From 6e6bdf857a59c64802027b30c2ae5248edb49f08 Mon Sep 17 00:00:00 2001 From: Michael Freund Date: Fri, 2 Oct 2026 15:51:05 +0200 Subject: [PATCH 1/3] support MySQL 8.4 in db_mysql.yml Signed-off-by: Michael Freund --- roles/install_nextcloud/files/mysql_nextcloud.cnf | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/roles/install_nextcloud/files/mysql_nextcloud.cnf b/roles/install_nextcloud/files/mysql_nextcloud.cnf index c2a1bdcc..36689c9f 100644 --- a/roles/install_nextcloud/files/mysql_nextcloud.cnf +++ b/roles/install_nextcloud/files/mysql_nextcloud.cnf @@ -7,6 +7,5 @@ [mysqld] binlog_format = MIXED -innodb_large_prefix=on -innodb_file_format=barracuda -innodb_file_per_table=true \ No newline at end of file +innodb_file_per_table=true + From 2d2a575a69f92872c741d96403b7850e37f22fd3 Mon Sep 17 00:00:00 2001 From: Michael Freund Date: Fri, 2 Oct 2026 15:52:04 +0200 Subject: [PATCH 2/3] support MySQL 8.4 in db_mysql.yml Signed-off-by: Michael Freund --- roles/install_nextcloud/tasks/db_mysql.yml | 69 +++++++++++++++------- 1 file changed, 49 insertions(+), 20 deletions(-) diff --git a/roles/install_nextcloud/tasks/db_mysql.yml b/roles/install_nextcloud/tasks/db_mysql.yml index e961a153..cb1b501c 100644 --- a/roles/install_nextcloud/tasks/db_mysql.yml +++ b/roles/install_nextcloud/tasks/db_mysql.yml @@ -15,6 +15,14 @@ changed_when: false check_mode: false +# Parse the first x.y.z number from the client output, e.g. +# MySQL: "mysql Ver 8.4.11-0ubuntu0.26.04.1 for Linux ..." -> 8.4.11 +# MariaDB: "mysql Ver 15.1 Distrib 10.11.6-MariaDB, ..." -> 10.11.6 +- name: db_mysql | Parse MySQL/MariaDB version + ansible.builtin.set_fact: + nc_mysql_is_mariadb: "{{ 'mariadb' in (mysql_cli_version.stdout | lower) }}" + nc_mysql_version: "{{ mysql_cli_version.stdout | regex_search('[0-9]+[.][0-9]+[.][0-9]+') | default('0.0.0', true) }}" + - name: db_mysql | Install packages for MySQL ansible.builtin.package: name: "{{ nc_mysql_deps }}" @@ -22,6 +30,8 @@ vars: nc_mysql_deps: - "python3-pymysql" + # needed by PyMySQL for caching_sha2_password (MySQL >= 8.4) over TCP + - "python3-cryptography" - name: db_mysql | Ensure MySQL is started and enabled on boot ansible.builtin.service: @@ -43,28 +53,36 @@ # Note: We do not use mysql_user for this operation, as it doesn't always update # the root password correctly. See: https://goo.gl/MSOejW -- name: db_mysql | Update MySQL root password for localhost root account (5.7.x) - ansible.builtin.shell: > - mysql -u root -NBe - 'ALTER USER "root"@"{{ item }}" - IDENTIFIED WITH mysql_native_password BY "{{ nextcloud_mysql_root_pwd }}"; FLUSH PRIVILEGES;' - with_items: "{{ mysql_root_hosts.stdout_lines | default([]) }}" - when: > - ((mysql_install_packages | bool) or nextcloud_mysql_root_pwd_update) - and ('5.7.' in mysql_cli_version.stdout or '8.0.' in mysql_cli_version.stdout) - register: output - changed_when: "output.rc == 0" - -- name: db_mysql | Update MySQL root password for localhost root account (< 5.7.x) - ansible.builtin.shell: > - mysql -NBe - 'SET PASSWORD FOR "root"@"{{ item }}" = PASSWORD("{{ nextcloud_mysql_root_pwd }}"); FLUSH PRIVILEGES;' +# +# The authentication plugin must be set explicitly: ALTER USER ... IDENTIFIED BY +# keeps the current plugin, and root uses auth_socket on Debian/Ubuntu. +# - MySQL 5.7 up to (excluding) 8.4: mysql_native_password +# - MySQL >= 8.4: caching_sha2_password (mysql_native_password is disabled by +# default there) +# - MariaDB: plain ALTER USER ... IDENTIFIED BY (supported since MariaDB 10.2) +# SET PASSWORD = PASSWORD() was removed in MySQL 8.0 and is not used anymore. +- name: db_mysql | Update MySQL root password for localhost root account + ansible.builtin.command: + argv: + - mysql + - -u + - root + - -NBe + - >- + ALTER USER 'root'@'{{ item }}' + IDENTIFIED {{ nc_mysql_root_auth }}BY '{{ nextcloud_mysql_root_pwd }}'; + FLUSH PRIVILEGES; + vars: + nc_mysql_root_auth: >- + {{ '' if nc_mysql_is_mariadb + else 'WITH caching_sha2_password ' if nc_mysql_version is version('8.4', '>=') + else 'WITH mysql_native_password ' if nc_mysql_version is version('5.7', '>=') + else '' }} with_items: "{{ mysql_root_hosts.stdout_lines | default([]) }}" - when: > - ((mysql_install_packages | bool) or nextcloud_mysql_root_pwd_update) - and ('5.7.' not in mysql_cli_version.stdout and '8.0.' not in mysql_cli_version.stdout) + when: (mysql_install_packages | bool) or nextcloud_mysql_root_pwd_update register: output changed_when: "output.rc == 0" + no_log: true - name: db_mysql | Copy .my.cnf file with root password credentials ansible.builtin.template: @@ -108,12 +126,23 @@ config_file: "{{ mysql_credential_file[(ansible_os_family | lower)] | default(omit) }}" state: present +# The "password" parameter of community.mysql.mysql_user only works with +# mysql_native_password, which is disabled by default since MySQL 8.4. +# For caching_sha2_password the password has to be passed as plugin_auth_string. - name: db_mysql | Configure the database user community.mysql.mysql_user: name: "{{ nextcloud_db_admin }}" - password: "{{ nextcloud_db_pwd }}" + password: "{{ omit if nc_mysql_user_sha2 | bool else nextcloud_db_pwd }}" + plugin: "{{ 'caching_sha2_password' if nc_mysql_user_sha2 | bool else omit }}" + plugin_auth_string: "{{ nextcloud_db_pwd if nc_mysql_user_sha2 | bool else omit }}" + # the plugin_auth_string cannot be compared with the stored hash, so only + # set it when the user is created to keep the task idempotent + update_password: "{{ 'on_create' if nc_mysql_user_sha2 | bool else 'always' }}" priv: "{{ nextcloud_db_name }}.*:ALL" login_user: root login_password: "{{ nextcloud_mysql_root_pwd }}" config_file: "{{ mysql_credential_file[(ansible_os_family | lower)] | default(omit) }}" state: present + vars: + nc_mysql_user_sha2: "{{ not nc_mysql_is_mariadb and nc_mysql_version is version('8.4', '>=') }}" + From 1c7804a602c49045518a493d5873a0905412f757 Mon Sep 17 00:00:00 2001 From: Michael Freund Date: Fri, 2 Oct 2026 16:07:18 +0200 Subject: [PATCH 3/3] make yaml-lint happy Signed-off-by: Michael Freund --- roles/install_nextcloud/tasks/db_mysql.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/roles/install_nextcloud/tasks/db_mysql.yml b/roles/install_nextcloud/tasks/db_mysql.yml index cb1b501c..8ce1afe2 100644 --- a/roles/install_nextcloud/tasks/db_mysql.yml +++ b/roles/install_nextcloud/tasks/db_mysql.yml @@ -145,4 +145,3 @@ state: present vars: nc_mysql_user_sha2: "{{ not nc_mysql_is_mariadb and nc_mysql_version is version('8.4', '>=') }}" -