---- Welcome ---- This is a full-stack Nextcloud deployment combined with hardening, a Collabora CODE server for in-browser document editing, and a Nextcloud Talk High-Performance Backend (HPB) for group calls. The minimum setup of this deployment would be a single server (this context wasn't tested yet). The optimal setup uses one server per role: - Nextcloud (Apache + PHP + MariaDB) - Collabora CODE (document editing backend) - Nextcloud Talk HPB (NATS + Janus Gateway + signaling server, via Docker) The current playbook stack is made for a theoretical infinite amount of Nextcloud instance setups (not load balanced or anything in that direction) and a single server each for Collabora CODE and the Talk HPB. Currently this setup assumes that every server is Ubuntu 24.04 server. This can be changed but hasn't been tested yet and requires some tinkering (e.g. in the deploy_collabora_code.yml file for the APT sources). ---- Directory structure ---- /nextcloud_full_deployment | - README.txt (this file) | - deploy_hardened_nextcloud.yml | - deploy_collabora_code.yml | - connect_nextcloud_collabora.yml | - deploy_nc_talk_hpb.yml | - connect_nextcloud_open-xchange.yml | - /inventory | - hosts.ini.example | - /vars | - shared_vars.yml.example ---- Requirements ---- On the Ansible control node: - Ansible collections: community.general, community.mysql, community.docker On every managed host: - Ubuntu 24.04 server (see note above about other versions) - User with sudo rights, reachable over SSH ---- Quickstart ---- First of all specify your hosts in the inventory folder. Copy the hosts.ini.example in the same directory to hosts.ini and edit that file. Please also add the username and password as host vars in the inventory file. /nextcloud_full_deployment | - /inventory | - hosts.ini | - hosts.ini.example The inventory has one host group per role: [nextcloud], [collabora_code] and [nextcloud_talk_hpb]. A single host can be a member of more than one group if you want to co-locate roles on one server. After that is done, copy vars/shared_vars.yml.example to vars/shared_vars.yml and go change all the variables in it according to your needs. Every secret in that file (database password, admin password, Collabora admin password, Talk HPB signaling/TURN/hash/block secrets) ships with a "ChangeMe..." placeholder - replace all of them before deploying. /nextcloud_full_deployment | - vars | - shared_vars.yml | - shared_vars.yml.example When you are done preparing your deployment, you can start it. Run the playbooks against hosts in this order, since each one depends on the previous: 1. Nextcloud itself (Apache, PHP, MariaDB, TLS, hardening, fail2ban): ansible-playbook deploy_hardened_nextcloud.yml -i inventory/hosts.ini --ask-become-pass 2. Collabora CODE (document editing backend): ansible-playbook deploy_collabora_code.yml -i inventory/hosts.ini --ask-become-pass 3. Connect Collabora CODE to your Nextcloud instance(s): ansible-playbook connect_nextcloud_collabora.yml -i inventory/hosts.ini --ask-become-pass 4. Nextcloud Talk High-Performance Backend (NATS + Janus + signaling server, via Docker): ansible-playbook deploy_nc_talk_hpb.yml -i inventory/hosts.ini --ask-become-pass This playbook only sets up the backend itself. Nextcloud does not pick it up automatically - finish the connection by hand on each Nextcloud instance under Administration -> Talk -> High-performance backend: Signaling server URL: https:///standalone-signaling Shared secret: nc_talk_hpb_signaling_secret (from shared_vars.yml) TURN server: :3478, protocols UDP and TCP TURN secret: nc_talk_hpb_turn_secret (from shared_vars.yml) You can debug all the playbooks by using this command. ansible-playbook -i inventory/hosts.ini --ask-become-pass -vv # This file was written by Ebbe Baß (umpi) - ebbe@ping-mee.de