Files
MemRelay/projects/d1932ed6-07d3-4463-a224-8534ffd69a07/ONLYOFFICE 改为同源路径 -ds-vpath- 反向代理(单端口、不依赖固定 IP).md
T

29 lines
3.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: ONLYOFFICE 改为同源路径 /ds-vpath/ 反向代理(单端口、不依赖固定 IP)
type: decision
permalink: main/projects/d1932ed6-07d3-4463-a224-8534ffd69a07/onlyoffice-改为同源路径-ds-vpath-反向代理单端口、不依赖固定-ip
stable_id: 1588ca3e-58fe-48b9-ad34-3e660324d24e
scope: project
project_id: d1932ed6-07d3-4463-a224-8534ffd69a07
memory_type: decision
status: active
revision: 1
restored_from_commit: 6a6a895eafcca6052e81a14fca103a42635dd1c2
created_at: '2026-09-23T15:05:01.119380+00:00'
updated_at: '2026-09-23T15:05:01.119437+00:00'
tags:
- nextoffice
- onlyoffice
- ds-vpath
- apache
- architecture
---
需求:用户担心服务器迁入内网换 IP 后 ONLYOFFICE 编辑器失效,要求“不限制 IP”。
决定(提交 f1c5a8f,已推送并部署):
- 自建镜像 nextoffice/nextcloud:34.0.3-oo10.1.2-r2:Dockerfile 增加 `a2enmod proxy proxy_http proxy_wstunnel && a2enconf onlyoffice-proxy`,配置文件 build/onlyoffice-proxy.conf:`<Location /ds-vpath/>` 内 `ProxyPass http://onlyoffice/ upgrade=websocket`(Apache 2.4.68,不需 rewrite)、`ProxyPassReverse`、`ProxyAddHeaders Off`(否则 mod_proxy 会把自己的 X-Forwarded-Host 合并成双值)、`RequestHeader setifempty X-Forwarded-For/Proto`、`<If "-n req('X-Forwarded-Host')">` 时用外层代理的主机名否则 `%{HTTP_HOST}`,值带 `/ds-vpath` 后缀(ONLYOFFICE 官方 docker-onlyoffice-nextcloud 同款方案)。
- 镜像 tag 加 -rN 后缀,build/ 变化必须升版,否则服务器会复用旧镜像;deploy.py NEXTCLOUD_IMAGE 常量与 docker-compose.yml、versions.json 三处同步,manage.py backup 从 deploy 导入。
- docker-compose.yml 不再发布 ONLYOFFICE 宿主机端口;.env 去掉 ONLYOFFICE_PORT/ONLYOFFICE_BIND_IP;deploy.py/manage.py 只有 --nextcloud-port;DocumentServerUrl=/ds-vpath/(由 configure_access_urls 写,reconfigure 也会重设);DocumentServerInternalUrl=http://onlyoffice/、StorageUrl=http://nextcloud/ 不变;wait_services 先等 status.php 再等 /ds-vpath/healthcheck;ensure_images 在离线 tar 缺镜像时在线补齐;reconfigure 先 ensure_images 再 `compose up -d --wait --remove-orphans`,可用于旧实例升级,并删除 legacy 端口键。
- 验证方法(已在本机就地升级实例和服务器新安装上通过):/ds-vpath/healthcheck 返回 true;GET /ds-vpath/ 的 302 Location 随请求 Host 变化、带 /ds-vpath/、无逗号双值;外层 X-Forwarded-Host/Proto 被尊重(https://office.company.lan/ds-vpath/welcome/);非版本化 index.html 重定向到 /ds-vpath/9.4.0-<hash>/...并可达;/ds-vpath/doc/<key>/c/?EIO=4&transport=websocket 返回 101,polling 返回 0{"sid"...};occ onlyoffice:documentserver --check 输出“Document server /ds-vpath/ version 9.4.0.129 is successfully connected”;OCS /ocs/v2.php/apps/onlyoffice/api/v1/config/{fileId}?format=json 返回 documentServerUrl=/ds-vpath/,document.url/callbackUrl 为 http://nextcloud/...。DS 9.x 的 api.js 是静态文件,不嵌入基址,不能用它验证转发头。
- HTTPS 改为单域名单证书方案,docs/HTTPS.md 已重写;DocumentServerUrl 必须保持相对路径。