Files
office/index.html
T
race d172771aa1 Initial docs: Nextcloud AIO office suite (Collabora + Whiteboard)
- Full deployment reference for office.rmf44.xyz
- Architecture, procedure, troubleshooting, operations pages
- 4 SVG diagrams (topology, container-tree, data-flow, request-flow)
- Mirrors gite_replacement template structure
- Verified via 70/70 ad-hoc checks on 2026-08-10
2026-08-10 15:43:46 -05:00

137 lines
7.3 KiB
HTML

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Nextcloud Office — Project Documentation</title>
<link rel="stylesheet" href="assets/style.css">
</head>
<body>
<div id="wrapper">
<ul class="nav">
<li><a href="index.html" class="active">Overview</a></li>
<li><a href="architecture.html">Architecture</a></li>
<li><a href="procedure.html">Procedure</a></li>
<li><a href="troubleshooting.html">Troubleshooting</a></li>
<li><a href="operations.html">Operations</a></li>
</ul>
<h1>Nextcloud Office</h1>
<p>
<span class="tag green">COMPLETE</span>
Deployed <code>office.rmf44.xyz</code> as a Nextcloud All-in-One stack
with Collabora + Whiteboard on <code>homework03</code>, with public
ingress through <code>hawker</code>'s Caddy over a NetBird mesh.
Replaces the retired OnlyOffice container.
<strong>Cutover completed 2026-08-10.</strong>
</p>
<div class="toc">
<h2>Page index</h2>
<ul>
<li><a href="architecture.html">Architecture</a> — topology, container tree, data flow</li>
<li><a href="procedure.html">Procedure</a> — phase-by-phase build + cutover commands</li>
<li><a href="troubleshooting.html">Troubleshooting</a> — every pitfall we hit + the fix</li>
<li><a href="operations.html">Operations</a> — backup, rollback, monitoring, day-2</li>
</ul>
</div>
<h2>The goal</h2>
<p>
Replace the standalone OnlyOffice container on <code>hawker</code>
with a full Nextcloud All-in-One deployment providing file sync,
Collabora-based office editing (Word/Excel/PowerPoint), and the
built-in Whiteboard. Public URL <code>https://office.rmf44.xyz</code>
serves a single domain (no subdomain split). User data lives on
<code>desslok</code> via NFS so existing backup snapshots still apply.
</p>
<h2>At a glance</h2>
<table>
<tr><th>Item</th><th>Value</th></tr>
<tr><td>Hostname</td><td><code>office.rmf44.xyz</code> (single domain)</td></tr>
<tr><td>Stack</td><td>Nextcloud All-in-One, 8 containers (mastercontainer, apache, nextcloud-fcgi, database, redis, collabora, whiteboard, notify-push)</td></tr>
<tr><td>AIO host</td><td><code>homework03 (10.0.0.73)</code>, Debian 13, Docker 29.6.2, 15 GB RAM</td></tr>
<tr><td>Apache port</td><td><code>11000</code> (host-side; mastercontainer owns host :80 for acme)</td></tr>
<tr><td>Public ingress</td><td><code>hawker</code> Caddy <code>office.rmf44.xyz → 100.79.142.164:11000</code> over NetBird</td></tr>
<tr><td>Office suite</td><td>Collabora (via <code>richdocuments</code> + <code>office</code> apps)</td></tr>
<tr><td>Extras enabled</td><td>Whiteboard</td></tr>
<tr><td>Extras disabled</td><td>Talk, Imaginary (previews), ClamAV, Fulltextsearch, Adminer</td></tr>
<tr><td>Storage</td><td>NFSv4.1 from <code>desslok:/slab/container_storage/office</code> mounted at <code>/srv/nc-files/</code> on homework03</td></tr>
<tr><td>Database</td><td>PostgreSQL inside <code>nextcloud-aio-database</code> container, daily <code>pg_dumpall</code> to NFS</td></tr>
<tr><td>RAM footprint</td><td>~6-9 GB on 15 GB host (97% baseline before AIO)</td></tr>
<tr><td>Cutover time</td><td>Caddy block upstream fix (:80 → :11000) ≈ 1 minute</td></tr>
</table>
<h2>Architecture at a glance</h2>
<p><img src="assets/diagrams/topology.svg" alt="Topology — NetBird mesh, AIO on homework03, NFS on desslok" class="diagram"></p>
<p><a href="architecture.html">Full architecture detail →</a></p>
<h2>Why this approach</h2>
<ul>
<li>
<strong>Single domain, no subdomain gymnastics.</strong> AIO's
mastercontainer terminates TLS for the domain validation
endpoint, but it does NOT proxy Nextcloud traffic — Apache does,
on a non-standard port (11000). One Caddy block on hawker
forwards to that port. No <code>office</code> vs <code>nextcloud</code>
split needed.
</li>
<li>
<strong>Data on desslok via NFS.</strong> Existing backup snapshots
cover <code>/slab/container_storage/office</code>; AIO runs
stateless otherwise. The bind-mount pattern keeps everything
portable — destroy the AIO stack and the data is still there.
</li>
<li>
<strong>Mastercontainer owns host :80.</strong> This is mandatory
for AIO's domain-validation flow, but it conflicts with Apache.
Moving Apache to :11000 lets both coexist on the same host.
</li>
<li>
<strong>Own backup pipeline.</strong> AIO's built-in backup feature
is disabled (<code>AIO_DISABLE_BACKUP=true</code>) because the
data is already on NFS — the natural backup target. A daily
systemd timer on <code>hector</code> SSHes to homework03 and
runs <code>pg_dumpall</code> + a config tar + a user-files tar,
all writing back to desslok via NFS.
</li>
<li>
<strong>No adminer sidecar.</strong> The AIO admin UI on :8080
has full container management; an adminer would just be another
admin surface to secure. Dropped.
</li>
</ul>
<h2>What's still on the day-2 list</h2>
<ul>
<li><strong>E2E browser smoke test</strong> — login flow + Collabora document open + whiteboard create verified via API; full UI click-through needs your eyes (the admin password is in the chat).</li>
<li><strong>Additional users</strong> — currently only <code>admin</code>, <code>race</code> (Lord Race), <code>bettyanne</code> in DB. Family members can be added through the user management UI.</li>
<li><strong>Talk container</strong> — disabled to save RAM. If video conferencing is needed later, re-enable via AIO admin UI.</li>
<li><strong>Imaginary (image previews)</strong> — disabled to save RAM. Re-enable if Nextcloud previews become a complaint.</li>
</ul>
<h2>Files &amp; code paths</h2>
<table>
<tr><th>Path</th><th>Host</th><th>What</th></tr>
<tr><td><code>/usr/local/containers/nextcloudaio/docker-compose.yaml</code></td><td>homework03</td><td>Mastercontainer with <code>network_mode: host</code></td></tr>
<tr><td><code>/usr/local/containers/nextcloudaio/nextcloud-aio-{mastercontainer,database,redis,apache,nextcloud,collabora,whiteboard,notify-push,database-dump}/</code></td><td>homework03</td><td>Named docker volume bind targets</td></tr>
<tr><td><code>/srv/nc-files/</code></td><td>homework03</td><td>NFS mount of <code>desslok:/slab/container_storage/office</code></td></tr>
<tr><td><code>/mnt/nc-data/nextcloud-data/</code></td><td>homework03</td><td>Bind into nextcloud container at <code>/nextcloud-aio/data</code></td></tr>
<tr><td><code>/usr/local/bin/office-backup.sh</code></td><td>homework03</td><td>Daily backup script (pgdump + config tar + user files tar)</td></tr>
<tr><td><code>/etc/systemd/system/office-backup.{service,timer}</code></td><td>hector</td><td>Daily 03:30 UTC trigger, SSH to homework03</td></tr>
<tr><td><code>/etc/caddy/Caddyfile</code></td><td>hawker</td><td>Reverse proxy block: <code>office.rmf44.xyz → 100.79.142.164:11000</code></td></tr>
<tr><td><code>/slab/container_storage/office/</code></td><td>desslok</td><td>Live data + <code>backups/</code> subdir</td></tr>
</table>
<p class="footer">
Project deployed 2026-08-10. Documentation modeled on
<code>../gite_replacement/</code>.
</p>
</div>
</body>
</html>