQL__NAME: authentik
|
||||
AUTHENTIK_POSTGRESQL__USER: authentik_user
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${AUTHENTIK_DB_PASSWORD:?database password required}
|
||||
|
||||
# Cache configuration (shared Redis, database 1)
|
||||
AUTHENTIK_REDIS__HOST: redis-shared
|
||||
AUTHENTIK_REDIS__PORT: 6379
|
||||
AUTHENTIK_REDIS__DB: 1
|
||||
|
||||
# Authentik secret key
|
||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||
|
||||
# Error reporting (disabled)
|
||||
AUTHENTIK_ERROR_REPORTING__ENABLED: "false"
|
||||
|
||||
# Performance tuning for home use
|
||||
WORKERS: 2
|
||||
|
||||
# Email configuration (optional - configure later if needed)
|
||||
# AUTHENTIK_EMAIL__HOST: smtp.gmail.com
|
||||
# AUTHENTIK_EMAIL__PORT: 587
|
||||
# AUTHENTIK_EMAIL__USERNAME: your-email@gmail.com
|
||||
# AUTHENTIK_EMAIL__PASSWORD: your-app-password
|
||||
# AUTHENTIK_EMAIL__USE_TLS: "true"
|
||||
# AUTHENTIK_EMAIL__FROM: authentik@schweitz.net
|
||||
|
||||
# Timezone
|
||||
TZ: Europe/Amsterdam
|
||||
volumes:
|
||||
- /home/jpmschweitzer/docker-data/authentik/media:/media
|
||||
- /home/jpmschweitzer/docker-data/authentik/custom-templates:/templates
|
||||
networks:
|
||||
- docker-dataplane
|
||||
depends_on:
|
||||
- postgres-shared
|
||||
- redis-shared
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 256M
|
||||
|
||||
authentik-worker:
|
||||
image: ghcr.io/goauthentik/server:latest
|
||||
container_name: authentik-worker
|
||||
restart: unless-stopped
|
||||
command: worker
|
||||
environment:
|
||||
# Database configuration (shared PostgreSQL)
|
||||
AUTHENTIK_POSTGRESQL__HOST: postgres-shared
|
||||
AUTHENTIK_POSTGRESQL__PORT: 5432
|
||||
AUTHENTIK_POSTGRESQL__NAME: authentik
|
||||
AUTHENTIK_POSTGRESQL__USER: authentik_user
|
||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${AUTHENTIK_DB_PASSWORD}
|
||||
|
||||
# Cache configuration (shared Redis, database 1)
|
||||
AUTHENTIK_REDIS__HOST: redis-shared
|
||||
AUTHENTIK_REDIS__PORT: 6379
|
||||
AUTHENTIK_REDIS__DB: 1
|
||||
|
||||
# Authentik secret key
|
||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY}
|
||||
|
||||
# Error reporting (disabled)
|
||||
AUTHENTIK_ERROR_REPORTING__ENABLED: "false"
|
||||
|
||||
# Timezone
|
||||
TZ: Europe/Amsterdam
|
||||
user: root
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- /home/jpmschweitzer/docker-data/authentik/media:/media
|
||||
- /home/jpmschweitzer/docker-data/authentik/certs:/certs
|
||||
- /home/jpmschweitzer/docker-data/authentik/custom-templates:/templates
|
||||
networks:
|
||||
- docker-dataplane
|
||||
depends_on:
|
||||
- postgres-shared
|
||||
- redis-shared
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 192M
|
||||
|
||||
authentik-proxy-outpost:
|
||||
image: ghcr.io/goauthentik/proxy:latest
|
||||
container_name: authentik-proxy-outpost
|
||||
restart: unless-stopped
|
||||
network_mode: host
|
||||
environment:
|
||||
# Authentik connection
|
||||
AUTHENTIK_HOST: http://192.168.86.149:9000
|
||||
AUTHENTIK_INSECURE: "false"
|
||||
AUTHENTIK_TOKEN: ${AUTHENTIK_OUTPOST_TOKEN:?outpost token required}
|
||||
|
||||
# Logging
|
||||
AUTHENTIK_LOG_LEVEL: info
|
||||
|
||||
# Port configuration
|
||||
AUTHENTIK_LISTEN__HTTP: 0.0.0.0:9001
|
||||
AUTHENTIK_LISTEN__METRICS: 0.0.0.0:9300
|
||||
depends_on:
|
||||
- authentik-server
|
||||
labels:
|
||||
- "com.centurylinklabs.watchtower.enable=true"
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "--spider", "-q", "http://localhost:9001/outpost.goauthentik.io/ping"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
start_period: 30s
|
||||
|
||||
networks:
|
||||
docker-dataplane:
|
||||
external: true
|
||||
name: docker-dataplane
|
||||
|
||||
# Prerequisites:
|
||||
#
|
||||
# 1. Deploy shared-infrastructure stack first!
|
||||
# docker-compose -f shared-infrastructure.yml up -d
|
||||
#
|
||||
# 2. Verify shared services are running:
|
||||
# docker ps | grep -E 'postgres-shared|redis-shared'
|
||||
#
|
||||
# 3. Create Authentik data directories (if not exists):
|
||||
# mkdir -p ~/docker-data/authentik/{media,certs,custom-templates}
|
||||
#
|
||||
# 4. Create .env file with:
|
||||
# AUTHENTIK_DB_PASSWORD=<from shared-infrastructure .env>
|
||||
# AUTHENTIK_SECRET_KEY=<generate with: openssl rand -base64 60>
|
||||
#
|
||||
# 5. Deploy this stack:
|
||||
# docker-compose -f authentik-shared.yml --env-file .env.authentik-shared up -d
|
||||
#
|
||||
# After Deployment:
|
||||
#
|
||||
# 1. Wait for containers to start (may take 30-60 seconds for DB migrations)
|
||||
#
|
||||
# 2. Check logs:
|
||||
# docker logs authentik-server
|
||||
# docker logs authentik-worker
|
||||
#
|
||||
# 3. Access initial setup: http://localhost:9000/if/flow/initial-setup/
|
||||
# - Create admin account (akadmin recommended)
|
||||
# - Set strong password
|
||||
#
|
||||
# 4. Configure NPM reverse proxy:
|
||||
# - Domain: auth.schweitz.net
|
||||
# - Forward to: authentik-server:9000
|
||||
# - SSL: Let's Encrypt
|
||||
# - Websockets: Enabled
|
||||
#
|
||||
# 5. Access admin interface: https://auth.schweitz.net/if/admin/
|
||||
#
|
||||
# Connection Details:
|
||||
#
|
||||
# Database:
|
||||
# - Host: postgres-shared (from containers) / localhost (from host)
|
||||
# - Port: 5432
|
||||
# - Database: authentik
|
||||
# - User: authentik_user
|
||||
#
|
||||
# Cache:
|
||||
# - Host: redis-shared (from containers) / localhost (from host)
|
||||
# - Port: 6379
|
||||
# - Database: 1
|
||||
#
|
||||
# Resource Usage (optimized for home use):
|
||||
# - Server: 256MB RAM limit (WORKERS=2 reduces Gunicorn processes)
|
||||
# - Worker: 192MB RAM limit
|
||||
# - Proxy Outpost: ~32MB RAM
|
||||
# - Total Authentik: ~480MB max (vs ~700MB with dedicated PostgreSQL/Redis)
|
||||
# - Savings: ~400MB by using shared infrastructure!
|
||||
+1
-1
@@ -29,7 +29,7 @@ services:
|
||||
/venv/bin/uvicorn src.main:app
|
||||
--host 0.0.0.0
|
||||
--port 8083
|
||||
--workers 2
|
||||
--workers 1
|
||||
"
|
||||
|
||||
ports:
|
||||
|
||||
@@ -1,398 +0,0 @@
|
||||
# Nextcloud Database Consolidation Plan
|
||||
|
||||
**Goal**: Fresh Nextcloud installation using shared PostgreSQL + Redis infrastructure
|
||||
|
||||
**Date**: 2025-11-16
|
||||
**Status**: APPROVED - Complete wipe and fresh start
|
||||
**Approach**: No migration, no backups - complete fresh installation
|
||||
|
||||
---
|
||||
|
||||
## Current State
|
||||
|
||||
### Existing Setup
|
||||
```yaml
|
||||
nextcloud-db (MariaDB 10.11)
|
||||
├─ Database: nextcloud
|
||||
├─ User: nextcloud
|
||||
├─ Data: /home/jpmschweitzer/docker-data/nextcloud/db
|
||||
└─ Network: docker-dataplane
|
||||
|
||||
nextcloud-redis (Redis Alpine)
|
||||
├─ Standalone instance
|
||||
├─ Data: In-memory only (no persistence configured)
|
||||
└─ Network: docker-dataplane
|
||||
|
||||
nextcloud (Nextcloud Stable)
|
||||
├─ Config: /home/jpmschweitzer/docker-data/nextcloud/config
|
||||
├─ Data: /mnt/media/nextcloud/data
|
||||
└─ Dependencies: nextcloud-db, nextcloud-redis
|
||||
```
|
||||
|
||||
### Target Setup
|
||||
```yaml
|
||||
postgres-shared (PostgreSQL 16)
|
||||
├─ New database: nextcloud
|
||||
├─ New user: nextcloud_user
|
||||
└─ Database allocation: DB 3
|
||||
|
||||
redis-shared (Redis Alpine)
|
||||
├─ Database allocation: DB 3 (Nextcloud)
|
||||
├─ Existing DB 0: General cache
|
||||
├─ Existing DB 1: Authentik
|
||||
└─ Existing DB 2: Gitea
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Migration Challenges
|
||||
|
||||
### Critical Issue: MariaDB → PostgreSQL
|
||||
⚠️ **Nextcloud cannot simply switch database types!**
|
||||
|
||||
Nextcloud's database schema is different between MariaDB and PostgreSQL:
|
||||
- Different data types (e.g., LONGTEXT vs TEXT)
|
||||
- Different auto-increment handling
|
||||
- Different JSON field types
|
||||
- Different index structures
|
||||
|
||||
**Options:**
|
||||
|
||||
### Option A: Fresh Install + Data Migration (RECOMMENDED)
|
||||
✅ **Pros:**
|
||||
- Clean database schema
|
||||
- Opportunity to optimize
|
||||
- Lower risk of corruption
|
||||
- Can test before switching
|
||||
|
||||
❌ **Cons:**
|
||||
- Must recreate users/settings
|
||||
- Requires careful data migration
|
||||
- More complex process
|
||||
|
||||
### Option B: Database Conversion
|
||||
✅ **Pros:**
|
||||
- Preserves all settings
|
||||
- Preserves user data
|
||||
|
||||
❌ **Cons:**
|
||||
- Complex conversion process
|
||||
- High risk of data loss
|
||||
- Nextcloud doesn't officially support this
|
||||
- May leave corrupted data
|
||||
|
||||
**RECOMMENDATION: Option A (Fresh Install)**
|
||||
|
||||
---
|
||||
|
||||
## Fresh Installation Plan
|
||||
|
||||
### Phase 1: Complete Cleanup - PURGE ALL DATA
|
||||
|
||||
**Estimated Time:** 2 minutes
|
||||
|
||||
⚠️ **DESTRUCTIVE OPERATION - REQUIRES EXPLICIT APPROVAL** ⚠️
|
||||
|
||||
The following will be PERMANENTLY DELETED:
|
||||
- All Nextcloud containers (nextcloud, nextcloud-db, nextcloud-redis)
|
||||
- All Nextcloud configuration (/home/jpmschweitzer/docker-data/nextcloud)
|
||||
- All Nextcloud user files (/mnt/media/nextcloud)
|
||||
- All Nextcloud database data
|
||||
|
||||
**APPROVAL REQUIRED BEFORE EACH DELETION STEP**
|
||||
|
||||
```bash
|
||||
# Step 1: Stop and remove containers
|
||||
# APPROVAL: Stop containers? (y/n)
|
||||
docker stop nextcloud nextcloud-db nextcloud-redis 2>/dev/null || true
|
||||
docker rm nextcloud nextcloud-db nextcloud-redis 2>/dev/null || true
|
||||
|
||||
# Step 2: Delete config directory
|
||||
# APPROVAL: Delete /home/jpmschweitzer/docker-data/nextcloud? (y/n)
|
||||
sudo rm -rf /home/jpmschweitzer/docker-data/nextcloud
|
||||
|
||||
# Step 3: Delete user data directory
|
||||
# APPROVAL: Delete /mnt/media/nextcloud? (y/n)
|
||||
sudo rm -rf /mnt/media/nextcloud
|
||||
|
||||
# Step 4: Verify complete removal
|
||||
ls /home/jpmschweitzer/docker-data/ | grep nextcloud # Should be empty
|
||||
ls /mnt/media/ | grep nextcloud # Should be empty
|
||||
```
|
||||
|
||||
### Phase 2: Prepare Shared Infrastructure
|
||||
|
||||
**Estimated Time:** 5 minutes
|
||||
|
||||
```bash
|
||||
# 1. Create Nextcloud database in postgres-shared
|
||||
docker exec -i postgres-shared psql -U postgres <<'EOF'
|
||||
-- Nextcloud database
|
||||
CREATE DATABASE nextcloud;
|
||||
CREATE USER nextcloud_user WITH PASSWORD 'GENERATE_NEW_PASSWORD_HERE';
|
||||
GRANT ALL PRIVILEGES ON DATABASE nextcloud TO nextcloud_user;
|
||||
\c nextcloud
|
||||
GRANT ALL ON SCHEMA public TO nextcloud_user;
|
||||
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO nextcloud_user;
|
||||
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON SEQUENCES TO nextcloud_user;
|
||||
EOF
|
||||
|
||||
# 2. Update redis-shared documentation (already supports DB 3)
|
||||
# No action needed - redis-shared already configured for multi-database
|
||||
```
|
||||
|
||||
### Phase 3: Create Fresh Nextcloud Stack Configuration
|
||||
|
||||
**Estimated Time:** 5 minutes
|
||||
|
||||
Create new `nextcloud-shared.yml`:
|
||||
|
||||
```yaml
|
||||
services:
|
||||
nextcloud:
|
||||
image: nextcloud:stable
|
||||
container_name: nextcloud
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "8082:80"
|
||||
volumes:
|
||||
# Fresh config directory
|
||||
- /home/jpmschweitzer/docker-data/nextcloud/config:/var/www/html/config
|
||||
# Fresh user data directory
|
||||
- /mnt/media/nextcloud/data:/var/www/html/data
|
||||
environment:
|
||||
# PostgreSQL configuration
|
||||
- POSTGRES_HOST=postgres-shared
|
||||
- POSTGRES_DB=nextcloud
|
||||
- POSTGRES_USER=nextcloud_user
|
||||
- POSTGRES_PASSWORD=${NEXTCLOUD_DB_PASSWORD}
|
||||
|
||||
# Redis configuration (Database 3)
|
||||
- REDIS_HOST=redis-shared
|
||||
- REDIS_HOST_PORT=6379
|
||||
- REDIS_DB_INDEX=3
|
||||
|
||||
# Timezone
|
||||
- TZ=Europe/Amsterdam
|
||||
depends_on:
|
||||
- postgres-shared
|
||||
- redis-shared
|
||||
networks:
|
||||
- docker-dataplane
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 1G
|
||||
|
||||
networks:
|
||||
docker-dataplane:
|
||||
external: true
|
||||
name: docker-dataplane
|
||||
```
|
||||
|
||||
### Phase 5: Deploy Fresh Nextcloud
|
||||
|
||||
**Estimated Time:** 5 minutes
|
||||
|
||||
```bash
|
||||
# 1. Create new config directory
|
||||
mkdir -p /home/jpmschweitzer/docker-data/nextcloud-shared/config
|
||||
|
||||
# 2. Create .env file with database password
|
||||
cat > /mnt/media/Projects/portainer-core/stacks/.env.nextcloud-shared <<EOF
|
||||
NEXTCLOUD_DB_PASSWORD=<GENERATED_PASSWORD_FROM_PHASE2>
|
||||
EOF
|
||||
|
||||
# 3. Deploy new stack
|
||||
cd /mnt/media/Projects/portainer-core/stacks
|
||||
docker compose -f nextcloud-shared.yml --env-file .env.nextcloud-shared up -d
|
||||
|
||||
# 4. Wait for initialization
|
||||
docker logs -f nextcloud
|
||||
```
|
||||
|
||||
### Phase 6: Initial Setup & Configuration
|
||||
|
||||
**Estimated Time:** 10 minutes
|
||||
|
||||
```bash
|
||||
# 1. Access Nextcloud web interface
|
||||
# Navigate to: http://localhost:8082 or https://cloud.schweitz.net
|
||||
|
||||
# 2. First-time setup wizard:
|
||||
# - Admin username: admin
|
||||
# - Admin password: <STRONG_PASSWORD>
|
||||
# - Data folder: /var/www/html/data (default)
|
||||
# - Database: PostgreSQL
|
||||
# - Database user: nextcloud_user
|
||||
# - Database password: <FROM_ENV_FILE>
|
||||
# - Database name: nextcloud
|
||||
# - Database host: postgres-shared
|
||||
|
||||
# 3. Wait for installation (2-3 minutes)
|
||||
|
||||
# 4. Configure trusted domains
|
||||
docker exec -u www-data nextcloud php occ config:system:set trusted_domains 1 --value=cloud.schweitz.net
|
||||
docker exec -u www-data nextcloud php occ config:system:set trusted_domains 2 --value=192.168.86.149
|
||||
|
||||
# 5. Configure Redis caching
|
||||
docker exec -u www-data nextcloud php occ config:system:set redis host --value=redis-shared
|
||||
docker exec -u www-data nextcloud php occ config:system:set redis port --value=6379
|
||||
docker exec -u www-data nextcloud php occ config:system:set redis dbindex --value=3
|
||||
docker exec -u www-data nextcloud php occ config:system:set memcache.local --value='\\OC\\Memcache\\APCu'
|
||||
docker exec -u www-data nextcloud php occ config:system:set memcache.distributed --value='\\OC\\Memcache\\Redis'
|
||||
docker exec -u www-data nextcloud php occ config:system:set memcache.locking --value='\\OC\\Memcache\\Redis'
|
||||
|
||||
# 6. Optimize database
|
||||
docker exec -u www-data nextcloud php occ db:add-missing-indices
|
||||
docker exec -u www-data nextcloud php occ db:convert-filecache-bigint
|
||||
|
||||
# 7. Configure background jobs
|
||||
docker exec -u www-data nextcloud php occ background:cron
|
||||
```
|
||||
|
||||
### Phase 7: Verify Fresh Installation
|
||||
|
||||
**Estimated Time:** 5 minutes
|
||||
|
||||
```bash
|
||||
# 1. Verify admin user can login via web interface
|
||||
# Navigate to: https://cloud.schweitz.net
|
||||
|
||||
# 2. Check PostgreSQL connection
|
||||
docker exec postgres-shared psql -U nextcloud_user -d nextcloud -c '\dt'
|
||||
|
||||
# 3. Check Redis caching
|
||||
docker exec redis-shared redis-cli -n 3 DBSIZE
|
||||
|
||||
# 4. Verify storage location
|
||||
docker exec -u www-data nextcloud php occ config:system:get datadirectory
|
||||
|
||||
# 5. Test file upload/download
|
||||
# Upload a test file via web interface
|
||||
# Download it back
|
||||
# Delete it
|
||||
```
|
||||
|
||||
### Phase 8: Final Cleanup & Documentation
|
||||
|
||||
**Estimated Time:** 2 minutes
|
||||
|
||||
```bash
|
||||
# 1. Update postgres-shared.yml documentation
|
||||
# Add Nextcloud to "Applications Using This Database" list
|
||||
|
||||
# 2. Update redis-shared.yml documentation
|
||||
# Add "DB 3: Nextcloud (file locking, distributed cache)"
|
||||
|
||||
# 3. Rename stack file
|
||||
cd /mnt/media/Projects/portainer-core/stacks
|
||||
mv nextcloud.yml nextcloud-mariadb-archived.yml
|
||||
mv nextcloud-shared.yml nextcloud.yml
|
||||
|
||||
# 4. Delete old archived stack (already purged data in Phase 1)
|
||||
# All old containers and data already removed
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Rollback Plan
|
||||
|
||||
⚠️ **NO ROLLBACK POSSIBLE** ⚠️
|
||||
|
||||
Since all old data is purged in Phase 1, there is no rollback option.
|
||||
|
||||
If fresh installation fails:
|
||||
1. Review error logs
|
||||
2. Fix configuration issues
|
||||
3. Retry fresh installation
|
||||
|
||||
This is acceptable since Nextcloud is not in production use.
|
||||
|
||||
---
|
||||
|
||||
## Testing Checklist
|
||||
|
||||
After fresh installation, verify:
|
||||
|
||||
- [ ] Admin login works
|
||||
- [ ] File upload works
|
||||
- [ ] File download works
|
||||
- [ ] File delete works
|
||||
- [ ] Redis caching active (`docker exec redis-shared redis-cli -n 3 DBSIZE` shows keys)
|
||||
- [ ] PostgreSQL connection stable (`docker exec postgres-shared psql -U nextcloud_user -d nextcloud -c '\dt'` shows tables)
|
||||
- [ ] Memory usage acceptable (<1GB for Nextcloud container)
|
||||
- [ ] Nextcloud accessible via https://cloud.schweitz.net
|
||||
- [ ] No errors in logs (`docker logs nextcloud`)
|
||||
|
||||
---
|
||||
|
||||
## Resource Savings
|
||||
|
||||
**Before Migration:**
|
||||
- nextcloud-db (MariaDB): ~117 MB RAM
|
||||
- nextcloud-redis: ~10 MB RAM
|
||||
- **Total:** ~127 MB RAM + 2 containers
|
||||
|
||||
**After Migration:**
|
||||
- Shared postgres-shared: Already running (minimal additional overhead for one more DB)
|
||||
- Shared redis-shared: Already running (DB 3 uses ~5-10 MB additional)
|
||||
- **Savings:** ~110-120 MB RAM + 2 fewer containers to manage
|
||||
|
||||
**Benefits:**
|
||||
- Simplified infrastructure
|
||||
- Centralized backups
|
||||
- Better resource utilization
|
||||
- Easier monitoring
|
||||
- Consistent database management
|
||||
|
||||
---
|
||||
|
||||
## Risks & Mitigation
|
||||
|
||||
| Risk | Impact | Mitigation |
|
||||
|------|--------|------------|
|
||||
| Data loss during migration | HIGH | Full backups before starting, test on copy first |
|
||||
| Incompatible plugins/apps | MEDIUM | Fresh install allows clean app selection |
|
||||
| User resistance to re-setup | LOW | Minimal - same interface, same files |
|
||||
| Extended downtime | MEDIUM | Plan migration during low-usage window |
|
||||
| Redis DB conflict | LOW | Using dedicated DB 3, isolated from other apps |
|
||||
|
||||
---
|
||||
|
||||
## Timeline
|
||||
|
||||
**Total estimated time:** 20-30 minutes
|
||||
|
||||
- Phase 1: Purge all data: 2 min
|
||||
- Phase 2: Prepare PostgreSQL/Redis: 5 min
|
||||
- Phase 3: Create stack config: 2 min
|
||||
- Phase 4: Create directories: 1 min
|
||||
- Phase 5: Deploy Nextcloud: 3 min
|
||||
- Phase 6: Initial setup & config: 10 min
|
||||
- Phase 7: Testing: 5 min
|
||||
- Phase 8: Documentation: 2 min
|
||||
|
||||
**Can be done anytime** - No production impact, no backups needed
|
||||
|
||||
---
|
||||
|
||||
## Approval Required
|
||||
|
||||
- [ ] Backup strategy approved
|
||||
- [ ] Fresh install approach approved
|
||||
- [ ] Downtime window approved
|
||||
- [ ] Testing checklist reviewed
|
||||
- [ ] Rollback plan understood
|
||||
- [ ] Ready to proceed
|
||||
|
||||
---
|
||||
|
||||
## Notes
|
||||
|
||||
- **COMPLETE FRESH START** - All old data deleted
|
||||
- Clean database, optimal performance from day one
|
||||
- PostgreSQL generally faster than MariaDB for Nextcloud workloads
|
||||
- Redis DB 3 dedicated to Nextcloud (isolated from other apps)
|
||||
- No migration complexity - just a clean installation
|
||||
- Ready for production use immediately after setup
|
||||
+84
-73
@@ -1,38 +1,4 @@
|
||||
version: '3.8'
|
||||
|
||||
# Nextcloud - Cloud Storage with Database and Redis
|
||||
# Backlog: Application Deployment
|
||||
# Ports: 8082
|
||||
# GPU: No
|
||||
# Storage: SSD (config/database), HDD (user data)
|
||||
|
||||
services:
|
||||
nextcloud-db:
|
||||
image: mariadb:10.11
|
||||
container_name: nextcloud-db
|
||||
command: --transaction-isolation=READ-COMMITTED --log-bin=binlog --binlog-format=ROW
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
# Database on SSD for performance
|
||||
- /home/jpmschweitzer/docker-data/nextcloud/db:/var/lib/mysql
|
||||
environment:
|
||||
- MYSQL_ROOT_PASSWORD=xDgobrmzXOl+GgvBdXC9+z5v0OrWb29t
|
||||
- MYSQL_PASSWORD=maF91Sw9is6Zb57JVxU/gPGP8O/DsxFq
|
||||
- MYSQL_DATABASE=nextcloud
|
||||
- MYSQL_USER=nextcloud
|
||||
- TZ=Europe/Amsterdam
|
||||
networks:
|
||||
- docker-dataplane
|
||||
|
||||
nextcloud-redis:
|
||||
image: redis:alpine
|
||||
container_name: nextcloud-redis
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- TZ=Europe/Amsterdam
|
||||
networks:
|
||||
- docker-dataplane
|
||||
|
||||
nextcloud:
|
||||
image: nextcloud:stable
|
||||
container_name: nextcloud
|
||||
@@ -40,61 +6,106 @@ services:
|
||||
ports:
|
||||
- "8082:80"
|
||||
volumes:
|
||||
# App config on SSD
|
||||
- /home/jpmschweitzer/docker-data/nextcloud/config:/var/www/html
|
||||
|
||||
# User data on HDD (large files)
|
||||
# Fresh config directory
|
||||
- /home/jpmschweitzer/docker-data/nextcloud/config:/var/www/html/config
|
||||
# Fresh user data directory
|
||||
- /mnt/media/nextcloud/data:/var/www/html/data
|
||||
environment:
|
||||
- MYSQL_HOST=nextcloud-db
|
||||
- MYSQL_PASSWORD=maF91Sw9is6Zb57JVxU/gPGP8O/DsxFq
|
||||
- MYSQL_DATABASE=nextcloud
|
||||
- MYSQL_USER=nextcloud
|
||||
- REDIS_HOST=nextcloud-redis
|
||||
# PostgreSQL configuration
|
||||
- POSTGRES_HOST=postgres-shared
|
||||
- POSTGRES_DB=nextcloud
|
||||
- POSTGRES_USER=nextcloud_user
|
||||
- POSTGRES_PASSWORD=${NEXTCLOUD_DB_PASSWORD}
|
||||
|
||||
# Redis configuration (Database 3)
|
||||
- REDIS_HOST=redis-shared
|
||||
- REDIS_HOST_PORT=6379
|
||||
- REDIS_DB_INDEX=3
|
||||
|
||||
# Timezone
|
||||
- TZ=Europe/Amsterdam
|
||||
depends_on:
|
||||
- nextcloud-db
|
||||
- nextcloud-redis
|
||||
networks:
|
||||
- docker-dataplane
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 1G
|
||||
|
||||
networks:
|
||||
docker-dataplane:
|
||||
external: true
|
||||
name: docker-dataplane
|
||||
|
||||
# ⚠️ SECURITY WARNING:
|
||||
# Change MYSQL_ROOT_PASSWORD and MYSQL_PASSWORD before deploying!
|
||||
# Use strong, unique passwords.
|
||||
# Nextcloud - Personal Cloud Storage (Using Shared Infrastructure)
|
||||
# Port: 8082
|
||||
# GPU: No
|
||||
# Dependencies: postgres-shared, redis-shared
|
||||
#
|
||||
# Prerequisites:
|
||||
#
|
||||
# 1. Shared infrastructure must be running:
|
||||
# docker ps | grep -E 'postgres-shared|redis-shared'
|
||||
#
|
||||
# 2. Database and user already created in postgres-shared:
|
||||
# - Database: nextcloud
|
||||
# - User: nextcloud_user
|
||||
# - Redis DB: 3
|
||||
#
|
||||
# 3. Create .env file with:
|
||||
# NEXTCLOUD_DB_PASSWORD=<password from shared infrastructure setup>
|
||||
#
|
||||
# 4. Deploy this stack:
|
||||
# cd /mnt/media/Projects/portainer-core/stacks
|
||||
# docker compose -f nextcloud-shared.yml --env-file .env.nextcloud-shared up -d
|
||||
#
|
||||
# After Deployment:
|
||||
# 1. Access http://localhost:8082
|
||||
# 2. First-time setup:
|
||||
# - Create admin account (strong password!)
|
||||
#
|
||||
# 1. Wait for initialization (2-3 minutes)
|
||||
#
|
||||
# 2. Access web interface: http://localhost:8082 or https://cloud.schweitz.net
|
||||
#
|
||||
# 3. First-time setup wizard:
|
||||
# - Admin username: admin
|
||||
# - Admin password: <STRONG_PASSWORD>
|
||||
# - Data folder: /var/www/html/data (default)
|
||||
# - Database: MySQL/MariaDB
|
||||
# - Database user: nextcloud
|
||||
# - Database password: (the one you set above)
|
||||
# - Database: PostgreSQL
|
||||
# - Database user: nextcloud_user
|
||||
# - Database password: <FROM_ENV_FILE>
|
||||
# - Database name: nextcloud
|
||||
# - Database host: nextcloud-db
|
||||
# 3. Wait for installation (may take a few minutes)
|
||||
# - Database host: postgres-shared
|
||||
#
|
||||
# 4. Configure trusted domains:
|
||||
# docker exec -u www-data nextcloud php occ config:system:set trusted_domains 1 --value=tower-of-joy
|
||||
# docker exec -u www-data nextcloud php occ config:system:set trusted_domains 2 --value=192.168.x.x
|
||||
# docker exec -u www-data nextcloud php occ config:system:set trusted_domains 1 --value=cloud.schweitz.net
|
||||
# docker exec -u www-data nextcloud php occ config:system:set trusted_domains 2 --value=192.168.86.149
|
||||
#
|
||||
# Optimization (recommended):
|
||||
# docker exec -u www-data nextcloud php occ db:add-missing-indices
|
||||
# docker exec -u www-data nextcloud php occ db:convert-filecache-bigint
|
||||
# docker exec -u www-data nextcloud php occ background:cron
|
||||
# 5. Configure Redis caching:
|
||||
# docker exec -u www-data nextcloud php occ config:system:set redis host --value=redis-shared
|
||||
# docker exec -u www-data nextcloud php occ config:system:set redis port --value=6379
|
||||
# docker exec -u www-data nextcloud php occ config:system:set redis dbindex --value=3
|
||||
# docker exec -u www-data nextcloud php occ config:system:set memcache.local --value='\\OC\\Memcache\\APCu'
|
||||
# docker exec -u www-data nextcloud php occ config:system:set memcache.distributed --value='\\OC\\Memcache\\Redis'
|
||||
# docker exec -u www-data nextcloud php occ config:system:set memcache.locking --value='\\OC\\Memcache\\Redis'
|
||||
#
|
||||
# Add cron job for background tasks:
|
||||
# echo "*/5 * * * * docker exec -u www-data nextcloud php cron.php" | sudo tee -a /etc/crontab
|
||||
# 6. Optimize database:
|
||||
# docker exec -u www-data nextcloud php occ db:add-missing-indices
|
||||
# docker exec -u www-data nextcloud php occ db:convert-filecache-bigint
|
||||
#
|
||||
# Features:
|
||||
# - File sync and share
|
||||
# - Calendar and contacts
|
||||
# - Collaborative editing
|
||||
# - Photo gallery
|
||||
# - Mobile apps (iOS/Android)
|
||||
# - Desktop sync client
|
||||
# - External storage support
|
||||
# 7. Configure background jobs:
|
||||
# docker exec -u www-data nextcloud php occ background:cron
|
||||
#
|
||||
# Connection Details:
|
||||
#
|
||||
# Database:
|
||||
# - Host: postgres-shared (from containers) / localhost (from host)
|
||||
# - Port: 5432
|
||||
# - Database: nextcloud
|
||||
# - User: nextcloud_user
|
||||
#
|
||||
# Cache:
|
||||
# - Host: redis-shared (from containers) / localhost (from host)
|
||||
# - Port: 6379
|
||||
# - Database: 3
|
||||
#
|
||||
# Resource Usage:
|
||||
# - Nextcloud: 1GB RAM limit
|
||||
# - Savings: ~110-120 MB RAM + 2 fewer containers (MariaDB + Redis removed)
|
||||
|
||||
@@ -132,4 +132,5 @@ networks:
|
||||
# Applications Using This Database:
|
||||
# - Authentik (identity provider)
|
||||
# - Gitea (git hosting) - migrated from dedicated instance
|
||||
# - Nextcloud (personal cloud storage) - migrated from MariaDB
|
||||
# - Future applications as needed
|
||||
|
||||
@@ -66,7 +66,7 @@ networks:
|
||||
# DB 0: General cache (default, shared lightweight caching)
|
||||
# DB 1: Authentik (sessions, cache, message queue)
|
||||
# DB 2: Gitea (cache, sessions)
|
||||
# DB 3: Open WebUI (cache, if needed)
|
||||
# DB 3: Nextcloud (file locking, distributed cache, sessions)
|
||||
# DB 4-15: Reserved for future applications
|
||||
#
|
||||
# Connection Examples:
|
||||
@@ -144,6 +144,7 @@ networks:
|
||||
# Applications Using This Cache:
|
||||
# - Authentik (sessions, policies, background tasks)
|
||||
# - Gitea (sessions, cache, queues) - if migrated
|
||||
# - Nextcloud (file locking, distributed cache, sessions)
|
||||
# - Future applications as needed
|
||||
#
|
||||
# Performance Tips:
|
||||
|
||||
Reference in New Issue
Block a user