Deployment Overview of OnlyOffice on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Ubuntu
-
Privileges: Root or sudo access is required for installing Docker and managing containers.
-
Ports:
-
8080/TCP: Internal application traffic (localhost). -
443/TCP: External HTTPS traffic via Nginx proxy.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | only-docs |
| Domain | hostkey.in |
| Full template | only-docs{Server_ID}.hostkey.in |
Application installation process¶
The application is deployed using a combination of Docker container orchestration and an Nginx reverse proxy setup:
-
Docker Installation: The system environment is prepared by installing the Docker engine.
-
Application Deployment: The OnlyOffice Docs container is started using the
onlyoffice/documentserver:9.3image. -
Proxy Configuration: An Nginx service is deployed via Docker Compose to handle SSL termination and traffic routing.
Access Rights and Security¶
-
Firewall: Access is restricted to port
443for external users. The application itself listens on127.0.0.1:8080to prevent direct exposure to the public internet. -
JWT Security: JSON Web Token (JWT) security is enabled by default to secure communication between the document server and integrated applications.
Docker Containers and Their Deployment¶
The deployment consists of two primary containerized components:
OnlyOffice Docs Container¶
-
Image:
onlyoffice/documentserver:9.3 -
Ports:
127.0.0.1:8080:80 -
Environment Variables:
-
JWT_ENABLED:true -
JWT_SECRET:change_me -
Restart Policy:
always
Nginx Proxy Container¶
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Volumes:
-
nginx_secrets:/etc/letsencrypt(SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(User configuration files) -
Restart Policy:
unless-stopped
Custom Scripts and Additional Setup¶
The deployment includes automated configuration updates to ensure the Nginx proxy correctly routes traffic to the application:
-
Proxy Configuration Update: A script modifies the Nginx configuration file located at
/data/nginx/user_conf.d/{prefix}{server_id}.hostkey.in.conf. It replaces existingproxy_passdirectives withproxy_pass http://127.0.0.1:8080;to ensure traffic is directed to the local OnlyOffice container. -
Directory Setup: The directory
/root/nginxis created to manage the Nginx Docker Compose configuration.
Application Update Instructions¶
To update the main application, perform the following steps:
-
Pull the latest image for the document server.
-
Recreate the container to apply changes:
Location of configuration files and data¶
-
Nginx Configuration Directory:
/root/nginx -
User Nginx Configs:
/data/nginx/user_conf.d/ -
SSL Certificates: Managed via the
nginx_secretsDocker volume.
Available ports for connection¶
| Port | Protocol | Usage |
|---|---|---|
443 | TCP | External HTTPS Access |
8080 | TCP | Internal Application Service (Localhost only) |