User Tools

Site Tools


computing:onlyoffice

This is an old revision of the document!



  • onlyoffice
  • Jonathan Haack
  • Haack's Networking
  • webmaster@haacksnetworking.org

OnlyOffice


Introduction

This tutorial is for Debian users who wish to spin up an Only Office container using podman. It presumes you have a Cockpit container VM/host setup already. If not, head over to Cockpit before you start here. Once podman is setup and you have a dedicated rootless user, you can proceed. To begin with, let's setup a directory for this container and generate our jwt secret:

1. Directories and secret (worker)

mkdir -p ~/onlyoffice/{data,logs,lib,db}
umask 077
openssl rand -hex 32 | tee ~/onlyoffice/jwt.secret
chmod 600 ~/onlyoffice/jwt.secret

This will generate the secret and use tee to place it in the expected directory and file.

2. Quadlet

After the secret is cut, we can now build our quadlet unit to manage the container, restart it on reboot/failure, etc. To do that, let's create our systemd directory and then create our quadlet configuration.

mkdir -p ~/.config/containers/systemd
cat > ~/.config/containers/systemd/container-onlyoffice.container << 'EOF'
[Container]
ContainerName=onlyoffice
Image=docker.io/onlyoffice/documentserver:latest
PublishPort=127.0.0.1:8082:80
Environment=JWT_ENABLED=true
Environment=JWT_SECRET=replace-with-your-jwt-secret
Environment=JWT_HEADER=Authorization
Environment=ALLOW_PRIVATE_IP_ADDRESS=false
Volume=/home/worker/onlyoffice/logs:/var/log/onlyoffice:Z
Volume=/home/worker/onlyoffice/data:/var/www/onlyoffice/Data:Z
Volume=/home/worker/onlyoffice/lib:/var/lib/onlyoffice:Z
Volume=/home/worker/onlyoffice/db:/var/lib/postgresql:Z
Volume=/home/worker/podman-local/volumes/84a360c1a5dd357b0cfe5af71a59f7338eeca694336b1ea8bef5d5c41fe7deb7/_data:/usr/share/fonts/truetype/custom:Z
PodmanArgs=--cpus=4 --memory=8g
[Service]
Restart=always
TimeoutStopSec=120
[Install]
WantedBy=default.target
EOF

systemctl --user daemon-reload
systemctl --user reset-failed container-onlyoffice.service
systemctl --user start container-onlyoffice.service

WantedBy=default.target starts it. Do not systemctl enable a Quadlet unit. Do not podman generate systemd. Drop the fonts Volume= line if you have no custom fonts. JWT header must be Authorization, not AuthorizationJwt.

3. Verify

sleep 90
systemctl --user is-active container-onlyoffice.service
podman inspect onlyoffice --format '{{.Name}} cpus={{.HostConfig.NanoCpus}} memory={{.HostConfig.Memory}}'
curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck
podman exec onlyoffice supervisorctl status

Expect active, cpus=4000000000, memory=8589934592, HTTP 200, and ds:converter / ds:docservice RUNNING. First start takes about 90 seconds.

4. Upgrade script

/usr/local/bin/upgrade-onlyoffice.sh. A tag change is an edit to Image= in the .container file before daemon-reload. The script does not recreate the unit.

#!/bin/bash
set -euo pipefail

podman pull docker.io/onlyoffice/documentserver:latest

systemctl --user stop container-onlyoffice.service
systemctl --user daemon-reload
systemctl --user reset-failed container-onlyoffice.service
systemctl --user start container-onlyoffice.service

sleep 90
curl -sS -o /dev/null -w '%{http_code}\n' http://127.0.0.1:8082/healthcheck

Run it as worker:

su - worker -c '/bin/bash /usr/local/bin/upgrade-onlyoffice.sh'

Do not sudo -u worker. That drops the session bus.

5. Apache reverse proxy (root)

a2enmod proxy proxy_http proxy_wstunnel headers rewrite ssl

/etc/apache2/sites-available/files.haacksnetworking.org.conf:

<VirtualHost *:80>
    ServerName files.haacksnetworking.org
    RewriteEngine On
    RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>

<VirtualHost *:443>
    ServerName files.haacksnetworking.org
    SSLEngine on
    SSLCertificateFile /etc/letsencrypt/live/files.haacksnetworking.org/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/files.haacksnetworking.org/privkey.pem
    Include /etc/letsencrypt/options-ssl-apache.conf
    SetEnvIf Host "^(.*)$" THE_HOST=$1
    RequestHeader setifempty X-Forwarded-Proto "https"
    RequestHeader setifempty X-Forwarded-Host %{THE_HOST}e
    ProxyAddHeaders Off
    ProxyPreserveHost On
    RewriteEngine On
    RewriteCond %{HTTP:Upgrade} websocket [NC]
    RewriteCond %{HTTP:Connection} upgrade [NC]
    RewriteRule ^/?(.*) "ws://127.0.0.1:8082/$1" [P,L]
    ProxyPass / http://127.0.0.1:8082/
    ProxyPassReverse / http://127.0.0.1:8082/
    ErrorLog ${APACHE_LOG_DIR}/onlyoffice-error.log
    CustomLog ${APACHE_LOG_DIR}/onlyoffice-access.log combined
</VirtualHost>
a2ensite files.haacksnetworking.org.conf
apache2ctl configtest && systemctl reload apache2
curl -sI https://files.haacksnetworking.org/healthcheck

6. Nextcloud

Admin → ONLYOFFICE:

JWT header must be Authorization.

Facts

— oemb1905 2026/10/10 03:15

computing/onlyoffice.1791602858.txt.gz · Last modified: by oemb1905