Self-hosting ShareLaTeX (now Overleaf Community Edition) enables collaborative scientific paper writing with full data privacy. Deploying ShareLaTeX via its official Docker container is straightforward, but servers protected by ConfigServer Security & Firewall (CSF) require specific iptables routing configurations to allow containerized network traffic without exposing internal services.
1. Deploying the Container
docker run -d -v ~/sharelatex_data:/var/lib/sharelatex --name=sharelatex -p 3000:80 sharelatex/sharelatex
2. Resolving CSF Firewall and Docker Bridging Conflicts
By default, CSF disables Docker's automated iptables forwarding rules, cutting off outbound container traffic and external port mapping. Add the following exceptions to /etc/csf/csfpost.sh to restore seamless Docker connectivity:
#!/bin/bash
# Allow bridge network traffic for Docker containers
iptables -A FORWARD -i docker0 -o eth0 -j ACCEPT
iptables -A FORWARD -i eth0 -o docker0 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -t nat -A POSTROUTING -s 172.17.0.0/16 -o eth0 -j MASQUERADE
Make /etc/csf/csfpost.sh executable and restart CSF:
chmod +x /etc/csf/csfpost.sh
csf -r