Ansible role for installing and configuring OnlyOffice
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 546992188c
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:21 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:49:36 +00:00
defaults feat: change jwt_secret 2026-05-29 14:39:05 +02:00
meta feat: initial commit 2026-05-29 14:34:39 +02:00
roles feat: initial commit 2026-05-29 14:34:39 +02:00
tasks feat: revert back to onlyoffice image 2026-09-21 08:17:17 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:50 +02:00
.editorconfig feat: initial commit 2026-05-29 14:34:39 +02:00
.gitattributes feat: initial commit 2026-05-29 14:34:39 +02:00
.gitignore feat: initial commit 2026-05-29 14:34:39 +02:00
.markdownlint-cli2.jsonc feat: initial commit 2026-05-29 14:34:39 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:57 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:33 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:04 +02:00
readme.md docs: improve readme 2026-10-05 17:28:21 +02:00
renovate.json feat: initial commit 2026-05-29 14:34:39 +02:00

Ansible Role: OnlyOffice

Installs and configures the OnlyOffice Document Server, a self-hosted office suite, as a Docker container.

Requirements

Docker and the community.docker collection on the host. The role needs root.

Dependencies

The onlyoffice role itself declares none (dependencies: []). The playbook runs these roles first, all fetched from roles/requirements.yml:

Role Repository
docker https://git.simoncor.net/ansible/docker.git
traefik https://git.simoncor.net/ansible/traefik.git

Variables

Variable Required Default Description
onlyoffice_jwt_secret Yes "change_me" JWT secret for the OnlyOffice API. The default is a placeholder and must be overridden

The role also reads timezone (used for the container TZ), which is not defined by this role and has to come from the inventory or another role.

Example

The JWT secret belongs in sops-encrypted inventory vars.

timezone: "Europe/Amsterdam"
onlyoffice_jwt_secret: "<sops-encrypted secret>"

Usage

Run playbook.yaml via Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on the controller, then includes the docker, traefik and onlyoffice roles on all hosts.

Operational notes

  • Image: cr.simoncor.net/dockerhub/onlyoffice/documentserver:9.4.0.1 (always pulled), container onlyoffice, restart policy always, json-file logs (10m, 3 files).
  • Port 8000 on the host is published to port 80 in the container. The role sets no Traefik labels.
  • Data directories on the host: /mnt/onlyoffice/logs, /mnt/onlyoffice/data and /mnt/onlyoffice/lib.
  • After the install the role runs a Docker prune of all unused containers, images, networks and volumes on the host, and then repeats it with docker system prune --all --force --volumes.