# Collabora CODE for Nextcloud with Docker

**URL:** <https://help.nextcloud.com/t/collabora-code-for-nextcloud-with-docker/216725>\
**Category:** 📑 How to\
**Tags:** snap, docker, code, wopi, office, collabora-online, docker-compose\
**Created:** [February 5, 2025, 9:36am UTC](https://help.nextcloud.com/t/collabora-code-for-nextcloud-with-docker/216725 "2025-02-05T09:36:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![scubamuc](https://help.nextcloud.com/user_avatar/help.nextcloud.com/scubamuc/32/63165_2.png) [@scubamuc](https://help.nextcloud.com/u/scubamuc)\
**Post date:** [February 5, 2025, 9:36am UTC](https://help.nextcloud.com/t/collabora-code-for-nextcloud-with-docker/216725/1 "2025-02-05T09:36:26Z")

</div>

# Install & configure Collabora CODE for Nextcloud with Docker

- [**Collabora integration guide**](https://help.nextcloud.com/t/collabora-integration-guide/151879)

[Collabora Online](https://www.collaboraonline.com) is a LibreOffice-based online office suite with collaborative editing, which supports all major documents, spreadsheet and presentation file formats and works together with all modern browsers. The [Nextcloud Office](https://apps.nextcloud.com/apps/richdocuments) integration app provides an interface for editing documents in Nextcloud with Collabora Online.

[Collabora CODE](https://www.collaboraonline.com/code/) ( **C** ollabora **O** ffice **D** evelopment **E** dition) is the development version of Collabora Online. It is perfect for testing, home use or small teams but not recommended for production environments. [Collabora CODE](https://www.collaboraonline.com/code/) together with [Nextcloud Office](https://apps.nextcloud.com/apps/richdocuments) enables editing Office documents within your Nextcloud instance.

There are various methods to run Collabora CODE together with Nextcloud Office:

- **Collabora CODE Docker service**
  - Standalone Docker [community instance](https://www.collaboraonline.com/code/#learnmorecode), instructions below

- **Collabora Online - Built-in CODE Server**
  - Built-in CODE Server installed from Nextcloud app store

- **Collabora CODE Linux server**
  - Standalone server from source using [Linux installation packages](https://www.collaboraonline.com/code/#learnmorecode)

> ### TIP
> 
> Regardless which [Collabora CODE](https://www.collaboraonline.com/code/) service you’re planning to use, [Nextcloud Office](https://apps.nextcloud.com/apps/richdocuments) is required and must be installed on your Nextcloud instance to provide an interface for editing documents in Nextcloud.

## Example Collabora CODE [Docker](https://www.docker.com/) service with [reverse proxy](https://help.nextcloud.com/t/101-reverse-proxy/194840).

1. Install Docker on host
2. Create a DNS entry for subdomain like `office.mydomain.tld`
3. Set reverse proxy host for office domain to forward and encrypt HTTP & WSS (WebSockets Support) for port **9980** to `https://office.mydomain.tld`.

### Create and run docker Stack:

- **or** create a `docker-compose.yaml` in place and execute in docker

```auto
name: 'code'

services:
  collabora:
    image: collabora/code:latest
    container_name: collabora
    environment:
      - aliasgroup1=https://cloud.mydomain.tld:443,https://cloud\\.mydomain\\.tld:443 # enable for aliasgroup1
      # - aliasgroup2=https://cloud.otherdomain.tld:443,https://cloud\\.otherdomain\\.tld:443 # enable for aliasgroup2
      # - aliasgroup3=https://cloud.somedomain.tld:443,https://cloud\\.somedomain\\.tld:443 # enable for aliasgroup3
      - username=admin
      - password= ******** # Replace with a strong password
      - dictionaries=en_GB en_US de_DE
      - extra_params=
      --o:ssl.enable=false 
      --o:ssl.termination=true
      --o:logging.level=warning
    ports:
      - "9980:9980"
    restart: always

```

> ### TIP
> 
> **Permitted client domain** instead of **WOPI** clients, see example below
> 
> - Prefer using `- aliasgroup` instead of `- server_name` for environment definition.
> - Aliasgroups ensures that only permitted encrypted client domains will be able to connect.
> - Define `- aliasgroup` iterating 1,2,3 for multiple encrypted client domains.
> - Be aware of the syntax for defining client domains using `\\` as separator before `.`
> 
> extra parameters etc. see [configuration documentation](https://sdk.collaboraonline.com/docs/installation/Configuration.html)
> 
> - `-extra_params=`
> - `--o:ssl.enable=false # disable ssl termination in coolswd/collabora`
> - `--o:ssl.termination=true # forward http to reverse proxy = ssl termination`
> - `--o:logging.level=warning # log level, verbosity`
> - `--o:logging.level_startup=warning # log level at start up, verbosity`
> - `--o:logging.disable_server_audit=true # disable server-audit`

> **dictionaries**
> 
> - `- dictionaries` add dictionaries space separated `en_US en_GB de_DE` etc.

### Collabora CODE docker options (multiple permitted client domains)

Each aliasgroup represents the allowed client domain, which will prevent unregistered clients from accessing the CODE service. Thus using aliasgroups resolves the issue of allowed WOPI client IP’s.

```auto
- aliasgroup1=https://cloud.mydomain.tld:443,https://cloud\\.mydomain\\.tld:443
## - aliasgroup2=https://cloud.otherdomain.tld:443,https://cloud\\.otherdomain\\.tld:443
## - aliasgroup3=https://cloud.somedomain.tld:443,https://cloud\\.somedomain\\.tld:443

```

> #### TIP
> 
> be aware of the syntax when defining client domains using `\\` as separator before `.`

### Collabora docker options

there are several options available see [documentation](https://sdk.collaboraonline.com/docs/installation/Configuration.html):

**example optional parameters:**

```auto
- extra_params=
 --o:ssl.enable=false # disable collabora/coolswd ssl termination
 --o:ssl.termination=true # enable reverse proxy ssl termination
 --o:user_interface.mode=compact # web ui view
 --o:mount_jail_tree=true # refer to documentation
 --o:home_mode.enable=true # refer to documentation 
 --o:logging.level=warning # logging level, verbosity
 --o:logging.level_startup=warning # log level at start up, verbosity
 --o:logging.disable_server_audit=true # enable disable server audit 

```

- assuming a reverse proxy is handling ssl termination, `coolswd` termination would be disabled: `ssl.enable=false` and `ssl.termination=true`

- alternatively, without a reverse proxy letting `coolswd` handle ssl termination using `Certbot` or `acme.sh` → `coolswd` termination would be enabled: `ssl.enable=true` and `ssl.termination=false`

- Disable server-audit: [enable/disable server audit](https://sdk.collaboraonline.com/docs/installation/Configuration.html#server-audit)

see official docs for details:

- [CODE Docker image — SDK https://sdk.collaboraonline.com/ documentation](https://sdk.collaboraonline.com/docs/installation/CODE_Docker_image.html)
- [Configuration — SDK https://sdk.collaboraonline.com/ documentation](https://sdk.collaboraonline.com/docs/installation/Configuration.html#multihost-configuration)

### Dictionaries

[Official documentation](https://sdk.collaboraonline.com/docs/installation/CODE_Docker_image.html#how-to-configure-docker-image)

```auto
`- dictionaries` add dictionaries space separated `en_US en_GB de_DE` etc.

```

> By default only limited set of spelling dictionaries and thesauri are configured for CODE, mainly for performance reasons. The default set of languages is the following: `de_DE en_GB en_US es_ES fr_FR it nl pt_BR pt_PT ru`. With the dictionaries environment variable you can change this list. The dictionaries environment variable should contain the **space separated list** of language codes (optionally followed by country code). In order to save resources, it makes sense to load only those dictionaries that are actually needed.

### Collabora CODE statistics and administration interface

```auto
https://office.mydomain.tld/browser/dist/admin/admin.html

```

> **Upgrade Collabora Code Docker image**
>
> - stop docker container see [Docker stop](https://docs.docker.com/reference/cli/docker/compose/stop/)
> - remove image see [Docker rm](https://docs.docker.com/reference/cli/docker/image/rm/)
> - start docker stack see [Docker compose start](https://docs.docker.com/reference/cli/docker/compose/start/)

### Reverse proxy

[official Collabora reverse proxy settings for Nginx and Apache](https://sdk.collaboraonline.com/docs/installation/Proxy_settings.html)

> **Example: NPM, NGINX Reverse Proxy Manager configuration**
>
> Be aware that you are forwarding **http** and **Websockets support** (WSS) only!
> 
> ![grafik](https://github.com/user-attachments/assets/9c891779-dc78-4f9f-ab1f-d5bd3a762d29)

> **Example: Configure Apache as Reverse Proxy for Collabora**
>
> [wiki-md/nextcloud/install-configure-collabora-online-nextcloud-snap-server.md at main · yannicklescure/wiki-md · GitHub](https://github.com/yannicklescure/wiki-md/blob/main/nextcloud/install-configure-collabora-online-nextcloud-snap-server.md#2-configure-apache-as-reverse-proxy-for-collabora)

> **Example: Reverse proxy settings in Apache2 config (SSL termination)**
>
> [Making sure you're not a bot!](https://sdk.collaboraonline.com/docs/installation/Proxy_settings.html#reverse-proxy-settings-in-apache2-config-ssl-termination)

## Troubleshooting

> #### TIP
> 
> ![grafik](https://help.nextcloud.com/uploads/default/original/3X/1/5/1569941aefb648e9382cf06169ba54889557f5ce.png)
> 
> later Office versions (8.x.x) require a `/` slash at the end of your URL to connect successfully!

* * *

Resources

- [Collabora integration guide](https://help.nextcloud.com/t/collabora-integration-guide/151879)
- [Official documentation](https://sdk.collaboraonline.com/docs/installation/CODE_Docker_image.html#how-to-configure-docker-image)
- [Collabora Online](https://www.collaboraonline.com)
- [Collabora CODE](https://www.collaboraonline.com/code/)
- [Nextcloud Office](https://apps.nextcloud.com/apps/richdocuments)
- [101: reverse proxy](https://help.nextcloud.com/t/101-reverse-proxy/194840)
- [Collabora reverse proxy settings](https://sdk.collaboraonline.com/docs/installation/Proxy_settings.html)

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [February 5, 2025, 9:50am UTC](https://help.nextcloud.com/t/collabora-code-for-nextcloud-with-docker/216725/2 "2025-02-05T09:50:40Z")

</div>



---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [August 6, 2026, 8:23pm UTC](https://help.nextcloud.com/t/collabora-code-for-nextcloud-with-docker/216725/3 "2026-08-06T20:23:50Z")

</div>

Important note on latest CODE images - new distroless images don’t consume ssl.enable and ssl.termination settings right - either mount coolwsd.xml or stay on 26.04.2.1.1 until the issue is fixed. see [Solved: Collabora CODE 26.04.2.2.1 (Docker) behind Nginx reverse proxy - #2 by wwe - Installation & Configuration - Collabora Online](https://forum.collaboraonline.com/t/solved-collabora-code-26-04-2-2-1-docker-behind-nginx-reverse-proxy/4894/2) for details

**UPDATE** : Problem is solved with 26.04.2.4.1 ✅ and `extra_params` works on distroless as before 🥳 → only a small warning remains - don’t use 26.04.2.3.1

Reference: [Distroless migration docs](https://sdk.collaboraonline.com/docs/installation/Distroless_migration.html)

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [August 11, 2026, 8:18pm UTC](https://help.nextcloud.com/t/collabora-code-for-nextcloud-with-docker/216725/4 "2026-08-11T20:18:32Z")

</div>

# running CODE container as custom UID

hint only relevant for “real” Docker users (rootless/podman/K8n work different).

## problem

COOL uses hardcoded UID 1001 to start coolwsd:

> <https://github.com/CollaboraOnline/online/blob/6e2456e766f912e6c62a5f1fa3d69730ddad5da7/docker/from-source-gh-action/Dockerfile#L86-L89>

so with classic “rootfull” Docker it ends up running whatever user has UID 1001 on your system. In general it is not an issue as COOL/CODE container is really secure by default and never runs as root.. But personally I prefer to separate services using custom UID - because of security but also because of convenience - especially if you run multiple instances of the same application e.g. test and prod Nextcloud - by default it’s hard to know to which instance any of database or apache or nginx processes belongs. if each instance has it’s own user it’s easy to see which one is consuming resources - simply using ` ps aux` you already see the application in the first raw, try `ps -Ao user,uid,pid,comm --sort=uid`

 ![image](https://help.nextcloud.com/uploads/default/original/3X/4/d/4dfff73e030f2eecd24330e3209e04797b4e2c8f.png)

for this reason I tried hard to make it work for CODE Docker image - which is not easy because the UID 1001 is baked into an image and you can’t simply add `user: 1234:1234` to a #docker-compose. But fortunately solution exists already because OpenShift always run images using custom UID and there is small hack included in the CODE image:

> <https://github.com/CollaboraOnline/online/blob/6e2456e766f912e6c62a5f1fa3d69730ddad5da7/docker/from-source-gh-action/start-collabora-online.sh#L29-L41>

## solution

with help from very supportive Collabora people (thx Darshan 🤝) I crafted this instructions. ⚠ → run command from the directory whee your docker-compose file lives.

1. create the user to run COOL/CODE  
I’m using 1998 as user id - adjust to your needs (but keep the name cool)

```bash
sudo useradd --no-create-home --shell /usr/sbin/nologin --uid 1998 cool

```

1. required host directories  
create directories on the host to use as volume mounts and adjust user rights for host directories  
 → this is required to overwrite directories built-in in the Docker image owned by user 1001

```bash
mkdir -p ./cool/child-roots ./cool/cache ./cool/tmp
sudo chown -R 1998:0 ./cool/child-roots ./cool/cache ./cool/tmp
sudo chmod -R g+rwx ./cool/child-roots ./cool/cache ./cool/tmp

```

1. download the SElinux profile  
from: [online/docker/cool-seccomp-profile.json at main · CollaboraOnline/online · GitHub](https://github.com/CollaboraOnline/online/blob/main/docker/cool-seccomp-profile.json)

```auto
wget https://raw.githubusercontent.com/CollaboraOnline/online/refs/heads/main/docker/cool-seccomp-profile.json -o ./cool/cool-seccomp-profile.json

```

1. directories should now look like below (take into account the group is `0` which equals root)

```bash
$ ls -al ./cool
drwxrwxr-x+ 6 cool cool 4096 Aug 10 19:38 .
drwxrwxr-x+ 10 root root 4096 Aug 10 19:51 ..
drwxrwxr-x+ 4 cool root 4096 Aug 10 19:39 cache
drwxrwx--- 3 cool root 4096 Aug 10 19:38 child-roots
drwxr-xr-x+ 2 cool cool 4096 May 29 21:50 code_no_welcome
-rw-rw-r--+ 1 cool cool 16029 Aug 8 19:54 cool-seccomp-profile.json
drwxrwxr-x+ 2 cool root 4096 Aug 10 19:36 tmp

$ ls -aln cool
drwxrwxr-x+ 6 1998 1998 4096 Aug 11 19:19 .
drwxrwxr-x+ 11 0 0 4096 Aug 11 20:07 ..
drwxrwxr-x+ 4 1998 0 4096 Aug 11 19:22 cache
drwxrwx--- 3 1998 0 4096 Aug 11 19:21 child-roots
drwxr-xr-x+ 2 1998 1998 4096 May 29 21:50 code_no_welcome
-rw-rw-r--+ 1 1998 1998 16029 Aug 8 19:54 cool-seccomp-profile.json
-rw-r--r--+ 1 1998 1998 43631 Aug 6 20:08 coolwsd.xml
-rwxrwxrwx+ 1 1998 1998 46 Aug 11 19:19 passwd
drwxrwxr-x+ 2 1998 0 4096 Aug 11 19:20 tmp

```

1. adjust your compose file

- add `user: 1998:0`
- add `security_opt` section
- bind mount referring the 3 directories above

```yml
services:
  collabora:
    image: collabora/code:${CODE_VERSION}
    container_name: collabora
    restart: unless-stopped
    user: 1998:0
    security_opt:
      - seccomp:./cool/cool-seccomp-profile.json
      - apparmor:unconfined
...
    volumes:
      - ./cool/child-roots:/opt/cool/child-roots
      - ./cool/cache:/opt/cool/cache
      - ./cool/tmp:/tmp
      - ./cool/code_no_welcome:/usr/share/coolwsd/browser/dist/welcome:ro

```

/cool/code\_no\_welcome - is not relevant for this guide but is nifty trick to remove welcome banner on first connection.

1. restart your CODE container

```bash
docker compose down collabora && docker compose up -d collabora

```

1. final checks

- review if the container is “healthy” and returns if the proper discovery information and if there are errors in the log (`docker compose ps`, `../hosting/discovery` ,`docker compose logs collabora`)
- and finally the process runs with a UID of 1998 (cool) and the there is no audit warning 🙂

```bash
$ ps -au |grep coolwsd
cool 178201 0.7 0.1 593976 79748 pts/0 Ssl+ 19:38 0:02 /usr/bin/coolwsd --use-env-vars --o:sys_template_path=/opt/cool/systemplate --o:child_root_path=/opt/cool/child-roots --o:file_server_root_path=/usr/share/coolwsd --o:cache_files.path=/opt/cool/cache --o:logging.color=false --o:stop_on_config_change=true
cool 178371 0.6 0.5 631980 363640 pts/0 S+ 19:38 0:02 /usr/bin/coolforkit-ns --systemplate=/opt/cool/systemplate --lotemplate=/opt/collaboraoffice --childroot=/opt/cool/child-roots/1-06FBE50F/ --clientport=9980 --masterport=coolwsd-DleInVI2 --rlimits=limit_virt_mem_mb:0;limit_stack_mem_kb:8000;limit_file_size_mb:0;limit_num_open_files:0 --version --ui=classic --namespace

```
