Hey, I've been unable to configure Nextcloud with Onlyoffice fully and now Sparkbox Doctor is reporting my WG-Easy port is accessible on the information superhighway. Here's the doctor output... Doctor still flags WG‑Easy’s port 51820 as publicly reachable. If you don’t use WG‑Easy, disabling that server is the right fix; Tailscale is already installed and healthy. There are two separate things here: WG‑Easy is the remote-access server you want to stop using, while the media stack uses WireGuard for its Surfshark VPN connection. Don’t remove or change that Surfshark setting. I can’t safely disable WG‑Easy with the available controls, and I won’t guess at a removal command. Don’t use --remove-orphans; it could remove other SparkBox containers. Is there a way to stop WG-Easy but keep all other WG settings active? TIA
19 replies
Chris wrote:
Yes. WG-Easy is SparkBox's separate remote-access module (vpn); the media stack's Surfshark VPN is separate, so disabling vpn won't change that. If you don't use WG-Easy, run sudo sparkbox disable vpn on the SparkBox host. This stops and disables only that module; its configuration files are left in place, and you can re-enable it later if needed. It will also remove WG-Easy's published port while disabled. This doesn't address the separate Nextcloud/OnlyOffice setup issue.
m7vdj wrote:
Thanks for the speedy reply Chris. Shall I raise a new card for the Nextcloud/onlyoffice setup issue or will we deal with it here? Just checking before I disable the vpn
Chris wrote:
We can work through the Nextcloud/OnlyOffice issue here; no new card needed. I’m sorry—I shouldn’t have assured you that sudo sparkbox disable vpn will definitely remove WG-Easy’s port: the command can report success even if stopping the module fails, so the port may remain exposed. Please hold off on running or retrying it while I verify the right path for your installed version. For the Nextcloud issue, what exactly happens when you try to connect or configure OnlyOffice (the error/message and where it stops)? Please leave out passwords and tokens. I’ve corrected what I rely on about that command so I don’t give the next person the same assurance without verification.
m7vdj wrote:
I received help the other day to get nextcloud setup and thoughT all was well. When I try to access the admin settings page it times out doing the server checks and I can't get into setup Onlyoffice
m7vdj wrote:
here's the output of those checks, timeout wasn't actually true! Security & setup warnings It is important for the security and performance of your instance that everything is configured correctly. To help you with that we are doing some automatic checks. Please see the linked documentation for more information. There are some warnings regarding your setup. Errors in the log 182 errors in the logs since 30 September 2026, 15:45:23 Maintenance window start Server has no maintenance window start time configured. This means resource intensive daily background jobs will also be executed during your main usage time. We recommend to set it to a time of low usage, so users are less impacted by the load caused from these heavy tasks. Mimetype migrations available One or more mimetype migrations are available. Occasionally new mimetypes are added to better handle certain file types. Migrating the mimetypes take a long time on larger instances so this is not done automatically during upgrades. Use the command occ maintenance:repair --include-expensive to perform the migrations. Database configuration 5 database checks are failing. Show the findings… Database missing indices Detected some missing optional indices. Occasionally new indices are added (by Nextcloud or installed applications) to improve database performance. Adding indices can sometimes take awhile and temporarily hurt performance so this is not done automatically during upgrades. Once the indices are added, queries to those tables should be faster. Use the command occ db:add-missing-indices to add them. Missing indices: "mailmessagesstrucanalyzidx" in table "mailmessages", "mailaccprovidx" in table "mailaccounts", "mailaliasaccididx" in table "mailaliases", "mailmessagesmbiduiduidx" in table "mailmessages", "mailsmimecertsuidemailidx" in table "mailsmimecertificates", "mailtrustedsendersidx" in table "mailtrustedsenders", "mailcollidx" in table "mailcolladdresses" HTTP headers Some headers are not set correctly on your instance - The Strict-Transport-Security HTTP header is not set (should be at least 15552000 seconds). For enhanced security, it is recommended to enable HSTS. AppAPI deploy daemon AppAPI default deploy daemon is not set. Please register a default deploy daemon in the settings to install External Apps (Ex-Apps). Second factor configuration Second factor providers are available but two-factor authentication is not enforced. Default phone region Your installation has no default phone region set. This is required to validate phone numbers in the profile settings without a country code. To allow numbers without a country code, please add "defaultphoneregion" with the respective ISO 3166-1 code of the region to your config file. Email test You have not set or verified your email server configuration, yet. Please head over to the "Basic settings" in order to set them. Afterwards, use the "Send email" button below the form to verify your settings. Configuration server ID Server identifier isn’t configured. It is recommended if your Nextcloud instance is running on several PHP servers. Add a server ID in your configuration.
Chris wrote:
Thanks for checking—and you’re right, that output doesn’t show a server-check timeout. Those are Nextcloud setup warnings, and by themselves they don’t identify why the OnlyOffice setup is blocked. What exact message do you see when you try to configure or connect OnlyOffice, and what action were you taking when it appeared? Please leave out passwords and tokens.
m7vdj wrote:
I am unable to get onlyoffice configuration to save without an error. can you walk me through the steps to configure onlyoffice properly?
Chris wrote:
Yes—I can walk you through it. The Nextcloud warnings you pasted don't identify why the OnlyOffice settings won't save, so let's pin down the exact failure before changing anything. Please reply with the exact error shown when you save, your Nextcloud and ONLYOFFICE integration-app versions, and whether your Document Server is the one installed through SparkBox or an external server. Don't include passwords, tokens, or the server address; then I'll give you the next step based on what you're running.
m7vdj wrote:
this is from the OnlyOffice server settings page... Error when trying to connect (Bad healthcheck status) I assume I am trying to access the document server installed via sparkbox
Chris wrote:
Thanks—that gives us the actual error. “Bad healthcheck status” means the connection check is failing, but it doesn’t identify the cause by itself. I can’t safely give you setup steps until I know which versions and server you have: please share the SparkBox version shown on your dashboard, the version of Nextcloud’s ONLYOFFICE integration app, and confirm whether the Document Server was installed through SparkBox. Please don’t post passwords, tokens, or the server address.
m7vdj wrote:
sparkbox - v1.6.881 onlyoffice - 10.2.1 yes, document server was setup via sparkbox
Chris wrote:
Thanks—that confirms the Document Server was installed through SparkBox. In Nextcloud’s ONLYOFFICE settings, the main Document Editing Service address should be your SparkBox address on port 8790; under Advanced server settings, set the internal address to https://sb-nextcloud and turn off certificate verification for that internal address. The Secret key must match the Document Server secret shown in SparkBox’s Settings → Passwords—please don’t post the key or either address here. As a first check, compare those two address fields with the values above and tell me which one, if either, differs; don’t change anything else yet. The setup warnings you shared earlier don’t explain this healthcheck error.
m7vdj wrote:
still receiving the same bad health check error using those values
Chris wrote:
Thanks for trying those settings. The two addresses can be right and the connection check can still fail if the connector's Secret key doesn't match the Document Server's key. Could you check, without posting the key, whether Nextcloud's ONLYOFFICE Secret key exactly matches the OnlyOffice Document Server secret shown in SparkBox → Settings → Passwords? Just reply yes or no; please don't share the key.
m7vdj wrote:
I've just done a hard refresh and the settings have now been saved in onlyoffice
Chris wrote:
Good, glad the hard refresh let the settings save. Could you check whether the connection healthcheck now passes? If it still shows the same error, just let me know that result—please keep the secret key private.
m7vdj wrote:
nextcloud health check... still failing with the same message as shown previously Onlyoffice error... Error. An error occurred while processing your request. /snapshot/nodejs/views/index.ejs:105 103| <img class="info info-tooltip" data-id="language" data-tooltip="Choose the language for ONLYOFFICE editors interface" src="images/info.svg" / 104| <select class="select-user collectable" name="lang" id="language" 105| <% languages.forEach(lang = { % 106| <option value="<%= lang
Chris wrote:
Thanks for checking, and I’m sorry this is still failing after the settings we tried. The repeated “Bad healthcheck status” and the error page don’t yet tell us whether the Document Server itself is failing or the browser-facing route is. As one read-only check, from a browser on your home network open the same Document Editing Service address you entered in Nextcloud and tell me whether you see the normal ONLYOFFICE welcome page or the same error page. Please don’t post the address or any keys, and don’t change or reset anything for now.