Nextcloud Server in one container: embedded SQLite by default; MySQL/MariaDB/PostgreSQL optional
4.8K
readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1
A cosign-signed build of github.com/nextcloud/server v34.0.3 (AGPL-3.0-or-later), built clean-room from official upstream source by ReadyStack.
Signature, user, attestations and grade below were measured on the published digest sha256:c956fab4a42abbb34a5466ae2470ba427f4656056102d3728d588fac711da725 on 2026-10-07.
docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue.b698e6e62c09a245) on this release's index digest sha256:c956fab4a42abbb34a5466ae2470ba427f4656056102d3728d588fac711da725; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1. The linux/amd64 image-manifest digest sha256:33835b7e0d85e9008d36aefa54af2472d0e0ffd01499a3b869cf4ee2b7164164 carries no signature of its own; verify the tag (or the index digest).www-data).This image follows the ReadyStack release-tag convention:
The current release is v34.0.3-CE-debian-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1
# ✗ unsupported (do not pull)
docker pull readystack/nextcloud:internal-...
This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected], as set out in the ReadyStack Agreement.
Single container (Apache + mod_php, one foreground process) running Nextcloud Server. SELF-CONTAINED: the default database is a self-managed EMBEDDED SQLite file under /var/www/html/data — the image IS the complete running instance, no external DB and no sidecar required. (Operators MAY instead point Nextcloud at an external MySQL/MariaDB or PostgreSQL for larger deployments, but the CE image ships SQLite-default.) NOT a multi-service cluster, NOT docker-compose/Kubernetes-only.
docker run -d --name nextcloud -p 8080:8080 -e NEXTCLOUD_ADMIN_USER=admin -e NEXTCLOUD_ADMIN_PASSWORD=YOUR_STRONG_PASSWORD -e NEXTCLOUD_TRUSTED_DOMAINS='localhost 127.0.0.1 cloud.example.com' -v nextcloud-data:/var/www/html/data -v nextcloud-config:/var/www/html/config readystack/nextcloud:v34.0.3-CE-debian-bookworm-r1
Or omit the admin env and complete the web setup wizard on first visit.
The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html. The latest clean-room rebuild from this release's archive (2026-09-25) did not reproduce the published digest (first failing step: digest_match).
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:a32543b43…
Size
351 Bytes
Last updated
about 3 hours ago
docker pull readystack/nextcloud:sha256-33835b7e0d85e9008d36aefa54af2472d0e0ffd01499a3b869cf4ee2b7164164.sig