# Secure my Collabora office

**URL:** <https://forum.collaboraonline.com/t/secure-my-collabora-office/3356>\
**Category:** Installation & Configuration\
**Created:** [January 27, 2025, 1:56pm UTC](https://forum.collaboraonline.com/t/secure-my-collabora-office/3356 "2025-01-27T13:56:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![djshades2004](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/djshades2004/32/1535_2.png) [@djshades2004](https://forum.collaboraonline.com/u/djshades2004)\
**Post date:** [January 27, 2025, 1:56pm UTC](https://forum.collaboraonline.com/t/secure-my-collabora-office/3356/1 "2025-01-27T13:56:43Z")

</div>

Hi, I currrently have the application installed on the same server as my nextcloud server in docker. this is the command I used:

> docker run -t -d -p 192.168.1.182:9980:9980 -e “aliasgroup1=[https://nextcloud.domain.online:443](https://nextcloud.domain.online:443)” --restart always collabora/code

how can I make sure that no one uses my office server domain located at: office.domain.online.

I have seen details about editing an xml file but how do I do that with a docker container image.

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [January 27, 2025, 3:04pm UTC](https://forum.collaboraonline.com/t/secure-my-collabora-office/3356/2 "2025-01-27T15:04:44Z")

</div>

hii @djshades2004 welcome to the collabora online forum

To ensure that no one else uses your Collabora Office server (hosted at `office.domain.online`), you can secure it by restricting access to only your Nextcloud server. Here’s how:

1. **Alias Group Security** :  
In your `docker run` command, you’ve already added the `aliasgroup1` to allow only requests from `https://nextcloud.domain.online`. This is a good first step.

2. **Edit Security Settings in XML** :  
To further restrict access, you’ll need to edit the `coolwsd.xml` configuration file. Since you’re using Docker:

3. **Forum Resources** :  
These threads provide detailed steps to secure your server:

4. **Explore More Solutions** :  
There are several other topics on the Collabora Online forums related to securing your setup. Explore the forums to discover more ways to restrict access and ensure a secure deployment.

[https://forum.collaboraonline.com/search?q=secure](https://forum.collaboraonline.com/search?q=secure)

Thanks  
Darshan

---

<div class="post-metadata">

**Author:** ![djshades2004](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/djshades2004/32/1535_2.png) [@djshades2004](https://forum.collaboraonline.com/u/djshades2004)\
**Post date:** [January 27, 2025, 3:36pm UTC](https://forum.collaboraonline.com/t/secure-my-collabora-office/3356/3 "2025-01-27T15:36:39Z")

</div>

Thank you Darshan for your reply, I wondered what the aliasgroup statement did. Should this be enough for security?

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [January 27, 2025, 4:25pm UTC](https://forum.collaboraonline.com/t/secure-my-collabora-office/3356/4 "2025-01-27T16:25:22Z")

</div>

Hi @djshades2004,

I hope you’re doing well!  
To help you secure your environment, I recommend checking out the official documentation here:  
[Collabora Online Security Settings](https://sdk.collaboraonline.com/docs/installation/Configuration.html#security-settings)

It provides detailed guidance on setting up options to enhance the security of your deployment.

Thanks,  
Darshan

---

<div class="post-metadata">

**Author:** ![iamdoubz](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/iamdoubz/32/1522_2.png) [@iamdoubz](https://forum.collaboraonline.com/u/iamdoubz)\
**Post date:** [January 27, 2025, 5:23pm UTC](https://forum.collaboraonline.com/t/secure-my-collabora-office/3356/5 "2025-01-27T17:23:36Z")

</div>

> [@darshan](#):
>
> /etc/coolwsd/coolwsd.xml

You can do quick additional things:

`docker run -t -d -p 127.0.0.1:9980:9980 -e “aliasgroup1=https://nextcloud.domain.online:443” --restart always collabora/code`

This binds to localhost. You will have to use your reverse proxy to redirect your Collabora office URL to it.

Additionally, you can “map” the quoted xml file to a local file and change the contents of the file to only read from your local IP’s.

`docker run -t -d -p 127.0.0.1:9980:9980 -v /local/docker/filepath/coolwsd.xml:/etc/coolwsd/coolwsd.xml:rw -e “aliasgroup1=https://nextcloud.domain.online:443” --restart always collabora/code`

You also should add to your environment `-e` a username and password to further harden your “admin” Collabora path.

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [January 29, 2025, 9:54am UTC](https://forum.collaboraonline.com/t/secure-my-collabora-office/3356/6 "2025-01-29T09:54:59Z")

</div>


