Nextcloud
Health, version drift, setup checks, app updates and compatibility, verified backups and occ maintenance for a self-hosted Nextcloud. sync reads status.php and, with a serverinfo token, storage and user statistics; drift compares the running version against stable GitHub releases and reports the patch target and the next major separately, because Nextcloud refuses to skip a major and the newest release is often not a legal target; setupchecks records the admin overview's warnings as data; talkBots flags a Nextcloud Talk bot that is not enabled, whose webhook delivery errors rose since the last reading (Talk drops a message whose delivery fails and never resets the count, so the rise is the signal, not the total), or that is expected and missing; apps lists app store updates and, given a targetVersion, which enabled store apps have no release for it. backup dumps MySQL/MariaDB and archives the web-root directories an upgrade changes onto the machine swamp runs on, then reads both back (dump completion line and table count, tar header checksums and gzip CRC) and renames a backup that fails .FAILED; the database password stays in the container's environment and never reaches a command line. maintenance, dbRepair, updateApps and backup change state and are dry runs unless apply=true; each apply path re-reads the state afterwards and fails if the change did not take. occ runs through docker exec, locally or on a host over SSH with BatchMode. Four behaviours shape the implementation. Nextcloud 34 enforces trusted_domains on status.php and answers HTTP 400/code 15 when probed by IP, and Deno's fetch silently drops a Host header override, so baseUrl must be a trusted name and the error is named rather than reported as a bare 400. occ setupchecks exits 1 whenever any check warns, so exit 1 with a JSON report is data, not failure. Prerelease tags are spelled inconsistently (rc2 and RC2 both exist), so any suffixed tag is excluded, not parsed. And updates.nextcloud.com answers an empty 200 both for nothing to offer and for a query it did not understand, so it is not used. A failure to measure is raised, never reported as healthy, current or no updates.
Global Arguments
| Argument | Type | Description |
|---|---|---|
| baseUrl | string | Base URL of the instance, e.g. https://cloud.example.com. Must be a name |
| serverinfoToken? | string | Optional serverinfo token, sent as the `NC-Token` header. Set it on the |
| sshHost? | string | Host to run `occ` on over SSH. Omit to run `docker exec` locally, on the |
| sshUser? | string | SSH user. Omit to use the SSH client's own configuration for the host. |
| strictHostKeyChecking | enum | SSH StrictHostKeyChecking. `yes` refuses an unknown host key, which is |
| knownHostsFile? | string | Optional UserKnownHostsFile for SSH. |
| dockerBin | string | Docker CLI on the target. Give a full path where docker is not on the |
| container | string | Name of the Nextcloud application container. |
| occUser | string | User `occ` runs as inside the container. Must own config.php, or occ |
| githubRepo | string | GitHub `owner/repo` whose releases define what is current. |
| githubToken? | string | Optional GitHub token, only to raise the API rate limit. Needs no scopes |
| imageRepository | string | Image the deployment pulls. Reported in `drift` so a bump can be |
| imageVariant | string | Tag suffix the deployment uses, e.g. `apache` for `34.0.4-apache` or |
| verifyRegistry | string | Registry that image existence is checked against. Must answer the |
| verifyRepository | string | Repository path within `verifyRegistry`. Docker Hub official images live |
| appStoreUrl | string | Nextcloud app store, used by `apps` with a `targetVersion` to check |
| timeoutMs | number | Abort each HTTP call after this long. |
| occTimeoutMs | number | Abort a read-only `occ` command after this long. Commands that change |
| Argument | Type | Description |
|---|---|---|
| runningVersion? | string | Version to compare. Omit to read it from status.php. Supply it |
| pageSize | number | Recent releases to examine. Nextcloud ships three supported majors |
| verifyImage | boolean | Confirm each offered target tag exists in the registry. |
| Argument | Type | Description |
|---|---|---|
| expectedBots | array | Bot names that must be installed and enabled. When given, only |
| Argument | Type | Description |
|---|---|---|
| targetVersion? | string | A Nextcloud version to check app compatibility against, usually |
| Argument | Type | Description |
|---|---|---|
| mode | enum | The state to put it in. |
| apply | boolean | Actually change the mode. Without it, report only. |
| Argument | Type | Description |
|---|---|---|
| apply | boolean | Run the repairs. Adding an index to a large table can take |
| Argument | Type | Description |
|---|---|---|
| apps | array | App ids to update. Empty means every app with an update. |
| apply | boolean | Run the updates. Without it, report the plan only. |
| Argument | Type | Description |
|---|---|---|
| destDir | string | Existing absolute directory, on the machine swamp runs on, to |
| label | string | Prefix of the backup directory, which is <label>-<UTC timestamp>. |
| dbContainer | string | Name of the MySQL/MariaDB container. |
| dbName | string | |
| dbUser | string | Database user to dump as. root sees routines and events; the |
| dbPasswordEnv | string | Environment variable, inside the database container, that holds |
| webRoot | string | The web root inside the application container. |
| paths | array | Directories directly under webRoot to archive. The defaults are |
| apply | boolean | Write the backup. Without it, measure what would be backed up |
Resources
Modified 1 models. updated labels
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned