This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| computing:onlyoffice [2026/10/10 01:01] – created oemb1905 | computing:onlyoffice [2026/10/10 04:38] (current) – oemb1905 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | # OnlyOffice Document Server — Rootless Podman Quadlet | + | ------------------------------------------- |
| - | Rootless Podman as user `worker` on host `support`. Apache + Let' | + | * **onlyoffice** |
| + | * **Jonathan Haack** | ||
| + | * **Haack' | ||
| + | * **webmaster@haacksnetworking.org** | ||
| - | | Role | Bind | Public | | + | ------------------------------------------- |
| - | | --- | --- | --- | | + | |
| - | | Document Server | `127.0.0.1: | + | |
| - | Image: `docker.io/onlyoffice/documentserver: | + | //OnlyOffice// |
| - | Data: `~/onlyoffice/{data, | + | |
| - | Custom fonts: optional bind under `~/ | + | |
| - | Do not use `podman generate systemd`. Units come from Quadlet files in `~/ | + | ------------------------------------------- |
| - | Do not bind-mount `/ | + | ~~NOTOC~~ |
| - | --- | + | ==== Introduction ==== |
| - | ## 1. Directories | + | This tutorial is for Debian users who wish to spin up an Only Office container using podman. It presumes you have a Cockpit container VM/host setup already. If not, head over to [[https:// |
| - | ```bash | + | ==== 1. Directories and secret (worker) ==== |
| + | < | ||
| mkdir -p ~/ | mkdir -p ~/ | ||
| umask 077 | umask 077 | ||
| openssl rand -hex 32 | tee ~/ | openssl rand -hex 32 | tee ~/ | ||
| chmod 600 ~/ | chmod 600 ~/ | ||
| - | ``` | + | </ |
| - | Placeholder used below: | + | This will generate the secret and use '' |
| - | ``` | + | ==== 2. Quadlet ==== |
| - | JWT_SECRET=replace-with-your-jwt-secret | + | |
| - | ``` | + | |
| - | --- | + | After the secret is cut, we can now build our quadlet unit to manage the container, restart it on reboot/failure, etc. To do that, let's create our systemd |
| - | + | ||
| - | ## 2. Quadlet | + | |
| - | + | ||
| - | ```bash | + | |
| - | systemctl --user disable --now container-onlyoffice.service 2>/ | + | |
| - | rm -f ~/.config/systemd/ | + | |
| - | podman rm -f onlyoffice | + | |
| + | < | ||
| mkdir -p ~/ | mkdir -p ~/ | ||
| cat > ~/ | cat > ~/ | ||
| Line 66: | Line 58: | ||
| systemctl --user reset-failed container-onlyoffice.service | systemctl --user reset-failed container-onlyoffice.service | ||
| systemctl --user start container-onlyoffice.service | systemctl --user start container-onlyoffice.service | ||
| - | ``` | + | </ |
| - | `WantedBy=default.target` starts it. Do not `systemctl enable` a Quadlet unit. Do not `podman generate systemd`. | + | ==== 3. Verify ==== |
| - | Drop the fonts `Volume=` line if you have no custom fonts. | + | |
| - | JWT header must be `Authorization`, | + | |
| - | --- | + | Once the quadlet is built, we now need to verify the container is up and running. Wait a minute or two so the container can spin up, then check its status as follows: |
| - | ## 3. Verify | + | < |
| - | + | ||
| - | ```bash | + | |
| - | sleep 90 | + | |
| systemctl --user is-active container-onlyoffice.service | systemctl --user is-active container-onlyoffice.service | ||
| podman inspect onlyoffice --format ' | podman inspect onlyoffice --format ' | ||
| curl -sS -o /dev/null -w ' | curl -sS -o /dev/null -w ' | ||
| podman exec onlyoffice supervisorctl status | podman exec onlyoffice supervisorctl status | ||
| - | ``` | + | </ |
| - | Expect `active`, `cpus=4000000000`, `memory=8589934592`, HTTP `200`, and `ds: | + | Look for '' |
| - | --- | + | ==== 4. Upgrade script ==== |
| - | ## 4. Upgrade | + | Now that the quadlet unit is built, we can create a simple script to update the container. To do that, let's create a script called '' |
| - | `/ | + | < |
| - | + | ||
| - | ```bash | + | |
| #!/bin/bash | #!/bin/bash | ||
| set -euo pipefail | set -euo pipefail | ||
| + | export XDG_RUNTIME_DIR=/ | ||
| + | export DBUS_SESSION_BUS_ADDRESS=unix: | ||
| podman pull docker.io/ | podman pull docker.io/ | ||
| Line 103: | Line 90: | ||
| systemctl --user start container-onlyoffice.service | systemctl --user start container-onlyoffice.service | ||
| - | sleep 90 | + | sleep 90 #let's the container start up before verifying the endpoint |
| curl -sS -o /dev/null -w ' | curl -sS -o /dev/null -w ' | ||
| - | ``` | + | </ |
| - | Run it as `worker`: | + | ==== 5. Apache reverse proxy (root) ==== |
| - | ```bash | + | Alright, now that the container is running and the unit for managing it is ready to go, we can create a reverse proxy virtual host so it can be accessed externally. Let's enable the appropriate packages in apache and cut the cert: |
| - | su - worker -c '/ | + | |
| - | ``` | + | |
| - | Do not `sudo -u worker`. That drops the session bus. | + | < |
| + | sudo a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl authz_host | ||
| + | sudo certbot certonly --apache | ||
| + | </ | ||
| - | --- | + | Now let's configure the virtual host with '' |
| - | ## 5. Apache reverse proxy (root) | + | < |
| - | + | ||
| - | ```bash | + | |
| - | a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl | + | |
| - | ``` | + | |
| - | + | ||
| - | `/ | + | |
| - | + | ||
| - | ```apache | + | |
| < | < | ||
| ServerName files.haacksnetworking.org | ServerName files.haacksnetworking.org | ||
| Line 131: | Line 111: | ||
| RewriteRule ^ https:// | RewriteRule ^ https:// | ||
| </ | </ | ||
| + | </ | ||
| + | |||
| + | You can add the TLS block to the same virtual host and/or, if you prefer, create a dedicated vhost. I prefer a dedicated vhost, so I create '' | ||
| < | < | ||
| Line 152: | Line 135: | ||
| CustomLog ${APACHE_LOG_DIR}/ | CustomLog ${APACHE_LOG_DIR}/ | ||
| </ | </ | ||
| - | ``` | + | </ |
| - | ```bash | + | Once the virtual hosts are created, let's enable them and check the endpoint: |
| + | |||
| + | < | ||
| a2ensite files.haacksnetworking.org.conf | a2ensite files.haacksnetworking.org.conf | ||
| apache2ctl configtest && systemctl reload apache2 | apache2ctl configtest && systemctl reload apache2 | ||
| curl -sI https:// | curl -sI https:// | ||
| - | ``` | + | </ |
| - | + | ||
| - | --- | + | |
| - | + | ||
| - | ## 6. Nextcloud | + | |
| - | ``` | + | If anything barfs here, stop and debug. If not, we can move on to configuring Nextcloud. |
| - | Admin → ONLYOFFICE: | + | ==== 6. Nextcloud ==== |
| - | - Document Editing Service address: `https:// | + | In Nextcloud, go to apps and disable the default Office Suites. After that, install Only Office and then go to Admin Settings > OnlyOffice and enter in your credentials: |
| - | - Secret: contents of `~/ | + | |
| - | - Save | + | |
| - | JWT header must be `Authorization`. | + | * Document Editing Service address: '' |
| + | * Secret: contents of '' | ||
| - | --- | + | Click Save and then navigate to an office file and test it out. If it works, you are done. If not, debug and trace back over the steps taken. |
| - | ## Facts | + | --- // |
| - | - | + | |