2 Commits
Author SHA1 Message Date
LeoVasanko d4dfc57994 onlyoffice: hardcode oonet gateway as callback host, drop docker detection
The cista service account has no docker CLI access, so detecting the
gateway via docker network inspect silently fell back to docker0/legacy
behavior. With the pinned subnet the gateway is always 172.30.0.1;
ONLYOFFICE_CALLBACK_HOST remains as an env override.
2026-08-13 07:38:52 +00:00
LeoVasanko 65e2fddf1a onlyoffice: drop legacy localhost:8988 URL fallback
The container always lives on the isolated oonet network at the fixed
IP; falling back to a published localhost port silently masked broken
setups with confusing 'not reachable at localhost:8988' diagnostics.
2026-08-13 07:26:57 +00:00
+16 -61
View File
@@ -50,9 +50,11 @@ logger = logging.getLogger(__name__)
# Isolated docker network for the OnlyOffice container: internal-only (no # Isolated docker network for the OnlyOffice container: internal-only (no
# outbound internet), the container can only reach the host on this bridge. # outbound internet), the container can only reach the host on this bridge.
# Docker discards published ports on internal networks, so the container is # Docker discards published ports on internal networks, so the container is
# reached at its fixed IP instead of a published localhost port. # reached at its fixed IP instead of a published localhost port. The host is
# always the first address of the pinned subnet (the bridge gateway).
OO_NETWORK = "oonet" OO_NETWORK = "oonet"
OO_SUBNET = "172.30.0.0/24" OO_SUBNET = "172.30.0.0/24"
OO_GATEWAY = "172.30.0.1"
OO_CONTAINER_IP = "172.30.0.2" OO_CONTAINER_IP = "172.30.0.2"
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
@@ -65,73 +67,28 @@ _httpx_client_loop: asyncio.AbstractEventLoop | None = None
def _get_onlyoffice_url() -> str: def _get_onlyoffice_url() -> str:
if url := os.environ.get( # The container runs on the isolated oonet network at a fixed IP; the
"ONLYOFFICE_URL", os.environ.get("ONLYOFFICE_CISTA_URL") # host is the bridge gateway and reaches it directly, no published port.
): return os.environ.get(
return url "ONLYOFFICE_URL",
# When the isolated network exists, the container is at its fixed IP and os.environ.get("ONLYOFFICE_CISTA_URL", f"http://{OO_CONTAINER_IP}"),
# no localhost port is published (Docker discards ports on internal )
# networks). Otherwise assume a legacy setup with a published port.
if _docker_network_gateway(OO_NETWORK):
return f"http://{OO_CONTAINER_IP}"
return "http://localhost:8988"
def _get_jwt_secret() -> str: def _get_jwt_secret() -> str:
return os.environ.get("ONLYOFFICE_JWT_SECRET", "") return os.environ.get("ONLYOFFICE_JWT_SECRET", "")
def _docker_network_gateway(network: str) -> str | None:
"""Return the host-side gateway IP of a docker network, or None."""
try:
result = subprocess.run(
[
"docker",
"network",
"inspect",
network,
"--format",
"{{range .IPAM.Config}}{{.Gateway}}{{end}}",
],
capture_output=True,
text=True,
timeout=2,
check=False,
)
gateway = result.stdout.strip()
if result.returncode == 0 and gateway:
return gateway
except Exception:
logger.debug("Failed to inspect docker network %s", network)
return None
@lru_cache(maxsize=1) @lru_cache(maxsize=1)
def _get_callback_host() -> str: def _get_callback_host() -> str:
"""Return the host IP that OnlyOffice (in Docker) can use to reach us.""" """Return the host IP that OnlyOffice (in Docker) can use to reach us.
The host is always the gateway of the pinned oonet subnet; no detection
is needed (the cista service account may not have docker CLI access).
"""
if host := os.environ.get("ONLYOFFICE_CALLBACK_HOST"): if host := os.environ.get("ONLYOFFICE_CALLBACK_HOST"):
return host return host
# Prefer the gateway of the isolated network setup_docker() creates — return OO_GATEWAY
# this is the network the container is actually attached to.
if gateway := _docker_network_gateway(OO_NETWORK):
return gateway
# Fall back to the default docker bridge IP
try:
result = subprocess.run(
["/sbin/ip", "-4", "addr", "show", "docker0"],
capture_output=True,
text=True,
timeout=2,
check=False,
)
for line in result.stdout.splitlines():
if "inet " in line:
parts = line.strip().split()
addr_part = parts[1] # e.g. 172.17.0.1/16
return addr_part.split("/")[0]
except Exception:
logger.debug("Failed to auto-detect docker bridge IP")
return "127.0.0.1"
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
@@ -271,9 +228,7 @@ def setup_docker(name: str = "onlyoffice-mediapreview") -> str:
# Docker discards published ports on internal networks, so the container # Docker discards published ports on internal networks, so the container
# is reached at its fixed IP; no localhost port is exposed. # is reached at its fixed IP; no localhost port is exposed.
logger.info("OnlyOffice is running on http://%s", OO_CONTAINER_IP) logger.info("OnlyOffice is running on http://%s", OO_CONTAINER_IP)
logger.info( logger.info("Callback host for file downloads: %s", OO_GATEWAY)
"Callback host for file downloads: %s", _docker_network_gateway(OO_NETWORK)
)
return secret return secret