From e2b3723dd9ed7994edbf2f01d09967d296e75d04 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 13:47:03 +0200 Subject: [PATCH] nextcloud: fix hardcoded sidecar port and missing docker CLI in runtime image - MESH_NEXTCLOUD_URL hardcoded :80 instead of the mesh-assigned ${port:80} - sidecar's occ() shells to docker exec but the docker CLI binary was never present in the runtime image, only the mounted socket --- modules/nextcloud/Dockerfile | 5 +++++ modules/nextcloud/module.json | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/modules/nextcloud/Dockerfile b/modules/nextcloud/Dockerfile index 5a6e5a8..0d4460e 100644 --- a/modules/nextcloud/Dockerfile +++ b/modules/nextcloud/Dockerfile @@ -22,6 +22,11 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts FROM ${RUNTIME_BASE} COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist +# occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs +# the docker CLI itself present here, not only the socket. Copied from Docker's own official client +# image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no +# systemd unit, no package manager tree pulled in for it). +COPY --from=docker:cli /usr/local/bin/docker /usr/local/bin/docker # Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a # provider's provisioner runs its reconcile loop in the same process, with the broker connected — # the convention novox/hq issues 060/061 settled. A container that instead ran only its diff --git a/modules/nextcloud/module.json b/modules/nextcloud/module.json index 7c8103b..a2e7da9 100644 --- a/modules/nextcloud/module.json +++ b/modules/nextcloud/module.json @@ -111,7 +111,7 @@ ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_NEXTCLOUD_URL": "http://127.0.0.1:80", + "MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}", "MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json", "MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "/run/secrets/admin" },