# Nextcloud

> Install Nextcloud from the App Store, create the admin account behind the setup lock, set up cron, email and clients, and back up and update your own cloud drive.

Source: https://zopanel.net/docs/app-nextcloud  
Updated: 2026-10-09

Nextcloud is a self-hosted cloud drive: file sync and sharing with desktop and mobile apps, plus calendar, contacts, notes and many optional apps. The App Store version runs the official Nextcloud image with SQLite, which suits one person, a family or a small team. Choose it to move files off Google Drive or Dropbox and keep them on your own server.

## Requirements

| Item | Value |
| --- | --- |
| Image | `nextcloud:35-apache` (Nextcloud 35, Apache) |
| Memory limit | 1024 MB, 1 CPU |
| Free disk to install | About 3.3 GB on the Docker disk (the image plus 1 GB kept free for the server), plus room for your files |
| Database | SQLite, created by the installer |
| Upload limit | 2 GB per request inside the container (`PHP_UPLOAD_LIMIT`); nginx in front accepts the website's **Upload size**, set to 10 GB (10240 MB) at install |

Files are stored on the server's disk under `/var/lib/zopanel-apps`, not in the hosting account, so they do **not** count toward the account's disk quota. Administrators should watch the server's free disk space. The website counts toward the account's website limit; customers need a package with **Docker apps** and 1024 MB of **RAM (MB)** free.

**Note:** Nextcloud recommends MySQL/MariaDB or PostgreSQL for larger installations. Containers cannot reach the server's own database servers (see [Network limits](#network-limits)), so plan a dedicated setup if a whole company will sync many files.

## Install Nextcloud

1. Point the domain's A record (for example `cloud.example.com`) to the server.
2. Open **App Store** and click **Install** on the **Nextcloud** card. Customers find **App Store** in their menu; the card at the top shows the app and memory quota of the package.
3. Fill in the fields and click **Install**. The image download takes a few minutes the first time.

| Field | What to enter |
| --- | --- |
| **Domain** | The domain or subdomain for Nextcloud, without `http://`. |
| **Owner** | Administrators only: the hosting account that owns the app. |
| **Free SSL (Let's Encrypt)** | Leave on. |

ZoPanel sets these container variables for you:

| Variable | Value | Why |
| --- | --- | --- |
| `NEXTCLOUD_TRUSTED_DOMAINS` | your domain | Nextcloud only answers on trusted domains. |
| `OVERWRITEPROTOCOL` | `https` | Nextcloud is behind nginx with SSL and builds `https://` links. |
| `TRUSTED_PROXIES` | `172.16.0.0/12` | Nextcloud trusts the Docker bridge and logs the real visitor IP. |
| `PHP_UPLOAD_LIMIT` | `2G` | Larger uploads than the image default (512 MB). |

ZoPanel also sets the website's upload size to 10 GB (the website's **Tools** tab → **Upload size** card, field **Maximum upload (MB)**). A Nextcloud installed with an older ZoPanel version keeps the former 256 MB until you raise it there.

**Important:** Because Nextcloud always builds `https://` links, wait until the certificate is issued (**SSL** tab) before you open the app. On plain `http://` the login page redirects to an address that does not work yet.

## Run the installer behind the setup lock

Nextcloud's installer creates the administrator, so whoever opens it first would own the server. ZoPanel locks the app until you finish.

1. On the **Docker** tab, click **Open the app (only for me)**. Your browser gets a setup cookie (valid 30 days) and opens Nextcloud.
2. In the installer, enter an **administration account name** and **password**. Use a strong password: this account can see every user's settings.
3. Leave the data folder (`/var/www/html/data`) and the database (SQLite) as they are. Nextcloud shows a warning that SQLite is meant for small installations; this is expected.
4. Click **Install**. Installation takes up to a minute.
5. Nextcloud offers recommended apps (calendar, contacts, mail, Talk and others). Install them or skip; you can add apps later from the **Apps** page.
6. Back on the **Docker** tab, click **Setup finished — open to everyone**.

Until step 6, other browsers see "This app is being set up" and the desktop and mobile apps cannot connect.

## Essential settings

Run Nextcloud's command-line tool `occ` as root on the server. The container is named `zp-app-<instance>`, where `<instance>` is the domain with dots replaced by hyphens (`cloud.example.com` becomes `cloud-example-com`):

```bash
docker exec -u www-data zp-app-cloud-example-com php occ status
```

### Background jobs (cron)

Nextcloud starts in **AJAX** mode, which runs jobs only while someone has a page open. Use system cron instead, from root's crontab on the server:

```bash
crontab -e
```

Add this line:

```cron
*/5 * * * * docker exec -u www-data zp-app-cloud-example-com php -f /var/www/html/cron.php
```

Then switch Nextcloud to cron mode:

```bash
docker exec -u www-data zp-app-cloud-example-com php occ background:cron
```

The container keeps its name when you update it, so the cron line keeps working.

### Warnings on the overview page

**Administration settings → Overview** lists security and setup warnings. The usual ones on a new install:

```bash
# Default country for phone numbers (VN, US, DE…)
docker exec -u www-data zp-app-cloud-example-com php occ config:system:set default_phone_region --value="VN"
# Start of the 4-hour window for heavy maintenance jobs, in UTC (1 = 01:00–05:00 UTC; 18 = 01:00–05:00 in Vietnam)
docker exec -u www-data zp-app-cloud-example-com php occ config:system:set maintenance_window_start --type=integer --value=1
# Add database indices after updates
docker exec -u www-data zp-app-cloud-example-com php occ db:add-missing-indices
```

Warnings about SQLite and a missing Redis cache are expected with this setup.

### Email

Nextcloud sends password resets, share notifications and activity emails. In **Administration settings → Basic settings → Email server**, choose SMTP and enter your mail server: for a mailbox on this server, use the mail server's host name, port `587` with STARTTLS (or `465` with SSL/TLS), and the mailbox address and password. Click **Send email** to test; the administrator account needs an email address in its personal settings first.

### Desktop and mobile apps

Install the Nextcloud desktop app or the iOS/Android app, enter `https://<domain>` as the server address and sign in. Calendars and contacts sync over CalDAV and CardDAV to the same address.

### Another domain

To make Nextcloud answer on a second domain (added as an alias of the website), add it to the trusted domains:

```bash
docker exec -u www-data zp-app-cloud-example-com php occ config:system:set trusted_domains 1 --value=files.example.org
```

## Data and backups

| What | Where on the server |
| --- | --- |
| Entire Nextcloud folder: code, `config/config.php`, apps, user files (`data/`) and the SQLite database (`data/<name>.db`) | `/var/lib/zopanel-apps/<instance>/html/` (mounted at `/var/www/html`) |
| Environment file (root only) | `/var/lib/zopanel-apps/<instance>/.env` |

**ZoPanel's account backups do not include this folder.** Full account backups and incremental snapshots cover the account's website folders under `/home`, databases and mail. Nextcloud's files and database are in `/var/lib/zopanel-apps`, outside the account, and are backed up by the **Backups** card on the website's **Docker** tab instead. The configuration backup (`.zpb`) restores only the app's entry in the panel.

Click **Back up now** on the **Backups** card. Administrators can also set a **Schedule** (**Off**, **Every day** or **Every week**; off by default) and how many copies to **Keep** (1–60, default 7), then click **Save**. Each backup archives the whole `/var/lib/zopanel-apps/<instance>/` folder (files, database and `.env`) into `/var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz`, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) during the copy, so the copy is consistent; a large drive takes longer to archive and needs as much free disk again. Older copies beyond **Keep** are removed, and a failed scheduled backup sends administrators the **Backup failed** alert.

To restore, an administrator clicks **Restore** next to a backup. Nextcloud is stopped and its folder replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too. Customers can click **Back up now** and see the list; the schedule and restores are done by the provider. Customers can also keep a copy of important files with the desktop app.

The archives stay on the same server: copy important ones off it (for example with `scp` or `rclone` from `/var/backups/zopanel-apps/<instance>/`) and store them encrypted, since they contain your files and Nextcloud's secrets. For very large drives, copying the folder with `rsync -aH --numeric-ids` to another machine, or a restic job on it, remains an option.

To restore on another server, install Nextcloud on the same domain there, copy the archive into `/var/backups/zopanel-apps/<instance>/` on the new server and click **Restore** on its **Backups** card. This only works when both servers use the same `dockremap` range for Docker's user namespaces (compare `grep dockremap /etc/subuid`).

## Update Nextcloud

Administrators click **Update to latest** on the **Docker** tab. ZoPanel pulls `nextcloud:35-apache` again and recreates the container; the folder is kept. When the image is newer than the installed version, the image upgrades Nextcloud by itself on start (watch **Application output**). Then run `occ db:add-missing-indices` again.

- Updates stay within the 35 line. A newer major version arrives when a ZoPanel update moves the catalog to it. Nextcloud can only go up one major version at a time.
- Make a backup (**Back up now**) before every update.
- Update Nextcloud apps from the **Apps** page in Nextcloud.

Customers do not see **Update to latest**; ask your provider.

## Network limits

App containers are cut off from the server's internal network. For Nextcloud this means:

- **No local database or Redis.** The server's MySQL/MariaDB, PostgreSQL and Redis cannot be reached, so Nextcloud uses SQLite and its built-in cache.
- **External storage** (SMB, SFTP, FTP, WebDAV, S3) works only with public addresses. Shares on a private network (`192.168.x`, `10.x`) and SFTP to this same server are refused. A ZoPanel S3 bucket works when S3 storage is published on a domain (HTTPS on port 443).
- **Mail works** to this server on ports 25, 465 and 587, and to any mail provider on the internet.
- The Nextcloud app store, federation and link previews reach public addresses normally.

## Troubleshooting

| Symptom or message | What to do |
| --- | --- |
| Desktop or phone app cannot connect; a browser shows "This app is being set up" | The setup lock is still on. Click **Setup finished — open to everyone** on the **Docker** tab. |
| "Access through untrusted domain" | You opened Nextcloud on an address that is not trusted. Use the installed domain, or add the other one with `occ config:system:set trusted_domains`. |
| Login loops or redirects to a broken `https://` page | SSL is not issued yet. Issue it on the **SSL** tab and reload. |
| Upload fails with **413 Request Entity Too Large** | The request is larger than the website's **Upload size** (10 GB for new installs, 256 MB for Nextcloud installed with older ZoPanel versions). Raise **Maximum upload (MB)** on the website's **Tools** tab → **Upload size** (up to 10240 MB). Alternatively upload in smaller chunks: the web interface uploads in chunks; for the desktop app, set a smaller chunk in `nextcloud.cfg`, section `[General]`: `maxChunkSize=100000000`, then restart the app. |
| Some files never sync and the server answers **403** | ZoPanel's nginx refuses file names that are usually leaked secrets: names starting with a dot (except `.well-known`), files ending in `.sql`, `.env`, `.log`, `.ini`, `.sh`, `.bak`, `.old`, `.orig`, `.swp`, `.dump`, `.sql.gz`, `.sql.zip`, and `backup…`/`backups…` archives (`.zip`, `.tar`, `.tar.gz`, `.tgz`, `.gz`). Rename those files or keep them in an archive with another name. |
| Requests fail with **429** during a big first sync | nginx limits each IP to 50 requests per second with bursts. Let the client retry, or sync in smaller batches. |
| Requests blocked while the web application firewall is on | WebDAV requests can trigger OWASP rules. Set the website's firewall to **Detect only (log)**, check the events and use **Allow this** on the rules that hit Nextcloud. |
| "This website is very busy right now" | Nextcloud is starting, upgrading or using all its memory. Wait; if it persists, check **Application output** and consider a larger memory budget. |
| "not enough disk space: this app needs about 3.3 GB free…" | Free disk space on the server before installing. |

## Related

- [App Store and S3 storage](/docs/apps)
- [What each app does](/docs/app-catalog)
- [Website tools](/docs/website-tools)
- [Backups](/docs/backups)
- [Nextcloud Administration Manual](https://docs.nextcloud.com/server/latest/admin_manual/)
- [Official Nextcloud Docker image](https://github.com/nextcloud/docker)
