Inaccessible Installation after Caddy Community Container

The Basics

  • Nextcloud Server version (e.g., 29.x.x):
    • latest from AIO (34.0.4.1)
  • Operating system and version (e.g., Ubuntu 24.04):
    • Linux Mint 22.3
  • Web server and version (e.g, Apache 2.4.25):
    • latest from AIO
  • Reverse proxy and version _(e.g. nginx 1.27.2)
    • None
  • PHP version (e.g, 8.3):
    • latest from AIO (8.4.x)
  • Installation method (e.g. AlO, NCP, Bare Metal/Archive, etc.)
    • AIO
  • Are you using CloudfIare, mod_security, or similar? (Yes / No)
    • No

Summary of the issue you are facing:

I just setup a new AIO installation of Nextcloud. Everything worked fine until I tried to get LocalAI to work and installed Caddy community container like their guides told me to. I could not proceed with the guide, because my Nextcloud instance is already a subdomain and sub-subdomains cannot be “spawned” like Caddy tries. I decided to give up on that and removed Caddy community container and also the LocalAI one.
Now the installation is no longer accessible.

I found Caddy community version - how to safely remove? but unsure what to do. I did not specify neither Apache address nor port bindings during installation. The --env APACHE_PORT=443 created a collision with the Talk container. If I keep 11000 and try to connect via :11000 Firefox complains about RX Record Too Long and refuses connection, so I guess the Caddy container broke the SSL certificate also. I could not find a way to trigger a renewal so I tried to switch to another domain and back ( GitHub - nextcloud/all-in-one: 📦 The official Nextcloud installation method. Provides easy deployment and maintenance with most features included in this one Nextcloud instance. · GitHub ) It did not help.

Can anyone help me fixing this installation without a complete reinstallation? Because this would be my next step and I really don’t want to handle the 1+TB backup again.

Configuration

Nextcloud

The output of occ config:list system:

{
    "system": {
        "one-click-instance": true,
        "one-click-instance.user-limit": 100,
        "update_channel": "stable",
        "memcache.local": "\\OC\\Memcache\\APCu",
        "apps_paths": [
            {
                "path": "\/var\/www\/html\/apps",
                "url": "\/apps",
                "writable": false
            },
            {
                "path": "\/var\/www\/html\/custom_apps",
                "url": "\/custom_apps",
                "writable": true
            }
        ],
        "check_data_directory_permissions": false,
        "memcache.distributed": "\\OC\\Memcache\\Redis",
        "memcache.locking": "\\OC\\Memcache\\Redis",
        "redis": {
            "host": "***REMOVED SENSITIVE VALUE***",
            "timeout": 3,
            "read_timeout": 10,
            "password": "***REMOVED SENSITIVE VALUE***",
            "port": 6379
        },
        "overwritehost": "hackar.dns-cloud.net",
        "overwriteprotocol": "https",
        "serverid": 445,
        "passwordsalt": "***REMOVED SENSITIVE VALUE***",
        "secret": "***REMOVED SENSITIVE VALUE***",
        "trusted_domains": [
            "localhost",
            "hackar.dns-cloud.net"
        ],
        "datadirectory": "***REMOVED SENSITIVE VALUE***",
        "dbtype": "pgsql",
        "version": "34.0.4.1",
        "overwrite.cli.url": "https:\/\/hackar.dns-cloud.net\/",
        "instanceid": "***REMOVED SENSITIVE VALUE***",
        "dbname": "***REMOVED SENSITIVE VALUE***",
        "dbhost": "***REMOVED SENSITIVE VALUE***",
        "dbtableprefix": "oc_",
        "dbuser": "***REMOVED SENSITIVE VALUE***",
        "dbpassword": "***REMOVED SENSITIVE VALUE***",
        "installed": true,
        "maintenance": false,
        "updatechecker": false,
        "loglevel": 2,
        "log_type": "file",
        "log_type_audit": "file",
        "logfile": "\/var\/www\/html\/data\/nextcloud.log",
        "logfile_audit": "\/var\/www\/html\/data\/audit.log",
        "log_rotate_size": 10485760,
        "log.condition": {
            "apps": [
                "admin_audit"
            ]
        },
        "preview_max_x": 2048,
        "preview_max_y": 2048,
        "jpeg_quality": 60,
        "enabledPreviewProviders": {
            "1": "OC\\Preview\\Image",
            "2": "OC\\Preview\\MarkDown",
            "3": "OC\\Preview\\MP3",
            "4": "OC\\Preview\\TXT",
            "5": "OC\\Preview\\OpenDocument",
            "6": "OC\\Preview\\Movie",
            "7": "OC\\Preview\\Krita",
            "0": "OC\\Preview\\Imaginary",
            "23": "OC\\Preview\\ImaginaryPDF"
        },
        "enable_previews": true,
        "upgrade.disable-web": true,
        "mail_smtpmode": "smtp",
        "trashbin_retention_obligation": "auto, 30",
        "versions_retention_obligation": "auto, 30",
        "activity_expire_days": 30,
        "simpleSignUpLink.shown": false,
        "share_folder": "\/Shared",
        "one-click-instance.link": "https:\/\/nextcloud.com\/all-in-one\/",
        "upgrade.cli-upgrade-link": "https:\/\/github.com\/nextcloud\/all-in-one\/discussions\/2726",
        "updatedirectory": "\/nc-updater",
        "maintenance_window_start": 100,
        "allow_local_remote_servers": true,
        "davstorage.request_timeout": 3600,
        "documentation_url.server_logs": "https:\/\/github.com\/nextcloud\/all-in-one\/discussions\/5425",
        "htaccess.RewriteBase": "\/",
        "dbpersistent": false,
        "auth.bruteforce.protection.enabled": true,
        "ratelimit.protection.enabled": true,
        "files_external_allow_create_new_local": false,
        "trusted_proxies": "***REMOVED SENSITIVE VALUE***",
        "preview_imaginary_url": "***REMOVED SENSITIVE VALUE***",
        "preview_imaginary_key": "***REMOVED SENSITIVE VALUE***",
        "DOMAIN": "hackar.dns-cloud.net",
        "AIO_VERSION": "v14.2.0"
    }
}

Apps

Enabled:
  - activity: 7.0.0
  - admin_audit: 1.24.0
  - appstore: 1.0.0
  - assistant: 3.5.0
  - bruteforcesettings: 7.0.0
  - calendar: 6.6.2
  - circles: 34.0.0
  - cloud_federation_api: 1.18.0
  - comments: 1.24.0
  - contacts: 8.9.1
  - contactsinteraction: 1.15.0
  - dashboard: 7.14.0
  - dav: 1.40.0
  - deck: 1.18.5
  - federatedfilesharing: 1.24.0
  - federation: 1.24.0
  - files: 2.6.0
  - files_downloadlimit: 5.2.0
  - files_lock: 34.0.1
  - files_pdfviewer: 7.0.0
  - files_reminders: 1.7.0
  - files_sharing: 1.26.0
  - files_trashbin: 1.24.0
  - files_versions: 1.27.0
  - firstrunwizard: 7.0.0-dev.0
  - impersonate: 5.0.0
  - integration_openai: 4.5.2
  - logreader: 7.0.0
  - lookup_server_connector: 1.22.0
  - nextcloud-aio: 0.9.0
  - nextcloud_announcements: 6.0.0
  - notes: 6.1.0
  - notifications: 7.0.0-dev.1
  - notify_push: 1.4.1
  - oauth2: 1.22.0
  - office: 1.0.0
  - password_policy: 6.0.0-dev.0
  - photos: 7.0.0
  - privacy: 6.0.0-dev.1
  - profile: 1.3.0
  - provisioning_api: 1.24.0
  - recommendations: 7.0.0
  - related_resources: 5.0.0-dev.0
  - richdocuments: 11.1.2
  - serverinfo: 6.0.0
  - settings: 1.17.0
  - sharebymail: 1.24.0
  - spreed: 24.0.5
  - support: 6.0.0
  - survey_client: 6.0.0-dev.0
  - systemtags: 1.24.0
  - tasks: 0.18.1
  - text: 8.0.0
  - theming: 2.9.0
  - twofactor_backupcodes: 1.23.0
  - twofactor_totp: 16.0.0
  - updatenotification: 1.24.0
  - user_migration: 10.5.0
  - user_status: 1.14.0
  - viewer: 7.0.0-dev.0
  - weather_status: 1.14.0
  - webhook_listeners: 1.6.0
  - whiteboard: 2.0.0
  - workflowengine: 2.16.0
Disabled:
  - app_api: 34.0.0 (installed 33.0.0)
  - encryption: 2.22.0
  - files_external: 1.26.0
  - suspicious_login: 12.0.0-dev.0
  - twofactor_nextcloud_notification: 8.0.0
  - user_ldap: 1.25.0

Hi, see all-in-one/reverse-proxy.md at main · nextcloud/all-in-one · GitHub.

Alternatively, restore a backup from before you first enabled the caddy community container.

Hey. I’m commenting cos you tagged my previous post. I’ll explain how I resolved things and the way I ended up going altogether, because perhaps it might help you.

So the Caddy problem, first of all. It really was impossible to remove. It was a pain. So restoring a backup is the way to go.

However, in the process of all that, I ended up re-evaluating my use of AIO, because it just isn’t very easy to use alongside other things on the same server. You lose a fair bit of control, in exchange for ease of use. So that part is not really a Caddy problem. Caddy is kind of a symptom of that.

What I ended up doing instead was using the Community Nextcloud image, with the CODE and AIO Talk images on top for those components. I have backups taken care of separately (I use Backrest for Restic - highly recommended). I have antivirus running on the server level with an API or web socket (forget which) to connect so Nextcloud can use it. I have security taken care of via CrowdSec with custom Nextcloud scenarios, plus some of my own tweaks, and Nginx (also WordPress bouncers, incidentally).

With everything separated out of Nextcloud AIO’s closed system, my brain just has less hassle with it all and things don’t break. Or if they do, I know exactly why.

Hope the perspective helps!

This guide is already known to me and it seems not be a correct solution, as I’ve stated above.

No, my linked guide is correct. Enabling the caddy community container changes some internal configs which you can revert by following the linked guide.

So, to sum this up, you did not resolve the issue at all, but started from scratch.

The guide cannot be correct solution for the state of my installation, because if I follow it, container with Apache won’t start at all, complaining port 443 is already taken.

I see, then you need to stop any service or container first that already uses that port.

Can you post the output of sudo docker ps here?

The start-up order of the containers is not controlled by me. Assuming Apache will get the 443 port, won’t it disable the (HPB) Talk container instead? Since the AIO asks me to forward the 443 for the HPB, I assume the 443 should be owned by the HPB container.

CONTAINER ID   IMAGE                                               COMMAND                  CREATED       STATUS                 PORTS                                                                                                                                     NAMES
bf33e4dc8c2f   ghcr.io/nextcloud-releases/aio-apache:latest        "/start.sh dinit --s…"   5 hours ago   Up 5 hours (healthy)   80/tcp, 0.0.0.0:11000->11000/tcp                                                                                                          nextcloud-aio-apache
291d9b4c197b   ghcr.io/nextcloud-releases/aio-nextcloud:latest     "/start.sh dinit --s…"   5 hours ago   Up 5 hours (healthy)   9000/tcp                                                                                                                                  nextcloud-aio-nextcloud
7d55ee7c664d   ghcr.io/nextcloud-releases/aio-imaginary:latest     "/start.sh"              5 hours ago   Up 5 hours (healthy)                                                                                                                                             nextcloud-aio-imaginary
94e9e888cb9b   ghcr.io/nextcloud-releases/aio-redis:latest         "/start.sh"              5 hours ago   Up 5 hours (healthy)   6379/tcp                                                                                                                                  nextcloud-aio-redis
0673cd05fe92   ghcr.io/nextcloud-releases/aio-postgresql:latest    "/start.sh"              5 hours ago   Up 5 hours (healthy)   5432/tcp                                                                                                                                  nextcloud-aio-database
480e732e5760   ghcr.io/nextcloud-releases/aio-whiteboard:latest    "/start.sh"              5 hours ago   Up 5 hours (healthy)   3002/tcp                                                                                                                                  nextcloud-aio-whiteboard
a12e5a8308ca   ghcr.io/nextcloud-releases/aio-notify-push:latest   "/start.sh"              5 hours ago   Up 5 hours (healthy)                                                                                                                                             nextcloud-aio-notify-push
ac1e66d92102   ghcr.io/nextcloud-releases/aio-talk:latest          "/start.sh dinit --s…"   5 hours ago   Up 5 hours (healthy)   443/tcp, 0.0.0.0:443->443/udp, [::]:443->443/udp                                                                                          nextcloud-aio-talk
794e90d5bc97   ghcr.io/nextcloud-releases/aio-collabora:latest     "/usr/bin/coolwsd --…"   5 hours ago   Up 5 hours (healthy)   9980/tcp                                                                                                                                  nextcloud-aio-collabora
d046677251fa   ghcr.io/nextcloud-releases/all-in-one:latest        "/start.sh"              5 hours ago   Up 5 hours (healthy)   0.0.0.0:80->80/tcp, [::]:80->80/tcp, 0.0.0.0:8080->8080/tcp, [::]:8080->8080/tcp, 0.0.0.0:8443->8443/tcp, [::]:8443->8443/tcp, 9000/tcp   nextcloud-aio-mastercontainer

Ah I see the problem now. The mastercontainer command is missing a --env TALK_PORT=3478 \. This should probably make it work.

I don’t like changing setting for unrelated container, even if it would make it “work”. It does not looks like Caddy container changed that setting to me, or did it? I really would like to “revert” to default AIO settings.

It changed that setting too. See all-in-one/community-containers/caddy/caddy.json at 4187eaf8b614d95f39a7d49c620f744717d9a65e · nextcloud/all-in-one · GitHub. Best would be to simply restore a backup from before you enabled the caddy community container.

Thanks a LOT. This “something changed my system in a way that influences Nextcloud installation” is exactly what I tried to prevent by switching to AIO (from a “native” installation directly on server os).
I put these 3 setting into the composer file, so I won’t forget them in case I need to recreate the master image again.

Just a big recommendation from my side to create a backup before enabling any community container in the future like suggested in the AIO-interface. This would have prevented this situation for you as you could have restored the former state.

Its a new installation. The existing “backup” is not from AIO, so it’s not trivial to restore and on a slow drive, so it’s a multi-day event anyway. Now this installation is “finished”, I retire the old installation and switch the backup to this new one.