01 · capture
Capture the complete instance
Record the rendered model and image references, then back up configuration, custom apps, data, themes, database, and declared external storage.
Complete when
Every authoritative state location belongs to one dated recovery point.
02 · quiesce
Enter maintenance control
Review third-party app compatibility, enable maintenance mode, and allow active clients and background work to reach the planned stop boundary.
Complete when
New logins and writes are controlled and the backup set is complete.
03 · apply
Upgrade forward
Apply the supported image transition and complete the application database and app migration path for that release.
Complete when
The migration finishes successfully while the previous recovery set remains intact.
04 · verify
Reopen and synchronize
Check status and logs, disable maintenance mode, then verify login, download, upload, sharing, background jobs, apps, and representative clients.
Complete when
Server and client workflows agree on the recovered file and metadata state.
Rollback boundary
A Nextcloud downgrade is a restore operation: rebuild the previous compatible application state and restore its matching database, data, configuration, custom apps, and themes rather than pointing an older image at a migrated database.