Skip to content

install_nextcloud: support MySQL 8.4 (Ubuntu 26.04) in db_mysql.yml - #478

Open
Adfinis-Freund wants to merge 3 commits into
nextcloud:mainfrom
Adfinis-Freund:main
Open

Adfinis-Freund wants to merge 3 commits into
nextcloud:mainfrom
Adfinis-Freund:main

Conversation

@Adfinis-Freund

Copy link
Copy Markdown

🤖 AI (if applicable)

  • The content of this PR was partly or fully generated using AI

Fixes #477

What this changes

roles/install_nextcloud/tasks/db_mysql.yml

  • Version detection: parse the version from mysql --version once (nc_mysql_version, nc_mysql_is_mariadb) and use version comparisons instead of substring matches like '5.7.' in ....
  • Root password: the two root-password tasks (5.7/8.0 and "< 5.7") are merged into one ALTER USER task. The authentication plugin is now set explicitly, because ALTER USER ... IDENTIFIED BY alone keeps the current plugin (auth_socket on Debian/Ubuntu):
    • MySQL 5.7 up to (excluding) 8.4: WITH mysql_native_password (unchanged behaviour)
    • MySQL >= 8.4: WITH caching_sha2_password (mysql_native_password is disabled by default)
    • MariaDB: plain IDENTIFIED BY
    • SET PASSWORD = PASSWORD(...) is gone, as the function was removed in MySQL 8.0.
    • Added no_log: true, and the SQL is passed via argv instead of shell.
  • Nextcloud database user: on MySQL >= 8.4 the password is passed as plugin_auth_string together with plugin: caching_sha2_password instead of password. The password parameter of community.mysql.mysql_user always results in a mysql_native_password hash (CREATE USER ... IDENTIFIED WITH mysql_native_password AS '<hash>'), which fails on 8.4 with error 1524. On MySQL 8.0 and MariaDB the task behaves as before.
  • Packages: added python3-cryptography, which PyMySQL needs for caching_sha2_password on non-socket connections.

roles/install_nextcloud/files/mysql_nextcloud.cnf

  • Removed innodb_large_prefix and innodb_file_format, both of which no longer exist in MySQL 8.0+.

Testing

Each test used a fresh VM, followed by a second run of the role.

OS MySQL Nextcloud First run Second run Instance works
Ubuntu 26.04 8.4.11 36 ok no changes in DB tasks yes
Ubuntu 24.04 8.0.46 36 ok no changes in DB tasks yes
Ubuntu 22.04 8.0.46 36 ok no changes in DB tasks yes

Verified with SELECT user, host, plugin FROM mysql.user:

  • Ubuntu 26.04 (MySQL 8.4): root and the Nextcloud user use caching_sha2_password.
  • Ubuntu 24.04 (MySQL 8.0): root and the Nextcloud user use mysql_native_password, as before.
    Not tested: MariaDB (nextcloud_db_backend: mariadb, e.g. Debian), Ubuntu 25.x, MySQL 5.7.

Behaviour changes to be aware of

  • MariaDB: the previous "< 5.7.x" task effectively served MariaDB (via SET PASSWORD = PASSWORD(...)). It now uses ALTER USER ... IDENTIFIED BY, which MariaDB supports since 10.2. This path is untested.
  • MySQL < 5.7 is no longer handled by a dedicated branch, since PASSWORD() does not exist in the supported distributions.
  • Password changes on MySQL >= 8.4: plugin_auth_string cannot be compared with the stored hash, so the task uses update_password: on_create. This keeps it idempotent, but changing nextcloud_db_pwd later does not update an existing user on MySQL >= 8.4.

Checklist

  • Changelog entry added (if the repository requires one)
  • Test matrix / README updated (if Ubuntu 26.04 should be listed)

Signed-off-by: Michael Freund <michael.freund@adfinis.com>
Signed-off-by: Michael Freund <michael.freund@adfinis.com>
Signed-off-by: Michael Freund <michael.freund@adfinis.com>
@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@aalaesar

aalaesar commented Oct 9, 2026

Copy link
Copy Markdown
Member

Hello there @Adfinis-Freund thank you for reporting this.
it is in fact a legacy part of the role that should be considered technical debt.
We can definitively simplify this part by removing cases for mysql < 8.4

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants