Skip to content

ownCloud Infinite Scale (OCIS)

TL;DR / when to use this: OCIS is the sibling to Nextcloud — a modern, Go-based file platform with Collabora integration. The ocis_full compose example ships with Traefik; since I already run Nginx as the reverse proxy, strip Traefik and let Nginx terminate TLS. Like Nextcloud, it needs its three domains (ocis, wopiserver, collabora) resolved consistently — see Context-Aware DNS.

Base project

Use the official ubuntu-compose production example (the ocis_full project in the owncloud/ocis repo), then delete all Traefik references — Nginx handles proxying and TLS.

Nginx: three proxy hosts

OCIS needs three hostnames proxied separately:

Host Upstream
owncloud.<domain> https://127.0.0.1:9200
wopiserver.<domain> http://127.0.0.1:9300
collabora.<domain> Collabora container

Each block includes the standard HSTS + websocket confs, and the OCIS block sets proxy_set_header Origin https://owncloud.<domain> — Collabora's proof-key flow depends on the Origin header matching the public domain.

.env essentials

OCIS_DOMAIN=owncloud.tail.example.com
OCIS_CONFIG_DIR=/mnt/md0/apps/owncloud/config
OCIS_DATA_DIR=/mnt/md0/apps/owncloud/data

COLLABORA_DOMAIN=collabora.tail.example.com
WOPISERVER_DOMAIN=wopiserver.tail.example.com

# Nginx already handles SSL, so disable in-container SSL
COLLABORA_SSL_ENABLE=false
COLLABORA_SSL_VERIFICATION=true

csp.yaml

Add all three domains to connect-src and frame-src in config/ocis/csp.yaml — otherwise Collabora embedding fails CSP checks:

directives:
  connect-src:
    - '''self'''
    - 'blob:'
    - 'https://${OCIS_DOMAIN}'
    - 'https://${COLLABORA_DOMAIN}'
    - 'https://${WOPISERVER_DOMAIN}'
  frame-src:
    - '''self'''
    - 'blob:'
    - 'https://embed.diagrams.net/'
    - 'https://${OCIS_DOMAIN}'
    - 'https://${COLLABORA_DOMAIN}'
    - 'https://${WOPISERVER_DOMAIN}'

The compose file is split per plugin (ocis.yml is the primary) — add the port mapping there and comment out unneeded settings.

See also