Nextcloud VPS Guide: Self-Host Nextcloud AIO with Backups (2026)

Self-host Nextcloud on a VPS with the official All-in-One container: sizing from AIO's documented minimums, a locked-down admin port, Caddy reverse-proxy mode, S3 trade-offs and encrypted backups to a second server.

Title card reading “Nextcloud AIO on a VPS” for the HourlyVPS guide to self-hosting Nextcloud with Docker, HTTPS and off-server backups

A Nextcloud VPS needs four things: a KVM server that meets the documented minimum, a domain name pointed at it, Docker Engine, and one container, the mastercontainer of Nextcloud All-in-One (AIO), which Nextcloud calls its official installation method. AIO then deploys Nextcloud, PostgreSQL, Redis, automatic HTTPS and encrypted BorgBackup backups, all managed from a small web interface. With an office suite or Talk enabled, AIO’s minimum is 2 GB of RAM, a dual-core CPU and 40 GB of disk, and it recommends 1 GB more RAM than that.

This guide follows Nextcloud’s admin manual and the AIO repository as of AIO v14.2.0 (released September 21, 2026), which ships Nextcloud 34.0.4 and lets new instances install Nextcloud 35 directly. It also covers what most AIO tutorials skip: why UFW doesn’t guard AIO’s ports, keeping the admin interface off the internet, disk math, S3 limits and off-server backups.

Key takeaways

  • Nextcloud calls All-in-One (AIO) its official installation method: one Docker container that deploys Nextcloud, PostgreSQL, Redis, HTTPS and BorgBackup and updates them from a web interface.
  • With any optional container on, AIO's floor is 2 GB of RAM, a dual-core CPU and 40 GB of disk, and it recommends 1 GB more RAM, so a 2 vCPU, 4 GB server is the practical start.
  • Docker publishes AIO's ports around UFW, so bind the AIO interface on port 8080 to 127.0.0.1 and reach it through an SSH tunnel.
  • AIO's maintainers don't support S3 as primary storage because it breaks AIO's backup and restore; use External storage for bulk folders, or a manual install.
  • Send AIO's encrypted borg backups to a remote repository in a different data center, keep the encryption password off both servers, and rehearse a restore on a server you delete after a few hours.

AIO or manual install: which Nextcloud install method fits a VPS?

Nextcloud’s Installation on Linux chapter calls AIO “the official Nextcloud installation method”. The same chapter recommends the .tar archive for building the classic web server, database and PHP stack by hand. Snap, the Nextcloud VM, NextcloudPi and the micro-services Docker image are community options that Nextcloud GmbH does not officially support.

Nextcloud AIOArchive (manual install)Community Docker image
Maintained byNextcloud GmbHNextcloud GmbH ships the code; you maintain the web server, PHP and databaseCommunity volunteers; its README says it is “designed for expert use”
What you installDocker and one container. AIO adds Nextcloud, PostgreSQL, Redis, Apache with automatic HTTPS, Client Push and optional Office, Talk, ClamAV, full-text search and moreApache or nginx, PHP 8.3, 8.4 or 8.5, a database, Redis, TLS certificates and a cron jobNextcloud with Apache or PHP-FPM; you add the database, the proxy and the rest
UpdatesButtons in the AIO interface, or automatic updates after each daily backupNextcloud’s updater or occ, plus your OS packagesPull new images and track breaking changes yourself
BackupsBuilt in: BorgBackup, encrypted and incremental, restored from the interfaceYou script the config, data, theme and custom-app folders and a database dumpYou script the volumes and the database
Subfolder URL (example.com/nextcloud)Not supported: a dedicated (sub)domain onlySupportedSupported
CachingRedis and APCu set up, OPcache onYou install and configure Redis, APCu and OPcacheOPcache on; Redis is a container you add and name in REDIS_HOST
S3 as primary storageNot supported by AIO’s maintainers (it breaks AIO’s backup and restore)Supported through config.phpSupported through OBJECTSTORE_S3_* variables
Sources: Nextcloud’s Installation on Linux chapter, the AIO README and reverse-proxy docs, the nextcloud/docker README and AIO discussion 1807, checked October 3, 2026.

This guide uses AIO. It takes over the two jobs that most often go wrong on a hand-built server: keeping PHP, the database and the web server in step with Nextcloud’s requirements, and having a backup that restores. Choose the archive install if you need S3 primary storage, a subfolder URL or a component AIO won’t let you change.

Nextcloud VPS requirements: how much RAM, CPU and disk?

Nextcloud’s system requirements give memory per PHP process, not per server: at least 128 MB, with 512 MB recommended. AIO sets PHP’s memory limit to that 512 MB. The server-level minimums come from the AIO interface itself (v14.2.0):

  • With any optional container enabled: at least 2 GB of RAM, a dual-core CPU and 40 GB of system storage.
  • With ClamAV, full-text search or the Talk Recording server: at least 3 GB of RAM. Talk Recording also needs 2 additional vCPUs.
  • With everything enabled: at least 5 GB of RAM and a quad-core CPU.
  • In every case, AIO recommends at least 1 GB more RAM than the minimum.

In AIO v14.2.0’s source code, a fresh install starts with an office suite (Nextcloud Office powered by Euro-Office), Talk, Imaginary (extra preview formats) and Whiteboard selected, so the 2 GB, dual-core line applies unless you untick them all before the first start. To keep performance up, AIO’s maintainers add 1 GB of RAM and 1 vCore per active user on top of that base, and recommend SSD storage for everything.

SetupAIO’s documented floorPlanRunsReasoning
Test drive: one user, every optional container untickedNo figure published for the core stack; 512 MB per PHP processQuartz Q2 (1 vCPU, 2 GB, 50 GB)A few hours, then deleteEnough to click through setup and sync a few folders, then delete the server. Below AIO’s dual-core line, so keep optional containers off.
Personal or family, default containers (office, Talk, previews, Whiteboard)2 GB + 1 GB recommended, dual-core, 40 GBQuartz Q4 (2 vCPU, 4 GB, 80 GB)24/7Meets the floor plus headroom. By the per-user rule the last 1 GB covers one active user, though that rule would also want a third vCore.
Small team, plus ClamAV or full-text search3 GB + 1 GB recommended, dual-coreQuartz Q8 (4 vCPU, 8 GB, 160 GB)24/7After the 4 GB floor, RAM covers four active users; by the same rule the 4 vCPUs cover two at full speed.
Everything enabled, including Talk recordings5 GB + 1 GB recommended, quad-core, +2 vCPUs for recordingQuartz Q16 (8 vCPU, 16 GB, 320 GB)24/710 GB left for users after the floor; 8 vCPUs cover the quad-core base, recording and two active users. Chrono C32 (8 dedicated vCPUs) suits CPU that stays busy all day.
Minimums from the AIO v14.2.0 interface; per-user figures from AIO’s performance recommendations, where we read “active” as using Nextcloud at the same time. The plan choices are our arithmetic from those figures, not benchmark results.

AIO’s README recommends KVM servers for Docker and warns that container-based VPS with a /proc/user_beancounters file and a low numproc limit misbehave under AIO. Every HourlyVPS plan is KVM. On another host, the first command should print kvm and the second should find no such file:

systemd-detect-virt
ls /proc/user_beancounters

How to install Nextcloud AIO on a VPS, step by step

These steps use AIO’s standard mode, in which AIO owns ports 80 and 443 and gets its own Let’s Encrypt certificate. If another web server already uses port 443 on this VPS, read the reverse-proxy section first. Run every command as your sudo user, not as root.

Step 1: Harden the server and point DNS at it

Start from a server you reach with an SSH key, with root and password logins off and automatic security updates on; our guides to connecting to a VPS with SSH and the VPS security checklist cover that. This guide uses Ubuntu 24.04 LTS, which Nextcloud’s requirements list; with AIO the host OS matters little, because Nextcloud, PHP and the database run in containers.

Then create an A record for a dedicated subdomain, such as cloud.example.com, pointing at the server’s IPv4 address. AIO checks it before installing anything and never accepts a bare IP address; without a domain, the AIO interface can register a free *.dedyn.io name through deSEC. Add an AAAA record only after Step 2 enables IPv6 in Docker. Confirm the name resolves:

getent hosts cloud.example.com

Step 2: Install Docker and check daemon.json

Install Docker Engine and the Compose plugin from Docker’s apt repository, as in our guide to installing Docker on a VPS. AIO does not support snap-packaged Docker; this check from its README must print nothing:

sudo docker info | grep "Docker Root Dir" | grep "/var/snap/docker/"

Two settings in /etc/docker/daemon.json matter on an AIO host:

  • Skip the Docker guide’s optional “localhost by default” setting ("ip" and host_binding_ipv4). AIO v14.2.0 publishes Talk’s port 3478 without a host address, as it does Apache’s port unless you set APACHE_IP_BINDING, and the Compose file below publishes port 80 the same way. With that default, all of them would listen on 127.0.0.1 only.
  • For IPv6, AIO’s IPv6 page uses default-network-opts plus a nextcloud-aio network created before the first start.

This file combines the Docker guide’s log rotation with AIO’s IPv6 setting. Leave out the default-network-opts block if you won’t publish an AAAA record:

sudo tee /etc/docker/daemon.json <<'EOF'
{
  "log-driver": "local",
  "log-opts": {
    "max-size": "10m",
    "max-file": "3"
  },
  "default-network-opts": {
    "bridge": {
      "com.docker.network.enable_ipv6": "true"
    }
  }
}
EOF
sudo dockerd --validate --config-file=/etc/docker/daemon.json
sudo systemctl restart docker

With IPv6 on, create AIO’s network now and check that the second command shows "EnableIPv6": true:

sudo docker network create nextcloud-aio
sudo docker network inspect nextcloud-aio | grep EnableIPv6

Step 3: Start the mastercontainer with Docker Compose

For production, the AIO README suggests its example Compose file over docker run. Below is that file without comments and with two changes of ours: the AIO interface on port 8080 listens on 127.0.0.1 only, and port 8443 (the interface with a public certificate) is left out. Docker publishes ports around UFW, so the 127.0.0.1 binding is what keeps 8080 off the internet.

mkdir -p ~/nextcloud-aio && cd ~/nextcloud-aio

Save this as ~/nextcloud-aio/compose.yaml, for example with nano compose.yaml:

name: nextcloud-aio
services:
  nextcloud-aio-mastercontainer:
    image: ghcr.io/nextcloud-releases/all-in-one:latest
    init: true
    restart: always
    container_name: nextcloud-aio-mastercontainer
    volumes:
      - nextcloud_aio_mastercontainer:/mnt/docker-aio-config
      - /var/run/docker.sock:/var/run/docker.sock:ro
    network_mode: bridge
    ports:
      - "80:80"
      - "127.0.0.1:8080:8080"

volumes:
  nextcloud_aio_mastercontainer:
    name: nextcloud_aio_mastercontainer

Start it and follow the log (Ctrl+C stops following):

sudo docker compose up -d
sudo docker compose logs -f

Three rules for this file:

  • Keep the container and volume names. Mastercontainer updates and the built-in backups depend on them.
  • Don’t pin a version. The mastercontainer updates itself and every container it manages from :latest; :beta is for testers.
  • Settings are read at creation. Options such as NEXTCLOUD_UPLOAD_LIMIT (default 1G for unchunked uploads), NEXTCLOUD_MEMORY_LIMIT (512M) and BORG_RETENTION_POLICY go under an environment: key. NEXTCLOUD_DATADIR must never change after the first install.

Step 4: Open the AIO interface through an SSH tunnel

On your own computer (macOS, Linux or Windows 10 and 11 all ship OpenSSH), forward local port 8080 to the server’s loopback port; our guide to SSH local port forwarding explains -L in depth:

ssh -L 8080:127.0.0.1:8080 [email protected]

Keep it open, browse to https://127.0.0.1:8080 and accept the self-signed certificate AIO uses here on purpose. Use the IP address, never your domain: AIO warns that HSTS from your Nextcloud domain can block port 8080 later.

Step 5: Save the passphrase, submit the domain and start the containers

  1. Copy the passphrase from the setup page into a password manager. It is the only login to the AIO interface; treat it like a root password.
  2. Log in, enter cloud.example.com and select Submit domain. AIO checks DNS and port 443; if it rejects the domain, hints appear top right.
  3. Under Optional containers, untick what you won’t use, including the office suite if nobody edits documents in the browser: each container costs RAM. Set your timezone on the same screen.
  4. If the interface offers to install the newer Nextcloud major version, tick it for a new instance.
  5. Select Download and start containers. The images add up to a few GB; AIO says this takes 5 to 10 minutes or more.
  6. When everything runs, reveal the initial credentials (user admin and a generated password) and log in to your Nextcloud.

Step 6: Lock down the first login

  • Turn on two-factor authentication. AIO installs the TOTP app (twofactor_totp) by default. Set it up in your personal Security settings, then enforce 2FA for everyone or chosen groups under Administration settings > Security, per Nextcloud’s 2FA docs.
  • Work as a normal user. Create a personal account for daily use and keep admin for administration.
  • Set up outgoing email with your mail provider’s authenticated SMTP submission port. Outbound port 25 is blocked on new HourlyVPS servers, as our acceptable use policy explains.
  • Clear the warnings under Administration settings > Overview. The usual one on a new AIO install, the missing default phone region, takes one occ command with your two-letter country code (every occ command runs this way):
sudo docker exec --user www-data nextcloud-aio-nextcloud php occ config:system:set default_phone_region --value="US"

Already running a web server? Nextcloud AIO behind Caddy

Standard mode needs port 443 for AIO alone. If another web server already serves sites on this VPS, use AIO’s reverse-proxy mode: AIO’s Apache container listens on a local port (11000 in AIO’s examples), your proxy handles HTTPS, and Nextcloud keeps its own subdomain. AIO recommends Caddy if you have no proxy yet; our Caddy reverse proxy guide installs it on the host from the official apt repository.

1. Add the site. Put AIO’s sample site block in /etc/caddy/Caddyfile, with your own domain:

https://cloud.example.com:443 {
    reverse_proxy localhost:11000
}

2. Validate and reload. Check the file as the caddy user, then reload, as in the Caddy guide:

sudo -u caddy caddy validate --config /etc/caddy/Caddyfile
sudo systemctl reload caddy

3. Change compose.yaml. Delete the "80:80" line (Caddy owns port 80 now) and add an environment: block, so the mastercontainer section ends like this:

    network_mode: bridge
    ports:
      - "127.0.0.1:8080:8080"
    environment:
      APACHE_PORT: 11000
      APACHE_IP_BINDING: 127.0.0.1

4. Start AIO. Run sudo docker compose up -d, then continue with Step 4 above.

AIO recommends APACHE_IP_BINDING: 127.0.0.1 when the proxy runs on the same host and connects via localhost, so port 11000 never reaches the internet. Caddy runs on the host, not in Docker, so UFW does control it: allow ports 80 and 443 as in the Caddy guide’s firewall step. Choose the mode before the first start; switching later means stopping the containers and recreating the mastercontainer.

Cloudflare in front? The AIO README lists the limits of Cloudflare’s proxy: on the free plan, uploads over 100 MB fail when they aren’t chunked, requests time out after 100 seconds, Talk’s TURN server may be blocked, and domain validation can fail. Cloudflare also terminates TLS, so it decrypts all traffic on its side, and AIO’s performance notes advise against its proxy and tunnel. Unless you need the proxy, make the Nextcloud record DNS-only.

How do you secure Nextcloud AIO on a VPS?

AIO’s defaults are sound: its own Docker network, many containers running as non-root with read-only root file systems, brute-force protection on, and what the README reports as an A+ in Nextcloud’s security scan. On a VPS, the gaps are the published ports and the AIO interface.

PortUsed byPublic?In this guide
80/tcpMastercontainer: redirect to HTTPS, certificate challenge for port 8443Standard mode onlyPublished; removed in reverse-proxy mode
443/tcpApache container: Nextcloud over HTTPSYesPublished by AIO, or served by Caddy in reverse-proxy mode
443/udpHTTP/3OptionalPublished by AIO
3478/tcp and udpTalk’s TURN serverYes, if Talk is enabledPublished by AIO
8080/tcpAIO interface, self-signed certificateNo127.0.0.1 only, reached through SSH
8443/tcpAIO interface with a valid certificateNot neededNot published
11000/tcpApache container in reverse-proxy modeNo127.0.0.1 only
Port roles from the AIO README’s explanation of used ports and the reverse-proxy docs.

UFW does not filter these ports. Docker’s firewall documentation says traffic to published container ports is diverted before UFW’s rules apply, so ufw deny 8080 would not close a port published as 8080:8080. Bind to 127.0.0.1, as above (our Docker guide covers the other options), then test from your own computer; this should fail to connect:

curl -k -m 5 https://203.0.113.10:8080
  • The interface controls Docker. The mastercontainer holds the Docker socket to manage the other containers, so whoever logs in to the AIO interface controls containers on the host. AIO’s manual-install mode avoids that, at the cost of the interface, update notifications and AIO’s backups.
  • Logging in later. The AIO login is blocked while Nextcloud runs; use the automatic-login button on Administration settings > Overview. It opens the address you last used to start the containers, so open the SSH tunnel first.
  • Fail2ban. The AIO README points to Nextcloud’s hardening guide, with the log at /var/lib/docker/volumes/nextcloud_aio_nextcloud/_data/data/nextcloud.log and chain=DOCKER-USER in the jail; without that chain, banned IPs still reach the container.
  • The host. AIO patches its containers, not Ubuntu. Keep automatic security updates on.

How much disk does Nextcloud use, and can it store files in S3?

By default AIO keeps every file on the server’s disk, in the nextcloud_aio_nextcloud_data Docker volume. Your files are not the only thing that grows:

What uses diskHow muchSource
System, Docker images and databaseAIO’s floor is 40 GB of system storage once any optional container is on; the container images alone are a few GBAIO interface
Your filesWhatever users upload; set a quota per account to cap itNextcloud user management
File versionsNever more than 50% of a user’s currently free space; AIO deletes versions after 30 daysVersions docs, AIO README
Deleted files (trash bin)AIO deletes trash items after 30 days; if trash pushes a user over quota, Nextcloud cleans it earlyAIO README, trash bin docs
PreviewsThumbnails, stored in the data directory’s appdata_*/preview folderAIO README
Treat AIO’s 40 GB as the floor for the disk itself, and budget files, versions and previews on top of what the system already uses.

Check free space, Docker’s usage and the data volume’s size:

df -h /
sudo docker system df
sudo du -sh /var/lib/docker/volumes/nextcloud_aio_nextcloud_data

HourlyVPS NVMe disks range from 25 GB (Quartz Q1) to 800 GB (Chrono C64): plenty for a household’s or small team’s documents, calendars and phone photos, but an expensive home for terabytes of cold data. That is where object storage comes in.

S3-compatible object storage as primary storage

Nextcloud’s admin manual supports Amazon S3 and S3-compatible stores such as MinIO or Ceph Object Gateway as primary storage, set with an objectstore block in config.php. Four rules from that page decide whether it fits:

  • Decide before the first start. Configuring a primary object store on an existing instance makes all existing files inaccessible.
  • The bucket belongs to Nextcloud. It needs exclusive access; names and folders live only in the database, and the bucket holds contents under IDs you can’t browse.
  • Back up both halves. The database and the bucket belong together.
  • AWS bucket naming applies everywhere, even on other providers: no underscores.

AIO is the catch. In AIO discussion 1807 (January 2023), AIO’s maintainer explained that the OBJECTSTORE_S3 variables are deliberately not passed to the Nextcloud container, because AIO’s backup and restore features stop working with primary object storage. If you need it, use the archive install or the community Docker image (which reads OBJECTSTORE_S3_* variables) and plan your own backups. Nextcloud’s docs give this pattern for a non-Amazon endpoint:

'objectstore' => [
    'class' => '\\OC\\Files\\ObjectStore\\S3',
    'arguments' => [
        'bucket' => 'my-nextcloud-store',
        'hostname' => 's3.example.com',
        'key' => 'YOUR_ACCESS_KEY',
        'secret' => 'YOUR_SECRET_KEY',
        // required for some non-Amazon S3 implementations
        'use_path_style' => true,
    ],
],

With AIO: S3 for bulk folders through External storage

AIO’s README suggests Nextcloud’s External storage app instead. Enable it and add an Amazon S3 mount (bucket, keys, and hostname and path-style settings for other providers): those folders live in the bucket, everything else stays on NVMe. AIO’s backups skip external storage, so protect that bucket separately.

How do you back up Nextcloud AIO?

AIO’s built-in backup runs BorgBackup from the interface. Backups are incremental, compressed and encrypted, and cover the database, your files and the mastercontainer’s configuration, but not External storage mounts. A new AIO install can restore the whole instance from the archive and its password. Containers stop while a backup runs, so pick a quiet hour (AIO takes the time in UTC).

  1. Open Backup and restore and enter a location: a local path such as /mnt/backup, or a remote borg repository URL (next section).
  2. Select Create backup.
  3. Copy the encryption password AIO shows into your password manager. Without it, no backup can be restored.
  4. After the first backup succeeds, enter a time and select Submit daily backup time and settings; the same panel offers automatic updates.

Retention defaults to --keep-within=7d --keep-weekly=4 --keep-monthly=6 (change it with BORG_RETENTION_POLICY), and the Check backup integrity button verifies the archives.

Send backups to a second server in another data center

A local backup directory protects you from a bad update, not from losing the server; AIO’s README suggests an external drive for that. On a VPS, use a remote borg repository instead: AIO supports it directly and keeps no local copy. Put the backup server in a different data center from Nextcloud, ideally with a different provider, so no single building or account holds both copies. Size its disk for your data plus retention.

On the backup server (Ubuntu 24.04), install borg and create a dedicated user:

sudo apt update
sudo apt install borgbackup
sudo adduser --disabled-password --comment "Nextcloud AIO backups" borg
sudo -u borg mkdir -m 700 /home/borg/.ssh

In the AIO interface, leave the local path empty, enter the remote repository URL in borg’s ssh:// format and submit it:

ssh://[email protected]:22/home/borg/nextcloud-aio

The first Create backup fails by design and shows the SSH public key AIO generated. Authorize it on the backup server, restricted to borg serve and to this one repository, as borg’s hosting guide recommends. Open the file:

sudo -u borg nano /home/borg/.ssh/authorized_keys

Add one line, with the key AIO showed in place of the placeholder, then save and tighten the permissions:

command="borg serve --restrict-to-repository /home/borg/nextcloud-aio",restrict ssh-ed25519 AAAA...your-aio-key...
sudo chmod 600 /home/borg/.ssh/authorized_keys

Select Create backup again: AIO initializes the repository with repokey-blake2 encryption and uploads the first archive, and later runs send only changes. Ubuntu 24.04 ships borg 1.2.8 and AIO’s container borg 1.4.4; borg’s version docs show a 1.4 client working with a 1.2 server.

Keep the borg password, the repository URL and your compose.yaml somewhere other than both servers. After the first backup, AIO can also include extra host paths or Docker volumes, so other files on the host can ride along in the same encrypted archive.

Rehearse a restore on an hourly server

A backup you have never restored is a hope. Deploy an hourly VPS such as Quartz Q4 at $0.03/hour, install Docker and start AIO with the same compose.yaml. In the interface, choose Restore former AIO instance from backup, enter the repository URL and password, select Submit location and encryption password, then Test path and encryption password. The first test fails and shows the new instance’s SSH key: add it as a second authorized_keys line with the same forced command, and test again. Then pick the newest archive and select Restore selected backup. AIO’s README notes that a remote restore extracts the whole archive, so a large instance takes a while.

A three-hour drill uses $0.09 of server time; each new server is ordered with an initial credit, prepaid and used for that server’s hours, as hourly VPS billing explained shows. Don’t start the restored containers while the original runs: the copy has the same backup schedule and repository. To move for real, follow AIO’s AIO-to-AIO migration: lower the DNS TTL to 60 seconds, stop the old instance, take a final backup, restore and switch DNS; the same steps move you to a bigger plan or another location. Then delete the drill server, after our checklist before you delete a VPS. A stopped server is still billed, because its vCPU, memory, disk and IP addresses stay reserved for you; only deleting the server stops billing.

How do you update Nextcloud AIO?

AIO updates Nextcloud, its apps and every container from the interface. Its update policy puts stability first: it waits for a new major version’s first patch release (x.0.1) and for important apps to support it, and updates can take about two weeks to reach the latest channel.

  1. Select Create backup and wait until it succeeds.
  2. Select Stop containers.
  3. If a mastercontainer update is announced, read the changelog, select Update mastercontainer and wait for the interface to come back.
  4. Select Start and update containers.

To automate it, enable daily backups with automatic updates: each night AIO stops the containers, backs up, updates and restarts them. AIO notifies admins on Saturdays when updates exist, and daily with “AIO is outdated!” once the Nextcloud image is over 90 days old, so update at least every three months.

The host is your job: keep unattended security updates on, and update Docker Engine with apt as in our Docker update steps, then start the containers from the AIO interface if they are down. Before a major upgrade, a provider snapshot is an extra rollback point, not a replacement for the off-server borg copy.

Nextcloud AIO troubleshooting matrix

SymptomLikely causeFix
https://127.0.0.1:8080 doesn’t loadThe SSH tunnel is closed, or port 8080 is busy on your computerReopen the tunnel; or forward -L 8081:127.0.0.1:8080 and open port 8081 instead.
Submit domain is rejectedThe A record doesn’t point at this server, port 443 is unreachable, or Cloudflare’s proxy blocks the checkCheck getent hosts, make the record DNS-only, retry. SKIP_DOMAIN_VALIDATION=true is a last resort.
The mastercontainer can’t create containersSnap-packaged Docker, or a moved Docker socketRun the snap check from Step 2; read sudo docker logs nextcloud-aio-mastercontainer.
AIO login says it is blockedNextcloud is running, by designLog in through Administration settings > Overview, or run sudo docker stop nextcloud-aio-apache to unblock it.
Talk calls fail for people outside your networkPort 3478 bound to 127.0.0.1 by a localhost-default daemon.json, or Cloudflare’s proxyRemove that default and recreate the containers; make the Nextcloud record DNS-only.
Public-link uploads over 1 GB failNEXTCLOUD_UPLOAD_LIMIT defaults to 1G for unchunked uploadsRaise it in compose.yaml and recreate the mastercontainer. Logged-in clients use chunking and aren’t affected.
A user or IP is locked out after failed loginsBrute-force protectionocc security:bruteforce:reset <ip>, or occ user:enable <name> for a disabled account.
Slow pages, out-of-memory killsOptional containers plus active users exceed RAMUntick unused containers while stopped, or restore onto a bigger plan. For slow thumbnails, AIO’s performance notes suggest the Preview Generator app.
Remote backup failsAIO’s key isn’t authorized, the path differs from --restrict-to-repository, or borg is missing on the targetCheck the borgbackup log link in the interface and compare the URL path with the authorized_keys line.
Disk fills upVersions, trash, previews, old images or a local backupRun sudo docker system df, use the Prune docker system button, and set quotas.
Causes and fixes from the AIO README FAQ, the reverse-proxy debug list and the AIO interface, AIO v14.2.0.

What does Nextcloud on a VPS cost, and when is it worth it?

Nextcloud Server and AIO are free software under the AGPLv3. AIO’s README says up to 100 users are free, with more possible through Nextcloud Enterprise. What you pay for is the server, a backup target and your time.

SetupRunsNextcloud serverBackup server
Personal or family, default containers24/7Quartz Q4: $15.00/month capQuartz Q2, 50 GB: $10.00/month cap
Small team with ClamAV or search24/7Quartz Q8: $25.00/month capQuartz Q4, 80 GB: $15.00/month cap
Everything on, with Talk recordings24/7Quartz Q16: $45.00/month capQuartz Q8, 160 GB: $25.00/month cap
Test drive or restore drill3 hours, then deleteQuartz Q4: $0.09Not needed
24/7 rows show each plan’s monthly price: servers bill by the hour, and one left on never costs more than this in a billing period. Prices render from the live HourlyVPS price list. The backup server only runs borg serve, so size it by disk (your data plus retention), not CPU, and keep it in a different data center from Nextcloud.

Nextcloud runs around the clock, so in a full billing period (one month from your order date) it reaches the cap: every hour it exists is billed, and once a server’s charges reach its plan’s monthly price, they stop for the rest of that billing period. That makes it a monthly VPS with no contract and no prepayment; the hourly vs monthly guide explains the cap, and the pricing page lists every plan. Put Nextcloud near the people who sync with it, and read how server location affects data protection before you store other people’s files; our locations page lists where you can deploy. Istanbul plans include the monthly traffic allowance listed for each plan, prorated for a server that exists for part of a billing period. The first upload and the first full backup are the big transfers; after that, sync and borg send only changes.

When Nextcloud on a VPS makes sense, and when it doesn’t

It fits when most of these are true:

  • Several people need files, calendars, contacts or documents on a server you control, reachable from anywhere over HTTPS.
  • Your data fits on NVMe today: tens to a few hundred GB.
  • Someone will apply updates at least every three months, as AIO’s outdated notice asks, and look at the backup results.
  • You want Talk or office editing without another SaaS subscription.

Look elsewhere when:

  • You need several TB of cold storage. Per GB, VPS disk is an expensive home for it; a home server, or a manual install with S3 primary storage, fits better.
  • Nobody wants to own updates and backups. Nextcloud’s sign-up page lists hosting partners that offer a free account with 2 to 5 GB of storage.
  • Everyone sits on one LAN and moves very large files. A home server avoids the trip to a data center, though AIO still needs a real domain and valid HTTPS there too.
  • You only need sync for one person and don’t mind where the data lives.

Deploy this setup

Run Nextcloud AIO 24/7 for a family or small team

Quartz Q4 · 2 shared vCPU · 4 GB RAM · 80 GB NVMe · Istanbul

  • Per hour$0.03/hour
  • Per day (24 h)$0.72/day
  • Monthly cap$15.00/monthFor this job
Deploy Quartz Q4

Starts with a $5 initial credit, which goes into the server’s balance and pays for its hours.

Billed by the hour, never more than $15.00 per billing period. Delete the server and billing stops.

FAQ

How much RAM does Nextcloud need on a VPS?

Nextcloud's docs ask for at least 128 MB per PHP process and recommend 512 MB. For a whole AIO server, the interface sets 2 GB of RAM and a dual-core CPU as the floor once any optional container is on, 3 GB with ClamAV, full-text search or Talk Recording, and 5 GB with everything, plus 1 GB of recommended headroom.

Is Nextcloud free to self-host?

Yes. Nextcloud Server and AIO are AGPLv3 software with no license fee, and AIO's README says up to 100 users are free, with larger installs served by Nextcloud Enterprise. You pay for the server, somewhere to keep backups, and the time to maintain them.

Can I install Nextcloud AIO without a domain name?

No. AIO won't use a bare IP address or a self-signed certificate for Nextcloud. If you don't own a domain, the AIO interface can register a free dedyn.io subdomain through deSEC, and Tailscale is the documented route for private-only access.

Can Nextcloud share a VPS with other websites?

Yes, in AIO's reverse-proxy mode: Caddy or another proxy keeps ports 80 and 443 and forwards a dedicated subdomain to AIO's Apache container on a local port such as 11000. AIO doesn't support subfolder URLs such as example.com/nextcloud.

Should I use Nextcloud AIO or the community Docker image?

For most people, AIO: Nextcloud GmbH maintains it, and backups, updates and the optional Office and Talk containers are built in. The community image is maintained by volunteers and labeled for expert use; pick it when you need something AIO doesn't offer, such as S3 primary storage.

Can Nextcloud store its files in S3?

Yes, either as primary storage set in config.php before the first start, or as an External storage mount. AIO doesn't support the primary-storage route because it breaks AIO's backup and restore, so on AIO use an External storage mount for bulk folders and back up that bucket yourself.

Is a VPS or a home server better for Nextcloud?

A VPS gives you a public IPv4 address, data-center power and network, and no router ports to forward. A home server gives cheap multi-terabyte disks and LAN speed, but AIO's maintainers recommend a fiber connection with the highest upload rate you can get for home hosting.

Sources

  1. Nextcloud All-in-One READMENextcloud (GitHub) · github.com · checked
  2. Using a reverse proxy or secure tunnel to access Nextcloud AIONextcloud (GitHub) · github.com · checked
  3. General recommendations for the best performance (AIO discussion 1335)Nextcloud (GitHub) · github.com · checked
  4. Configuring S3 for primary storage via environment variables (AIO discussion 1807)Nextcloud (GitHub) · github.com · checked
  5. System requirementsNextcloud Administration Manual · docs.nextcloud.com · checked
  6. Installation on LinuxNextcloud Administration Manual · docs.nextcloud.com · checked
  7. Configuring Object Storage as Primary StorageNextcloud Administration Manual · docs.nextcloud.com · checked
  8. Controlling file versions and agingNextcloud Administration Manual · docs.nextcloud.com · checked
  9. Hosting repositoriesBorgBackup documentation · borgbackup.readthedocs.io · checked
  10. Packet filtering and firewalls (Docker and ufw)Docker Docs · docs.docker.com · checked
All posts