No description
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-26 18:44:17 +00:00
defaults update 2026-09-26 18:44:17 +00:00
meta update 2026-09-26 18:44:17 +00:00
tasks update 2026-09-26 18:44:17 +00:00
.gitignore update 2026-09-26 18:44:17 +00:00
LICENSE update 2026-09-26 18:44:17 +00:00
README.md update 2026-09-26 18:44:17 +00:00

onlyoffice

Deploy ONLYOFFICE Document Server as a rootless Podman service.

This role follows the shared deployment role pattern used by other podman based services. It creates a pod named onlyoffice by default, with the Document Server container named onlyoffice-server.

Example

onlyoffice_service: onlyoffice
onlyoffice_http_listen: 127.0.0.1:8082

# Store in vault.
onlyoffice_jwt_secret: "{{ vault_onlyoffice_jwt_secret }}"

Use a sufficiently random JWT secret. A practical default is:

openssl rand -base64 48

Extra Document Server environment values can be supplied with onlyoffice_deploy_env:

onlyoffice_deploy_env:
  ALLOW_PRIVATE_IP_ADDRESS: "true"
  USE_UNAUTHORIZED_STORAGE: "false"

Storage

The role persists the community edition paths documented by upstream:

  • data -> /var/www/onlyoffice/Data
  • logs -> /var/log/onlyoffice
  • lib -> /var/lib/onlyoffice

The upstream compose file also declares anonymous volumes for image-populated paths such as fonts and cache directories. This role does not bind mount those paths by default because an empty host directory would hide the files shipped in the image.

Ports

The container serves HTTP on port 80. The default host binding is 127.0.0.1:8082, suitable for a local reverse proxy.

Define onlyoffice_https_listen only when TLS is terminated inside the Document Server container:

onlyoffice_https_listen: 127.0.0.1:8443

For normal Caddy deployments, leave HTTPS unpublished and terminate TLS in Caddy.

Operational note

ONLYOFFICE recommends running documentserver-prepare4shutdown.sh before stopping a server with active editing sessions. That command can take several minutes because it disconnects editors and prepares documents for shutdown.

References: