User Tools

Site Tools


computing:onlyoffice

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
computing:onlyoffice [2026/10/10 01:01] – created oemb1905computing:onlyoffice [2026/10/10 04:38] (current) – oemb1905
Line 1: Line 1:
-# OnlyOffice Document Server — Rootless Podman Quadlet+-------------------------------------------
  
-Rootless Podman as user `worker` on host `support`. Apache + Let's Encrypt run as `root`. OnlyOffice is bound to localhost only.+  * **onlyoffice** 
 +  * **Jonathan Haack** 
 +  * **Haack's Networking** 
 +  * **webmaster@haacksnetworking.org**
  
-| Role | Bind | Public | +-------------------------------------------
-| --- | --- | --- | +
-| Document Server | `127.0.0.1:8082` → container `80` | `https://files.haacksnetworking.org` |+
  
-Image: `docker.io/onlyoffice/documentserver:latest`   +//OnlyOffice//
-Data: `~/onlyoffice/{data,logs,lib,db}`   +
-Custom fonts: optional bind under `~/onlyoffice` or an existing Podman volume.+
  
-Do not use `podman generate systemd`. Units come from Quadlet files in `~/.config/containers/systemd/`.   +------------------------------------------- 
-Do not bind-mount `/etc/onlyoffice/documentserver/local.json`. The container rewrites that file on start. A mount desyncs nginx `secure_link` and produces `403` on `/cache/files/`. JWT is the restriction. There is no domain allow list.+~~NOTOC~~
  
----+==== Introduction ====
  
-## 1. Directories and secret (worker)+This tutorial is for Debian users who wish to spin up an Only Office container using podman. It presumes you have a Cockpit container VM/host setup already. If not, head over to [[https://wiki.haacksnetworking.org/doku.php?id=computing:cockpit|Cockpit]] before you start here. Once podman is setup and you have a dedicated rootless user, you can proceed. To begin with, let's setup a directory for this container and generate our jwt secret:
  
-```bash+==== 1. Directories and secret (worker) ==== 
 +<code>
 mkdir -p ~/onlyoffice/{data,logs,lib,db} mkdir -p ~/onlyoffice/{data,logs,lib,db}
 umask 077 umask 077
 openssl rand -hex 32 | tee ~/onlyoffice/jwt.secret openssl rand -hex 32 | tee ~/onlyoffice/jwt.secret
 chmod 600 ~/onlyoffice/jwt.secret chmod 600 ~/onlyoffice/jwt.secret
-```+</code>
  
-Placeholder used below:+This will generate the secret and use ''tee'' to place it in the expected directory and file. 
  
-``` +==== 2. Quadlet ====
-JWT_SECRET=replace-with-your-jwt-secret +
-```+
  
---- +After the secret is cut, we can now build our quadlet unit to manage the container, restart it on reboot/failure, etc. To do that, let's create our systemd directory and then create our quadlet configuration.
- +
-## 2. Quadlet +
- +
-```bash +
-systemctl --user disable --now container-onlyoffice.service 2>/dev/null || true +
-rm -f ~/.config/systemd/user/container-onlyoffice.service +
-podman rm -f onlyoffice+
  
 +<code>
 mkdir -p ~/.config/containers/systemd mkdir -p ~/.config/containers/systemd
 cat > ~/.config/containers/systemd/container-onlyoffice.container << 'EOF' cat > ~/.config/containers/systemd/container-onlyoffice.container << 'EOF'
Line 66: Line 58:
 systemctl --user reset-failed container-onlyoffice.service systemctl --user reset-failed container-onlyoffice.service
 systemctl --user start container-onlyoffice.service systemctl --user start container-onlyoffice.service
-```+</code>
  
-`WantedBy=default.target` starts it. Do not `systemctl enable` a Quadlet unit. Do not `podman generate systemd`.   +==== 3. Verify ====
-Drop the fonts `Volume=` line if you have no custom fonts.   +
-JWT header must be `Authorization`, not `AuthorizationJwt`.+
  
----+Once the quadlet is built, we now need to verify the container is up and running. Wait a minute or two so the container can spin up, then check its status as follows:
  
-## 3. Verify +<code>
- +
-```bash +
-sleep 90+
 systemctl --user is-active container-onlyoffice.service systemctl --user is-active container-onlyoffice.service
 podman inspect onlyoffice --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}' podman inspect onlyoffice --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}'
 curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
 podman exec onlyoffice supervisorctl status podman exec onlyoffice supervisorctl status
-```+</code>
  
-Expect `active`, `cpus=4000000000`, `memory=8589934592`, HTTP `200`, and `ds:converter` / `ds:docservice` `RUNNING`. First start takes about 90 seconds.+Look for ''active'', ''cpus=4000000000'', ''memory=8589934592'', HTTP ''200'', and ''ds:converter'' / ''ds:docservice'' ''RUNNING'' in the output and the endpoint check that you ran with curl. If your service is not accessible, stop here and debug.
  
----+==== 4. Upgrade script ====
  
-## 4. Upgrade script+Now that the quadlet unit is built, we can create a simple script to update the container. To do that, let's create a script called ''nano /usr/local/bin/upgrade-onlyoffice.sh''. Inside the script, let's put something like the following:
  
-`/usr/local/bin/upgrade-onlyoffice.sh`. A tag change is an edit to `Image=` in the `.container` file before `daemon-reload`. The script does not recreate the unit. +<code>
- +
-```bash+
 #!/bin/bash #!/bin/bash
 set -euo pipefail set -euo pipefail
 +export XDG_RUNTIME_DIR=/run/user/$(id -u)
 +export DBUS_SESSION_BUS_ADDRESS=unix:path=${XDG_RUNTIME_DIR}/bus
  
 podman pull docker.io/onlyoffice/documentserver:latest podman pull docker.io/onlyoffice/documentserver:latest
Line 103: Line 90:
 systemctl --user start container-onlyoffice.service systemctl --user start container-onlyoffice.service
  
-sleep 90+sleep 90 #let's the container start up before verifying the endpoint
 curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
-```+</code>
  
-Run it as `worker`:+==== 5. Apache reverse proxy (root) ====
  
-```bash +Alright, now that the container is running and the unit for managing it is ready to go, we can create a reverse proxy virtual host so it can be accessed externally. Let's enable the appropriate packages in apache and cut the cert:
-su - worker -c '/bin/bash /usr/local/bin/upgrade-onlyoffice.sh' +
-```+
  
-Do not `sudo -u worker`. That drops the session bus.+<code> 
 +sudo a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl authz_host 
 +sudo certbot certonly --apache -d files.haacksnetworking.org 
 +</code>
  
----+Now let's configure the virtual host with ''nano /etc/apache2/sites-available/files.haacksnetworking.org.conf'':
  
-## 5. Apache reverse proxy (root) +<code>
- +
-```bash +
-a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl +
-``` +
- +
-`/etc/apache2/sites-available/files.haacksnetworking.org.conf`: +
- +
-```apache+
 <VirtualHost *:80> <VirtualHost *:80>
     ServerName files.haacksnetworking.org     ServerName files.haacksnetworking.org
Line 131: Line 111:
     RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]     RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
 </VirtualHost> </VirtualHost>
 +</code>
 +
 +You can add the TLS block to the same virtual host and/or, if you prefer, create a dedicated vhost. I prefer a dedicated vhost, so I create ''nano /etc/apache2/sites-available/files.haacksnetworking.org-ssl.conf'' and enter the following in it:
  
 <VirtualHost *:443> <VirtualHost *:443>
Line 152: Line 135:
     CustomLog ${APACHE_LOG_DIR}/onlyoffice-access.log combined     CustomLog ${APACHE_LOG_DIR}/onlyoffice-access.log combined
 </VirtualHost> </VirtualHost>
-```+</code>
  
-```bash+Once the virtual hosts are created, let's enable them and check the endpoint: 
 + 
 +<code>
 a2ensite files.haacksnetworking.org.conf a2ensite files.haacksnetworking.org.conf
 apache2ctl configtest && systemctl reload apache2 apache2ctl configtest && systemctl reload apache2
 curl -sI https://files.haacksnetworking.org/healthcheck curl -sI https://files.haacksnetworking.org/healthcheck
-``` +</code>
- +
---- +
- +
-## 6. Nextcloud+
  
-```+If anything barfs here, stop and debug. If not, we can move on to configuring Nextcloud.
  
-Admin → ONLYOFFICE:+==== 6. Nextcloud ====
  
-- Document Editing Service address: `https://files.haacksnetworking.org` +In Nextcloud, go to apps and disable the default Office Suites. After that, install Only Office and then go to Admin Settings > OnlyOffice and enter in your credentials:
-- Secret: contents of `~/onlyoffice/jwt.secret` +
-- Save+
  
-JWT header must be `Authorization`.+  * Document Editing Service address: ''https://files.haacksnetworking.org'' 
 +  * Secret: contents of ''~/onlyoffice/jwt.secret''
  
----+Click Save and then navigate to an office file and test it out. If it works, you are done. If not, debug and trace back over the steps taken. 
  
-## Facts + --- //[[alerts@haacksnetworking.org|oemb1905]] 2026/10/10 03:27//
-- +
computing/onlyoffice.1791594096.txt.gz · Last modified: by oemb1905