Edouard Vanbelle baee4ac9b2 feat(storage): a backend that never answers is now a transient failure
Ed pulled the network mid-migration and got nothing: no log, no pause,
after more than two minutes. The cause is not the classification work
that preceded this — it is that there was no error to classify.

Pull a network on an ESTABLISHED TCP connection and there is no RST and
no ICMP. The peer simply stops answering and the socket read blocks
until the OS abandons retransmission, on the order of fifteen minutes.
For that whole window the job is neither running nor failed. Nothing
retries, because nothing failed. It looks exactly like a slow migration.

A refused connection is instant and does surface, which is what made
the earlier `127.0.0.1` test look reassuring. It exercised the one
network failure that cannot hang.

## Two layers, because one does not fit

`TimeoutBlobBackend` is innermost, below retry — a hang has to become an
error before any layer above can react to it. Bounds are per operation
class, because one number cannot fit both a HEAD and a 5 GB upload:

  metadata  30s   exists / size / delete / init / health / list
  open      60s   time to FIRST BYTE, not transfer duration
  write     off   the whole transfer is inside the future, so any
                  bound here is also a maximum upload duration

Write is unbounded by default deliberately: guessing it wrong truncates
legitimate uploads, which is worse than the hang it would prevent. All
three are configurable (`OXICLOUD_STORAGE_TIMEOUT_*_MS`, 0 = unbounded).

The S3 client also gets what it could always have had. It was built from
a bare `config::Builder::new()`, which carries NO `TimeoutConfig` at
all — so `SdkError::TimeoutError`, an arm `s3_domain_error` already
handles, was unreachable. It now sets connect/read timeouts plus
stalled-stream protection, which measures throughput rather than
elapsed time and is therefore the correct instrument for a stream: it
bounds a stalled upload without capping how long a large one may take.

## Local is not the justification

Ed's correction, and it is right: a local path is reached through the
kernel, and the kernel owns that timeout. iSCSI gives up after
`replacement_timeout` (120s default) and returns an I/O error; NVMe-oF
and soft-mounted NFS behave the same. Those arrive as `io::Error` and
`local_io_error` already classifies them. Local passes through the
decorator only because a uniform chain beats a conditional one, and a
bound that never fires costs nothing.

The real asymmetry is Azure: its 0.21 client has no timeout knob short
of a custom transport, and the SDK migration is deferred. That is why
this lives in the chain rather than being configured per SDK.

Also fixes the log gap: the timeout warns with the wrapper, backend,
operation and bound, so a stalled layer is visible before the pause
rather than only afterwards.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-08 06:23:25 +02:00
2026-05-31 03:53:33 +02:00
2026-09-08 06:23:24 +02:00
2026-05-28 22:37:31 +02:00
2026-06-16 13:51:51 -06:00
2026-08-13 00:30:55 +02:00
2026-08-29 11:57:48 +02:00
2026-06-16 13:51:51 -06:00
2026-06-16 13:51:51 -06:00
2026-08-29 11:57:48 +02:00
2026-09-06 21:52:18 +02:00

OxiCloud logo

A fast self-hosted cloud for people who want files, calendars, contacts, and office editing without dragging a heavy stack behind them.

Documentation · Quick Start · Star OxiCloud · Request a Feature · Supported Clients · Project Status

Latest release CI GitHub stars Docker image size Rust 1.93+ MIT license

If OxiCloud saves you setup time, RAM, or complexity, give it a star. If something is missing, ask for a feature or request a docs improvement.

OxiCloud dashboard

Why People Try OxiCloud

OxiCloud is aimed at self-hosters, home labs, and small teams who want the useful parts of a cloud suite without the operational drag of a traditional PHP stack.

What pulls people in:

  • Standard protocols first: WebDAV, CalDAV, and CardDAV are built in
  • Useful product surface already there: files, previews, sharing, trash, search, favorites, and recent items
  • Modern auth and admin basics: OIDC/SSO, quotas, roles, and shared links
  • Better interoperability: native desktop and mobile clients work without custom sync tooling for basic access
  • Lower deployment friction: Docker Compose, environment-based configuration, Helm chart, and Nix module

OxiCloud is not trying to mirror the full plugin ecosystem of Nextcloud. It is designed for a smaller stack, fast startup, and standards-based interoperability.

Quick Start

Docker Compose

Requires Docker and Docker Compose.

git clone https://github.com/AtalayaLabs/OxiCloud.git
cd OxiCloud
cp example.env .env

# If users will access OxiCloud through a domain or reverse proxy,
# set OXICLOUD_BASE_URL in .env before the first login.
docker compose up -d

Open http://localhost:8086.

Prebuilt binary

Binary releases (Linux musl amd64/arm64, macOS Intel/Apple Silicon) are attached to every tagged release on GitHub — the whole SPA + all operator subcommands + migrations bake into a single self-contained executable. See docs/install/binary.md for the download / verify / systemd walkthrough.

cargo binstall oxicloud works too once a release is out.

Run from source

Requires Rust 1.93+ and PostgreSQL.

git clone https://github.com/AtalayaLabs/OxiCloud.git
cd OxiCloud
cp example.env .env

# If PostgreSQL runs on your host instead of Docker, update both
# OXICLOUD_DB_CONNECTION_STRING and DATABASE_URL to use localhost:5432.
cargo run

Deployment details: deployment guide · example.env

What You Get

Area Included
Files Multi-file upload, folders, inline previews, thumbnails, chunked uploads, deduplication, trash
Sync and clients WebDAV, CalDAV, CardDAV, native OS clients, Thunderbird, DAVx5
Security JWT auth, Argon2id, OIDC/SSO, shared links, quotas, admin/user roles
Integrations REST API and WOPI for Collabora or OnlyOffice
Operations Docker image, Docker Compose, env-driven config, PostgreSQL backend
Project tooling Architecture docs, Helm chart, Nix module, CI

Supported Clients

OxiCloud uses standard DAV protocols, so it works with native clients instead of requiring a custom sync stack for basic access.

Use case URL
Files via WebDAV https://your-host/webdav/
Calendars via CalDAV https://your-host/caldav/
Contacts via CardDAV https://your-host/carddav/

Common clients that work well:

  • macOS Finder
  • Windows Explorer
  • GNOME Files and KDE Dolphin
  • Thunderbird
  • Apple Calendar and Contacts
  • DAVx5 on Android

Client setup guides: DAV client setup · WebDAV guide · CalDAV & CardDAV guide

Project Status

OxiCloud is actively developed and already covers the core self-hosted cloud workflow.

Capability Status Notes
File storage and web UI Ready Uploads, previews, sharing, trash, and search
WebDAV Ready Standard file access for desktop and mobile clients
CalDAV and CardDAV Ready Working with Thunderbird, Apple clients, and others
OIDC / SSO Ready Documentation and config examples included
WOPI office editing Ready Works with Collabora or OnlyOffice
DAVx5 Android support Partial File sync works well; calendar and contact behavior is still being refined
Desktop sync client Planned Not yet available
Mobile apps Planned Not yet available
End-to-end encryption Planned Roadmap item

Roadmap: TODO-LIST.md

Help Shape OxiCloud

If you want OxiCloud to get better faster, use the repo like a product feedback loop, not just a code dump.

The best feature ideas usually come from real deployment pain. If you hit friction, open an issue and describe the workflow you want.

Architecture and Deployment

OxiCloud follows a clean, hexagonal architecture so protocol handlers, business logic, and infrastructure stay separated.

  • Backend: Rust + Axum
  • Database: PostgreSQL
  • Configuration: environment variables
  • Default deployment: Docker Compose
  • Additional packaging: Helm chart and Nix module

Architecture docs: internal architecture · caching architecture · database transactions · storage safety

Configuration and Integrations

Start with example.env. The most important settings are:

  • OXICLOUD_BASE_URL for reverse proxies, domains, and external access
  • OXICLOUD_DB_CONNECTION_STRING for PostgreSQL
  • OXICLOUD_OIDC_ENABLED and related settings for SSO
  • OXICLOUD_WOPI_ENABLED and discovery URL for office editing
  • MIMALLOC_PURGE_DELAY=0 for lower idle RSS in constrained environments

Integration docs: OIDC setup · OIDC architecture · OIDC config examples · WOPI integration

Documentation

Development

cargo fmt --all --check
cargo clippy --all-features --all-targets -- -D warnings
cargo test --workspace

Contributing

Contributions are welcome. Read CONTRIBUTING.md before opening a pull request and CODE_OF_CONDUCT.md for community expectations.

If you are not ready to code yet, starring the project and opening a precise feature request is still a meaningful contribution.

Contributors

OxiCloud is a community-driven project, and we appreciate all contributions. Check out the Contributors page to see the amazing people who have helped make OxiCloud better.

Contributors

Star History

Star History Chart

License

MIT. See LICENSE.

OxiCloud is a trademark of the OxiCloud project. All other trademarks are the property of their respective owners.

S
Description
No description provided
Readme MIT 52 MiB
Languages
Rust 63.5%
Hurl 10.2%
TypeScript 8.5%
Svelte 8.2%
Shell 3.8%
Other 5.6%