2 GHz 或更高2 GB 或更多40 GB 的可用空间3.10 或更高版本的 amd64 Linux 发行版4 GB 的交换空间Docker 1.10 或更高版本# 镜像来源
FROM knoxzhang/oo-ce-docker-license:7.0.1.38
# 设置时区
ENV TZ=Asia/Shanghai
ENV DEBIAN_FRONTEND=noninteractive
# 设置时区为上海
RUN apt-get update \
&& apt-get install -y tzdata \
&& ln -fs /usr/share/zoneinfo/${TZ} /etc/localtime \
&& echo ${TZ} > /etc/timezone \
&& dpkg-reconfigure --frontend noninteractive tzdata \
&& rm -rf /var/lib/apt/lists/*
# 移除一些插件
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/youtube
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/translator
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/zotero
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/mendeley
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/thesaurus
RUN rm -rf /var/www/onlyoffice/documentserver/sdkjs-plugins/ocr
# 移除字体
RUN rm -rf /usr/share/fonts/truetype/dejavu
RUN rm -rf /usr/share/fonts/truetype/liberation
# 导入中文字体
COPY ./fonts/ /usr/share/fonts/
# 修正hightlight js引用问题
RUN sed -i "s/https:\/\/ajax.googleapis.com\/ajax\/libs\/jquery\/2.2.2\/jquery.min.js/vendor\/jQuery-2.2.2-min\/jquery-v2.2.2-min.js/" /var/www/onlyoffice/documentserver/sdkjs-plugins/highlightcode/index.html
# 添加中文字号
RUN sed -i "s/{value:8,displayValue:\"8\"}/{value:42,displayValue:\"初号\"},{value:36,displayValue:\"小初\"},{value:26,displayValue:\"一号\"},{value:24,displayValue:\"小一\"},{value:22,displayValue:\"二号\"},{value:18,displayValue:\"小二\"},{value:16,displayValue:\"三号\"},{value:15,displayValue:\"小三\"},{value:14,displayValue:\"四号\"},{value:12,displayValue:\"小四\"},{value:10.5,displayValue:\"五号\"},{value:9,displayValue:\"小五\"},{value:7.5,displayValue:\"六号\"},{value:6.5,displayValue:\"小六\"},{value:5.5,displayValue:\"七号\"},{value:5,displayValue:\"八号\"},{value:8,displayValue:\"8\"}/g" `grep -rwl --include="*.js" "{value:8,displayValue:\"8\"}" /var/www/onlyoffice/documentserver/web-apps/apps`
# 固定字体列表高度
RUN sed -i "s/{cls:\"input-group-nr\",menuStyle:\"min-width: 55px;\"/{cls:\"input-group-nr\",menuStyle:\"min-width: 55px;height: 500px;\"/g" `grep -rwl --include="*.js" "{value:8,displayValue:\"8\"}" /var/www/onlyoffice/documentserver/web-apps/apps`
# 修改文件缓存时间
# 修改24小时为1小时
RUN sed -i "s/86400/3600/" /etc/onlyoffice/documentserver/default.json
EXPOSE 80 443
ARG COMPANY_NAME=onlyoffice
VOLUME /var/log/$COMPANY_NAME /var/lib/$COMPANY_NAME /var/www/$COMPANY_NAME/Data /var/lib/postgresql /var/lib/rabbitmq /var/lib/redis /usr/share/fonts/truetype/custom
ENTRYPOINT ["/app/ds/run-document-server.sh"]
version: '3'
services:
onlyoffice:
container_name: onlyoffice
ports:
- 8099:80
volumes:
- /etc/localtime:/etc/localtime
# ONLYOFFICE文档日志
- /home/onlyoffice/logs:/var/log/onlyoffice
# 用于证书
- /home/onlyoffice/data:/var/www/onlyoffice/Data
# 用于文件缓存
- /home/onlyoffice/lib:/var/lib/onlyoffice
# 字体文件
# - /home/onlyoffice/customfonts:/usr/share/fonts/truetype/custom
environment:
- TZ=Asia/Shanghai
- USER_UID=0
- USER_GID=0
- NGINX_WORKER_CONNECTIONS=100000
- NGINX_WORKER_PROCESSES=2
#- JWT_ENABLED=true
#- JWT_HEADER=only_office
#- JWT_SECRET=0bfb3275c8884ec0afdda3956d430009
#- JWT_IN_BODY=true
- DB_TYPE=mysql
- DB_HOST=127.0.0.1
- DB_PORT=3306
- DB_NAME=onlyoffice
- DB_USER=root
- DB_PWD=123456
restart: unless-stopped
image: nn200433/onlyoffice-cn:latest
| 参数 | 说明 |
|---|---|
| ONLYOFFICE_HTTPS_HSTS_ENABLED | 用于关闭 HSTS 配置的高级配置选项。仅在使用 SSL 时适用。默认为 true |
| ONLYOFFICE_HTTPS_HSTS_MAXAGE | 用于在 onlyoffice NGINX vHost 配置中设置 HSTS max-age 的高级配置选项。仅在使用 SSL 时适用。默认为 31536000 |
| SSL_CERTIFICATE_PATH | 要使用的 SSL 证书的路径。默认为 /var/www/onlyoffice/Data/certs/tls.crt |
| SSL_KEY_PATH | SSL 证书私钥的路径。默认为 /var/www/onlyoffice/Data/certs/tls.key |
| SSL_DHPARAM_PATH | Diffie-Hellman 参数的路径。默认为 /var/www/onlyoffice/Data/certs/dhparam.pem |
| SSL_VERIFY_CLIENT | 启用使用 CA_CERTIFICATES_PATH file 文件验证客户证书,默认为 false |
| DB_TYPE | 数据库类型 支持的值为 postgres , mariadb或 mysql 默认为 postgres |
| DB_HOST | 运行数据库服务器的主机的 IP 地址或名称 |
| DB_PORT | 数据库服务器端口号 |
| DB_NAME | 镜像启动时要创建的数据库的名称 |
| DB_USER | 具有数据库帐户超级用户权限的用户名 |
| DB_PWD | 为数据库帐户设置的密码 |
| AMQP_URI | 连接到消息代理服务器的 AMQP URI |
| AMQP_TYPE | 消息代理类型。支持的值为 rabbitmq 或 activemq 。默认为 rabbitmq |
| REDIS_SERVER_HOST | 运行 Redis 服务器的主机的 IP 地址或名称 |
| REDIS_SERVER_PORT | Redis 服务器端口号 |
| NGINX_WORKER_PROCESSES | 定义 NGINX 工作进程的数量 |
| NGINX_WORKER_CONNECTIONS | 设置 NGINX 工作进程可以同时打开的最大连接数 |
| JWT_ENABLED | 指定 ONLYOFFICE Docs 启用 JSON Web 令牌验证。默认为 false |
| JWT_SECRET | 定义密钥以验证对 ONLYOFFICE Docs 的请求中的 JSON Web 令牌。默认为 secret |
| JWT_HEADER | 定义将用于发送 JSON Web 令牌的 HTTP 标头。默认为 Authorization |
| JWT_IN_BODY | 指定在 ONLYOFFICE Docs 的请求正文中启用令牌验证。默认为 false |
| USE_UNAUTHORIZED_STORAGE | 如果你的存储服务器使用自签名的证书,例如 Nextcloud ,则设置为 true 。默认值为 false 。 |
| GENERATE_FONTS | 如果为 true ,每次启动时都会重新生成字体列表和字体缩略图等。默认值为 true 。 |
| METRICS_ENABLED | 为 ONLYOFFICE Docs 指定启用 StatsD 默认为 false |
| METRICS_HOST | 定义 StatsD 监听主机。默认为 localhost |
| METRICS_PORT | 定义 StatsD 监听端口。默认为 8125 |
| METRICS_PREFIX | 定义后端服务的 StatsD 指标前缀。默认为 ds. 。 |
| LETS_ENCRYPT_DOMAIN | 定义 Let's Encrypt 证书的域 |
| LETS_ENCRYPT_MAIL | 定义 Let's Encrypt 证书的域管理员邮件地址 |
作为在线应用服务运行,通常是需要集成到内部网络中。因此,重要的是要如何配反向代理,并让 ONLYOFFICE Docs 能在代理后正常工作。在下面的文章中,我们提供了 3 种现成的配置示例。
为了使 ONLYOFFICE Docs 能够被客户端主机访问,您需要设置转发的 HTTP标头。它们的目的是在请求通过代理进入服务器时保留有关客户端的信息。您需要设置两种类型的HTTP 标头:X-Forwarded-Proto和X-Forwarded-Host。 X-Forwarded-Proto 标头是一个事实上的标准标头,用于标识客户端用于连接到代理或负载均衡器的协议(HTTP或HTTPS)。 X-Forwarded-Host是一个标准的标头,用于识别客户端在 Host HTTP 请求头中请求的原始主机。
当您需要配置代理时,可能有三种主要情况。以下是如何配置的例子。
当你需要简单地将出站流量重定向到本地服务器时,就会使用这种方案,以下是代理服务器的现成配置:
#Use this example for proxy traffic to the document server running at 'backendserver-address'.
upstream docservice {
server backendserver-address;
}
map $http_host $this_host {
"" $host;
default $http_host;
}
map $http_x_forwarded_proto $the_scheme {
default $http_x_forwarded_proto;
"" $scheme;
}
map $http_x_forwarded_host $the_host {
default $http_x_forwarded_host;
"" $this_host;
}
map $http_upgrade $proxy_connection {
default upgrade;
"" close;
}
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $proxy_connection;
proxy_set_header X-Forwarded-Host $the_host;
proxy_set_header X-Forwarded-Proto $the_scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
server {
listen 0.0.0.0:80;
listen [::]:80 default_server;
server_tokens off;
location / {
proxy_pass http://docservice;
proxy_http_version 1.1;
}
}
当您需要保护连接时使用此场景,所以所有的请求必须自动重定向到HTTPS,以下是代理服务器的现成配置:
# Use this example for proxy HTTPS traffic to the document server running at 'backendserver-address'.
# Replace {{SSL_CERTIFICATE_PATH}} with the path to the ssl certificate file
# Replace {{SSL_KEY_PATH}} with the path to the ssl private key file
upstream docservice {
server backendserver-address;
}
map $http_host $this_host {
"" $host;
default $http_host;
}
map $http_x_forwarded_proto $the_scheme {
default $http_x_forwarded_proto;
"" $scheme;
}
map $http_x_forwarded_host $the_host {
default $http_x_forwarded_host;
"" $this_host;
}
map $http_upgrade $proxy_connection {
default upgrade;
"" close;
}
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $proxy_connection;
proxy_set_header X-Forwarded-Host $the_host;
proxy_set_header X-Forwarded-Proto $the_scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
## Normal HTTP host
server {
listen 0.0.0.0:80;
listen [::]:80 default_server;
server_name _;
server_tokens off;
## Redirects all traffic to the HTTPS host
return 301 https://$server_name:443$request_uri;
}
server {
listen 0.0.0.0:443 ssl;
listen [::]:443 ssl default_server;
server_tokens off;
root /usr/share/nginx/html;
## Strong SSL Security
## https://raymii.org/s/tutorials/Strong_SSL_Security_On_nginx.html
ssl on;
ssl_certificate {{SSL_CERTIFICATE_PATH}};
ssl_certificate_key {{SSL_KEY_PATH}};
ssl_verify_client off;
ssl_ciphers "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH";
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_session_cache builtin:1000 shared:SSL:10m;
ssl_prefer_server_ciphers on;
## [Optional] Before enabling Strict-Transport-Security headers, ensure your server is properly configured for SSL.
## This directive informs the browser to always use HTTPS. For more info see:
## - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
# add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
# add_header X-Frame-Options SAMEORIGIN;
add_header X-Content-Type-Options nosniff;
## [Optional] If your certficate has OCSP, enable OCSP stapling to reduce the overhead and latency of running SSL.
## Replace with your ssl_trusted_certificate. For more info see:
## - https://medium.com/devops-programming/4445f4862461
## - https://www.ruby-forum.com/topic/4419319
## - https://www.digitalocean.com/community/tutorials/how-to-configure-ocsp-stapling-on-apache-and-nginx
# ssl_stapling on;
# ssl_stapling_verify on;
# ssl_trusted_certificate /etc/nginx/ssl/stapling.trusted.crt;
# resolver 208.67.222.222 208.67.222.220 valid=300s; # Can change to your DNS resolver if desired
# resolver_timeout 10s;
## [Optional] Generate a stronger DHE parameter:
## cd /etc/ssl/certs
## sudo openssl dhparam -out dhparam.pem 4096
##
# ssl_dhparam /etc/ssl/certs/dhparam.pem;
location / {
proxy_pass http://docservice;
proxy_http_version 1.1;
}
}
当您需要将主机上的某个目录映射到 Web 服务器中指定的路径时,这是一个合适的方案,以下是代理服务器的现成配置:
#Use this example for the proxy document server running at 'backendserver-address'
# into the virtual directory 'documentserver-virtual-path'.
upstream docservice {
server backendserver-address;
}
map $http_x_forwarded_proto $the_scheme {
default $http_x_forwarded_proto;
"" $scheme;
}
map $http_x_forwarded_host $the_host {
default $http_x_forwarded_host;
"" $host;
}
map $http_upgrade $proxy_connection {
default upgrade;
"" close;
}
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $proxy_connection;
proxy_set_header X-Forwarded-Host $the_host/documentserver-virtual-path;
proxy_set_header X-Forwarded-Proto $the_scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
server {
listen 0.0.0.0:80;
listen [::]:80 default_server;
server_tokens off;
location /documentserver-virtual-path/ {
proxy_pass http://docservice/;
proxy_http_version 1.1;
}
}
Content type
Image
Digest
sha256:cc17b0505…
Size
1.2 GB
Last updated
over 3 years ago
docker pull nn200433/onlyoffice-cn