Docudjeex
Cloud Drive & Photos

Nextcloud

Install Nextcloud to self-host your files, photos, and calendar, a privacy-friendly alternative to Google Drive, OneDrive, and iCloud.

Nextcloud is a self-hosted solution that allows you to access and synchronize your data across all your devices. It also includes collaboration features, calendar, and more. It’s a great alternative to services like Google Drive, iCloud, or OneDrive.

Installation

We'll be using the Docker image maintained by LinuxServer.io
  • /
    • srv
      • docker
        • nextcloud
          • config
          • data
          • compose.yaml
          • .env

Deploy the stack

Open Dockge, click on compose, name the stack nextcloud and paste the following:

compose.yaml
---
services:
  nextcloud:
    image: lscr.io/linuxserver/nextcloud:latest
    container_name: nextcloud
    environment:
      - PUID=${PUID}
      - PGID=${GUID}
      - TZ=Etc/UTC
    volumes:
      - /srv/docker/nextcloud/config:/config
      - /srv/docker/nextcloud/data:/data
    ports:
      - ${PORT}:443
    restart: unless-stopped
If you’re using a NAS or network-shared drive via Samba, replace /srv/docker/nextcloud/data with the path to your shared folder.

Set your environment variables

Find your PUID and GUID by running the following command:

Terminal
id username

Then fill out the .env file with your preferred port and the values found above, for example:

.env
PUID=1000
GUID=1000
PORT=4545

Deploy the stack and visit http://yourserverip:4545 to complete the setup.

Done !

If it fails: check your firewall rules.

Exposing Nextcloud with Swag

The goal of this setup is to access Nextcloud remotely from all your devices. We’ll use Swag to expose the app.

We assume you have a subdomain nextcloud.yourdomain.com with a CNAME pointing to yourdomain.com in your DNS zone. And unless you’re using Cloudflare Zero Trust, port 443 on your router must be forwarded to port 443 on your server using NAT rules.

Add Nextcloud's network to SWAG

In Dockge, go to your SWAG stack and edit the compose to add Nextcloud's network:

compose.yaml
---
services:
  swag:
     container_name: # ...
      # ... 
     networks:               
      # ...           
      - nextcloud            
    
networks:                    
  # ...
  nextcloud:                 
    name: nextcloud_default  
    external: true
We assume the Nextcloud network is named nextcloud_default. You can confirm connectivity by visiting the SWAG dashboard at http://yourserverip:81.

Redeploy the stack and wait for SWAG to become fully operational.

Configure trusted proxies

In Nextcloud’s files, edit the config.php file:

Tip: You can use File Browser Quantum to navigate and edit files instead of using terminal commands.
Terminal
sudo nano /srv/docker/nextcloud/config/www/nextcloud/config/config.php

Paste the following before the final );:

config.php
'trusted_proxies' => [gethostbyname('swag')],
'overwrite.cli.url' => 'https://nextcloud.example.com/',
'overwritehost' => 'nextcloud.example.com',
'overwriteprotocol' => 'https',

Also add your domain in the array section. It should look like this:

config.php
array (
   0 => '192.168.0.1:444', # This line may differ, don’t change it!
   1 => 'nextcloud.yourdomain.com', # Add your domain here
),

Press Ctrl+O, then Enter to save, and Ctrl+X to exit.

Create the subdomain.conf file

In Swag’s folders, create the file nextcloud.subdomain.conf:

Terminal
sudo nano /srv/docker/swag/config/nginx/proxy-confs/nextcloud.subdomain.conf

Paste the following:

nextcloud.subdomain.conf
## Version 2024/04/25
server {
    listen 443 ssl;
    listen [::]:443 ssl;

    server_name nextcloud.*;

    include /config/nginx/ssl.conf;

    client_max_body_size 0;

    location / {
        include /config/nginx/proxy.conf;
        include /config/nginx/resolver.conf;
        set $upstream_app nextcloud;
        set $upstream_port 443;
        set $upstream_proto https;
        proxy_pass $upstream_proto://$upstream_app:$upstream_port;

        # Hide proxy response headers from Nextcloud that conflict with ssl.conf
        proxy_hide_header Referrer-Policy;
        proxy_hide_header X-Content-Type-Options;
        proxy_hide_header X-Frame-Options;
        proxy_hide_header X-XSS-Protection;

        # Disable proxy buffering
        proxy_buffering off;
    }
}

Press Ctrl+O, then Enter to save, and Ctrl+X to exit.

Done !

That’s it! You’ve exposed Nextcloud! Don’t forget to install the desktop and mobile apps.

Protecting Nextcloud with Pocket ID

Nextcloud can also delegate login to an OIDC provider instead of (or alongside) its own accounts.

Install the OpenID Connect app

In Nextcloud, go to Apps > Integration and install OpenID Connect user backend (user_oidc).

Register Nextcloud as an OIDC client

Register an OIDC client in Pocket ID named Nextcloud, with this callback URL:

https://nextcloud.yourdomain.com/apps/user_oidc/code

Add the provider in Nextcloud

In Nextcloud, go to Administration > OpenID Connect, click the + button, and fill in:

FieldValue
IdentifierPocketID
Client IDThe client ID copied from Pocket ID
Client secretThe client secret copied from Pocket ID
Discovery endpointPocket ID's OIDC discovery URL
Scopeopenid email profile groups

Done !

✨ You can use Authentik instead of Pocket ID:
  1. In Authentik, create an application and an OAuth2/OpenID Connect provider named Nextcloud, with a redirect URI (type Strict) of https://nextcloud.yourdomain.com/apps/user_oidc/code.
  2. Note the provider's Client ID, Client Secret, and Slug.
  3. In Nextcloud's OpenID Connect settings, set the Discovery endpoint to https://authentik.yourdomain.com/application/o/<slug>/.well-known/openid-configuration, then fill in the Client ID and Client Secret.
Contributor:Djeex
Copyright © 2026