Collabora Online
Kubernetes YAML
apiVersion: v1
kind: Pod
metadata:
name: collabora
labels:
app: collabora
spec:
restartPolicy: Always
containers:
- name: collabora
image: docker.io/collabora/code:latest
imagePullPolicy: Always
ports:
- containerPort: 9980
hostPort: 9980
env:
- name: domain
value: cloud\.example\.com
- name: DONT_GEN_SSL_CERT
value: '1'
- name: extra_params
value: --o:ssl.enable=false --o:ssl.termination=true --o:mount_jail_tree=false
--o:mount_namespaces=false --o:welcome.enable=false --o:net.frame_ancestors=https://cloud.example.com
--o:num_prespawn_children=8 --o:net.connection_timeout_secs=30 --o:per_document.idle_timeout_secs=60
--o:per_document.max_concurrency=4
volumeMounts:
- name: vol-0
mountPath: /usr/local/share/fonts
readOnly: true
- name: vol-0
mountPath: /opt/cool/systemplate/usr/local/share/fonts
readOnly: true
securityContext:
runAsUser: 0
runAsGroup: 0
capabilities:
add:
- SYS_CHROOT
- MKNOD
- CHOWN
volumes:
- name: vol-0
persistentVolumeClaim:
claimName: collabora-fonts
Deployment Guide rootless
Prerequisites once as root
0. Install Podman
apt update && apt install -y podman
1. Create user (if not existing)
useradd -m -s /bin/bash passwd
2. Enable linger (service runs after reboot without login)
loginctl enable-linger
Switch to deployment user
su -
Use su - with the dash — this creates a proper login shell as . Without the dash, root environment variables carry over and rootless Podman will not work correctly.
As deployment user
Fix environment for rootless systemd (new users only — skip if already set)
Required once so systemctl --user works in non-login sessions.
cat << 'EOF' >> ~/.bashrc # Fix for systemd user services (rootless Podman/systemctl) export XDG_RUNTIME_DIR=/run/user/$(id -u) export DBUS_SESSION_BUS_ADDRESS=unix:path=$XDG_RUNTIME_DIR/bus EOF source ~/.bashrc
Save the YAML file
mkdir -p ~/.config/containers/ nano ~/.config/containers/collabora.yaml
Test the pod (without autostart)
podman play kube ~/.config/containers/collabora.yaml # Check status: podman pod ps && podman ps # Stop: podman play kube --down ~/.config/containers/collabora.yaml
Create Quadlet .kube file
%h is a systemd home-directory specifier — do not replace it with ~/.
Save to ~/.config/containers/systemd/:
mkdir -p ~/.config/containers/systemd/ nano ~/.config/containers/systemd/collabora.kube
Start systemd service
systemctl --user daemon-reload systemctl --user start collabora.service
Status & Logs
systemctl --user status collabora.service journalctl --user -u collabora.service -f podman pod ps podman ps
Enable automatic image updates optional
Requires AutoUpdate=registry in the .kube file. Podman then checks for new images and restarts the pod automatically:
systemctl --user enable --now podman.socket systemctl --user daemon-reload systemctl --user enable --now podman-auto-update.timer # Check status: systemctl --user status podman-auto-update.timer # Trigger manually: podman auto-update
Ports < 1024 (e.g. 80, 443)
Rootless cannot open privileged ports. Solution:
sysctl net.ipv4.ip_unprivileged_port_start=80
Make persistent in /etc/sysctl.d/99-podman.conf.
Containers communicate via localhost
All containers in the pod share the same network namespace. Always use localhost, not container names.
# Correct (e.g. app → db): localhost:5432 # Wrong (doesn't work in a pod): db-container:5432
List open ports
Which ports is the running pod listening on?
podman port collabora-pod
Custom DNS for the pod
Set a custom DNS server (e.g. local Pi-hole):
# In YAML under spec.dnsConfig:
spec:
dnsConfig:
nameservers:
- 192.168.1.x
Set volume ownership
Fix permission errors by adjusting UID/GID in the user namespace:
podman unshare chown 1000:1000 /path/to/volume
SELinux volume labels
On SELinux systems (RHEL, Fedora) set the volume suffix:
/host/path:/container/path:Z # private /host/path:/container/path:z # shared
List all volumes
podman volume ls podman volume inspect <volume-name>
Volume backup
Back up data from a named volume:
podman run --rm \ -v <volume-name>:/data:ro \ -v $(pwd):/backup \ busybox tar czf /backup/backup.tar.gz /data
Cleanup
Remove unused images, containers and volumes:
podman system prune -f # containers + images podman image prune -f # untagged images only podman volume prune -f # unused volumes
Manual update
Pull a new image version and restart the pod:
podman pull <image>:<tag> podman play kube --replace \ ~/.config/containers/collabora.yaml
Check for outdated images
List local images and test auto-update without applying:
podman images podman auto-update --dry-run
Shell into a running container
podman exec -it collabora-<container> /bin/sh # or bash: podman exec -it collabora-<container> /bin/bash
Follow live logs
# All containers in the pod: podman pod logs -f collabora-pod # Single container: podman logs -f collabora-<container>
Pod info & resource usage
podman pod inspect collabora-pod podman stats collabora-pod
Restart pod without data loss
podman pod restart collabora-pod # or via systemd: systemctl --user restart collabora.service
Stop & remove pod
podman pod stop collabora-pod podman pod rm collabora-pod
All in one
podman pod stop collabora-pod && podman pod rm collabora-pod