Skip to content

TutorialsSelf-hosted apps

How to install Nextcloud All-in-One (AIO) with Docker Compose

Install Nextcloud All-in-One with Docker Compose: official mastercontainer, automatic HTTPS, optional Office and Talk, BorgBackup backups and safe updates.

  • Intermediate
  • 40 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Prerequisites
  2. Step 1 — Check Docker and the firewall
  3. Step 2 — Start the mastercontainer
  4. Step 3 — Open the AIO interface and save the passphrase
  5. Step 4 — Enter your domain
  6. Step 5 — Choose optional containers and start Nextcloud
  7. Step 6 — Secure the accounts
  8. Run AIO behind Caddy
  9. Back up and restore
  10. Update Nextcloud AIO
  11. Troubleshooting
  12. Domain validation fails
  13. The interface says your IP address is internal or reserved
  14. You cannot log in to the AIO interface
  15. Port 80 or 443 is already in use
  16. Snap-based Docker installations are not supported
  17. Next steps

Nextcloud All-in-One (AIO) is the official way to run Nextcloud with Docker. A single mastercontainer creates, configures and updates every other part of the stack for you: Nextcloud itself, its database, Redis, a web server that obtains a TLS certificate automatically, and optional extras such as Nextcloud Office, Talk, ClamAV and full-text search. AIO also ships an encrypted backup solution based on BorgBackup.

This guide starts the mastercontainer with Docker Compose on a fresh server, walks through domain validation and the AIO interface, sets up local and off-site backups, and shows how updates work. If your server already runs Caddy on ports 80 and 443, a separate section shows the official reverse proxy setup instead.

Prerequisites

  • A 64-bit server (x86_64 or arm64) running Ubuntu 24.04 or 26.04 LTS or Debian 12 or 13.
  • A non-root user with sudo rights. See Secure a new Linux server and Set up SSH keys.
  • Docker Engine and the Compose plugin from Docker's repository: Ubuntu or Debian. AIO does not support Snap-based Docker installations.
  • A domain such as cloud.example.com with an A record (and AAAA record if you use IPv6) pointing at the server. If the domain uses Cloudflare, switch its proxy option off; AIO notes that domain validation and large uploads can fail behind the proxy.
  • Ports 80 and 443 free on the server, and reachable from the internet together with port 8443. Port 3478 TCP and UDP is needed only if you enable Talk.

AIO shows its hardware requirements in the interface; they depend on the optional containers you enable. SSD storage is recommended.

ResourceMinimum (official)Suggested starting point
RAM2 GB with any optional container; 3 GB with ClamAV, Talk Recording or full-text search; 5 GB with everything1 GB more than the minimum, as AIO recommends (for example 4 GB)
CPUDual-core; quad-core with everything enabled; Talk Recording needs 2 extra vCPUs2 to 4 vCPUs
Disk40 GB of system storage40 GB SSD plus the space your files and backups need

Step 1 — Check Docker and the firewall

AIO does not work with Docker from Snap. This command prints nothing on a supported installation:

Bash
sudo docker info | grep "Docker Root Dir" | grep "/var/snap/docker/"

If it prints a line, remove the Snap package and install Docker from Docker's repository first.

Turn on ufw for the host's own services. The ports that AIO publishes are opened by Docker itself, and Docker handles them before ufw's rules apply, so the list of published ports in the next step is what decides what is reachable:

Bash
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443
sudo ufw allow 8443/tcp
sudo ufw enable

Step 2 — Start the mastercontainer

AIO recommends a Compose file for production. Create a project folder and the file:

Bash
sudo mkdir -p /opt/nextcloud-aio
sudo chown $USER:$USER /opt/nextcloud-aio
cd /opt/nextcloud-aio
nano compose.yaml

Paste the official configuration. The container name, the volume name and the Docker socket mount must stay exactly as shown, because the mastercontainer relies on them:

YAML
name: nextcloud-aio
services:
  nextcloud-aio-mastercontainer:
    image: ghcr.io/nextcloud-releases/all-in-one:latest
    init: true
    restart: always
    container_name: nextcloud-aio-mastercontainer
    volumes:
      - nextcloud_aio_mastercontainer:/mnt/docker-aio-config
      - /var/run/docker.sock:/var/run/docker.sock:ro
    network_mode: bridge
    ports:
      - "80:80"
      - "8080:8080"
      - "8443:8443"
volumes:
  nextcloud_aio_mastercontainer:
    name: nextcloud_aio_mastercontainer

Port 80 serves the ACME challenge for the certificate, port 8080 serves the AIO interface with a self-signed certificate, and port 8443 serves the same interface with a valid certificate once your domain is set. The Apache container that AIO creates later publishes port 443 for Nextcloud.

Start it and watch the log:

Bash
docker compose up -d
docker compose ps
docker logs -f nextcloud-aio-mastercontainer

docker compose ps should show the mastercontainer as running. Press Ctrl+C to leave the log.

Step 3 — Open the AIO interface and save the passphrase

Browse to https://203.0.113.10:8080, using your server's IP address, not the domain. AIO advises this because the HSTS header that Nextcloud sends later could otherwise block the self-signed port. Accept the certificate warning.

The first page shows the AIO passphrase. Store it in a password manager, then log in with it. You need it for every later visit to the AIO interface.

Step 4 — Enter your domain

Enter cloud.example.com when AIO asks for your domain. AIO then checks that the domain points to this server and that it can reach this AIO instance through it; ports 80 and 443 must therefore be reachable from the internet. After this one check, the mastercontainer does not contact your domain again.

If the check fails, fix DNS or the firewall rather than skipping it. Verify the record from your computer with dig +short cloud.example.com; it must return your server's address. The troubleshooting section covers the common errors.

Step 5 — Choose optional containers and start Nextcloud

The interface now lists the optional containers. Enable only what you will use, because each one needs RAM:

  • Nextcloud Office or EuroOffice for editing documents in the browser,
  • Talk (with its high-performance backend and TURN server) and Talk Recording,
  • ClamAV antivirus, Imaginary for image previews, full-text search and Whiteboard,
  • Docker Socket Proxy, required by Nextcloud apps that use the App API.

If you enable Talk, Docker publishes port 3478 TCP and UDP for the TURN server. Start the containers with the start button in the interface. AIO pulls the images and starts them one after another, which takes several minutes on the first run. When all containers are running, the interface shows the initial Nextcloud admin username and password and a link to your Nextcloud.

Open https://cloud.example.com and log in. Check from your computer that HTTPS works:

Bash
curl -I https://cloud.example.com

You should see an HTTP 200 or a 302 redirect to the login page, served with a valid certificate.

Step 6 — Secure the accounts

Change the initial admin password under Personal settings → Security, and turn on two-factor authentication there (for example with the TOTP app from Apps). Create normal user accounts for daily use instead of working as admin.

The AIO interface protects itself: while Nextcloud is running, direct login with the passphrase is blocked. To open it, log in to Nextcloud as an administrator and visit https://cloud.example.com/settings/admin/overview; a button at the top opens the AIO interface for your browser session. In the standard setup you can also reach the interface with a valid certificate on https://cloud.example.com:8443.

Nextcloud emails password resets and notifications about shares and file changes; set up the mail server under Administration settings → Basic settings in the Email server section with host smtp.example.com, port 587 and the None/STARTTLS encryption option, then send a test message from the same page.

Run AIO behind Caddy

Use this setup instead of Step 2 when the server already runs Caddy (see How to set up Caddy as a reverse proxy) or another reverse proxy on ports 80 and 443. Decide before the first start. In reverse proxy mode the Apache container listens on a port you choose, without TLS, and Caddy handles HTTPS.

Change the ports: section of compose.yaml and add the environment variables from AIO's reverse proxy documentation:

YAML
    ports:
      - "8080:8080"
    environment:
      APACHE_PORT: 11000
      APACHE_IP_BINDING: 127.0.0.1

APACHE_PORT is the host port Caddy connects to, and APACHE_IP_BINDING: 127.0.0.1 keeps Apache on localhost so nothing else can bypass Caddy. Then add a site block to /etc/caddy/Caddyfile:

Caddyfile
cloud.example.com {
    reverse_proxy 127.0.0.1:11000
}

Reload Caddy, start AIO and continue with Step 3:

Bash
sudo systemctl reload caddy
docker compose up -d

Domain validation still runs in this mode and goes through Caddy. The variable SKIP_DOMAIN_VALIDATION=true exists, but AIO describes it as a last resort for setups where validation cannot work, such as a Caddy DNS challenge or a Cloudflare Tunnel; with it, a broken proxy configuration can go unnoticed. If your proxy runs on another machine and connects from an IP other than 127.0.0.1, set APACHE_IP_BINDING to 0.0.0.0, firewall port 11000, and add the proxy address to Nextcloud's trusted_proxies as shown in the reverse proxy documentation.

Back up and restore

AIO's backup solution uses BorgBackup: backups are incremental, compressed and encrypted. Ideally the backup folder is on a separate disk or volume; AIO's documentation uses /mnt/backup:

Bash
sudo mkdir -p /mnt/backup

In the AIO interface, enter /mnt/backup as the backup location and select Create Backup. AIO stops the containers, writes the Borg repository to /mnt/backup/borg and starts them again. The interface then shows the encryption password for the backups. Save it with your passphrase: without it, no restore is possible.

After the first backup you can enable daily backups in the interface. You can also trigger a backup or an integrity check from the shell:

Bash
sudo docker exec -it --env DAILY_BACKUP=1 nextcloud-aio-mastercontainer /daily-backup.sh
sudo docker exec --env DAILY_BACKUP=0 --env CHECK_BACKUP=1 --env STOP_CONTAINERS=0 nextcloud-aio-mastercontainer /daily-backup.sh

The check writes its result to the logs of the nextcloud-aio-borgbackup container. By default AIO keeps backups from the last 7 days, 4 weekly and 6 monthly ones.

Off-site copies. A backup on the same server does not protect you from losing the server. AIO can write directly to a remote Borg repository: leave the local path empty, enter the repository URL, and add the SSH public key that AIO shows after the first attempt to the remote account. Alternatively, copy /mnt/backup/borg to another machine with rsync or rclone outside the backup window; the AIO README explains how to lock the repository during the copy.

Restore on the same server. In the AIO interface, choose a backup from the list and select Restore selected backup.

Restore on a new server. Copy the borg folder to /mnt/backup on the new server, install Docker and create the same compose.yaml, then start only the mastercontainer with docker compose up -d. In the new AIO interface choose the option to restore a former AIO instance from backup, enter the encryption password and the path /mnt/backup, and select the latest backup. AIO generates a new passphrase during this process; save it.

Update Nextcloud AIO

AIO checks for updates daily and notifies administrators. Make a backup first, then:

  1. Open the AIO interface and select Stop containers.
  2. If a mastercontainer update is available, a note with a changelog link appears below the button, followed by a button to update the mastercontainer. Read the changelog and run the update.
  3. Select Start and update containers. AIO pulls the new images, updates Nextcloud and its apps, and starts everything again.

When daily backups are enabled, the interface also offers to update all containers automatically after each successful backup. That is a sensible default, because every automatic update then follows a fresh backup. Keep Docker Engine itself up to date with apt.

Troubleshooting

Domain validation fails

AIO could not reach this instance through your domain. Check that dig +short cloud.example.com returns the server's address, that ports 80 and 443 are not used by another web server (sudo ss -tlnp | grep -E ":80 |:443 "), and that the Cloudflare proxy is switched off for the record. Behind Caddy, check that the site block points to the same port as APACHE_PORT.

The interface says your IP address is internal or reserved

This happens when the domain resolves to a private address from inside the server. AIO's FAQ suggests mapping the domain to the public IP for the mastercontainer: add extra_hosts: with the entry "cloud.example.com:203.0.113.10" to the service in compose.yaml (the equivalent of --add-host in docker run) and run docker compose up -d.

You cannot log in to the AIO interface

Direct login is blocked while Nextcloud runs, and again for a while after five wrong passphrases. Use the indirect login from https://cloud.example.com/settings/admin/overview, or stop the containers first; while they are stopped, direct login is never blocked.

Port 80 or 443 is already in use

Another web server, often Apache, Nginx or Caddy installed on the host, holds the port, and the Apache container cannot start. Find it with sudo ss -tlnp | grep -E ":80 |:443 ". Either stop and disable that service, or switch to the reverse proxy setup described above.

Snap-based Docker installations are not supported

The check in Step 1 found Docker from Snap. Back up the data of any existing containers, remove the Snap package with sudo snap remove docker, install Docker from Docker's repository and start again from Step 2.

Next steps

Frequently asked questions

What is the difference between Nextcloud AIO and a manual Nextcloud install?

AIO is the official Docker-based installation method. One mastercontainer creates and updates the Nextcloud, database, Redis and web server containers for you and adds HTTPS and backups. A manual install gives you full control over Apache, PHP and the database, but you maintain every part yourself.

Where do I find the AIO passphrase?

The AIO interface shows the passphrase once, on your first visit to port 8080. Save it in a password manager. While Nextcloud is running you can also open the AIO interface from the Nextcloud admin overview page while logged in as an administrator.

Can I run Nextcloud AIO behind Caddy or another reverse proxy?

Yes. Start the mastercontainer with APACHE_PORT set to a free port such as 11000 and APACHE_IP_BINDING set to 127.0.0.1, publish only port 8080, and point your reverse proxy at 127.0.0.1:11000. The AIO reverse proxy documentation covers the details.

How much RAM does Nextcloud AIO need?

The AIO interface states at least 2 GB of RAM, a dual-core CPU and 40 GB of system storage when any optional container is enabled, 3 GB with ClamAV, Talk Recording or full-text search, and 5 GB with a quad-core CPU when everything is enabled. AIO recommends at least 1 GB more than the minimum.

Which HyperDC servers can run Nextcloud AIO?

AIO needs Docker Engine on a 64-bit Linux system, so it runs on a HyperDC Linux VPS, VDS or dedicated server with root access. Size the RAM for the optional containers you plan to enable and the disk for your files.

Sources

ایجاد گذرواژه

Please confirm