Sign inSign up

readystack/nextcloud

By readystack

•Updated about 3 hours ago

Nextcloud Server in one container: embedded SQLite by default; MySQL/MariaDB/PostgreSQL optional

Image
0

4.8K

readystack/nextcloud repository overview

⁠Nextcloud

Signed: cosign SBOM: SPDX attached Provenance: SLSA v0.2

readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1

A cosign-signed build of github.com/nextcloud/server v34.0.3 (AGPL-3.0-or-later), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user, attestations and grade below were measured on the published digest sha256:c956fab4a42abbb34a5466ae2470ba427f4656056102d3728d588fac711da725 on 2026-10-07.

  • Docker Scout grade D (44%) on 2026-10-07 — 4 of Docker's 7 default policies fail:
    • 16 fixable critical/high vulnerabilities (5 critical, 11 high) in 4 packages, e.g. perl 5.36.0-7+deb12u3 (fixed in 5.36.0-7+deb12u4); openssl 3.0.20-1deb12u2 (fixed in 3.0.22-1deb12u1).
    • Provenance attestation is SLSA v0.2; Docker Scout now requires v1.
    • Base image docker.io/library/php:8.4-apache-bookworm has been updated since this image was built (built on sha256:4a91c58ca74c…, the tag now points to sha256:9e811795a606…).
    • 116 packages carry copyleft licences (AGPL, GPL, LGPL, MPL), 112 of them operating-system packages. AGPL: icewind/searchdav, nextcloud/lognormalizer.
    • Measured with Docker Scout CLI 1.26.0 (docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue⁠.
  • ReadyStack release check — passed at release on 2026-09-13: no fixable critical or high vulnerability (Docker Scout and OSV), a non-root user, SBOM and provenance attached. This is ReadyStack's own test, not a Docker grade; vulnerabilities published since then are in today's result at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key (fingerprint b698e6e62c09a245) on this release's index digest sha256:c956fab4a42abbb34a5466ae2470ba427f4656056102d3728d588fac711da725; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1. The linux/amd64 image-manifest digest sha256:33835b7e0d85e9008d36aefa54af2472d0e0ffd01499a3b869cf4ee2b7164164 carries no signature of its own; verify the tag (or the index digest).
  • Attestations — An SPDX SBOM and SLSA v0.2 build provenance are attached to this digest (Docker Scout now requires SLSA v1).
  • Runs as a non-root user (www-data).
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v34.0.3-CE-debian-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1

# ✗ unsupported (do not pull)
docker pull readystack/nextcloud:internal-...

This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

Single container (Apache + mod_php, one foreground process) running Nextcloud Server. SELF-CONTAINED: the default database is a self-managed EMBEDDED SQLite file under /var/www/html/data — the image IS the complete running instance, no external DB and no sidecar required. (Operators MAY instead point Nextcloud at an external MySQL/MariaDB or PostgreSQL for larger deployments, but the CE image ships SQLite-default.) NOT a multi-service cluster, NOT docker-compose/Kubernetes-only.

docker run -d --name nextcloud -p 8080:8080 -e NEXTCLOUD_ADMIN_USER=admin -e NEXTCLOUD_ADMIN_PASSWORD=YOUR_STRONG_PASSWORD -e NEXTCLOUD_TRUSTED_DOMAINS='localhost 127.0.0.1 cloud.example.com' -v nextcloud-data:/var/www/html/data -v nextcloud-config:/var/www/html/config readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1

Or omit the admin env and complete the web setup wizard on first visit.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠. The latest clean-room rebuild from this release's archive (2026-09-25) did not reproduce the published digest (first failing step: digest_match).

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:a32543b43…

Size

351 Bytes

Last updated

about 3 hours ago

docker pull readystack/nextcloud:sha256-33835b7e0d85e9008d36aefa54af2472d0e0ffd01499a3b869cf4ee2b7164164.sig