Roundcube open-source webmail software merges with Nextcloud
phoronix.com
phoronix.com
My biggest gripe with it is the increasing schizophrenia of the UX devs. One thing I _loved_ about Nextcloud was that they paid a lot of attention to making it easy to navigate and use. The newer UX "enhancements" seem to be all about maximizing (useless) whitespace and making every widget as spherical as possible. The calendar UI used to be a joy to use, now it's the most frustrating calendar I have ever seen.
On the plus side, if you're using the docker image, upgrades are a breeze. Just bump the tag on the image, redeploy, and you're done. (It did take a _lot_ of effort to migrating my existing data to the docker container, though.)
I also use Roundcube as my main email client. I've looked at bunches of them, but Roundcube is the closest thing to a web-based Thunderbird that I have seen. Unfortunately, this had a UI "update" too and now practically nothing can be customized the way I prefer. If someone forks Roundcube and brings back the old theme, I will switch to it tomorrow.
Problem with free and open source software is that you have to follow the passion of the devs, which can sometimes optimize out of usefulness.
Because of this, I think this is very bad news for roundcube.
My home service has to deal with some huge users (wife, phone, camera) (dad, constant saving, vast numbers of docs).
Work instance - all of the above!
I very rarely deal with the web UI but when I do it simply works or when I look into /pictures etc: locks up but that is generally the browser giving up and not the app.
I migrated a post office with several domains from RC to Snappy Mail. RC seemed to have stalled a few years back. SM is rather nifty so I'll stick.
Roundcube has been languishing a bit since the failed Roundcube-next fiasco. You can criticize the Nextcloud group for many things but at least they have proven to be consistent with pushing forward their open source projects.
> tangled and ugly mess of a UI
Maybe I'm an odd one but I have no issues with the UI. It's clean yet more info dense than many other commercial offerings.
> It is slow
I have mine working better than any google property. Nextcloud relies heavily on a performant database setup, so moving that to a separate NVME drive was one of the greatest improvements I ever made. That and properly handling image preview generation.
> Problem with free and open source software is that you have to follow the passion of the devs
Nextcloud is produced by a commercial entity, they are not a passion project. They target large installations and so tend to focus on that use-case. This makes tuning the stack to a small deployment a little bit of work.
Maybe this has been improved, but I remember thinking that and then it biting me because updating to the latest image (linuxserver/nextcloud) wasn't actually updating nextcloud itself, just the environment (php, etc.)
When I realized this, I had to go through several major nextcloud upgrades, incrementally going from one major version to the next.
Then it bit me again a few months later where nextcloud updated their maximum supported php version, and the docker image I was on quickly bumped the bundled php version to the new maximum, so the older version of nextcloud suddenly refused to start - even to run the updater. I ended up finding the max version check in nextcloud's php code and commenting it out, after that I was able to run the nextcloud update manually.
After being bit twice, I finally automated the full process so that the nextcloud software is updated in addition to the environment.
It may feel convenient if someone did homelab without docker, but will bite you in the long run.
The trick was to isolate the weirdness in the wgconf files, the permissions of the containers, and their shared netns (a nomad group, in this case, with its netns configs tweaked by a startup script). The Dockerfile is simply FROM linuxserver/wireguard:latest.
(It's wrapped in a Dockerfile so its rebuilds are limited to when we rebuild our images (every commit), but AFAIU the linuxservers setup, it can also pull in wireguard updates at runtime.)
Try to understand what actually happens on container startup and you're stuck in three layers of base images that they use as framework, with hooks on each layer.
Wanna inherit some image and eg. copy something into config dir? Nope. Config dir is overwritten by symlink, by script on some layer. Actual config dir is moved somewhere to fit their internal convention.
Their framework allows them to quickly add new applications and keep them updated. But it's pain to work with.
I guess if you're willing to learn it and you're 100% sure, you're not going to modify image or configure application beyond of what they exposed - you might be okay using it. Otherwise just get official image.
But they make a lot of decisions that are not "best practices" in Docker - such as running multiple processes per container, under a supervisor.
IMO, they are great for single-machine home deployments.
The "major versions incremental upgrades" is a fundamental nextcloud thing, to do with their database migrations I expect. I was way behind and had to do three of them in a row when I containerized my Nextcloud instance, but they all worked fine, thankfully.
sudo -u abc php /data/www/nextcloud/updater/updater.phar --no-interaction
Although, it looks like I need to add this also: occ db:add-missing-indices
And, I thought I had it in my crontab, but now I don't see the job there. I haven't touched it in months, and I'm on the latest version of nextcloud, so presumably it's still working. But I honestly can't remember how I set it up.If so that feels a bit like an anti-pattern, just like the WordPress container which updates the WP files inside the container itself, the container just contains the webserver, php and database.
?? The old skins (Classic and Larry) are still available as plugins via PHP composer, aren't they?
Edit: nope, fork of Rainloop
I'm running on "bare metal" Digital Ocean VPS (like god intended), and I just use the web-based updater and it works well. APT on Debian handles everything else.
upgrades are a breeze even without docker... the self updating function of nextcloud works very well.
Then that's a new development. I've been using it since about v9 and it was a complete trainwreck that might have had a 25% success rate until I gave it up and moved to the docker around v17.
my non-docker install has been going strong for 3-4 years now, so that's hardly what I call recent...
My instance is dead now, after I failed to recover it the last time and couldn’t be bothered anymore.
YMMV, but I’m out.
I had issues with upgrading a few times on a modest VPS, when trying to upgrade via the web interface. I've since switched to upgrading via ssh by running the `updater.phar` script[0] and haven't experienced an issue upgrading since.
I of course don't know if this would've avoided the issues you experienced, @josteink, but I wanted to mention it in case others have a similar problem to what I had.
[0] https://docs.nextcloud.com/server/latest/admin_manual/mainte...
I used the Alpine packages to upgrade it, then afterwards I used the Nextcloud admin scripts to migrate the schema, apps & plugins.
Biggest clusterfuck I’ve ever dealt with. Not doing that again.
TBF the Alpine-setup probably made everything worse, and that’s a lesson learned, but I’m just fed up and can’t bother setting up a new instance now.
I have used Firefox my entire life and sometime back they added really stupid whitespace between the address bar on both ends. Every single time I reinstall the browser on a new OS I see it and remove the whitespace. It drives me up a wall. It looks so gimmicky and like a complete waste of a UI that didnt need to be changed.
Sometimes the best UI decision is to leave things as-is, especially if your UI has been plenty standard.
> [ their useless UX designers ruined it ]
Why do you have to wait for someone to fork it? Can’t you just not update to the bad version? I thought that was a major appeal of hosting your own email client like this.
And given the email protocols won’t ever change, I would assume it’ll continue working the same for a decade or more.
(My only guess is a security worry, but this seems like a rather niche thing that something this niche would be unlikely to be attacked unless I were targeted by some state-level actor)
In theory, the portions that are only accessible with authentication are less security sensitive if you have only a small set of trusted users, but that's still reducing the security of your server to the security of your least security-aware user.
Clearly I overassumed though, because you're right, when it could be that one would have such a thing accessible to a small team of people who don't use a VPN.
As much as people rag on Snap, Nextcloud being available on it is also super convenient if one doesn't feel like using Docker.
I kept upgrading the server because I thought the abysmal performance was a backend bottleneck. But no, if I turn on profiling in my browser, I can see it taking geologic ages to do... Whatever it's doing. The server is mostly idle just waiting for the browser to respond.
It's almost impressive how bad it is.
Or you could just run Watchtower beside it and it will automatically update your docker containers. https://github.com/containrrr/watchtower If you are OK with automated updates.
If we were talking about a video game, or some kind of testing/QA environment, then sure, automatic unattended upgrades would be fine.
Close the app to avoid disruptions
I've had problems that required fiddly manual interventions twice after updating to a new major version.
And what keeps me from using it for anything other than File synching is the lack of a functioning integrated backup mechanism. There is a plugin, but it's unusable shite (tries to keep the entire data in memory, big has been open for years), and I really don't want to depend on a self-made combination of Filesystem and DB backup.
So my Nextcloud backup solution is a cron job that shuts the entire container down and runs a restic job on it, then brings it back up when the backup is complete.
I'm not completely sure that's quite "self-made"; restic is standard enough. The only special sauce is just that I don't even bother with how to handle files that are open, especially with the database. I just shut it all down.
The nice thing is this works with all my docker stuff; the cron job just iterates them one at a time, shutting them down and doing the same standard backup on them all, then bringing them up. I don't need or want a Nextcloud-specific backup mechanism.
Interesting that you comment about SQLite being a problem. I am not a heavy user of Nextcloud, but I haven't had the operational problems many people report here; I wonder if that's correlated to using SQLite.
Since I'm using the same setup (docker compose for nextcloud, MariaDB, and some other stuff), maybe I should really look into that option, thank you!
Or you could just use some external storage. Like SMB or something. And then you would learn what updates aren't 'a breeze'. And there is no built-in SMB support in the default container.
Since I'm running it since OwnCloud days too, I have an opinion on it and it's Not. Good.
Desktop client for Windows is miserable and sucks:
a) you have something with a name longer than 30 symbols? You know need to guess what the full path of that file in the error log
b) this is like 4th year when you have an option to see the errors in a separate window, except it's... empty. Not an empty error log, it' empty window
c) Oh, best part: if the client decided to update it would kill your Explorer first (like -9), install the it's shit and then... force reboot your machine without any questions
d) when you click on the client icon in the notification area it shows multiple icons what you would thing would do something. Except it's just opens the web-interface of the instance
For years mobile client couldn't work properly with a self-signed certs, which is quite ludicrous for a solution boasted as the pinnacle of self-hosting.
UI overall is shit, it's a legacy of early 2010 concepts with Googlisation on every not needed aspect. And just outright stupid ideas, which 2.5 developers at NextCloud couldn't test, like littering EVERY (sorry for caps) folder you navigate through the web interface with README.md. And shitting bricks on non case sensitive mounts, because yes, it's hard.
Server side is always running to pump out new versions, while abandoning and deprecating addons. Oh, addon you are using is now deprecated, besides being made a mere year ago? Tough luck. Stay on the supported NC version. Except it's not supported anymore because it's a year old now version.
Oh, since 2016 it's no longer a file syncing solution, it's collaboration software or even groupware. That means there are now office suite, chat, contact lists and whatever else, including an email client. This also explains why did NC 'bought' RC. Except all those parts are not integrated good.
And finally it's a PHP app with a tons of legacy code. As soon as something breaks you are drowning in multiple screen heights of errors of PHP code. And consequently all performance troubles are solved by throwing RAM and CPU at the instance.
/rant
Finally? That's a security nightmare right there.
Or do you just mean because of the crazy dependencies in a typical node project?
Roundcube is on a whole other level in terms of stability and robustness compared to Nextcloud.
I'm also glad that the current Nextcloud client will be replaced, because it's not very good right now.
no company in the world is going to maintain 2 separate software products that compete with each other. They will be merged, my prediction is 12 to 18 mos
7.0 had some issues so bad it's almost impossible to find anymore. Seems like they tried to erase it from the internet. The language itself is an attack vector.
OT: please (re)read the HN Guidelines. https://news.ycombinator.com/newsguidelines.html
You said "i'm happy running it on my ...vps."
And now "Then I wouldn't use Roundcube either." So you're not running roundcube then?
Also, love how you said you loved roundcube because it works on "lightweight el cheapo VPS", and then backtracked once you found out it uses PHP.
Both start with coll/cooll, I've got to increase my zoom apparently.
"Neither will Roundcube replace Nextcloud Mail or the other way around. ... Nextcloud Mail will evolve as it is, focused on being used naturally within Nextcloud."
We just swapped out our old webmail system (made from twigs, mud and spit) for a nice and elegant Roundcube install with custom plugins and I was already dreading having to change it.
Some bugs I encountered in a few hours of testing and trying to make it work.
The Mac auto-update installs an incompatible version to my OS; the website offers only the new incompatible and an old version that also doesn’t work (OS can not scan the app). The solution is to find a suitable version from a hidden FTP, user-unfriendly.
Some files had modification timestamps on 1.1.1970 that causes obscure sync issues on Mac. Either run some arbitrary database scripts to fix this or a simpler solution is to ‘touch’ all affected files.
The Windows Client consistently shows random minus bytes, hangs, and freezes.
The Windows Client is stuck in a loop of calculations and transmissions. Also a reinstallation is impossible as AppData folder isn’t deleted during uninstallation.
A successful complete reinstall downloads all the existing files individually, creating conflicts with identical(!?) local and server files. Why is the file hash not checked before the download? It’s frustrating and seems poorly designed.
All bugs have open GitHub issues I didn’t bother to include. Some have open PRs for years. The last bug is open for 5 years now.
That's pretty cool.
The only thing I'd really want for Syncthing is some kind of simple interface for my desktops (all running SwayWM.) There's a GTK app that I use on my Pinephone, but it's a little janky. I mainly just want to be able to know that I'll get notifications when there's a conflict or error. (Dropbox style file emblems in file explorers, showing the state, would be nice, too...)
My wife and I had such a setup for years with Resilio Sync. But life is busy enough to maintain yet another thing, so we are happy to fork over the monthly fee for Dropbox Family.
Ideally I'd switch over to some other sync solution, because Dropbox is somewhat overpriced. But we've had bad experiences with Google Drive and OneDrive for local sync in the past.
But that's the thing. Especially notable compared to NextCloud, Syncthing is not like most "self-hosted" software. Because a node is a node is a node, and because it's relatively lightweight, it literally doesn't matter what you use. You can use a Raspberry Pi, an old phone or laptop, anything you can connect sufficient disk and a network to can be a Syncthing node. And if it catches on fire, it doesn't really matter since every node is equal. You can just add another node at any time.
So a lot of people think Syncthing is another thing you'll have to worry about and maintain, but it's not. It's one of the few pieces of software that I expected to have to deal with a lot of extra work to use, but then it wound up being dramatically easier and more flexible than I expected. I worry about robustness when it comes to something as complex as cross filesystem syncing, but Syncthing has never lost my data. I have backups turned on on most nodes for the important folders, but I've never consulted them before, because I've never needed to.
Surely it is possible to lose data with Syncthing, or otherwise create a headache. However, from my point of view, it certainly seems to be among the most reliable and lowest effort ways to sync stuff across devices. I haven't had to spend almost any time maintaining Syncthing, and I don't have to worry about limits. I just need one device with a big enough disk, then I can create however many shared folders are needed to get the granularity I want.
Syncthing also has a pretty cool encryption feature. It is considered "beta" still, so I only use it in "trusted" scenarios, but it works great.
When I started using Syncthing, I only intended to share some document files between my desktop and my laptop. Now I use it to sync my Keepass database, files between some servers (think seedbox etc.,) multiple different documents folders including some for collaborative projects, and even a couple of other things. So it really wound up over-delivering for me.
I'd strongly recommend people, even people who already feel like Resilio Sync wasn't a good fit, to just try to set up Syncthing before resigning to Dropbox. Comparatively, I think Syncthing is simpler to use and more robust than basically any other solution that isn't Dropbox.
It works well enough in a backup system, where the issue explained on the page isn't relevant.
I'm saying that you can disregard the warning in the case of a backup system (as opposed to the normal use which is full sync between two devices that both modify files).
Linux has davfs2, android has foldersync.
Apache2 is super streamlined for this, and has done dav stuff for at least 16 years.
And apache2 is a very well established implementation of it.
Clients handle partial snags.
I wouldn't rely upon anything that syncs like this, without backups. Any protocol at all.
Of course, the same may be said for anything at all. Backups are king.
Almost after every shoot, people come back "remember that one photo, where I smiled at sth? I'm very sentimental about that, cause it's [some important thing to them]", which necessitates the need to hold on to every photo taken on the session. So no real deletes here, even if it came out technically wrong (blurry, blown out, etc.).
Those requests lessen, but don't die down completely. Especially with cyclic events, organizers have this habit of a asking for things done exactly year ago.
Some just say: "hey, I remember you taking a photo of me then and then" for their dancing portfolio in my case.
Especially for videos, which can be a constant flow of editing requests, for supercuts and etc.
Now, if I were really smart, I'd just have some good way to archive after two years, and delete after - let's say three years. In practice though, there are so many unforseen circumstances that a habit of "never delete anything" forms really easily.
It's just a lot easier and cheaper to buy another drive instead of culling 10k of photos every once in a while, especially if external confirmation is involved.
Despite constantly crowing at researchers in my past life that they will lose all their data ... it only happened once or twice, and both times was related to theft and not drive failure.
I wonder if you could sell a type of "archive protection plan" as an add-on to your work. It's like $70 a year to store 500GB on Glacier. I am sort of assuming each shoot is 500GB? You could guarantee access for those customers who want it.
If we're being honest with each other, I would do the exact thing you're doing and focus more on my business. :)
[0] https://aws.amazon.com/s3/glacier/pricing/#Retrieval_request... <- under "Bulk"
I guess I could reinterpret your original comment as "Have fun paying a fortune if you need to get those files [out of AWS] again."
instead of my original interpretation "Have fun paying a fortune if you need to get those files [out of Glacier] again."
Agree!
I was able to recover a 13 year old photo I took with a D70s which was extremely noisy. By using what I learnt and state of the art software (which is Darktable), I was able to extract a very nice photo out of it.
Also, as your style improves and experience piles up, you look to your "bad" photos and say "Aha, there's a nice angle here. Let's process this".
You can see some of my "Remastered" photos at [0].
[0]: https://www.flickr.com/photos/zerocoder/albums/7215770242956...
https://www.dxo.com/fr/technology/deepprime/
I have a license for some older version, if you want to throw a .nef at me
Contributors send in calibrated RAW files per camera, taken at every ISO setting possible, so Darktable denoises your file according to your camera's profile at particular ISO. The result is pretty impressive.
I have uploaded that particular image to [0]. Taken in 2006 and processed in 2020, after 14 years!
[0]: https://www.flickr.com/photos/zerocoder/53363865806/in/datep...
Edit: EXIF says 2005, but it should be 2006.
I have been using Maestral for Dropbox sync on Mac for years now and it works great. The primary downside is that it doesn't have block-level sync because it's not supported by the API. The flip side is that you don't get the memory-hungry Dropbox app that embeds a web engine for some unfathomable reason.
I wish that Dropbox would bring back their old client that just did sync and not all the crap that I don't need.
Just a month ago there was news of a RoundCube XSS zero-day that was widely exploited (https://cyberpedia.medium.com/state-sponsored-cyberattacks-l...).
Don’t use RoundCube!
All software has vulnerabilities. The trick is to install it in a way which mitigates most of the typical ones: use VMs, SELINUX/APPARMOR, containers, chroots, user separations, etc.
Everything you mentioned is about protecting things the app should not have access to. Many vulnerabilities are about intent (did the admin user really mean to truncate the db they have permission to truncate) or target (did the user really mean to export all my emails in an archive to h4x0r@yahoo.com).
If you at all store any sensitive data within the application either serverside or clientside you need to consider the security of the application itself, not just the sandboxing/isolation.
It's more of "outsource to someone else" than "who won't fuck it up".
Edit: Yep that's the official position as per this post on the roundcube github https://github.com/roundcube/roundcubemail/issues/6030#issue...
Nextcloud is the OSS equivalent of IBM and ticking boxes so it's easy for management to pull the trigger but every feature is just a half-assed buggy implementation. Gobbling up OSS funds and fucking up government projects that try to rely on it. It's a disgrace.
With regards to box ticking, that is probably something you need to do if you want to compete with Gsuite and O365. Both have sales teams which are influencing some decision makers in organisations wherever they can. If you give these people the opportunity to say ‘Ha, we can’t use Nextcloud because it does not support XYZ’ then they will. You never get fired because you bought IBM. It is very difficult to get through this barrier. Sometimes you need to put a bit of lipstick on your pig, because others did it as well.
Plus, XYZ might be implemented half-aresed in Gsuite or O365 as well.
The largest has several tens of millions of users and they are using Global Scale. One customer runs nearly 4 million users on a single cluster.
Nextcloud is a complicated beast, and scaling to tens of thousands of users isn't trivial, but then that is what Nextcloud Enterprise is for. So if you need a large scale installation, no problem - contact our team and we get you up and running.
Finally there are very few orgs worldwide even with a few hundred k employees and any firm would get huge Microsoft discounts at that scale for products like SharePoint (on prem), Exchange (on prem) and Office Server (on prem also)... and oodles of support over a very mature product which Nextcloud is simply not.
Edit: Just so you know we are still a customer of yours with over 3k users but not for long anymore. We tried to work with you for over 4 years now and got absolutely nothing. Neither performance nor features.
Too bad "beta quality everywhere" attitude never gets fixed. Basic stuff like weird upload indicator on the web, desktop app freezing when synching some 10GB or so and I don't even want to touch most of the third party plugins which are at alpha quality.
It's like a selfish girl that you need to treat carefully or it starts crying real fast.
I'd like to see Nextcloud adopt Roundcube's commitment to reliable software. I've tried migrating my calendars, reminders and contacts several times, but it's never worked reliably. There were often subtle problems such as missing calendar entries that simply disappeared without a trace.
[0] https://en.wikipedia.org/wiki/Roundcube#Project_.22Roundcube...
Never expose any logs to strangers for anything anywhere
If I could find time to be better at self hosting and will be able to take care of a server's upkeep, security/OS/package patches/updates et cetera then if I have to setup two first tools on this it would be Syncthing and RClone.
On the other hand for my current needs I use filen.io (it's on BF sale right now). It's not the best but works fine for my use - like a remote hard disk acting like backup (its "local backup" sync mode).
- the core feature, file sync, has extremely unreliable clients that can't resolve even the simplest of conflicts reliably while sucking up 8 CPU cores to do... nothing, really
- all the ~ecosystem~ of plugins they decided to staple onto it because file sync doesn't make them money, are all low quality compared to dedicated solutions, and synergy between them isn't great enough to make up for all the problems
- the plugin API is utter garbage and deliberately underdocumented, to force you to hire the devs as consultants to undo their own mess (which probably is a major driver for #2, you spend too much time fighting the APIs to get useful work done)
- "core" plugins get randomly deprecated with no useful replacement
So whatever you use nextcloud for, something else does it better
As much as I hat to say it, but feature wise it's not very close to being a Microsoft 365 alternative.
Don't get me wrong, I'm thankful for Nextcloud and hope they can survive, but one needs to manage expectations when using it...
So far our AIO based installation worked well enough (with PC, Mac and Android clients). But we do not have a lot of files (yet).
After bad experience with incompetent MS support stuff regarding our (not cheap!) Office retail licenses I also had to manage expectations there: a lot of time wasted, they only wanted to move us to the 365 subscription model, could not help. Somehow I'm not convinced that with MS365 we would have a simple well-arranged flexible system (but just be bound forever).
It's basically fine but I can imagine the more advanced features not working so well. It has been on my list for years to add recurring task support to nextcloud tasks but it's a pretty big effort since I'm quite unfamiliar with the stack and there is a decent refactoring needed before the feature can be added.
Hosting files, calendar, and contacts is the primary reason I installed Nextcloud. The other features are just gravy.
It's not the best written, due partly to being written in PHP, but I've not seen anything better out there that you can get for free and you don't have to trust a for-profit entity that's dabbling in AI and violates privacy on the regular.
It was frankly shocking to see such negativity about one of the only projects in that space that is achieving goals.
What are the odds, a positive article relating to Nextcloud posted on HN the same day a negative article is posted about Owncloud on Reddit.
Turns out there's some extremely specific weirdness with docker on ZFS. I had to install a userspace FS overlay or something.
But even after all that, I pretty much never use the damn thing. The web interface is the slowest, most bloated and broken thing I've ever had the misfortune to interact with. The desktop and mobile apps have the absolute bare minimum features, and still somehow manage to be broken and unusable.
It sure sounds like a cool idea to glom together your files and email and jira and calendar and everything else into one unified dashboard for your life. But it takes nearly a minute for the web ui to respond to anything. Browsing files takes minutes. And absolutely forget about music or photos, that barely works at all.
At this point, I just use it as a place to blindly dump all my files. I get a notification every. Single. Day. that my backup succeeded, so my files are probably safe I guess. Can't turn off the notification, or filter notifications in general. So I have an unending torrent of useless garbage notifications that perfectly hide any truly important notices.
As much as I want to like it, it's just bad.
Later on, when I set up an old dell xeon workstation as a home server (using proxmox), I used the turnkey image of nextcloud, and have (knock on wood) not had any issues at all.
Anyway - I wanted to ensure it was fully virtualized this next time if/when this happens again. I have it backing up the base vm once a week (I have the file storage separate/outside of the vm). So... hopefully this doesn't happen again to the degree that it did.
Anecdotal evidence tho. Results vary. I like nextcloud because worst case all a wipe would cost me is a re-upload of my local folders over a couple of hours.
Docker monoculture and it's consequences.
"Use the Docker image. It just works!"
Until it doesn't.
I know this will sound very greybeard, but as sysadmins, we can slog through understanding the systems we are running when we set them up, or we can wait until they break to figure them out. You can tell which path a sysadmin chose when they things like, "I upgraded and my containers wouldn't start, so I gave up." Why wouldn't they start? What's in the error logs?
What you are seeing here is a lot of people trying to use it as a file synchronization tool, and discovering that it's bloated beyond reason (because well, it's a file-sharing/collaboration tool) and the file sync functionality isn't even as good as you'll get from specialized tools.
The root problem is that nextcloud started as a file sync tool, and moved into other niche, and never bothered to communicate it.
I made the mistake of recommending it and setting it up for my 10 person team earlier this year and it has only been constant headaches.
Reporting bugs to GitHub is especially frustrating because the devs will just discard them, regardless of how well documented and reproducible they are. There was a mess with its Postgres connection pool where it would quickly run out of available slots if you used Collabora, the Google Docs clone, the devs rejected the bug reports without a second thought although there were many users who reported the problem.
This last hour I've been fighting it trying to reset a user's password, it says that it "cannot decrypt the recovery key".
I check whether the recovery key is enabled for that user, it says "Recovery key is not enabled".
I check whether encryption is enabled, it reports it as "false".
It's by far the flakiest piece of software I've used in 2023.
Since then, I've been running an always-on Syncthing instance as a "cloud hub" and that's been great, though I doubt it would scale well.
I have used Nextcloud at home for years now without issues and we also used it at a large university where it worked just fine (from a user perspective; I don’t know if it gave the administrators nightmares). I do agree that they should invest more time in polish and stability and less in swanky new features that many won’t need, but that would not lead me to discourage anyone from using (or at least trying) Nextcloud.
Seafile is a close call if it gets more attention to remove rough edges and a bit more feature but interface looks more polished.
The just working part, at least for me, are the calendar and contact plugins. Never had any issues with those. File sync with the desktop client works mostly fine on Linux where I use it most of the time. However, I've run into issues with it on Windows. Using the automatic bandwidth limit for example might cause Explorer to freeze. [1] Also forget about the automatic upload feature in the Android client, I switched to FolderSync for a reliable experience.
I've managed to get OnlyOffice working, Collabora Office previously broke for some reason. However latest upgrade also broke OnlyOffice. The solution for this is to put the secret and authorization headers into config.php in addition to the OnlyOffice plugin settings. [2] No idea why, but that is a thing.
My Nextcloud runs as a normal PHP application and I haven't had any issues with upgrading yet. Going from, I think, version 23 on Debian 11 to 27.1 now on a different machine running Debian 12 since I started using it.
Maybe I should find something more focused on file syncing, but the all-in-one approach of Nextcloud and its various plugins makes trying some new services very easy.
[1] https://github.com/nextcloud/desktop/issues/5031
[2] https://github.com/ONLYOFFICE/onlyoffice-nextcloud/issues/60...
It has a lot of the same features, and generally seemed a little more stable. However, it was a little more painful to configure, and has a few unique terminologies you'll have to get used to. Also it's UI does load faster than Nextcloud, but once loaded, it is a little less snappy.
For the user downloaded client, I found that it works, but is a little less convenient than Nextcloud (no Automatic pinning of the folder, no partial downloads to save space)
I can't attest to how well it runs currently, as I haven't used it for a few years, but I used it a couple years ago and it was pretty solid
Nextcloud is nothing more than a collection of small apps. You can disable even core things like sharing.
I see people on selfhosting forums asking for alternatives.
It would be sad if they swallowed roundcube, which I remember as a decent web email client.
Nextcloud used to be small enough for this, but they kept adding things, bundling word processors and other stuff I don't need, meanwhile making the contacts and calendar optional. I have had to move to a larger server only for this reason, to keep Nextcloud at a supported version.
Does Syncthing have contacts and calendar syncing? Any others? I like having a central server.
Syncthing is nice but file-sync-only.
This is what I'm using these days.
I don't think so, as then Web Hosting Panels would loose out. But, you never know.
We'll look what users want, what's best for the ecosystem etc, but we're not looking to kill it and if we ever would, it won't be for the money.
More support for Roundcube, while Nextcloud gets a better Email client than the current one.
It would not really make sense to put Nextcloud inside a Sandstorm app because it is too bulky, but you would need a suite of other Sandstorm apps to do what Nextcloud does.
Very different approaches to a similar thing. Upsides and downsides to each approach.
With regards to security, nothing is perfect but I'm absolutely positive that Nextcloud is ahead of the vast majority of open source projects. And if you know of a security hole, go and collect your USD 10K at HackerOne.