Skip to main content

Nextcloud AIO

Purpose

Nextcloud AIO provides private file storage, synchronization, sharing, productivity, and collaboration services for the Bytek environment.

Nextcloud currently supports or is intended to support:

    Personal file storage. Shared folders. File synchronization across computers and mobile devices. Public and private file sharing. Calendar synchronization. Contact synchronization. Tasks and notes. Browser-based document editing. Simultaneous document collaboration. Authentik single sign-on. Desktop and mobile Nextcloud clients. WebDAV, CalDAV, and CardDAV access. Optional photo, communication, and productivity applications.

    Nextcloud runs as an isolated application VM and uses Nextcloud All-in-One to manage its containers.


    Service Information

    Setting Value Service name Nextcloud AIO Private IP address 192.168.2.100 Public hostname cloud.bytek.ca AIO management port TCP 8080 Traefik backend port TCP 11000 Deployment directory /opt/nextcloud-aio Operating-system disk 64 GB User-data disk 500 GB User-data mount /mnt/nextcloud-data Nextcloud data directory /mnt/nextcloud-data/ncdata Reverse proxy Traefik Authentication Authentik OIDC Office integration AIO-managed Collabora CODE Time zone America/Toronto Backup coverage Proxmox OS and data-disk backup Proxmox VM ID Confirm current VM ID

    User application:

    Open Nextcloud

    AIO management address:

    https://192.168.2.100:8080/


    Architecture Role

    Nextcloud is the central user-file and collaboration platform.

    Nextcloud is separate from:

      BookStack documentation. Vikunja task management. Authentik identity management. Traefik HTTPS routing. Uptime Kuma monitoring. Proxmox infrastructure management.

      This separation limits the effect of an application failure and allows Nextcloud storage to grow independently from the infrastructure VMs.


      Container Architecture

      Nextcloud AIO manages the application stack.

      Core containers include equivalents of:

        AIO master container. Apache and Caddy. Nextcloud. PostgreSQL. Redis. Notify Push. Domain validation during initial setup.

        Optional containers may include:

          Collabora Online. ClamAV. Full-text search. Imaginary. Nextcloud Talk. Talk recording. HaRP. Whiteboard. Community containers.

          Optional containers should be added one at a time and tested before enabling another.


          Public Request Flow

          When an external user opens Nextcloud:

            The browser opens cloud.bytek.ca. WHC public DNS resolves the hostname to 38.29.213.101. The public VPS accepts the HTTPS connection. The VPS forwards the traffic through WireGuard. The home WireGuard gateway forwards the request to Traefik. Traefik receives the request for cloud.bytek.ca. Traefik forwards the request to 192.168.2.100 on TCP port 11000. The AIO Apache container serves Nextcloud.

            Internal Request Flow

            When a LAN user opens Nextcloud:

              The client queries Pi-hole. Pi-hole resolves cloud.bytek.ca to 192.168.2.182. The client connects directly to Traefik. Traefik forwards the request to 192.168.2.100:11000. Nextcloud serves the request.

              Internal clients use the same HTTPS hostname as external clients.


              Traefik Route

              The Nextcloud Traefik router uses:

              Setting Value Hostname rule cloud.bytek.ca Entry point websecure Certificate resolver letsencrypt Backend protocol HTTP Backend destination 192.168.2.100:11000 Host-header forwarding Enabled Authentik ForwardAuth Disabled

              Do not attach Authentik ForwardAuth to the Nextcloud Traefik router.

              Nextcloud requires direct access for:

                Desktop clients. Mobile clients. WebDAV. CalDAV. CardDAV. Application passwords. Public shares. Federation. Synchronization APIs.

                Nextcloud performs user authentication through its native OIDC integration.


                AIO Management Interface

                The AIO management interface is available only by private IP:

                https://192.168.2.100:8080/

                The management interface uses its own certificate, so a browser warning may appear.

                Always use the private IP for AIO management.

                Do not use:

                  cloud.bytek.ca:8080 A public WHC record. A Traefik public router. VPS forwarding. Public router forwarding. Authentik ForwardAuth.

                  The AIO management interface controls:

                    Container startup and shutdown. Updates. Optional containers. Backup settings. AIO passphrase. Application version selection. Time-zone settings. Container logs.

                    Restricted Ports

                    The following ports must not be exposed publicly:

                    Port Purpose TCP 8080 AIO management TCP 11000 AIO Apache backend TCP 8443 AIO-managed certificate interface, not used in this reverse-proxy design TCP 9000 Internal AIO service Docker socket Container management

                    Only Traefik should reach TCP port 11000 during normal operation.

                    LAN administrators may reach TCP port 8080.


                    Storage Architecture

                    Nextcloud uses separate virtual disks for the operating system and user data.

                    Operating-System Disk

                    Setting Value Nominal size 64 GB Proxmox storage local-lvm Root filesystem ext4 Purpose Debian, Docker, AIO configuration, and system files

                    User-Data Disk

                    Setting Value Nominal size 500 GB Proxmox storage user-data Guest device /dev/sda1 at the time of configuration Filesystem ext4 Filesystem label nextcloud-data Mount point /mnt/nextcloud-data Nextcloud data path /mnt/nextcloud-data/ncdata Mount options Defaults and noatime

                    The operating-system disk appeared as /dev/sdb, while the 500 GB data disk appeared as /dev/sda during initial configuration.

                    Linux device names may change, so the permanent mount uses the filesystem UUID rather than /dev/sda1.


                    Data-Disk Validation

                    Confirm the data disk is mounted using:

                    findmnt /mnt/nextcloud-data

                    Confirm available capacity using:

                    df -h / /mnt/nextcloud-data

                    Confirm the filesystem using:

                    lsblk -o NAME,SIZE,FSTYPE,LABEL,UUID,MOUNTPOINTS

                    Confirm the data directory exists using:

                    sudo ls -ld /mnt/nextcloud-data/ncdata

                    The Nextcloud containers should not be started if the expected data filesystem is missing.

                    Starting the application with an unmounted data path could cause data to be written to the operating-system disk instead.


                    Filesystem Mount

                    The data filesystem is mounted through /etc/fstab using its UUID.

                    The mount point is:

                    /mnt/nextcloud-data

                    The intended behavior is:

                      The disk mounts automatically at boot. The mount fails visibly if the filesystem is unavailable. The path remains consistent even if Linux device letters change. Nextcloud AIO always receives the same data location.

                      Review the mount after every storage or boot issue.


                      AIO Data Directory

                      The AIO deployment uses:

                        Nextcloud data directory: /mnt/nextcloud-data/ncdata

                        The directory should remain on the 500 GB user-data disk.

                        Do not move the directory manually while Nextcloud containers are running.

                        Do not directly edit files inside the Nextcloud data directory using normal filesystem tools unless following a documented recovery process.

                        Nextcloud tracks files through its database and filesystem metadata.

                        Files manually copied into the data directory may not appear correctly until an application-level rescan is performed.


                        Authentication

                        Nextcloud uses native OpenID Connect through Authentik.

                        The installed Nextcloud application is:

                          OpenID Connect user backend Application ID: user_oidc

                          Do not install another OIDC login application alongside it unless a migration is deliberately planned.

                          Avoid enabling overlapping authentication applications such as:

                            OpenID Connect Login. Social Login. OpenID Connect SSO by Gluu. OIDC Identity Provider.

                            The OIDC Identity Provider application serves the opposite role by making Nextcloud an identity provider.


                            Authentik OIDC Configuration

                            Setting Value Authentik application name Nextcloud Application slug nextcloud Provider type OAuth2/OpenID Connect Client type Confidential Subject mode User UUID Signing key Selected Encryption key None Authorization callback https://cloud.bytek.ca/apps/user_oidc/code Required group bytek-users Required policy Allow bytek.ca users Policy engine ALL

                            Normal users must:

                              Belong to bytek-users. Pass the Allow bytek.ca users policy.

                              Do not attach bytek-admin as another required ALL binding for normal Nextcloud access.

                              Administrators who need Nextcloud should also belong to bytek-users.


                              Nextcloud OIDC Settings

                              Setting Value Provider identifier authentik Discovery endpoint Authentik discovery URL for application slug nextcloud Scopes openid email profile User ID mapping sub Display-name mapping name Email mapping email

                              The OIDC discovery endpoint must be reachable from inside the Nextcloud application container.

                              The client ID and client secret must match the Authentik Nextcloud provider.

                              Do not place the client secret in BookStack.


                              OIDC Login Flow

                                The user opens cloud.bytek.ca. Nextcloud offers Authentik login. The browser is redirected to portal.bytek.ca. Authentik requests authentication and MFA. Authentik evaluates the bytek-users group. Authentik evaluates the Bytek email policy. Authentik redirects to the Nextcloud callback. Nextcloud validates the OIDC response. Nextcloud creates or matches the user. The user enters Nextcloud.

                                Nextcloud application permissions remain controlled inside Nextcloud.


                                Local Break-Glass Administrator

                                The local Nextcloud administrator must remain available.

                                The local account provides recovery when:

                                  Authentik is unavailable. Pi-hole is unavailable. OIDC is misconfigured. Authentik policies deny access. The user OIDC application fails. A signing or discovery problem occurs.

                                  The direct local-login path is:

                                  Open the Nextcloud Local Login

                                  The local administrator password must:

                                    Be unique. Be stored in the password manager. Differ from the Authentik password. Be rotated if exposed. Be tested periodically.

                                    A local Nextcloud second factor may be enabled for the break-glass account if recovery codes are stored securely.


                                    Trusted Proxy

                                    Nextcloud must trust Traefik as its reverse proxy.

                                    Expected trusted proxy:

                                      192.168.2.182

                                      Review using:

                                      sudo docker exec --user www-data nextcloud-aio-nextcloud php occ config:system:get trusted_proxies

                                      The output should include Traefik’s current private address.

                                      If Traefik’s IP changes, update:

                                        Nextcloud trusted proxies. Traefik route. Pi-hole records if required. Proxmox firewall rules. Uptime Kuma monitors. Documentation.

                                        HTTPS Detection

                                        Nextcloud must generate HTTPS URLs when accessed through Traefik.

                                        If Nextcloud generates HTTP links, investigate:

                                          Trusted proxy. Forwarded protocol headers. overwriteprotocol. overwrite.cli.url. APP_URL equivalent settings. Traefik host-header forwarding.

                                          The expected external URL is:

                                          https://cloud.bytek.ca

                                          Do not set the external URL to the private IP or TCP port 11000.


                                          Office Integration

                                          Nextcloud uses the AIO-managed Collabora Online container.

                                          This component provides browser-based document editing and simultaneous collaboration.

                                          The Nextcloud Office application connects Nextcloud to the AIO-managed Collabora CODE server.

                                          Do not also install the separate Built-in CODE Server application.

                                          Using both would create competing office backends and complicate troubleshooting.


                                          Office Dictionaries

                                          Configured dictionaries:

                                            en_US fr_FR

                                            These provide:

                                              English, United States. French, France.

                                              Canadian French would normally use fr_CA, but the AIO interface should be checked before adding a locale not listed as supported.

                                              Locale values are separated by spaces.


                                              Office Validation

                                              To validate collaborative editing:

                                                Sign in as the first Nextcloud user. Create or upload an office document. Open the document in the browser editor. Share the document with a second user. Open a private browser session. Sign in as the second user. Open the same document. Make an edit from each session. Confirm both sessions see updates. Confirm the file is saved in Nextcloud.

                                                If a document does not open:

                                                  Check the AIO Collabora container. Check Nextcloud Office settings. Check Nextcloud logs. Check Traefik. Check browser console errors. Check the Collabora container log.

                                                  Enabled Applications

                                                    Files. OpenID Connect user backend. Nextcloud Office. Calendar. Contacts. Tasks. Notes.

                                                    Applications that may be added later include:

                                                      Team Folders. Deck. Forms. Collectives. Memories. Imaginary. Talk. Mail. Whiteboard.

                                                      Add applications only when there is a clear use case.

                                                      Every additional application becomes part of:

                                                        Update testing. Backup scope. Database growth. Background processing. Compatibility testing. Recovery procedures.

                                                        Team Folders

                                                        Team Folders may be used for administrator-managed shared storage.

                                                        Use Team Folders instead of placing every shared resource inside one user’s personal files.

                                                        Possible shared folders include:

                                                          Shared Documents. Family Photos. Game Project. Common Resources. Collaboration Files.

                                                          Team Folder permissions should use stable Nextcloud users and groups after OIDC account provisioning has been tested.


                                                          Optional AIO Containers

                                                          Collabora

                                                          Enabled for browser-based document editing.

                                                          Imaginary

                                                          May be enabled later for expanded preview support.

                                                          Possible preview formats include:

                                                            HEIC. HEIF. PDF. SVG. TIFF. WebP.

                                                            Review compatibility before enabling server-side encryption.

                                                            ClamAV

                                                            May be enabled later for antivirus scanning.

                                                            ClamAV requires additional memory and may affect upload processing.

                                                            May be enabled later when enough content exists to justify indexing.

                                                            Initial indexing can consume significant resources and affect availability.

                                                            Nextcloud Talk

                                                            May be enabled later.

                                                            Talk requires deliberate network configuration, including TCP and UDP port 3478 for TURN functionality.

                                                            Do not enable Talk before designing the complete VPS, WireGuard, firewall, and guest-port path.

                                                            HaRP

                                                            May be enabled if a future ExApp requires it.

                                                            Do not enable it without a specific application requirement.

                                                            Docker Socket Proxy

                                                            Do not enable the deprecated Docker Socket Proxy when HaRP is the supported alternative for the intended application.


                                                            Community Containers

                                                            AIO Community Containers are not official core Nextcloud containers.

                                                            Community containers may:

                                                              Have independent maintenance. Introduce additional dependencies. Become incompatible. Require additional ports. Expand backup size. Complicate AIO updates.

                                                              Do not enable community containers merely because they are available.

                                                              Plex was considered as an AIO Community Container but rejected in favor of a dedicated Plex VM.

                                                              Reasons include:

                                                                GPU isolation. Service separation. Backup control. Network separation. Avoiding dependency between Plex and Nextcloud. Keeping the media library outside the Nextcloud VM.

                                                                Time Zone

                                                                Nextcloud AIO uses:

                                                                  America/Toronto

                                                                  The Debian host should also use:

                                                                    America/Toronto

                                                                    Verify the host using:

                                                                    timedatectl

                                                                    Expected properties:

                                                                      Correct local time. Correct UTC time. System clock synchronized. NTP active. RTC stored in UTC.

                                                                      The AIO time-zone setting and Debian host time zone are separate settings.


                                                                      Email Configuration

                                                                      Nextcloud should use SMTP for:

                                                                        User notifications. Shares. Security events. Password-related messages. Calendar invitations. Administrative alerts.

                                                                        WHC SMTP settings should be obtained from:

                                                                          cPanel. Email Accounts. Connect Devices. Manual configuration.

                                                                          Typical secure combinations include:

                                                                          Port Encryption 587 STARTTLS 465 SSL/TLS

                                                                          The full mailbox address is normally used as the SMTP username.

                                                                          Use the mailbox password, not the cPanel password.

                                                                          Do not store the SMTP password in BookStack.


                                                                          Email Troubleshooting

                                                                          If Nextcloud cannot send email:

                                                                            Confirm the mailbox credentials in WHC webmail. Confirm the exact WHC SMTP hostname. Confirm the selected port and encryption match. Test DNS from the Nextcloud VM. Test TCP reachability from the VM. Test TCP reachability from the Nextcloud container. Test STARTTLS using OpenSSL if using port 587. Review the Nextcloud log. Review cPanel Email Track Delivery. Contact WHC support only after collecting the exact error.

                                                                            If no attempt appears in cPanel Track Delivery, the message may not have reached the WHC mail server.


                                                                            Application Administration Overview

                                                                            Review the Nextcloud administration overview after installation and updates.

                                                                            Common warnings may include:

                                                                              Missing default phone region. Email server not configured. Maintenance window. Missing database indexes. Mimetype migrations. Background-job configuration. Proxy-header issues. HTTPS URL detection. App compatibility warnings.

                                                                              Use the exact warning text from the installed Nextcloud version before running administrative commands.

                                                                              Do not copy commands from unrelated versions without reviewing the current warning.


                                                                              Default Phone Region

                                                                              For Canadian phone numbers, use:

                                                                                CA

                                                                                This helps Nextcloud interpret local phone-number formats.

                                                                                Review the current value using the Nextcloud system configuration.


                                                                                Container Management

                                                                                Nextcloud AIO containers should be managed through the AIO interface whenever practical.

                                                                                AIO management address:

                                                                                https://192.168.2.100:8080/

                                                                                Use the AIO interface for:

                                                                                  Starting containers. Stopping containers. Updating containers. Adding optional containers. Removing optional containers. Reviewing container logs. Changing the AIO configuration.

                                                                                  Do not manually recreate AIO-generated application containers unless following an AIO-specific recovery procedure.


                                                                                  Docker Compose Management

                                                                                  The master container deployment is stored under:

                                                                                  /opt/nextcloud-aio

                                                                                  Move to the directory using:

                                                                                  cd /opt/nextcloud-aio

                                                                                  Validate Compose using:

                                                                                  sudo docker compose config --quiet

                                                                                  Check the master container using:

                                                                                  sudo docker compose ps

                                                                                  View master-container logs using:

                                                                                  sudo docker logs nextcloud-aio-mastercontainer --tail 100

                                                                                  Container-level settings in the master Compose definition require recreation of the master container.

                                                                                  AIO-managed child containers remain controlled through AIO.


                                                                                  Container Health

                                                                                  List containers using:

                                                                                  sudo docker ps --format='table {{.Names}}\t{{.Status}}\t{{.Ports}}'

                                                                                  Expected core containers include equivalents of:

                                                                                    nextcloud-aio-mastercontainer nextcloud-aio-database nextcloud-aio-redis nextcloud-aio-nextcloud nextcloud-aio-apache nextcloud-aio-notify-push Collabora container when enabled

                                                                                    A running container may still be unhealthy.

                                                                                    Review the status and relevant application endpoint.


                                                                                    Backend Validation

                                                                                    Confirm TCP port 11000 from the Nextcloud VM using:

                                                                                    curl -I http://127.0.0.1:11000/

                                                                                    Confirm from the Traefik VM using:

                                                                                    curl -I http://192.168.2.100:11000/

                                                                                    A redirect or Nextcloud response confirms the HTTP backend is reachable.

                                                                                    A timeout indicates a firewall or routing issue.

                                                                                    A connection refusal indicates that the VM was reached but no service is listening.


                                                                                    Public Validation

                                                                                    Validate the public hostname using:

                                                                                    Open Nextcloud

                                                                                    Expected behavior:

                                                                                      Valid Let’s Encrypt certificate. Redirect to the Nextcloud login page when unauthenticated. Secure session cookies. HTTPS links. Authentik login option.

                                                                                      A browser cache previously caused a Firefox TLS error while Edge worked.

                                                                                      Before changing Traefik or certificates, test:

                                                                                        Another browser. Private mode. Browser DNS cache. Browser socket cache. DNS over HTTPS. Operating-system DNS.

                                                                                        Monitoring

                                                                                        Monitor Target Nextcloud VM Ping 192.168.2.100 Nextcloud AIO Apache TCP 192.168.2.100:11000 Nextcloud Through Traefik https://cloud.bytek.ca/status.php Nextcloud certificate cloud.bytek.ca AIO management Optional private monitor on TCP 8080

                                                                                        Expected routed status:

                                                                                          HTTP 200.

                                                                                          The Nextcloud VM firewall must allow Uptime Kuma if direct monitoring is used.


                                                                                          Firewall Policy

                                                                                          AIO Management

                                                                                          Allow TCP port 8080 only from approved LAN or VPN management sources.

                                                                                          AIO Apache Backend

                                                                                          Allow TCP port 11000 from:

                                                                                            Traefik at 192.168.2.182. Uptime Kuma at 192.168.2.115 only if direct backend monitoring is used.

                                                                                            SSH

                                                                                            Allow SSH only from approved LAN or VPN administration sources.

                                                                                            Public Exposure

                                                                                            Do not publicly forward:

                                                                                              TCP 8080. TCP 11000. TCP 8443. Docker ports. Database ports. Redis ports.

                                                                                              Backup Architecture

                                                                                              The AIO Borg backup location is currently not configured.

                                                                                              This is intentional because the currently available local destinations are not sufficiently separate from the live data or existing Proxmox backup.

                                                                                              Current backup protection consists of:

                                                                                                Proxmox backup of the 64 GB operating-system disk. Proxmox backup of the 500 GB data disk. Backup archive stored on the dedicated 4 TB HDD.

                                                                                                An AIO Borg repository placed on the same Nextcloud data disk would not protect against failure of that disk.

                                                                                                It would also cause the Proxmox backup to contain both live data and an embedded Borg backup copy.


                                                                                                Future AIO Backup

                                                                                                A future AIO Borg repository should use:

                                                                                                  Another physical computer. A remote Borg server. A dedicated storage device not included in the Nextcloud VM. A trusted remote host. A dedicated future backup platform.

                                                                                                  A remote AIO backup would add an application-aware recovery method alongside Proxmox’s whole-VM backup.

                                                                                                  The separate location is more important than simply enabling the backup field.


                                                                                                  Proxmox Backup Coverage

                                                                                                  Both Nextcloud virtual disks must be included in the Proxmox backup.

                                                                                                  Review the VM configuration using:

                                                                                                  qm config <NEXTCLOUD_VMID>

                                                                                                  Confirm the operating-system disk and data disk do not contain:

                                                                                                    backup=0

                                                                                                    The initial consistent baseline may use a stopped backup.

                                                                                                    Routine backups may use snapshot mode if brief application downtime is undesirable.


                                                                                                    Restore Testing

                                                                                                    A Nextcloud restore test must avoid creating a duplicate live instance.

                                                                                                      Restore the backup under a new VM ID. Disconnect the restored VM network adapter. Start the VM using the Proxmox console. Confirm the operating-system disk. Confirm the data disk. Confirm /mnt/nextcloud-data. Confirm Docker. Confirm the AIO containers. Confirm user files exist. Shut down and delete the restored test VM.

                                                                                                      Do not connect the restored clone to the production LAN while the live Nextcloud VM is active.


                                                                                                      Data Growth

                                                                                                      Monitor Nextcloud growth using:

                                                                                                      df -h /mnt/nextcloud-data

                                                                                                      Review directory usage using:

                                                                                                      sudo du -sh /mnt/nextcloud-data/ncdata

                                                                                                      Monitor the Proxmox user-data thin pool using:

                                                                                                      pvesm status

                                                                                                      Also review LVM-thin data and metadata utilization.

                                                                                                      Storage monitoring must account for:

                                                                                                        User uploads. File versions. Deleted-file retention. Application data. Previews. Office files. Shared folders. Future photo libraries.

                                                                                                        Security Considerations

                                                                                                          Nextcloud is available only through HTTPS. Traefik is explicitly trusted. AIO management remains private. The local administrator is preserved. Normal users authenticate through Authentik. MFA is handled by Authentik. Public registration is reviewed. Application installation is controlled. Optional containers are added deliberately. Backend ports remain private. SMTP credentials remain secret. Proxmox backups cover both disks. File sharing settings are reviewed. Administrative roles are assigned intentionally.

                                                                                                          Common Failure Scenarios

                                                                                                          AIO Management Loads but Nextcloud Does Not

                                                                                                          Check:

                                                                                                            AIO child containers. Apache container. TCP port 11000. Traefik route. Nextcloud application log. Database and Redis.

                                                                                                            Direct Backend Works but Public Hostname Fails

                                                                                                            Check:

                                                                                                              Pi-hole. Traefik router. Certificate. Public DNS. VPS. WireGuard. Browser cache.

                                                                                                              Public Hostname Works but OIDC Fails

                                                                                                              Check:

                                                                                                                Authentik readiness. OIDC discovery. Client ID and secret. Redirect URI. Scope mappings. Container DNS. Authentik policies. Nextcloud log.

                                                                                                                Discovery Endpoint Not Reachable

                                                                                                                Check DNS inside the Nextcloud container.

                                                                                                                Use:

                                                                                                                sudo docker exec nextcloud-aio-nextcloud getent hosts portal.bytek.ca

                                                                                                                No output indicates container DNS failure.

                                                                                                                After confirming Pi-hole, restart the AIO containers or Docker as appropriate.

                                                                                                                User Is Denied by Authentik

                                                                                                                Check the Nextcloud Authentik application bindings.

                                                                                                                Expected requirements:

                                                                                                                  bytek-users Allow bytek.ca users

                                                                                                                  Do not require bytek-admin for all Nextcloud users.

                                                                                                                  Wrong Time Display

                                                                                                                  Confirm:

                                                                                                                    Debian host time zone is America/Toronto. AIO time zone is America/Toronto. UTC clock is synchronized. NTP is active.

                                                                                                                    Data Disk Missing

                                                                                                                    Do not start normal application use until the data disk is mounted.

                                                                                                                    Check:

                                                                                                                      lsblk findmnt /etc/fstab Filesystem UUID Proxmox virtual disk

                                                                                                                      Power-Failure Recovery

                                                                                                                      After a power interruption:

                                                                                                                        Confirm Proxmox. Confirm Pi-hole. Confirm the WireGuard gateway. Confirm Authentik. Confirm Traefik. Confirm the Nextcloud VM owns 192.168.2.100. Confirm the user-data disk. Confirm /mnt/nextcloud-data. Confirm Docker. Open AIO management by private IP. Confirm the AIO master container. Confirm PostgreSQL. Confirm Redis. Confirm Nextcloud. Confirm Apache. Confirm Collabora. Test TCP port 11000. Test cloud.bytek.ca. Test Authentik login. Test a file download.

                                                                                                                        If container DNS remains broken after Pi-hole recovery, restart the affected containers in a controlled manner.


                                                                                                                        Recovery Procedure

                                                                                                                        If the Nextcloud application is unavailable:

                                                                                                                          Use the Proxmox console or SSH. Confirm the VM address. Confirm the data-disk mount. Confirm free disk space. Confirm Docker. Open the AIO interface. Review container states. Review master-container logs. Review the failing child-container log. Test the local backend. Test the Traefik route. Test the public route. Use the local administrator if Authentik is unavailable. Restore only after identifying the failure.

                                                                                                                          If the data disk is damaged:

                                                                                                                            Stop the AIO containers. Avoid writing to the damaged filesystem. Review filesystem and device health. Identify the latest valid Proxmox backup. Restore both the OS and data disks. Test the restored VM offline. Reconnect only after validation.

                                                                                                                            Validation Checklist

                                                                                                                              Nextcloud VM owns 192.168.2.100. Operating-system disk is available. User-data disk is mounted at /mnt/nextcloud-data. Nextcloud data directory exists. Docker is active. AIO master container is healthy. PostgreSQL is running. Redis is running. Nextcloud is running. Apache is running on TCP 11000. Collabora is running. Traefik can reach TCP 11000. cloud.bytek.ca has a valid certificate. Authentik login works. Local administrator login works. File upload works. File download works. Collaborative editing works. SMTP test works. Uptime Kuma reports healthy. Both VM disks are included in backup. Offline restore test has been completed. AIO management is not publicly exposed.

                                                                                                                              Document Control

                                                                                                                                Owner: Bryan Gagne-Plante Private address: 192.168.2.100 Public hostname: cloud.bytek.ca AIO management port: TCP 8080 Traefik backend port: TCP 11000 Deployment directory: /opt/nextcloud-aio Operating-system disk: 64 GB on local-lvm User-data disk: 500 GB on user-data Data mount: /mnt/nextcloud-data Data directory: /mnt/nextcloud-data/ncdata Authentication: Authentik OIDC OIDC application: OpenID Connect user backend Office integration: AIO-managed Collabora AIO backup repository: Not configured Proxmox VM ID: Confirm current VM ID Last verified: YYYY-MM-DD Last OIDC test: YYYY-MM-DD Last collaborative-editing test: YYYY-MM-DD Last SMTP test: YYYY-MM-DD Last backup test: YYYY-MM-DD Last restore test: YYYY-MM-DD Known limitations: No separate remote AIO Borg repository and no offsite backup copy