| Filename | Latest commit message | Latest commit date |
|---|---|---|
| defaults | ||
| meta | ||
| tasks | ||
| .gitignore | ||
| LICENSE | ||
| README.md | ||
onlyoffice
Deploy ONLYOFFICE Document Server as a rootless Podman service.
This role follows the shared deployment role pattern used by other podman based
services. It creates a pod named onlyoffice by default, with the Document
Server container named onlyoffice-server.
Example
onlyoffice_service: onlyoffice
onlyoffice_http_listen: 127.0.0.1:8082
# Store in vault.
onlyoffice_jwt_secret: "{{ vault_onlyoffice_jwt_secret }}"
Use a sufficiently random JWT secret. A practical default is:
openssl rand -base64 48
Extra Document Server environment values can be supplied with
onlyoffice_deploy_env:
onlyoffice_deploy_env:
ALLOW_PRIVATE_IP_ADDRESS: "true"
USE_UNAUTHORIZED_STORAGE: "false"
Storage
The role persists the community edition paths documented by upstream:
data->/var/www/onlyoffice/Datalogs->/var/log/onlyofficelib->/var/lib/onlyoffice
The upstream compose file also declares anonymous volumes for image-populated paths such as fonts and cache directories. This role does not bind mount those paths by default because an empty host directory would hide the files shipped in the image.
Ports
The container serves HTTP on port 80. The default host binding is
127.0.0.1:8082, suitable for a local reverse proxy.
Define onlyoffice_https_listen only when TLS is terminated inside the
Document Server container:
onlyoffice_https_listen: 127.0.0.1:8443
For normal Caddy deployments, leave HTTPS unpublished and terminate TLS in Caddy.
Operational note
ONLYOFFICE recommends running documentserver-prepare4shutdown.sh before
stopping a server with active editing sessions. That command can take several
minutes because it disconnects editors and prepares documents for shutdown.
References: