OneSync
OneSync 是面向 Unraid 的 OneDrive 双向同步管理容器,基于维护活跃的 abraunegg/onedrive。它提供浏览器管理页、设备代码授权、文件夹范围选择、单次同步、持续同步、受控重同步、中文日志和企业微信通知。
v0.1.18 组网地址部署修复
Unraid XML、Compose 与部署示例统一使用当前组网地址 100.103.237.80,避免容器只绑定组网地址时反向代理仍指向旧局域网地址
反向代理域名 one.speedtest.waning.site 可加入 ONESYNC_ALLOWED_HOSTS,并继续通过 ONESYNC_FORWARDED_ALLOW_IPS 校验可信代理来源
v0.1.17 反向代理来源修复
修复反向代理终止 HTTPS 时,管理页写请求被误判为跨来源而无法停止或控制同步的问题
增加 ONESYNC_FORWARDED_ALLOW_IPS,仅信任显式配置的代理来源并保留 Host、Origin 与跨站请求校验
v0.1.16 OpenSSL 安全更新
镜像构建阶段升级 Debian OpenSSL 包,修复基础镜像中的已知高危漏洞
保留 ONESYNC_ALLOWED_HOSTS=* 反向代理 Host 通配支持
v0.1.15 反代 Host 通配支持
ONESYNC_ALLOWED_HOSTS=* 可接受任意有效反向代理 Host
写操作继续执行 Origin 与 Host 同源校验
v0.1.14 Graph 通知防打扰
Graph 探测从每 15 秒降为每分钟一次,单次等待从 8 秒调整为 20 秒
只有连续 3 次探测失败才发送 Graph 掉线通知,同类通知至少间隔 30 分钟
通知事件开关现在生效
v0.1.13 持续监控自动恢复
在持续同步已启用时手动执行“同步一次”,任务结束后自动恢复持续监控
避免单次同步正常退出后停留在 stopped,确保后续本地与云端改动继续自动同步
v0.1.12 网络抗抖与连接恢复
针对长下载增加低并发、较长连接/数据等待和短空闲连接复用参数
Unraid 部署同步关闭 Realtek r8169 网卡 EEE,降低链路抖动导致的下载中断
v0.1.11 空闲传输状态修复
v0.1.10 HTTP 授权码复制修复
为非 HTTPS 的 Unraid 管理页增加浏览器兼容复制回退和清晰结果提示
v0.1.9 构建热修复
修复 React 前端构建阶段的基础镜像参数作用域,恢复发布流水线
v0.1.8 React 前端与免口令访问
管理页改为 React + TypeScript + 原生 CSS,保留同步、授权、范围、通知、日志与关于页功能
移除内置管理口令与浏览器会话,LAN 内直接访问管理页
容器将两个挂载根目录设置为 drwxrwxrwx,便于 Unraid、SMB 与同步进程协作
v0.1.7 Graph 状态热修复
恢复独立的 Graph 连通性校验,保持管理页健康状态轻量且不阻塞
v0.1.6 交互与重同步可见性更新
深色紧凑管理界面,统一同步、通知、关于页面的视觉层级
健康状态改为本地快速响应,避免慢速 Graph 请求阻塞管理页
日志仅读取最近记录并按传输、完成、警告、错误分色
重同步显示云端条目扫描数、待下载数和当前工作阶段
HTTP 403 下载失败按单个文件归因,避免多个失败项混淆
v0.1.5 同步稳定性修复
网络不稳定场景将 OneDrive 并发线程固定为 3,降低 Graph 连接被对端重置的概率
下载失败事件识别超过本地 255 字节上限的文件名,并提示在云端缩短名称
保留 HTTP/1.1、IPv4 和传输指标配置
v0.1.4 安全更新
增加严格 Host/Origin 校验、跨站请求防护和 API 速率限制
管理端口仅绑定指定 Unraid LAN 地址
Webhook 仅允许 HTTPS 企业微信机器人,并拒绝私网 DNS、环境代理与重定向
固定基础镜像摘要,使用带哈希的 Python 依赖锁定文件
构建阶段自动运行测试,生产镜像移除 pip、setuptools 和 wheel
发布流水线加入 Gitleaks、Hadolint、Trivy、Semgrep、SBOM、provenance 与 Cosign 签名
快速部署
镜像:docker.io/waning/onesync:latest 或 docker.io/waning/onesync:0.1.18
必填配置:
GRAPH_CLIENT_ID:Entra 应用 Client ID
GRAPH_TENANT_ID:租户 ID 或域名
ONESYNC_ALLOWED_HOSTS:允许访问的 Unraid IP 或域名;设为 * 可接受任意有效 Host
ONESYNC_FORWARDED_ALLOW_IPS:可信反向代理来源地址或网段;仅填写实际代理来源
持久化目录:
/onedrive/conf:授权、数据库和私有配置
/onedrive/data:真实同步文件
默认管理端口为 8098。只应绑定可信 LAN/VPN 地址,禁止直接暴露公网。升级前请备份两个持久化目录和部署配置。
完整 Compose、Unraid XML、Entra 权限、升级和回滚说明:
github.com/Wning-ady/OneSync
OneSync is a bidirectional OneDrive sync manager for Unraid, built on the maintained abraunegg/onedrive client. It provides a browser UI, device-code authorization, selective folder sync, one-shot and continuous sync, controlled resync, logs, and WeCom notifications.
v0.1.17 Reverse-proxy Origin Fix
Fix management writes being rejected as cross-origin when a reverse proxy terminates HTTPS
Add ONESYNC_FORWARDED_ALLOW_IPS for explicit trusted proxy sources while retaining Host, Origin, and cross-site request checks
v0.1.16 OpenSSL Security Update
Upgrade Debian OpenSSL packages during the image build to fix a known high-severity vulnerability in the base image
Retain ONESYNC_ALLOWED_HOSTS=* reverse-proxy Host wildcard support
v0.1.15 Reverse-proxy Host Wildcard Support
ONESYNC_ALLOWED_HOSTS=* accepts any valid reverse-proxy Host
Write operations still enforce same-origin Origin/Host validation
v0.1.14 Graph Notification Noise Control
Run Graph probes once per minute instead of every 15 seconds, and extend the single probe wait from 8 to 20 seconds
Send a Graph-disconnected notification only after three consecutive failed probes, then apply a 30-minute cooldown for the same event
Make notification event toggles effective
v0.1.13 Continuous Monitor Restore
When continuous sync was enabled, running a one-shot sync now restores monitoring after the task finishes
Prevent a successful one-shot sync from leaving the manager stopped, so later local and cloud changes continue syncing automatically
v0.1.12 Network Resilience
Add low-concurrency, longer connection/data waits, and shorter idle connection reuse for long downloads
The Unraid deployment disables Realtek r8169 EEE to reduce link flaps that interrupt downloads
v0.1.11 Idle Transfer Status Fix
Do not render an unavailable pending-download count as null while the engine is idle
v0.1.10 HTTP Device-code Copy Fix
Add a compatible clipboard fallback and visible result for non-HTTPS Unraid management pages
v0.1.9 Build Hotfix
Fix the React frontend-builder base-image argument scope and restore the release pipeline
v0.1.8 React UI and Password-Free LAN Access
React + TypeScript + native CSS management UI with sync, authorization, scope, notifications, logs, and about views
Remove built-in admin-token sessions for direct trusted-LAN access
Set both mounted root directories to drwxrwxrwx for Unraid, SMB, and sync-process collaboration
v0.1.7 Graph Status Hotfix
Restore independent Graph connectivity checks while keeping management health lightweight and non-blocking
v0.1.6 Interaction and Resync Visibility
Compact dark management interface with consistent sync, notifications, and about views
Local fast health responses so slow Graph calls do not block the management page
Recent log window with transfer, completion, warning, and error colors
Resync visibility for scanned cloud items, planned downloads, and current work phase
Per-file HTTP 403 classification to keep multiple failures distinct
v0.1.5 Sync Stability Fix
Fix OneDrive worker concurrency at 3 to reduce Graph peer resets on unstable links
Detect local 255-byte filename limit failures and explain that the cloud name must be shortened
Keep HTTP/1.1, IPv4, and transfer metrics enabled
v0.1.4 Security Update
Strict Host/Origin validation, cross-site request protection, and API rate limiting
Management port binding to an explicit Unraid LAN address
HTTPS-only WeCom webhook allowlist with private-DNS, proxy, and redirect rejection
Digest-pinned base image and hash-locked Python dependencies
Build-time tests and removal of pip, setuptools, and wheel from the production image
CI security gates plus SBOM, provenance, and keyless Cosign signing
Quick Deployment
Image: docker.io/waning/onesync:latest or docker.io/waning/onesync:0.1.16
Required settings:
GRAPH_CLIENT_ID: Entra application client ID
GRAPH_TENANT_ID: tenant ID or domain
ONESYNC_ALLOWED_HOSTS: allowed Unraid IP addresses or hostnames; set it to * to accept any valid Host
Persistent paths:
/onedrive/conf: authorization, database, and private configuration
/onedrive/data: synchronized files
The management service uses port 8098. Bind it only to a trusted LAN or VPN address and never expose it directly to the internet. Back up both persistent paths and the deployment configuration before upgrading.
Full deployment and recovery documentation:
github.com/Wning-ady/OneSync