Deployment Overview of Onlyoffice Workspace on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Debian (specifically Bookworm is supported).
-
Privileges: Root or sudo access is required for package installation and Docker configuration.
-
System Configuration: The system must have
vsyscall=emulateset in the GRUB command line (GRUB_CMDLINE_LINUX_DEFAULT) to ensure compatibility with certain containerized services. -
Network/Ports:
-
Port
80: HTTP (used for redirection and Let's Encrypt challenges). -
Port
443: HTTPS (main application access). -
Port
25,143,587: Mail server communication.
FQDN of the final panel on the hostkey.in domain¶
The application uses a dynamic Fully Qualified Domain Name (FQDN) based on the server ID and a specific prefix.
| Parameter | Value |
|---|---|
| Prefix | only-docwork |
| Domain | hostkey.in |
| Full template | only-docwork{Server_ID}.hostkey.in |
File and Directory Structure¶
The deployment utilizes several specific directories for configuration, data persistence, and SSL management:
-
/opt/Docker-CommunityServer: Contains the application source files, Docker Compose configurations, and database initialization scripts. -
/root/nginx: Stores the Nginx reverse proxy configuration and compose files. -
/data/nginx/user_conf.d: Location for custom Nginx virtual host configurations. -
/etc/letsencrypt: Managed directory for SSL certificates (via a Docker volume).
Application Installation Process¶
The installation is performed using a multi-step process involving package management, repository configuration, and container orchestration:
-
System Preparation: The system updates the package cache and installs essential utilities including
git,curl, andca-certificates. -
Docker Engine Installation: If Docker is not present, the installer adds the official Docker GPG key and repository, then installs
docker-ce,docker-ce-cli,containerd.io,docker-buildx-plugin, anddocker-compose-plugin. -
Source Retrieval: The application source code is cloned from the official GitHub repository into
/opt/Docker-CommunityServerat a specific version tag. -
Configuration Setup:
-
A
docker-compose.ymlfile is generated in the application directory. -
A MySQL initialization script (
onlyoffice-initdb.sql) is placed in the container's entrypoint directory to pre-configure databases and users. -
Container Orchestration: The deployment uses Docker Compose to pull images and start the service stack.
Access Rights and Security¶
Security is enforced through several mechanisms:
-
Database Security: Custom SQL scripts are used to create specific users (
onlyoffice_user,mail_admin) with restricted privileges, moving away from default root access where possible. -
JWT Authentication: JSON Web Tokens (JWT) are enabled for the Document Server to secure communication between components using a unique secret key.
-
SSL/TLS: An Nginx reverse proxy handles SSL termination using certificates obtained via Certbot.
-
Network Isolation: All application containers are placed within a dedicated Docker network named
onlyoffice.
Databases¶
The deployment includes an integrated MySQL database service to manage all workspace data.
| Database Name | Purpose |
|---|---|
onlyoffice | Core application and Document Server data |
onlyoffice_mailserver | Mail server specific data |
-
Connection Method: Containers communicate via the internal Docker network using the hostname
onlyoffice-mysql-server. -
Storage Location: Data is persisted in a Docker volume named
mysql_data.
Docker Containers and Their Deployment¶
The application is composed of several interconnected containers:
| Container Name | Image | Purpose | Restart Policy |
|---|---|---|---|
onlyoffice-mysql-server | mysql:<version> | Database management | always |
onlyoffice-community-server | onlyoffice/communityserver:<tag> | Main workspace application | always |
onlyoffice-elasticsearch | onlyoffice/elasticsearch:<tag> | Search and indexing | always |
onlyoffice-document-server | onlyoffice/documentserver:<tag> | Document editing engine | always |
onlyoffice-mail-server | onlyoffice/mailserver:<tag> | Email services | always |
onlyoffice-control-panel | onlyoffice/controlpanel:<tag> | Administrative interface | always |
Custom Scripts and Additional Setup¶
The deployment includes specific initialization actions:
-
Database Initialization: A custom SQL script (
onlyoffice-initdb.sql) is injected into the MySQL container to automate the creation of databases, users, and permission grants during the first boot. -
Nginx Configuration Generation: A template-based configuration is generated for Nginx to handle proxying requests from the public FQDN to the internal
onlyoffice-community-serveron port 80.
Application Update Instructions¶
To update the main application, follow these steps:
-
Navigate to the application directory:
-
Pull the latest images and restart the services:
Location of Configuration Files and Data¶
| Component | Path / Volume Name |
|---|---|
| Docker Compose File | /opt/Docker-CommunityServer/docker-compose.yml |
| Nginx Configs | /data/nginx/user_conf.d/ |
| MySQL Data | mysql_data (Docker Volume) |
| Community Server Data | community_data (Docker Volume) |
| Document Server Data | document_data (Docker Volume) |
Available Ports for Connection¶
-
80: HTTP (Redirect to HTTPS).
-
443: HTTPS (Application Access).
-
25, 143, 587: Mail protocols.
Starting and Stopping the Application¶
The application is managed via Docker Compose from the /opt/Docker-CommunityServer directory:
-
Start all services:
docker compose up -d -
Stop all services:
docker compose down -
Check status of containers:
docker compose ps