# security an collabora code /hosting/discovery etc....

**URL:** <https://forum.collaboraonline.com/t/security-an-collabora-code-hosting-discovery-etc/2826>\
**Category:** Installation & Configuration\
**Created:** [August 2, 2024, 7:11am UTC](https://forum.collaboraonline.com/t/security-an-collabora-code-hosting-discovery-etc/2826 "2024-08-02T07:11:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![chrismaster](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/chrismaster/32/1243_2.png) [@chrismaster](https://forum.collaboraonline.com/u/chrismaster)\
**Post date:** [August 2, 2024, 7:11am UTC](https://forum.collaboraonline.com/t/security-an-collabora-code-hosting-discovery-etc/2826/1 "2024-08-02T07:11:43Z")

</div>

I tried Collabora CODE with podman and it works, looks great. Thx!  
Are there some docs about security.  
[https://mydomain:9980](https://mydomain:9980/) is open to the world. Behind a proxy, but everyone can access mydomain:9980/hosting/discovery  
Acces sites like [https://mydomain:9980/cool/getMetrics](https://mydomain:9980/cool/getMetrics) and [https://mydomain:9980/browser/dist/admin/admin.html](https://mydomain:9980/browser/dist/admin/admin.html) are secured by basic auth. Without user/password, there is no access. (I think 🙂 )  
With aliasgroup i set the wopiserver and net.frame\_ancestors who is allowed to embed in frame.  
Is this the way it works, or do I have to secure it some more, that no unwanted service is using my collabora service in their environment or does some harmful stuff.  
Thx  
Chris

---

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [August 2, 2024, 7:27am UTC](https://forum.collaboraonline.com/t/security-an-collabora-code-hosting-discovery-etc/2826/2 "2024-08-02T07:27:45Z")

</div>

@chrismaster Welcome to the Collabora Online forums!

To enhance the security and configuration of your Collabora CODE instance, refer to the following resources from the Collabora Online SDK documentation:

1. **Security Settings** :

2. **Configuration Topics** :

3. **Proxy Settings** :

Let me know if you need more support.

Thanks,  
Darshan
