Deployment Overview of Nextcloud on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Compatible Linux distribution (e.g., CentOS, Rocky Linux, or AlmaLinux).
-
Privileges: Root or sudo access is required for installation and configuration.
-
Domain: A valid FQDN is required for SSL encryption via Certbot.
-
Ports: The following ports must be open and accessible:
-
80/tcp(HTTP) -
443/tcp(HTTPS) -
22/tcp(SSH)
FQDN of the final panel on the hostkey.in domain¶
The application is accessed via a subdomain generated based on the server ID and the configured zone.
| Parameter | Value |
|---|---|
| Prefix | nextcloud |
| Domain | hostkey.in |
| Full template | nextcloud{Server_ID_from_Invapi}.hostkey.in |
File and Directory Structure¶
The application uses the following directory structure for configuration and data persistence:
-
/opt/nextcloud/: Main application directory containing the Docker Compose file, installation scripts, and PHP configurations (php.ini,fpm.conf, etc.). -
/opt/nginx/: Nginx configuration files and SSL certificate management environment files. -
/var/www/html: The web root for Nextcloud (mapped via Docker volumes).
Application Installation Process¶
The installation is performed using a combination of Docker Compose and specialized setup scripts:
-
Environment Preparation: Directories are created with specific permissions (
0640for configs,0755for data) to ensure security. -
Docker Deployment: The application stack is launched using
docker compose. This includes the web server, database, and document processing services. -
SSL Provisioning: A Certbot process is executed within a container to obtain SSL certificates via the webroot method for the configured domain.
-
Automated Configuration: An installation script (
set_configuration.sh) is executed to perform the following: -
Initial Nextcloud setup (database connection, admin credentials).
-
Configuring trusted domains.
-
Optimizing performance by configuring Redis and APCu for memory caching and file locking.
-
Installing and integrating the OnlyOffice application.
-
System Optimization: The system runs
occcommands to add missing database indices/columns and sets a maintenance window.
Access Rights and Security¶
Security is maintained through several layers:
-
Firewall: Rules are configured via
firewalldorufwto allow only necessary traffic (80, 443, and 22). -
Permissions: Configuration files in
/opt/nextcloudand/opt/nginxare owned byrootwith restricted read permissions. -
SSL/TLS: All web traffic is redirected from HTTP to HTTPS using Nginx.
Databases¶
The application utilizes a PostgreSQL database for high-performance data management.
| Component | Details |
|---|---|
| Engine | postgres:16-alpine |
| Database Name | nextcloud |
| Storage Location | Managed via Docker volume db_data |
| Connection Method | Internal Docker network (host: db) |
Docker Containers and Their Deployment¶
The deployment consists of several interconnected containers:
| Container Name | Image | Ports | Volumes | Environment Variables / Notes |
|---|---|---|---|---|
app-server | nextcloud:fpm | 80, 9000 (internal) | app_data or custom path, /opt/nextcloud/php.ini | Configures DB, Redis, and Overwrite URLs |
db | postgres:16-alpine | 5432 (internal) | db_data | Sets PostgreSQL credentials |
redis | redis:alpine | N/A (internal) | N/A | Configured for memory caching and locking |
onlyoffice-document-server | onlyoffice/documentserver:latest | 80, 443 (internal) | document_data, document_log | JWT disabled; used for document editing |
nginx-certbot | jonasal/nginx-certbot:latest | 80, 443 | nginx_secrets, /opt/nginx/user_conf.d, /opt/nginx/nginx.conf | Handles SSL via Certbot and proxies requests to the app |
Custom Scripts and Additional Setup¶
The following scripts are used for post-deployment configuration:
-
/opt/nextcloud/set_configuration.sh: An installation script that automates theocccommand-line interface to configure the Nextcloud instance, set up Redis caching, and install the OnlyOffice integration. -
Database Optimization: Post-installation commands are executed via
docker execto ensure database indices and columns are correctly aligned with the application version.
Application Update Instructions¶
To update the main application, use the following command in the /opt/nextcloud directory:
Location of Configuration Files and Data¶
-
Nextcloud Web Files: Managed via Docker volumes (
app_data) or a custom path defined during installation. -
Database Data: Stored in the
db_dataDocker volume. -
OnlyOffice Data: Stored in the
document_dataDocker volume. -
Nginx Configurations: Located in
/opt/nginx/user_conf.d/.
Available Ports for Connection¶
-
HTTPS:
443(Primary access point) -
HTTP:
80(Redirects to HTTPS)