From f97cec953c4d3d7ccae6a48938cdbad7a47d8398 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Dario=20Sindi=C4=8Di=C4=87?= Date: Sat, 26 Sep 2026 16:55:24 +0200 Subject: [PATCH 1/2] [#2602] Added ports env variables in the entrypoint scripts --- 32/apache/entrypoint.sh | 6 ++++++ 32/fpm-alpine/entrypoint.sh | 6 ++++++ 32/fpm/entrypoint.sh | 6 ++++++ 33/apache/entrypoint.sh | 6 ++++++ 33/fpm-alpine/entrypoint.sh | 6 ++++++ 33/fpm/entrypoint.sh | 6 ++++++ 34/apache/entrypoint.sh | 6 ++++++ 34/fpm-alpine/entrypoint.sh | 6 ++++++ 34/fpm/entrypoint.sh | 6 ++++++ 35/apache/entrypoint.sh | 6 ++++++ 35/fpm-alpine/entrypoint.sh | 6 ++++++ 35/fpm/entrypoint.sh | 6 ++++++ docker-entrypoint.sh | 6 ++++++ 13 files changed, 78 insertions(+) diff --git a/32/apache/entrypoint.sh b/32/apache/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/32/apache/entrypoint.sh +++ b/32/apache/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/32/fpm-alpine/entrypoint.sh b/32/fpm-alpine/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/32/fpm-alpine/entrypoint.sh +++ b/32/fpm-alpine/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/32/fpm/entrypoint.sh b/32/fpm/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/32/fpm/entrypoint.sh +++ b/32/fpm/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/33/apache/entrypoint.sh b/33/apache/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/33/apache/entrypoint.sh +++ b/33/apache/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/33/fpm-alpine/entrypoint.sh b/33/fpm-alpine/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/33/fpm-alpine/entrypoint.sh +++ b/33/fpm-alpine/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/33/fpm/entrypoint.sh b/33/fpm/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/33/fpm/entrypoint.sh +++ b/33/fpm/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/34/apache/entrypoint.sh b/34/apache/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/34/apache/entrypoint.sh +++ b/34/apache/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/34/fpm-alpine/entrypoint.sh b/34/fpm-alpine/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/34/fpm-alpine/entrypoint.sh +++ b/34/fpm-alpine/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/34/fpm/entrypoint.sh b/34/fpm/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/34/fpm/entrypoint.sh +++ b/34/fpm/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/35/apache/entrypoint.sh b/35/apache/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/35/apache/entrypoint.sh +++ b/35/apache/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/35/fpm-alpine/entrypoint.sh b/35/fpm-alpine/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/35/fpm-alpine/entrypoint.sh +++ b/35/fpm-alpine/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/35/fpm/entrypoint.sh b/35/fpm/entrypoint.sh index d8d21c1f6..7aa3f1f96 100755 --- a/35/fpm/entrypoint.sh +++ b/35/fpm/entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then diff --git a/docker-entrypoint.sh b/docker-entrypoint.sh index d8d21c1f6..d3cd7b57d 100755 --- a/docker-entrypoint.sh +++ b/docker-entrypoint.sh @@ -137,6 +137,12 @@ if expr "$1" : "apache" 1>/dev/null; then if [ -n "${APACHE_DISABLE_REWRITE_IP+x}" ]; then a2disconf remoteip fi + if [ -n "${APACHE_HTTP_PORT}" ]; then + sed -i "s/Listen 80/Listen $APACHE_HTTP_PORT/" /etc/apache2/ports.conf + fi + if [ -n "${APACHE_HTTPS_PORT}" ]; then + sed -i "s/Listen 443/Listen $APACHE_HTTPS_PORT/" /etc/apache2/ports.conf + fi fi if expr "$1" : "apache" 1>/dev/null || [ "$1" = "php-fpm" ] || [ "${NEXTCLOUD_UPDATE:-0}" -eq 1 ]; then From 7809c929500f1c698c1f01bdd443a755838d4509 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Dario=20Sindi=C4=8Di=C4=87?= Date: Sat, 26 Sep 2026 16:55:46 +0200 Subject: [PATCH 2/2] [#2602] Added doc in README.md --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index f3fedb5d3..003378446 100644 --- a/README.md +++ b/README.md @@ -363,6 +363,10 @@ size of the HTTP request body sent from the client. It specifies the number of _ Check the [Nextcloud documentation](https://docs.nextcloud.com/server/latest/admin_manual/configuration_files/big_file_upload_configuration.html#apache) for more information. +To change the default HTTP and HTTPS port from `80` and `443`, use the following variables: +- `APACHE_HTTP_PORT` (default 80): Set the http port of the proxy +- `APACHE_HTTPS_PORT` (default 443) Set the https port of the proxy + ### Using the image behind a reverse proxy and specifying the server host and protocol By default, the apache image will replace the remote addr (IP address visible to Nextcloud) with the IP address from `X-Real-IP` if the request is coming from a reverse proxy in `10.0.0.0/8`, `172.16.0.0/12` or `192.168.0.0/16`. If you want Nextcloud to pick up the server host (`HTTP_X_FORWARDED_HOST`), protocol (`HTTP_X_FORWARDED_PROTO`) and client IP (`HTTP_X_FORWARDED_FOR`) from a trusted proxy, then disable rewrite IP and add the reverse proxy's IP address to `TRUSTED_PROXIES`.