User Tools

Site Tools


computing:onlyoffice

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
computing:onlyoffice [2026/10/10 01:05] – oemb1905computing:onlyoffice [2026/10/10 04:38] (current) – oemb1905
Line 1: Line 1:
 ------------------------------------------- -------------------------------------------
-  * **onlyoffice-documentserver**+ 
 +  * **onlyoffice**
   * **Jonathan Haack**   * **Jonathan Haack**
   * **Haack's Networking**   * **Haack's Networking**
   * **webmaster@haacksnetworking.org**   * **webmaster@haacksnetworking.org**
 +
 ------------------------------------------- -------------------------------------------
-//OnlyOffice Document Server on rootless Podman// 
-------------------------------------------- 
-==== Introduction ==== 
-Rootless Podman as user ''worker'' on host ''support''. Apache + Let's Encrypt run as ''root''. OnlyOffice is bound to localhost only. 
  
-^ Role ^ Bind ^ Public ^ +//OnlyOffice//
-| Document Server | ''127.0.0.1:8082'' → container ''80'' | ''https://files.haacksnetworking.org'' |+
  
-Image: ''docker.io/onlyoffice/documentserver:latest''   +------------------------------------------- 
-Data: ''~/onlyoffice/{data,logs,lib,db}''   +~~NOTOC~~ 
-Custom fonts: optional bind under ''~/onlyoffice'' or an existing Podman volume.+ 
 +==== Introduction ====
  
-Do not use ''podman generate systemd''. Units come from Quadlet files in ''~/.config/containers/systemd/''.   +This tutorial is for Debian users who wish to spin up an Only Office container using podman. It presumes you have a Cockpit container VM/host setup already. If not, head over to [[https://wiki.haacksnetworking.org/doku.php?id=computing:cockpit|Cockpit]] before you start here. Once podman is setup and you have a dedicated rootless user, you can proceed. To begin with, let's setup a directory for this container and generate our jwt secret:
-Do not bind-mount ''/etc/onlyoffice/documentserver/local.json''. The container rewrites that file on start. A mount desyncs nginx ''secure_link'' and produces ''403'' on ''/cache/files/''. JWT is the restriction. There is no domain allow list.+
  
 ==== 1. Directories and secret (worker) ==== ==== 1. Directories and secret (worker) ====
Line 28: Line 25:
 </code> </code>
  
-Placeholder used below:+This will generate the secret and use ''tee'' to place it in the expected directory and file. 
  
-<code> +==== 2. Quadlet ==== 
-JWT_SECRET=replace-with-your-jwt-secret + 
-</code>+After the secret is cut, we can now build our quadlet unit to manage the container, restart it on reboot/failure, etc. To do that, let's create our systemd directory and then create our quadlet configuration.
  
-==== 2. Quadlet ==== 
 <code> <code>
-systemctl --user disable --now container-onlyoffice.service 2>/dev/null || true 
-rm -f ~/.config/systemd/user/container-onlyoffice.service 
-podman rm -f onlyoffice 
- 
 mkdir -p ~/.config/containers/systemd mkdir -p ~/.config/containers/systemd
 cat > ~/.config/containers/systemd/container-onlyoffice.container << 'EOF' cat > ~/.config/containers/systemd/container-onlyoffice.container << 'EOF'
Line 67: Line 59:
 systemctl --user start container-onlyoffice.service systemctl --user start container-onlyoffice.service
 </code> </code>
- 
-''WantedBy=default.target'' starts it. Do not ''systemctl enable'' a Quadlet unit. Do not ''podman generate systemd''.   
-Drop the fonts ''Volume='' line if you have no custom fonts.   
-JWT header must be ''Authorization'', not ''AuthorizationJwt''. 
  
 ==== 3. Verify ==== ==== 3. Verify ====
 +
 +Once the quadlet is built, we now need to verify the container is up and running. Wait a minute or two so the container can spin up, then check its status as follows:
 +
 <code> <code>
-sleep 90 
 systemctl --user is-active container-onlyoffice.service systemctl --user is-active container-onlyoffice.service
 podman inspect onlyoffice --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}' podman inspect onlyoffice --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}'
Line 81: Line 71:
 </code> </code>
  
-Expect ''active'', ''cpus=4000000000'', ''memory=8589934592'', HTTP ''200'', and ''ds:converter'' / ''ds:docservice'' ''RUNNING''. First start takes about 90 seconds.+Look for ''active'', ''cpus=4000000000'', ''memory=8589934592'', HTTP ''200'', and ''ds:converter'' / ''ds:docservice'' ''RUNNING'' in the output and the endpoint check that you ran with curl. If your service is not accessible, stop here and debug.
  
 ==== 4. Upgrade script ==== ==== 4. Upgrade script ====
-''/usr/local/bin/upgrade-onlyoffice.sh''. A tag change is an edit to ''Image='' in the ''.container'' file before ''daemon-reload''. The script does not recreate the unit.+ 
 +Now that the quadlet unit is built, we can create a simple script to update the container. To do that, let's create a script called ''nano /usr/local/bin/upgrade-onlyoffice.sh''. Inside the script, let's put something like the following:
  
 <code> <code>
 #!/bin/bash #!/bin/bash
 set -euo pipefail set -euo pipefail
 +export XDG_RUNTIME_DIR=/run/user/$(id -u)
 +export DBUS_SESSION_BUS_ADDRESS=unix:path=${XDG_RUNTIME_DIR}/bus
  
 podman pull docker.io/onlyoffice/documentserver:latest podman pull docker.io/onlyoffice/documentserver:latest
Line 97: Line 90:
 systemctl --user start container-onlyoffice.service systemctl --user start container-onlyoffice.service
  
-sleep 90+sleep 90 #let's the container start up before verifying the endpoint
 curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
 </code> </code>
  
-Run it as ''worker'':+==== 5. Apache reverse proxy (root) ====
  
-<code> +Alright, now that the container is running and the unit for managing it is ready to go, we can create a reverse proxy virtual host so it can be accessed externally. Let's enable the appropriate packages in apache and cut the cert:
-su - worker -c '/bin/bash /usr/local/bin/upgrade-onlyoffice.sh' +
-</code>+
  
-Do not ''sudo -u worker''. That drops the session bus. 
- 
-==== 5. Apache reverse proxy (root) ==== 
 <code> <code>
-a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl+sudo a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl authz_host 
 +sudo certbot certonly --apache -d files.haacksnetworking.org
 </code> </code>
  
-''/etc/apache2/sites-available/files.haacksnetworking.org.conf'':+Now let's configure the virtual host with ''nano /etc/apache2/sites-available/files.haacksnetworking.org.conf'':
  
 <code> <code>
Line 122: Line 111:
     RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]     RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
 </VirtualHost> </VirtualHost>
 +</code>
 +
 +You can add the TLS block to the same virtual host and/or, if you prefer, create a dedicated vhost. I prefer a dedicated vhost, so I create ''nano /etc/apache2/sites-available/files.haacksnetworking.org-ssl.conf'' and enter the following in it:
  
 <VirtualHost *:443> <VirtualHost *:443>
Line 144: Line 136:
 </VirtualHost> </VirtualHost>
 </code> </code>
 +
 +Once the virtual hosts are created, let's enable them and check the endpoint:
  
 <code> <code>
Line 150: Line 144:
 curl -sI https://files.haacksnetworking.org/healthcheck curl -sI https://files.haacksnetworking.org/healthcheck
 </code> </code>
 +
 +If anything barfs here, stop and debug. If not, we can move on to configuring Nextcloud.
  
 ==== 6. Nextcloud ==== ==== 6. Nextcloud ====
-Admin → ONLYOFFICE:+ 
 +In Nextcloud, go to apps and disable the default Office Suites. After that, install Only Office and then go to Admin Settings > OnlyOffice and enter in your credentials:
  
   * Document Editing Service address: ''https://files.haacksnetworking.org''   * Document Editing Service address: ''https://files.haacksnetworking.org''
   * Secret: contents of ''~/onlyoffice/jwt.secret''   * Secret: contents of ''~/onlyoffice/jwt.secret''
-  * Save 
- 
-JWT header must be ''Authorization''. 
  
-==== Facts ==== +Click Save and then navigate to an office file and test it out. If it works, you are done. If not, debug and trace back over the steps taken. 
-  * +
  
- --- //[[alerts@haacksnetworking.org|oemb1905]] 2026/10/10 01:04//+ --- //[[alerts@haacksnetworking.org|oemb1905]] 2026/10/10 03:27//
computing/onlyoffice.1791594318.txt.gz · Last modified: by oemb1905