This is an old revision of the document!
OnlyOffice
This tutorial is for Debian users who wish to spin up an Only Office container using podman. It presumes you have a Cockpit container VM/host setup already. If not, head over to Cockpit before you start here. Once podman is setup and you have a dedicated rootless user, you can proceed. To begin with, let's setup a directory for this container and generate our jwt secret:
mkdir -p ~/onlyoffice/{data,logs,lib,db}
umask 077
openssl rand -hex 32 | tee ~/onlyoffice/jwt.secret
chmod 600 ~/onlyoffice/jwt.secret
This will generate the secret and use tee to place it in the expected directory and file.
After the secret is cut, we can now build our quadlet unit to manage the container, restart it on reboot/failure, etc. To do that, let's create our systemd directory and then create our quadlet configuration.
mkdir -p ~/.config/containers/systemd cat > ~/.config/containers/systemd/container-onlyoffice.container << 'EOF' [Container] ContainerName=onlyoffice Image=docker.io/onlyoffice/documentserver:latest PublishPort=127.0.0.1:8082:80 Environment=JWT_ENABLED=true Environment=JWT_SECRET=replace-with-your-jwt-secret Environment=JWT_HEADER=Authorization Environment=ALLOW_PRIVATE_IP_ADDRESS=false Volume=/home/worker/onlyoffice/logs:/var/log/onlyoffice:Z Volume=/home/worker/onlyoffice/data:/var/www/onlyoffice/Data:Z Volume=/home/worker/onlyoffice/lib:/var/lib/onlyoffice:Z Volume=/home/worker/onlyoffice/db:/var/lib/postgresql:Z Volume=/home/worker/podman-local/volumes/84a360c1a5dd357b0cfe5af71a59f7338eeca694336b1ea8bef5d5c41fe7deb7/_data:/usr/share/fonts/truetype/custom:Z PodmanArgs=--cpus=4 --memory=8g [Service] Restart=always TimeoutStopSec=120 [Install] WantedBy=default.target EOF systemctl --user daemon-reload systemctl --user reset-failed container-onlyoffice.service systemctl --user start container-onlyoffice.service
WantedBy=default.target starts it. Do not systemctl enable a Quadlet unit. Do not podman generate systemd.
Drop the fonts Volume= line if you have no custom fonts.
JWT header must be Authorization, not AuthorizationJwt.
sleep 90
systemctl --user is-active container-onlyoffice.service
podman inspect onlyoffice --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}'
curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
podman exec onlyoffice supervisorctl status
Expect active, cpus=4000000000, memory=8589934592, HTTP 200, and ds:converter / ds:docservice RUNNING. First start takes about 90 seconds.
/usr/local/bin/upgrade-onlyoffice.sh. A tag change is an edit to Image= in the .container file before daemon-reload. The script does not recreate the unit.
#!/bin/bash
set -euo pipefail
podman pull docker.io/onlyoffice/documentserver:latest
systemctl --user stop container-onlyoffice.service
systemctl --user daemon-reload
systemctl --user reset-failed container-onlyoffice.service
systemctl --user start container-onlyoffice.service
sleep 90
curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
Run it as worker:
su - worker -c '/bin/bash /usr/local/bin/upgrade-onlyoffice.sh'
Do not sudo -u worker. That drops the session bus.
a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl
/etc/apache2/sites-available/files.haacksnetworking.org.conf:
<VirtualHost *:80>
ServerName files.haacksnetworking.org
RewriteEngine On
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
<VirtualHost *:443>
ServerName files.haacksnetworking.org
SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/files.haacksnetworking.org/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/files.haacksnetworking.org/privkey.pem
Include /etc/letsencrypt/options-ssl-apache.conf
SetEnvIf Host "^(.*)$" THE_HOST=$1
RequestHeader setifempty X-Forwarded-Proto "https"
RequestHeader setifempty X-Forwarded-Host %{THE_HOST}e
ProxyAddHeaders Off
ProxyPreserveHost On
RewriteEngine On
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteRule ^/?(.*) "ws://127.0.0.1:8082/$1" [P,L]
ProxyPass / http://127.0.0.1:8082/
ProxyPassReverse / http://127.0.0.1:8082/
ErrorLog ${APACHE_LOG_DIR}/onlyoffice-error.log
CustomLog ${APACHE_LOG_DIR}/onlyoffice-access.log combined
</VirtualHost>
a2ensite files.haacksnetworking.org.conf apache2ctl configtest && systemctl reload apache2 curl -sI https://files.haacksnetworking.org/healthcheck
Admin → ONLYOFFICE:
https://files.haacksnetworking.org~/onlyoffice/jwt.secret
JWT header must be Authorization.
— oemb1905 2026/10/10 03:15