Sign inSign up

nn200433/onlyoffice-cn

By nn200433

•Updated over 3 years ago

ONLYOFFICE中文字体版(常用中文字体+字号)

Image
2

1.2K

nn200433/onlyoffice-cn repository overview

⁠配置要求

  • CPU:双核 2 GHz 或更高
  • 内存:2 GB 或更多
  • 硬盘:至少 40 GB 的可用空间
  • 操作系统:内核版本为 3.10 或更高版本的 amd64 Linux 发行版
  • 其他要求:
    • 至少 4 GB 的交换空间
    • Docker 1.10 或更高版本

⁠自行编译

⁠Dockerfile
# 镜像来源
FROM knoxzhang/oo-ce-docker-license:7.0.1.38

# 设置时区
ENV TZ=Asia/Shanghai
ENV DEBIAN_FRONTEND=noninteractive

# 设置时区为上海
RUN apt-get update \
    && apt-get install -y tzdata \
    && ln -fs /usr/share/zoneinfo/${TZ} /etc/localtime \
    && echo ${TZ} > /etc/timezone \
    && dpkg-reconfigure --frontend noninteractive tzdata \
    && rm -rf /var/lib/apt/lists/*

# 移除一些插件
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/youtube
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/translator
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/zotero
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/mendeley
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/thesaurus
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/ocr

# 移除字体
RUN rm -rf /usr/share/fonts/truetype/dejavu
RUN rm -rf /usr/share/fonts/truetype/liberation

# 导入中文字体
COPY ./fonts/ /usr/share/fonts/

# 修正hightlight js引用问题
RUN sed -i "s/https:\/\/ajax.googleapis.com\/ajax\/libs\/jquery\/2.2.2\/jquery.min.js/vendor\/jQuery-2.2.2-min\/jquery-v2.2.2-min.js/" /var/www/onlyoffice/documentserver/sdkjs-plugins/highlightcode/index.html

# 添加中文字号
RUN sed -i "s/{value:8,displayValue:\"8\"}/{value:42,displayValue:\"初号\"},{value:36,displayValue:\"小初\"},{value:26,displayValue:\"一号\"},{value:24,displayValue:\"小一\"},{value:22,displayValue:\"二号\"},{value:18,displayValue:\"小二\"},{value:16,displayValue:\"三号\"},{value:15,displayValue:\"小三\"},{value:14,displayValue:\"四号\"},{value:12,displayValue:\"小四\"},{value:10.5,displayValue:\"五号\"},{value:9,displayValue:\"小五\"},{value:7.5,displayValue:\"六号\"},{value:6.5,displayValue:\"小六\"},{value:5.5,displayValue:\"七号\"},{value:5,displayValue:\"八号\"},{value:8,displayValue:\"8\"}/g" `grep -rwl --include="*.js" "{value:8,displayValue:\"8\"}" /var/www/onlyoffice/documentserver/web-apps/apps`

# 固定字体列表高度
RUN sed -i "s/{cls:\"input-group-nr\",menuStyle:\"min-width: 55px;\"/{cls:\"input-group-nr\",menuStyle:\"min-width: 55px;height: 500px;\"/g" `grep -rwl --include="*.js" "{value:8,displayValue:\"8\"}" /var/www/onlyoffice/documentserver/web-apps/apps`

# 修改文件缓存时间
# 修改24小时为1小时
RUN sed -i  "s/86400/3600/" /etc/onlyoffice/documentserver/default.json

EXPOSE 80 443

ARG COMPANY_NAME=onlyoffice
VOLUME /var/log/$COMPANY_NAME /var/lib/$COMPANY_NAME /var/www/$COMPANY_NAME/Data /var/lib/postgresql /var/lib/rabbitmq /var/lib/redis /usr/share/fonts/truetype/custom

ENTRYPOINT ["/app/ds/run-document-server.sh"]
⁠附件

⁠快速运行

⁠docker-compose.yml
version: '3'
services:
  onlyoffice: 
    container_name: onlyoffice
    ports: 
      - 8099:80
    volumes: 
      - /etc/localtime:/etc/localtime
      # ONLYOFFICE文档日志
      - /home/onlyoffice/logs:/var/log/onlyoffice
      # 用于证书
      - /home/onlyoffice/data:/var/www/onlyoffice/Data
      # 用于文件缓存
      - /home/onlyoffice/lib:/var/lib/onlyoffice
      # 字体文件
      # - /home/onlyoffice/customfonts:/usr/share/fonts/truetype/custom
    environment: 
      - TZ=Asia/Shanghai
      - USER_UID=0
      - USER_GID=0
      - NGINX_WORKER_CONNECTIONS=100000
      - NGINX_WORKER_PROCESSES=2
      #- JWT_ENABLED=true
      #- JWT_HEADER=only_office
      #- JWT_SECRET=0bfb3275c8884ec0afdda3956d430009
      #- JWT_IN_BODY=true
      - DB_TYPE=mysql
      - DB_HOST=127.0.0.1
      - DB_PORT=3306
      - DB_NAME=onlyoffice
      - DB_USER=root
      - DB_PWD=123456
    restart: unless-stopped
    image: nn200433/onlyoffice-cn:latest
⁠参数说明
参数说明
ONLYOFFICE_HTTPS_HSTS_ENABLED用于关闭 HSTS 配置的高级配置选项。仅在使用 SSL 时适用。默认为 true
ONLYOFFICE_HTTPS_HSTS_MAXAGE用于在 onlyoffice NGINX vHost 配置中设置 HSTS max-age 的高级配置选项。仅在使用 SSL 时适用。默认为 31536000
SSL_CERTIFICATE_PATH要使用的 SSL 证书的路径。默认为 /var/www/onlyoffice/Data/certs/tls.crt
SSL_KEY_PATHSSL 证书私钥的路径。默认为 /var/www/onlyoffice/Data/certs/tls.key
SSL_DHPARAM_PATHDiffie-Hellman 参数的路径。默认为 /var/www/onlyoffice/Data/certs/dhparam.pem
SSL_VERIFY_CLIENT启用使用 CA_CERTIFICATES_PATH file 文件验证客户证书,默认为 false
DB_TYPE数据库类型 支持的值为 postgres , mariadb或 mysql 默认为 postgres
DB_HOST运行数据库服务器的主机的 IP 地址或名称
DB_PORT数据库服务器端口号
DB_NAME镜像启动时要创建的数据库的名称
DB_USER具有数据库帐户超级用户权限的用户名
DB_PWD为数据库帐户设置的密码
AMQP_URI连接到消息代理服务器的 AMQP URI
AMQP_TYPE消息代理类型。支持的值为 rabbitmq 或 activemq 。默认为 rabbitmq
REDIS_SERVER_HOST运行 Redis 服务器的主机的 IP 地址或名称
REDIS_SERVER_PORTRedis 服务器端口号
NGINX_WORKER_PROCESSES定义 NGINX 工作进程的数量
NGINX_WORKER_CONNECTIONS设置 NGINX 工作进程可以同时打开的最大连接数
JWT_ENABLED指定 ONLYOFFICE Docs 启用 JSON Web 令牌验证。默认为 false
JWT_SECRET定义密钥以验证对 ONLYOFFICE Docs 的请求中的 JSON Web 令牌。默认为 secret
JWT_HEADER定义将用于发送 JSON Web 令牌的 HTTP 标头。默认为 Authorization
JWT_IN_BODY指定在 ONLYOFFICE Docs 的请求正文中启用令牌验证。默认为 false
USE_UNAUTHORIZED_STORAGE如果你的存储服务器使用自签名的证书,例如 Nextcloud ,则设置为 true 。默认值为 false 。
GENERATE_FONTS如果为 true ,每次启动时都会重新生成字体列表和字体缩略图等。默认值为 true 。
METRICS_ENABLED为 ONLYOFFICE Docs 指定启用 StatsD 默认为 false
METRICS_HOST定义 StatsD 监听主机。默认为 localhost
METRICS_PORT定义 StatsD 监听端口。默认为 8125
METRICS_PREFIX定义后端服务的 StatsD 指标前缀。默认为 ds. 。
LETS_ENCRYPT_DOMAIN定义 Let's Encrypt 证书的域
LETS_ENCRYPT_MAIL定义 Let's Encrypt 证书的域管理员邮件地址

⁠反向代理

本文为官方文档⁠机翻!!!

本文仅摘抄 NGINX 方案,若需要 Apache、HAProxy、Traefik 反向代理方案,请前往官方文档⁠

官方文档:Using ONLYOFFICE Docs behind the proxy⁠

⁠前言

作为在线应用服务运行,通常是需要集成到内部网络中。因此,重要的是要如何配反向代理,并让 ONLYOFFICE Docs 能在代理后正常工作。在下面的文章中,我们提供了 3 种现成的配置示例。

为了使 ONLYOFFICE Docs 能够被客户端主机访问,您需要设置转发的 HTTP标头。它们的目的是在请求通过代理进入服务器时保留有关客户端的信息。您需要设置两种类型的HTTP 标头:X-Forwarded-Proto和X-Forwarded-Host。 X-Forwarded-Proto 标头是一个事实上的标准标头,用于标识客户端用于连接到代理或负载均衡器的协议(HTTP或HTTPS)。 X-Forwarded-Host是一个标准的标头,用于识别客户端在 Host HTTP 请求头中请求的原始主机。

当您需要配置代理时,可能有三种主要情况。以下是如何配置的例子。

⁠代理到本地服务器

当你需要简单地将出站流量重定向到本地服务器时,就会使用这种方案,以下是代理服务器的现成配置:

#Use this example for proxy traffic to the document server running at 'backendserver-address'.

upstream docservice {
  server backendserver-address;
}

map $http_host $this_host {
    "" $host;
    default $http_host;
}

map $http_x_forwarded_proto $the_scheme {
     default $http_x_forwarded_proto;
     "" $scheme;
}

map $http_x_forwarded_host $the_host {
    default $http_x_forwarded_host;
    "" $this_host;
}

map $http_upgrade $proxy_connection {
  default upgrade;
  "" close;
}

proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $proxy_connection;
proxy_set_header X-Forwarded-Host $the_host;
proxy_set_header X-Forwarded-Proto $the_scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;


server {
  listen 0.0.0.0:80;
  listen [::]:80 default_server;
  server_tokens off;

  location / {
    proxy_pass http://docservice;
    proxy_http_version 1.1;
  }
}
⁠代理HTTPS到HTTP

当您需要保护连接时使用此场景,所以所有的请求必须自动重定向到HTTPS,以下是代理服务器的现成配置:

# Use this example for proxy HTTPS traffic to the document server running at 'backendserver-address'.
# Replace {{SSL_CERTIFICATE_PATH}} with the path to the ssl certificate file
# Replace {{SSL_KEY_PATH}} with the path to the ssl private key file

upstream docservice {
  server backendserver-address;
}

map $http_host $this_host {
    "" $host;
    default $http_host;
}

map $http_x_forwarded_proto $the_scheme {
     default $http_x_forwarded_proto;
     "" $scheme;
}

map $http_x_forwarded_host $the_host {
    default $http_x_forwarded_host;
    "" $this_host;
}

map $http_upgrade $proxy_connection {
  default upgrade;
  "" close;
}

proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $proxy_connection;
proxy_set_header X-Forwarded-Host $the_host;
proxy_set_header X-Forwarded-Proto $the_scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

## Normal HTTP host
server {
  listen 0.0.0.0:80;
  listen [::]:80 default_server;
  server_name _;
  server_tokens off;

  ## Redirects all traffic to the HTTPS host
  return 301 https://$server_name:443$request_uri;
}

server {
  listen 0.0.0.0:443 ssl;
  listen [::]:443 ssl default_server;
  server_tokens off;
  root /usr/share/nginx/html;

  ## Strong SSL Security
  ## https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html
  ssl on;
  ssl_certificate {{SSL_CERTIFICATE_PATH}};
  ssl_certificate_key {{SSL_KEY_PATH}};
  ssl_verify_client off;

  ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";

  ssl_protocols  TLSv1 TLSv1.1 TLSv1.2;
  ssl_session_cache  builtin:1000  shared:SSL:10m;

  ssl_prefer_server_ciphers   on;

  ## [Optional] Before enabling Strict-Transport-Security headers, ensure your server is properly configured for SSL.
  ## This directive informs the browser to always use HTTPS. For more info see:
  ## - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
  # add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
  # add_header X-Frame-Options SAMEORIGIN;
  add_header X-Content-Type-Options nosniff;

  ## [Optional] If your certficate has OCSP, enable OCSP stapling to reduce the overhead and latency of running SSL.
  ## Replace with your ssl_trusted_certificate. For more info see:
  ## - https://medium.com/devops-programming/4445f4862461
  ## - https://www.ruby-forum.com/topic/4419319
  ## - https://www.digitalocean.com/community/tutorials/how-to-configure-ocsp-stapling-on-apache-and-nginx
  # ssl_stapling on;
  # ssl_stapling_verify on;
  # ssl_trusted_certificate /etc/nginx/ssl/stapling.trusted.crt;
  # resolver 208.67.222.222 208.67.222.220 valid=300s; # Can change to your DNS resolver if desired
  # resolver_timeout 10s;

  ## [Optional] Generate a stronger DHE parameter:
  ##   cd /etc/ssl/certs
  ##   sudo openssl dhparam -out dhparam.pem 4096
  ##
  # ssl_dhparam /etc/ssl/certs/dhparam.pem;

  location / {
    proxy_pass http://docservice;
    proxy_http_version 1.1;
  }
}
⁠虚拟路径

当您需要将主机上的某个目录映射到 Web 服务器中指定的路径时,这是一个合适的方案,以下是代理服务器的现成配置:

#Use this example for the proxy document server running at 'backendserver-address'
# into the virtual directory 'documentserver-virtual-path'.

upstream docservice {
  server backendserver-address;
}

map $http_x_forwarded_proto $the_scheme {
     default $http_x_forwarded_proto;
     "" $scheme;
}

map $http_x_forwarded_host $the_host {
    default $http_x_forwarded_host;
    "" $host;
}

map $http_upgrade $proxy_connection {
  default upgrade;
  "" close;
}

proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $proxy_connection;
proxy_set_header X-Forwarded-Host $the_host/documentserver-virtual-path;
proxy_set_header X-Forwarded-Proto $the_scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;


server {
  listen 0.0.0.0:80;
  listen [::]:80 default_server;
  server_tokens off;

  location /documentserver-virtual-path/ {
    proxy_pass http://docservice/;
    proxy_http_version 1.1;
  }
}

⁠官方开发文档

⁠特别鸣谢

Tag summary

Content type

Image

Digest

sha256:cc17b0505…

Size

1.2 GB

Last updated

over 3 years ago

docker pull nn200433/onlyoffice-cn