Unraid, Synology, TrueNAS
A NAS that runs containers can run Office Sentry: it uses the one-file stack,
v2/deploy/stack/compose.yaml, with the data on the NAS's own disks.
Tested: the stack file, with Docker Compose 5.6, with Docker volumes and with host folders owned by user ID 10001. Unraid, DSM and TrueNAS themselves: not yet. If a step doesn't match what you see, please open an issue.
Before you start #
- Memory and CPU. Office Sentry wants 2 CPUs and 4 GB of memory of its own, on top of what the NAS already uses. An Intel or AMD NAS works with any release; an ARM one (arm64) from 2.1.0.
- HTTPS, and who can reach it. The NAS's own web interface usually holds ports 80 and 443, so the stack's Caddy can't use them. The simplest way to reach the portal from outside the office, with HTTPS and no port opened on your router, is Cloudflare Tunnel, which the stack includes. On the office network only, the NAS's own reverse proxy works too (Synology, below). Nothing from Microsoft connects to the portal, so it doesn't need to be on the internet at all; but sign-in needs HTTPS.
- The keys. The key that decrypts the stored certificates is generated into its own folder or volume. Save a copy in your password manager (Where the keys are) and keep it out of your NAS backups where you can (each section says how).
Unraid #
Unraid 6.12 or later, with the Docker Compose Manager plugin (Apps, search "Compose Manager").
-
Make the folders, owned by the user Office Sentry runs as. Open the terminal (the
>_icon at the top right) and run:mkdir -p /mnt/user/appdata/officesentry/data /mnt/user/appdata/officesentry-keys chown 10001 /mnt/user/appdata/officesentry/data /mnt/user/appdata/officesentry-keysKeep
appdataon a pool (the cache), as Unraid does by default: the database wants a fast disk, not the array. -
Docker → Compose → Add New Stack, named
officesentry. Open its gear menu: Edit Stack → Compose File, paste the stack file and save; then Edit Stack → ENV File:OFFICESENTRY_VERSION=2.1.0 OFFICESENTRY_BASE_URL=https://sentry.yourmsp.com OFFICESENTRY_TIMEZONE=Europe/London OFFICESENTRY_DATA=/mnt/user/appdata/officesentry/data OFFICESENTRY_KEYS=/mnt/user/appdata/officesentry-keys COMPOSE_PROFILES=tunnel CLOUDFLARE_TUNNEL_TOKEN=<the tunnel's token>Leave out the last two lines if you put a proxy container in front instead (Nginx Proxy Manager or SWAG: see Behind your own proxy).
-
Compose Up. The Docker tab shows
officesentry-web-1andofficesentry-worker-1. -
The first admin's link is in
officesentry-web-1's log (its icon → Logs), on the line starting No admin account yet. Then carry on from step 6 of First start. -
Nightly backup: with the User Scripts plugin, add a script scheduled daily:
#!/bin/bash docker exec officesentry-web-1 python -m officesentry backup --keep 14The copies land in
/mnt/user/appdata/officesentry/data/backups, which an appdata backup (the Appdata Backup plugin) then copies off the pool. The keys are in their own folder,/mnt/user/appdata/officesentry-keys: exclude it from the appdata backup and keep itssecrets.jsonin your password manager instead.
Don't run Tools → New Permissions (or "Docker Safe New Perms") over these folders: it gives them back to
nobody, and the portal then stops with PermissionError: [Errno 1] Operation not permitted: '/data'. If
it happens, run the chown line from step 1 again.
Synology #
DSM 7.2 or later, with Container Manager (Package Center). Container Manager projects don't take environment variables, so you write your settings into the stack itself; the file stays on the NAS.
-
In File Station, make a folder
officesentryin thedockershared folder. -
Container Manager → Project → Create: name
officesentry, path/docker/officesentry, source Create docker-compose.yml. Paste the stack file, then change the lines underx-settingsat the top, replacing each${...}with your value:x-settings: &settings OFFICESENTRY_BASE_URL: https://sentry.yourmsp.com OFFICESENTRY_TIMEZONE: Europe/London OFFICESENTRY_COLLECT_CRON: 0 2 * * * OFFICESENTRY_WORKER_CONCURRENCY: 4 OFFICESENTRY_TRUSTED_PROXIES: 1 OFFICESENTRY_SECRET_KEY: "" OFFICESENTRY_ENCRYPTION_KEYS: "" OFFICESENTRY_SECRETS_FILE: /keys/secrets.jsonand on the
image:line, put the release instead of${OFFICESENTRY_VERSION:-2}(ghcr.io/jackd99/officesentry:2.1.0). For Cloudflare Tunnel, also delete theprofiles: ["tunnel"]line undercloudflaredand put the token in place of${CLOUDFLARE_TUNNEL_TOKEN:-}. Leave the data and keys as Docker volumes: Container Manager makes them writable for Office Sentry by itself. -
Next, Done. The project builds and starts; Container shows
officesentry-web-1andofficesentry-worker-1. -
The first admin's link is in
officesentry-web-1's Log tab, on the line starting No admin account yet. Then carry on from step 6 of First start. -
Save the keys: the container's Terminal tab, Create, then run
cat /keys/secrets.jsonand put the line in your password manager. -
Nightly backup: Control Panel → Task Scheduler → Create → Scheduled Task → User-defined script, user root, daily at 03:45, with:
/usr/local/bin/docker exec officesentry-web-1 python -m officesentry backup --keep 14 mkdir -p /volume1/docker/officesentry/backups /usr/local/bin/docker cp officesentry-web-1:/data/backups/. /volume1/docker/officesentry/backups/The second command copies the backups out of the Docker volume into the shared folder, where Hyper Backup can take them off the NAS. The keys never go there.
HTTPS on the office network: Control Panel → Login Portal → Advanced → Reverse Proxy → Create: source
HTTPS, your hostname, port 443; destination HTTP, localhost, port 8000. Give it a certificate under
Control Panel → Security → Certificate. Then check it as in Checking it worked.
To update, change the release on the image: line (Project → officesentry → YAML configurations), then
Build the project again.
TrueNAS #
TrueNAS Community Edition (SCALE) 24.10 or later, where apps run on Docker. Earlier SCALE releases ran apps on Kubernetes and aren't covered.
-
Apps → Discover Apps → Custom App (the menu beside it) → Install via YAML. Name it
officesentry. -
Paste the stack file and set your values under
x-settingsand on theimage:line exactly as in step 2 of Synology. For the tunnel, deletecloudflared'sprofiles:line and put in its token. Leave the data and keys as Docker volumes. -
Save. The app starts; its page shows the containers and their logs. The first admin's link is in the
webcontainer's log, on the line starting No admin account yet. Then carry on from step 6 of First start. -
Nightly backup: System → Advanced Settings → Cron Jobs → Add, user
root, daily at 03:45. TrueNAS names the containers after the app withix-in front; check withdocker psin System → Shell. The command:docker exec ix-officesentry-web-1 python -m officesentry backup --keep 14 && mkdir -p /mnt/tank/backups/officesentry && docker cp ix-officesentry-web-1:/data/backups/. /mnt/tank/backups/officesentry/with
/mnt/tank/backupsa dataset of yours that a replication or Cloud Sync task already takes off the NAS. -
Save the keys:
docker exec ix-officesentry-web-1 cat /keys/secrets.jsonin System → Shell, into your password manager.
To update, edit the app's YAML (Apps → officesentry → Edit), change the release on the image: line and
save.
Checking it worked #
Sign in through the HTTPS address, then open Settings → Activity log: your sign-in should show your own
address, not the proxy's or 127.0.0.1. In the browser's developer tools the page should carry a
Strict-Transport-Security header; if it doesn't, the proxy isn't telling the portal it's on HTTPS
(Securing the portal).