Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Nextcloud
  3. [💡 Guide] How to move Nextcloud to an encrypted volume

[💡 Guide] How to move Nextcloud to an encrypted volume

Scheduled Pinned Locked Moved Nextcloud
12 Posts 4 Posters 1.8k Views 5 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • robiR robi

    @3246 said in [💡 Guide] How to move Nextcloud to an encrypted volume:

    You will manually need to mount this volume using the same command as in Step 2 when you restart your Cloudron!

    Perhaps improve Step 2 with fstab automounting

    32463 Offline
    32463 Offline
    3246
    wrote on last edited by
    #3

    @robi that's an idea, although I think it is somewhat insecure to automatically mount the encrypted volume 😉

    👉 Find our more www.bebraver.online

    robiR 1 Reply Last reply
    0
    • 32463 3246

      @robi that's an idea, although I think it is somewhat insecure to automatically mount the encrypted volume 😉

      robiR Offline
      robiR Offline
      robi
      wrote on last edited by
      #4

      @3246 does it ask for a key/passphrase?

      Conscious tech

      32463 1 Reply Last reply
      0
      • robiR robi

        @3246 does it ask for a key/passphrase?

        32463 Offline
        32463 Offline
        3246
        wrote on last edited by
        #5

        @robi yup. I need to paste in a password to decrypt.

        👉 Find our more www.bebraver.online

        robiR 1 Reply Last reply
        0
        • 32463 3246

          @robi yup. I need to paste in a password to decrypt.

          robiR Offline
          robiR Offline
          robi
          wrote on last edited by
          #6

          @3246 right, then it's more about key management than convenience, and what you're actually preventing.

          If the idea is to protect from offline data theft and disk imaging, then it's less relevant if it's (auto)mounted or not.

          As long as it's online & mounted, it's readable.

          Thanks for the great guide!

          Conscious tech

          32463 1 Reply Last reply
          0
          • robiR robi

            @3246 right, then it's more about key management than convenience, and what you're actually preventing.

            If the idea is to protect from offline data theft and disk imaging, then it's less relevant if it's (auto)mounted or not.

            As long as it's online & mounted, it's readable.

            Thanks for the great guide!

            32463 Offline
            32463 Offline
            3246
            wrote on last edited by
            #7

            @robi you are welcome, glad you found it useful and thanks for your feedback.

            I want to prevent unauthorised access to the volume when the server is offline as well as somebody who might take the server out of its rack and boot it. If the volume automatically mounts, they have full access to the data if they can circumnavigate the login cough recovery mode cough

            That's covering for physical access to the machine, in what likely would be a read-only, forensic access scenario by a 'bad' actor. In my case, it's a virtualised server, so not as likely to matter, unless they move the VM to a dedicated slice to get busy with it.

            Granted, this is somewhat unlikely but being paranoid is better than being sorry 😄

            I am in the UK and storing professional data abroad (in nasty Europe no less - just kidding!) means encryption can cover the requirements nicely (as far as I know - I am not an expert in that field, so somebody please correct me if I'm wrong).

            👉 Find our more www.bebraver.online

            1 Reply Last reply
            1
            • andreasduerenA Offline
              andreasduerenA Offline
              andreasdueren
              wrote on last edited by
              #8

              Hi @3246 Are you still using this setup? I'm interested in how it would work with an externally mounted Storage Box

              jdaviescoatesJ 1 Reply Last reply
              1
              • andreasduerenA andreasdueren

                Hi @3246 Are you still using this setup? I'm interested in how it would work with an externally mounted Storage Box

                jdaviescoatesJ Offline
                jdaviescoatesJ Offline
                jdaviescoates
                wrote on last edited by
                #9

                @andreasdueren said in [💡 Guide] How to move Nextcloud to an encrypted volume:

                how it would work with an externally mounted Storage Box

                I don't think that would be possible as I don't think it's possible to use storage boxes for the data directory

                Only volumes with Mount Type EXT4 and NFS can be used as the data directory, as other Mount Types do not properly support file permissions.

                https://docs.cloudron.io/volumes/

                I use Cloudron with Gandi & Hetzner

                andreasduerenA 1 Reply Last reply
                0
                • jdaviescoatesJ jdaviescoates

                  @andreasdueren said in [💡 Guide] How to move Nextcloud to an encrypted volume:

                  how it would work with an externally mounted Storage Box

                  I don't think that would be possible as I don't think it's possible to use storage boxes for the data directory

                  Only volumes with Mount Type EXT4 and NFS can be used as the data directory, as other Mount Types do not properly support file permissions.

                  https://docs.cloudron.io/volumes/

                  andreasduerenA Offline
                  andreasduerenA Offline
                  andreasdueren
                  wrote on last edited by
                  #10

                  @jdaviescoates I've been using it for my Nextcloud storage directory for a few years without problems now. Highly recommend.

                  jdaviescoatesJ 1 Reply Last reply
                  1
                  • andreasduerenA andreasdueren

                    @jdaviescoates I've been using it for my Nextcloud storage directory for a few years without problems now. Highly recommend.

                    jdaviescoatesJ Offline
                    jdaviescoatesJ Offline
                    jdaviescoates
                    wrote on last edited by
                    #11

                    @andreasdueren said in [💡 Guide] How to move Nextcloud to an encrypted volume:

                    storage directory

                    Storage directory isn't the same as data directory though (and I noted "Step 5: Move your Nextcloud app's data directory")

                    I use Cloudron with Gandi & Hetzner

                    andreasduerenA 1 Reply Last reply
                    1
                    • jdaviescoatesJ jdaviescoates

                      @andreasdueren said in [💡 Guide] How to move Nextcloud to an encrypted volume:

                      storage directory

                      Storage directory isn't the same as data directory though (and I noted "Step 5: Move your Nextcloud app's data directory")

                      andreasduerenA Offline
                      andreasduerenA Offline
                      andreasdueren
                      wrote on last edited by
                      #12

                      @jdaviescoates Yes it's something else. But works well and I have never encountered any problems with Nextcloud and file permissions. This is my setup:

                      Screenshot 2025-01-20 at 07.44.48.png

                      Screenshot 2025-01-20 at 07.45.02.png

                      Screenshot 2025-01-20 at 07.47.23.png

                      1 Reply Last reply
                      1
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search