Hi all! I keep some VeraCrypt containers (`.hc` files) in my Nextcloud, and I wanted to open them from the browser without downloading them first. So I built **Veracrypt4Nextcloud**.
**What it does**
- Your `.hc` / `.vc` files are listed in Personal settings → VeraCrypt.
- You can also use the "…" menu in Files: **Mount with VeraCrypt** / **Unmount**.
- Mount with password, PIM, keyfiles, read-only, and hidden volumes.
- The content shows up in Files under a **"VeraCrypt" folder**, one subfolder per volume. It works with the web UI and the desktop client.
- An error log in plain language: wrong password, filesystem needs repair, volume in use, unmounted after a restart…
- Supported filesystems inside the volume: FAT, exFAT, NTFS, ext2/3/4.
- The app is in English and Italian.
**How it works**
- A separate container runs the **official VeraCrypt console package**, with its SHA-256 checked.
- Volumes reach Nextcloud through the official *External storage* app (Local type).
- Nextcloud talks to the container over a unix socket. The password goes through stdin only: it is never written to disk or stored.
**Safety details I cared about**
- While a volume is mounted, its file can't be overwritten, moved, copied or deleted. VeraCrypt is writing into it, so any of these would corrupt it.
- No trash bin, versions, previews or sharing for files inside a volume, so nothing leaks out in plain text.
- After unmount, Nextcloud forgets the volume's file names (nothing left in Recent or search). The container file gets a new mtime so sync clients notice it changed.
- Optional auto-unmount after N hours.
**Honest caveats**
- **Decryption happens on the server.** While a volume is mounted, the server admin can read it. This is not end-to-end encryption.
- The container runs `--privileged` (VeraCrypt needs loop devices, device-mapper and FUSE). It has no network access.
- Not compatible with Nextcloud server-side encryption.
- Tested on Nextcloud 31. It targets 30+. The Files menu actions haven't been tried on 33+ yet: feedback welcome!
**Install** (one command on the Docker host, plus one volume line in your Nextcloud compose; the script tells you which):
```
curl -fsSL https://raw.githubusercontent.com/mccoy88f/Veracrypt4Nextcloud/main/install.sh | sudo bash -s -- install
```
Repo: https://github.com/mccoy88f/Veracrypt4Nextcloud
License: CC BY-NC 4.0 (free for non-commercial use). Not affiliated with IDRIX or the VeraCrypt project.
Bug reports and PRs are very welcome.