Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (10.11.19, 2026-09-18), podman (10.11.19, 2026-09-14); Proxmox VM: docker (10.11.19, 2026-09-14), podman (10.11.19, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
nextcloud-app:
image: nextcloud:stable
container_name: nextcloud-app
restart: always
labels:
- "com.centurylinklabs.watchtower.enable=false"
depends_on:
- nextcloud-db
- nextcloud-redis
ports:
- "8080:80"
networks:
- njorddeploy_net
- nextcloud-internal
volumes:
- "./data/nextcloud/data:/var/www/html"
environment:
TZ: "Europe/Amsterdam"
MYSQL_PASSWORD: "ChangeMeSecurePassword123!"
MYSQL_DATABASE: "nextcloud_db"
MYSQL_USER: "nextcloud_user"
MYSQL_HOST: "nextcloud-db"
REDIS_HOST: "nextcloud-redis"
NEXTCLOUD_TRUSTED_DOMAINS: "nextcloud.home.lan"
MAIL_FROM_ADDRESS: "nextcloud"
MAIL_DOMAIN: "example.com"
SMTP_HOST: "smtp.example.com"
SMTP_PORT: "587"
SMTP_SECURE: "tls"
SMTP_AUTHTYPE: "LOGIN"
SMTP_AUTH: "true"
SMTP_NAME: "notifications@example.com"
SMTP_PASSWORD: "ChangeMeSecurePassword123!"
networks:
njorddeploy_net:
nextcloud-internal:
name: nextcloud-internal
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
PORT_NEXTCLOUD |
8080 |
Port to access the Nextcloud web interface. |
NEXTCLOUD_DATA_PATH |
/opt/njorddeploy/data/nextcloud/data |
Host path for storing Nextcloud application data and files. |
NEXTCLOUD_TRUSTED_DOMAINS |
nextcloud.home.lan |
Space-separated list of domains Nextcloud will trust. |
NEXTCLOUD_MAIL_FROM_ADDRESS |
nextcloud |
The sender name for system notifications. |
NEXTCLOUD_MAIL_DOMAIN |
example.com |
The email domain for system notifications. |
NEXTCLOUD_MAIL_SMTPHOST |
smtp.example.com |
The SMTP server address for outgoing mails. |
NEXTCLOUD_MAIL_SMTPPORT |
587 |
The SMTP port (e.g. 587 or 465). |
NEXTCLOUD_MAIL_SMTPSECURE |
tls |
SMTP security layer (tls or ssl). |
NEXTCLOUD_MAIL_SMTPNAME |
notifications@example.com |
The email address used to log into the SMTP server. |
NEXTCLOUD_MAIL_SMTPPASSWORD |
*None* |
The password for the SMTP user. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.