Ansible role for installing and configuring OnlyOffice
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: OnlyOffice
Installs and configures the OnlyOffice Document Server, a self-hosted office suite, as a Docker container.
Requirements
Docker and the community.docker collection on the host. The role needs root.
Dependencies
The onlyoffice role itself declares none (dependencies: []). The playbook runs these roles first, all fetched
from roles/requirements.yml:
| Role | Repository |
|---|---|
docker |
https://git.simoncor.net/ansible/docker.git |
traefik |
https://git.simoncor.net/ansible/traefik.git |
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
onlyoffice_jwt_secret |
Yes | "change_me" |
JWT secret for the OnlyOffice API. The default is a placeholder and must be overridden |
The role also reads timezone (used for the container TZ), which is not defined by this role and has to come
from the inventory or another role.
Example
The JWT secret belongs in sops-encrypted inventory vars.
timezone: "Europe/Amsterdam"
onlyoffice_jwt_secret: "<sops-encrypted secret>"
Usage
Run playbook.yaml via Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on
the controller, then includes the docker, traefik and onlyoffice roles on all hosts.
Operational notes
- Image:
cr.simoncor.net/dockerhub/onlyoffice/documentserver:9.4.0.1(always pulled), containeronlyoffice, restart policyalways, json-file logs (10m, 3 files). - Port
8000on the host is published to port80in the container. The role sets no Traefik labels. - Data directories on the host:
/mnt/onlyoffice/logs,/mnt/onlyoffice/dataand/mnt/onlyoffice/lib. - After the install the role runs a Docker prune of all unused containers, images, networks and volumes on the host,
and then repeats it with
docker system prune --all --force --volumes.