This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| computing:onlyoffice [2026/10/10 03:22] – oemb1905 | computing:onlyoffice [2026/10/10 04:38] (current) – oemb1905 | ||
|---|---|---|---|
| Line 25: | Line 25: | ||
| </ | </ | ||
| - | This will generate the secret and use '' | + | This will generate the secret and use '' |
| ==== 2. Quadlet ==== | ==== 2. Quadlet ==== | ||
| - | < | ||
| - | systemctl --user disable --now container-onlyoffice.service 2>/ | ||
| - | rm -f ~/ | ||
| - | podman rm -f onlyoffice | ||
| + | After the secret is cut, we can now build our quadlet unit to manage the container, restart it on reboot/ | ||
| + | |||
| + | < | ||
| mkdir -p ~/ | mkdir -p ~/ | ||
| cat > ~/ | cat > ~/ | ||
| Line 60: | Line 59: | ||
| systemctl --user start container-onlyoffice.service | systemctl --user start container-onlyoffice.service | ||
| </ | </ | ||
| - | |||
| - | '' | ||
| - | Drop the fonts '' | ||
| - | JWT header must be '' | ||
| ==== 3. Verify ==== | ==== 3. Verify ==== | ||
| + | |||
| + | Once the quadlet is built, we now need to verify the container is up and running. Wait a minute or two so the container can spin up, then check its status as follows: | ||
| + | |||
| < | < | ||
| - | sleep 90 | ||
| systemctl --user is-active container-onlyoffice.service | systemctl --user is-active container-onlyoffice.service | ||
| podman inspect onlyoffice --format ' | podman inspect onlyoffice --format ' | ||
| Line 74: | Line 71: | ||
| </ | </ | ||
| - | Expect | + | Look for '' |
| ==== 4. Upgrade script ==== | ==== 4. Upgrade script ==== | ||
| - | ''/ | + | |
| + | Now that the quadlet unit is built, we can create a simple script to update the container. To do that, let's create a script called | ||
| < | < | ||
| #!/bin/bash | #!/bin/bash | ||
| set -euo pipefail | set -euo pipefail | ||
| + | export XDG_RUNTIME_DIR=/ | ||
| + | export DBUS_SESSION_BUS_ADDRESS=unix: | ||
| podman pull docker.io/ | podman pull docker.io/ | ||
| Line 90: | Line 90: | ||
| systemctl --user start container-onlyoffice.service | systemctl --user start container-onlyoffice.service | ||
| - | sleep 90 | + | sleep 90 #let's the container start up before verifying the endpoint |
| curl -sS -o /dev/null -w ' | curl -sS -o /dev/null -w ' | ||
| </ | </ | ||
| - | Run it as '' | + | ==== 5. Apache reverse proxy (root) ==== |
| - | < | + | Alright, now that the container is running and the unit for managing it is ready to go, we can create a reverse proxy virtual host so it can be accessed externally. Let's enable the appropriate packages in apache and cut the cert: |
| - | su - worker -c '/ | + | |
| - | </ | + | |
| - | Do not '' | ||
| - | |||
| - | ==== 5. Apache reverse proxy (root) ==== | ||
| < | < | ||
| - | a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl | + | sudo a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl authz_host |
| + | sudo certbot certonly --apache -d files.haacksnetworking.org | ||
| </ | </ | ||
| - | ''/ | + | Now let's configure the virtual host with '' |
| < | < | ||
| Line 115: | Line 111: | ||
| RewriteRule ^ https:// | RewriteRule ^ https:// | ||
| </ | </ | ||
| + | </ | ||
| + | |||
| + | You can add the TLS block to the same virtual host and/or, if you prefer, create a dedicated vhost. I prefer a dedicated vhost, so I create '' | ||
| < | < | ||
| Line 137: | Line 136: | ||
| </ | </ | ||
| </ | </ | ||
| + | |||
| + | Once the virtual hosts are created, let's enable them and check the endpoint: | ||
| < | < | ||
| Line 143: | Line 144: | ||
| curl -sI https:// | curl -sI https:// | ||
| </ | </ | ||
| + | |||
| + | If anything barfs here, stop and debug. If not, we can move on to configuring Nextcloud. | ||
| ==== 6. Nextcloud ==== | ==== 6. Nextcloud ==== | ||
| - | Admin → ONLYOFFICE: | + | |
| + | In Nextcloud, go to apps and disable the default Office Suites. After that, install Only Office and then go to Admin Settings > OnlyOffice and enter in your credentials: | ||
| * Document Editing Service address: '' | * Document Editing Service address: '' | ||
| * Secret: contents of '' | * Secret: contents of '' | ||
| - | * Save | ||
| - | |||
| - | JWT header must be '' | ||
| - | ==== Facts ==== | + | Click Save and then navigate to an office file and test it out. If it works, you are done. If not, debug and trace back over the steps taken. |
| - | * | + | |
| - | --- // | + | --- // |