Sign inSign up

waning/onesync

By waning

•Updated 27 days ago

安全、可控的 Unraid OneDrive 选择性双向同步管理器

Image
0

5.7K

waning/onesync repository overview

OneSync logo

⁠OneSync

OneSync 是面向 Unraid 的 OneDrive 双向同步管理容器,基于维护活跃的 abraunegg/onedrive。它提供浏览器管理页、设备代码授权、文件夹范围选择、单次同步、持续同步、受控重同步、中文日志和企业微信通知。

⁠v0.1.18 组网地址部署修复

  • Unraid XML、Compose 与部署示例统一使用当前组网地址 100.103.237.80,避免容器只绑定组网地址时反向代理仍指向旧局域网地址
  • 反向代理域名 one.speedtest.waning.site 可加入 ONESYNC_ALLOWED_HOSTS,并继续通过 ONESYNC_FORWARDED_ALLOW_IPS 校验可信代理来源

⁠v0.1.17 反向代理来源修复

  • 修复反向代理终止 HTTPS 时,管理页写请求被误判为跨来源而无法停止或控制同步的问题
  • 增加 ONESYNC_FORWARDED_ALLOW_IPS,仅信任显式配置的代理来源并保留 Host、Origin 与跨站请求校验

⁠v0.1.16 OpenSSL 安全更新

  • 镜像构建阶段升级 Debian OpenSSL 包,修复基础镜像中的已知高危漏洞
  • 保留 ONESYNC_ALLOWED_HOSTS=* 反向代理 Host 通配支持

⁠v0.1.15 反代 Host 通配支持

  • ONESYNC_ALLOWED_HOSTS=* 可接受任意有效反向代理 Host
  • 写操作继续执行 Origin 与 Host 同源校验

⁠v0.1.14 Graph 通知防打扰

  • Graph 探测从每 15 秒降为每分钟一次,单次等待从 8 秒调整为 20 秒
  • 只有连续 3 次探测失败才发送 Graph 掉线通知,同类通知至少间隔 30 分钟
  • 通知事件开关现在生效

⁠v0.1.13 持续监控自动恢复

  • 在持续同步已启用时手动执行“同步一次”,任务结束后自动恢复持续监控
  • 避免单次同步正常退出后停留在 stopped,确保后续本地与云端改动继续自动同步

⁠v0.1.12 网络抗抖与连接恢复

  • 针对长下载增加低并发、较长连接/数据等待和短空闲连接复用参数
  • Unraid 部署同步关闭 Realtek r8169 网卡 EEE,降低链路抖动导致的下载中断

⁠v0.1.11 空闲传输状态修复

  • 空闲时不再把未提供的待下载数量显示为 null

⁠v0.1.10 HTTP 授权码复制修复

  • 为非 HTTPS 的 Unraid 管理页增加浏览器兼容复制回退和清晰结果提示

⁠v0.1.9 构建热修复

  • 修复 React 前端构建阶段的基础镜像参数作用域,恢复发布流水线

⁠v0.1.8 React 前端与免口令访问

  • 管理页改为 React + TypeScript + 原生 CSS,保留同步、授权、范围、通知、日志与关于页功能
  • 移除内置管理口令与浏览器会话,LAN 内直接访问管理页
  • 容器将两个挂载根目录设置为 drwxrwxrwx,便于 Unraid、SMB 与同步进程协作

⁠v0.1.7 Graph 状态热修复

  • 恢复独立的 Graph 连通性校验,保持管理页健康状态轻量且不阻塞

⁠v0.1.6 交互与重同步可见性更新

  • 深色紧凑管理界面,统一同步、通知、关于页面的视觉层级
  • 健康状态改为本地快速响应,避免慢速 Graph 请求阻塞管理页
  • 日志仅读取最近记录并按传输、完成、警告、错误分色
  • 重同步显示云端条目扫描数、待下载数和当前工作阶段
  • HTTP 403 下载失败按单个文件归因,避免多个失败项混淆

⁠v0.1.5 同步稳定性修复

  • 网络不稳定场景将 OneDrive 并发线程固定为 3,降低 Graph 连接被对端重置的概率
  • 下载失败事件识别超过本地 255 字节上限的文件名,并提示在云端缩短名称
  • 保留 HTTP/1.1、IPv4 和传输指标配置

⁠v0.1.4 安全更新

  • 增加严格 Host/Origin 校验、跨站请求防护和 API 速率限制
  • 管理端口仅绑定指定 Unraid LAN 地址
  • Webhook 仅允许 HTTPS 企业微信机器人,并拒绝私网 DNS、环境代理与重定向
  • 固定基础镜像摘要,使用带哈希的 Python 依赖锁定文件
  • 构建阶段自动运行测试,生产镜像移除 pip、setuptools 和 wheel
  • 发布流水线加入 Gitleaks、Hadolint、Trivy、Semgrep、SBOM、provenance 与 Cosign 签名

⁠快速部署

镜像:docker.io/waning/onesync:latest 或 docker.io/waning/onesync:0.1.18

必填配置:

  • GRAPH_CLIENT_ID:Entra 应用 Client ID
  • GRAPH_TENANT_ID:租户 ID 或域名
  • ONESYNC_ALLOWED_HOSTS:允许访问的 Unraid IP 或域名;设为 * 可接受任意有效 Host
  • ONESYNC_FORWARDED_ALLOW_IPS:可信反向代理来源地址或网段;仅填写实际代理来源

持久化目录:

  • /onedrive/conf:授权、数据库和私有配置
  • /onedrive/data:真实同步文件

默认管理端口为 8098。只应绑定可信 LAN/VPN 地址,禁止直接暴露公网。升级前请备份两个持久化目录和部署配置。

完整 Compose、Unraid XML、Entra 权限、升级和回滚说明: github.com/Wning-ady/OneSync⁠


OneSync is a bidirectional OneDrive sync manager for Unraid, built on the maintained abraunegg/onedrive client. It provides a browser UI, device-code authorization, selective folder sync, one-shot and continuous sync, controlled resync, logs, and WeCom notifications.

⁠v0.1.17 Reverse-proxy Origin Fix

  • Fix management writes being rejected as cross-origin when a reverse proxy terminates HTTPS
  • Add ONESYNC_FORWARDED_ALLOW_IPS for explicit trusted proxy sources while retaining Host, Origin, and cross-site request checks

⁠v0.1.16 OpenSSL Security Update

  • Upgrade Debian OpenSSL packages during the image build to fix a known high-severity vulnerability in the base image
  • Retain ONESYNC_ALLOWED_HOSTS=* reverse-proxy Host wildcard support

⁠v0.1.15 Reverse-proxy Host Wildcard Support

  • ONESYNC_ALLOWED_HOSTS=* accepts any valid reverse-proxy Host
  • Write operations still enforce same-origin Origin/Host validation

⁠v0.1.14 Graph Notification Noise Control

  • Run Graph probes once per minute instead of every 15 seconds, and extend the single probe wait from 8 to 20 seconds
  • Send a Graph-disconnected notification only after three consecutive failed probes, then apply a 30-minute cooldown for the same event
  • Make notification event toggles effective

⁠v0.1.13 Continuous Monitor Restore

  • When continuous sync was enabled, running a one-shot sync now restores monitoring after the task finishes
  • Prevent a successful one-shot sync from leaving the manager stopped, so later local and cloud changes continue syncing automatically

⁠v0.1.12 Network Resilience

  • Add low-concurrency, longer connection/data waits, and shorter idle connection reuse for long downloads
  • The Unraid deployment disables Realtek r8169 EEE to reduce link flaps that interrupt downloads

⁠v0.1.11 Idle Transfer Status Fix

  • Do not render an unavailable pending-download count as null while the engine is idle

⁠v0.1.10 HTTP Device-code Copy Fix

  • Add a compatible clipboard fallback and visible result for non-HTTPS Unraid management pages

⁠v0.1.9 Build Hotfix

  • Fix the React frontend-builder base-image argument scope and restore the release pipeline

⁠v0.1.8 React UI and Password-Free LAN Access

  • React + TypeScript + native CSS management UI with sync, authorization, scope, notifications, logs, and about views
  • Remove built-in admin-token sessions for direct trusted-LAN access
  • Set both mounted root directories to drwxrwxrwx for Unraid, SMB, and sync-process collaboration

⁠v0.1.7 Graph Status Hotfix

  • Restore independent Graph connectivity checks while keeping management health lightweight and non-blocking

⁠v0.1.6 Interaction and Resync Visibility

  • Compact dark management interface with consistent sync, notifications, and about views
  • Local fast health responses so slow Graph calls do not block the management page
  • Recent log window with transfer, completion, warning, and error colors
  • Resync visibility for scanned cloud items, planned downloads, and current work phase
  • Per-file HTTP 403 classification to keep multiple failures distinct

⁠v0.1.5 Sync Stability Fix

  • Fix OneDrive worker concurrency at 3 to reduce Graph peer resets on unstable links
  • Detect local 255-byte filename limit failures and explain that the cloud name must be shortened
  • Keep HTTP/1.1, IPv4, and transfer metrics enabled

⁠v0.1.4 Security Update

  • Strict Host/Origin validation, cross-site request protection, and API rate limiting
  • Management port binding to an explicit Unraid LAN address
  • HTTPS-only WeCom webhook allowlist with private-DNS, proxy, and redirect rejection
  • Digest-pinned base image and hash-locked Python dependencies
  • Build-time tests and removal of pip, setuptools, and wheel from the production image
  • CI security gates plus SBOM, provenance, and keyless Cosign signing

⁠Quick Deployment

Image: docker.io/waning/onesync:latest or docker.io/waning/onesync:0.1.16

Required settings:

  • GRAPH_CLIENT_ID: Entra application client ID
  • GRAPH_TENANT_ID: tenant ID or domain
  • ONESYNC_ALLOWED_HOSTS: allowed Unraid IP addresses or hostnames; set it to * to accept any valid Host

Persistent paths:

  • /onedrive/conf: authorization, database, and private configuration
  • /onedrive/data: synchronized files

The management service uses port 8098. Bind it only to a trusted LAN or VPN address and never expose it directly to the internet. Back up both persistent paths and the deployment configuration before upgrading.

Full deployment and recovery documentation: github.com/Wning-ady/OneSync⁠

Tag summary

Content type

Image

Digest

sha256:ae29af839…

Size

72.8 MB

Last updated

27 days ago

docker pull waning/onesync