diff --git a/apps/only-office-kasm/1.19.0-rolling-weekly/.env.sample b/apps/only-office-kasm/1.19.0-rolling-weekly/.env.sample new file mode 100644 index 000000000..9e5bb150d --- /dev/null +++ b/apps/only-office-kasm/1.19.0-rolling-weekly/.env.sample @@ -0,0 +1,5 @@ +PANEL_APP_PORT_HTTPS=41013 +HTTP_PWD=replace-with-a-random-value +SHM_SIZE=1024m +APP_DATA_DIR=./data +CONTAINER_NAME= diff --git a/apps/only-office-kasm/1.19.0-rolling-weekly/data.yml b/apps/only-office-kasm/1.19.0-rolling-weekly/data.yml new file mode 100644 index 000000000..570575933 --- /dev/null +++ b/apps/only-office-kasm/1.19.0-rolling-weekly/data.yml @@ -0,0 +1,69 @@ +additionalProperties: + formFields: + - default: 41013 + edit: true + envKey: PANEL_APP_PORT_HTTPS + labelEn: HTTPS Port + labelZh: HTTPS 端口 + label: + en: HTTPS Port + zh: HTTPS 端口 + zh-Hant: HTTPS 連接埠 + ja: HTTPS ポート + ko: HTTPS 포트 + ru: Порт HTTPS + ms: Port HTTPS + pt-br: Porta HTTPS + required: true + rule: paramPort + type: number + - default: "" + edit: true + envKey: HTTP_PWD + labelEn: Access Password + labelZh: 访问密码 + label: + en: Access Password + zh: 访问密码 + zh-Hant: 存取密碼 + ja: アクセスパスワード + ko: 접속 비밀번호 + ru: Пароль доступа + ms: Kata Laluan Akses + pt-br: Senha de Acesso + random: true + required: true + rule: paramComplexity + type: password + - default: 1024m + edit: true + envKey: SHM_SIZE + labelEn: Shared Memory Size + labelZh: 共享内存大小 + label: + en: Shared Memory Size + zh: 共享内存大小 + zh-Hant: 共享記憶體大小 + ja: 共有メモリサイズ + ko: 공유 메모리 크기 + ru: Размер общей памяти + ms: Saiz Memori Dikongsi + pt-br: Tamanho da Memória Compartilhada + required: true + type: text + - default: ./data + edit: true + envKey: APP_DATA_DIR + labelEn: Data Directory + labelZh: 数据目录 + label: + en: Data Directory + zh: 数据目录 + zh-Hant: 資料目錄 + ja: データディレクトリ + ko: 데이터 디렉터리 + ru: Каталог данных + ms: Direktori Data + pt-br: Diretório de Dados + required: true + type: text diff --git a/apps/only-office-kasm/1.19.0-rolling-weekly/docker-compose.yml b/apps/only-office-kasm/1.19.0-rolling-weekly/docker-compose.yml new file mode 100644 index 000000000..a05ba8427 --- /dev/null +++ b/apps/only-office-kasm/1.19.0-rolling-weekly/docker-compose.yml @@ -0,0 +1,35 @@ +services: + only-office-kasm: + image: "kasmweb/only-office:1.19.0-rolling-weekly@sha256:c2d9651d9d600d1633dbc2d56fbfa1a67dbbe780d498d6de0677594780e68d50" + container_name: ${CONTAINER_NAME} + restart: unless-stopped + networks: + - 1panel-network + ports: + - "${PANEL_APP_PORT_HTTPS}:6901" + environment: + - VNC_PW=${HTTP_PWD} + shm_size: ${SHM_SIZE} + cap_drop: + - ALL + security_opt: + - no-new-privileges:true + healthcheck: + test: + - CMD-SHELL + - >- + curl --insecure --fail --silent --show-error + --user "kasm_user:$$VNC_PW" + https://127.0.0.1:6901/ + interval: 30s + timeout: 10s + start_period: 90s + retries: 5 + volumes: + - "${APP_DATA_DIR}:/home/kasm-user" + labels: + createdBy: "Apps" + +networks: + 1panel-network: + external: true diff --git a/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/init.sh b/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/init.sh new file mode 100755 index 000000000..338044ef8 --- /dev/null +++ b/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/init.sh @@ -0,0 +1,50 @@ +#!/usr/bin/env bash +set -euo pipefail + +ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)" +ENV_FILE="${ENV_FILE:-$ROOT_DIR/.env}" + +read_env_value() { + local key="$1" + [[ -f "$ENV_FILE" ]] || return 0 + local value + value="$(sed -n "s/^${key}=//p" "$ENV_FILE" | tail -n 1)" + case "$value" in + \"*\") value="${value#\"}"; value="${value%\"}" ;; + \'*\') value="${value#\'}"; value="${value%\'}" ;; + esac + printf '%s\n' "$value" +} + +data_raw="${APP_DATA_DIR:-}" +if [[ -z "$data_raw" ]]; then + data_raw="$(read_env_value APP_DATA_DIR)" +fi +data_raw="${data_raw:-./data}" + +[[ "$data_raw" != /* ]] || { + printf '%s\n' 'APP_DATA_DIR must be a relative path' >&2 + exit 1 +} + +data_dir="$(realpath -m -- "$ROOT_DIR/${data_raw#./}")" +case "$data_dir" in + "$ROOT_DIR"/*) ;; + *) + printf '%s\n' 'APP_DATA_DIR must remain inside the application version directory' >&2 + exit 1 + ;; +esac + +mkdir -p -- "$data_dir" +resolved_data_dir="$(realpath -e -- "$data_dir")" +case "$resolved_data_dir" in + "$ROOT_DIR"/*) ;; + *) + printf '%s\n' 'APP_DATA_DIR resolves outside the application version directory' >&2 + exit 1 + ;; +esac + +chown 1000:1000 -- "$resolved_data_dir" +chmod 0700 -- "$resolved_data_dir" diff --git a/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/uninstall.sh b/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/uninstall.sh new file mode 100755 index 000000000..e043feffb --- /dev/null +++ b/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/uninstall.sh @@ -0,0 +1,4 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Preserve APP_DATA_DIR so uninstall does not destroy user files. diff --git a/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/upgrade.sh b/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/upgrade.sh new file mode 100755 index 000000000..692e341e2 --- /dev/null +++ b/apps/only-office-kasm/1.19.0-rolling-weekly/scripts/upgrade.sh @@ -0,0 +1,4 @@ +#!/usr/bin/env bash +set -euo pipefail + +"$(dirname "$0")/init.sh" diff --git a/apps/only-office-kasm/README.md b/apps/only-office-kasm/README.md new file mode 100644 index 000000000..1baee7588 --- /dev/null +++ b/apps/only-office-kasm/README.md @@ -0,0 +1,55 @@ +# Only Office (Kasm) + +## 产品介绍 + +Only Office (Kasm) 将 Only Office 作为浏览器工作区运行。镜像由 Kasm Technologies 构建,1Panel 应用包直接使用固定 digest,不在本地重打包镜像。 + +## 主要功能 + +- 在浏览器中使用完整的 Linux 图形界面 +- 将用户配置、下载和工作文件保存在独立数据目录 +- 通过 KasmVNC 的 HTTPS 入口和安装时随机生成的密码访问 + +## 访问说明 + +安装后访问 `https://<服务器 IP>:`,用户名为 `kasm_user`,密码为安装表单中的访问密码。镜像使用自签名证书,浏览器首次访问会显示证书警告;公网部署应在可信反向代理后使用有效 HTTPS 证书,并限制来源地址。 + +Kasm 官方说明,音频、上传、下载和麦克风透传等部分功能只有在完整 Kasm Workspaces 平台编排下才能完整使用。独立部署不应假定这些集成功能可用。 + +## 数据持久化 + +`APP_DATA_DIR` 挂载到 `/home/kasm-user`,保存用户配置和文件,默认值为版本目录下的 `./data`。该值必须是版本目录内的相对路径;生命周期脚本会拒绝绝对路径、目录逃逸和指向目录外的符号链接。卸载或迁移前请备份该目录;不要把多个实例指向同一目录。 + +`SHM_SIZE` 控制浏览器工作区共享内存,默认 `1024m`。大型文件或高分辨率会话可适当提高,但必须确认主机有足够内存。 + +## 版本与安全说明 + +- `workspaces-images` 使用 MIT 许可文本(SPDX: MIT),但上游声明只覆盖该仓库直接维护的源码,不自动覆盖镜像内第三方应用或依赖。各产品许可和商标条款仍独立适用;本应用包只引用上游镜像,不重分发镜像内容。 +- 本包固定 Kasm 官方 `1.19.0-rolling-weekly` 在 2026-07-22 发布的 amd64 digest `sha256:c2d9651d9d600d1633dbc2d56fbfa1a67dbbe780d498d6de0677594780e68d50`,不会随远端标签静默变化。 +- 2026-07-28 对此精确 digest 的 fresh Trivy 扫描结果为 `0 Critical / 0 High`。 +- 容器以上游 UID 1000 运行,移除全部 Linux capabilities,并启用 `no-new-privileges`。上游启动过程需要写入 `/dockerstartup` 和 `/var/run/pulse`,因此不能使用只读根文件系统。 +- `VNC_PW` 通过 1Panel 随机密码字段传入并保存在应用 `.env` 中。不要复用其他系统密码,并限制 1Panel、Docker 和应用目录的读取权限。 + +## Introduction + +Only Office (Kasm) runs Only Office as a browser-accessible workspace. Kasm Technologies builds the image, and this package references a pinned digest without rebuilding it. + +The `workspaces-images` source uses the MIT license text (SPDX: MIT) only for code directly maintained in that repository. It does not extend to third-party applications or dependencies in the image. This package references the upstream image without redistributing its contents. + +## Features + +- Full Linux graphical application streamed through the browser +- Per-install persistence for user settings, downloads, and working files +- KasmVNC HTTPS access protected by an installation-time random password + +Open `https://:`, sign in as `kasm_user`, and use the access password generated during installation. The image presents a self-signed certificate. Use a trusted HTTPS reverse proxy and restrict source addresses for Internet-facing deployments. + +`APP_DATA_DIR` persists `/home/kasm-user`. The image is pinned to the 2026-07-22 `1.19.0-rolling-weekly` digest. A fresh Trivy scan of this exact digest on 2026-07-28 found `0 Critical / 0 High`. + +## References + +- Product website: +- Kasm official registry: +- Docker Hub image and stand-alone instructions: +- Pinned image source: +- Source license: diff --git a/apps/only-office-kasm/data.yml b/apps/only-office-kasm/data.yml new file mode 100644 index 000000000..1fdf09da2 --- /dev/null +++ b/apps/only-office-kasm/data.yml @@ -0,0 +1,29 @@ +name: Only Office (Kasm) +tags: + - 实用工具 +title: 浏览器版 Only Office +description: 可通过浏览器访问的 Only Office 工作区 +additionalProperties: + key: only-office-kasm + name: Only Office (Kasm) + tags: + - Tool + shortDescZh: 可通过浏览器访问的 Only Office 工作区 + shortDescEn: Browser-accessible Only Office workspace + description: + en: Browser-accessible Only Office workspace + zh: 可通过浏览器访问的 Only Office 工作区 + zh-Hant: 可透過瀏覽器存取的 Only Office 工作區 + ja: ブラウザーから利用できる Only Office ワークスペース + ko: 브라우저에서 사용할 수 있는 Only Office 워크스페이스 + ru: Рабочее пространство Only Office с доступом через браузер + ms: Ruang kerja Only Office yang boleh diakses melalui pelayar + pt-br: Ambiente Only Office acessível pelo navegador + type: tool + crossVersionUpdate: true + limit: 0 + website: https://www.onlyoffice.com/ + github: https://github.com/kasmtech/workspaces-images/blob/bafab6d531eefd5a5aa6f2c9088ebc8f02e12fae/dockerfile-kasm-only-office + document: https://hub.docker.com/r/kasmweb/only-office + architectures: + - amd64 diff --git a/apps/only-office-kasm/logo-LICENSE.txt b/apps/only-office-kasm/logo-LICENSE.txt new file mode 100644 index 000000000..17e9ba10b --- /dev/null +++ b/apps/only-office-kasm/logo-LICENSE.txt @@ -0,0 +1,10 @@ +Only Office (Kasm) typographic workspace icon + +Created in this repository on 2026-07-28 with ImageMagick using only geometric shapes and the text "Only Office" and "WEB WORKSPACE". +Font: DejaVu Sans and DejaVu Sans Bold +Font source: https://dejavu-fonts.github.io/ +Font license: Bitstream Vera font license; DejaVu changes are public domain +Font license text: https://dejavu-fonts.github.io/License.html +SHA-256: 3552f2f29df1f036ac08285c9a5037f2166a1ac060b8db8f10763a76b1305ff3 + +The generated composition is original project artwork. Product names may be trademarks of their respective owners and are used only for identification. diff --git a/apps/only-office-kasm/logo.png b/apps/only-office-kasm/logo.png new file mode 100644 index 000000000..f1920256a Binary files /dev/null and b/apps/only-office-kasm/logo.png differ