# Solved: Collabora CODE 26.04.2.2.1 (Docker) behind Nginx reverse proxy

**URL:** <https://forum.collaboraonline.com/t/solved-collabora-code-26-04-2-2-1-docker-behind-nginx-reverse-proxy/4894>\
**Category:** Installation & Configuration\
**Created:** [July 23, 2026, 11:57am UTC](https://forum.collaboraonline.com/t/solved-collabora-code-26-04-2-2-1-docker-behind-nginx-reverse-proxy/4894 "2026-07-23T11:57:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ikumi](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/ikumi/32/2345_2.png) [@ikumi](https://forum.collaboraonline.com/u/ikumi)\
**Post date:** [July 23, 2026, 11:57am UTC](https://forum.collaboraonline.com/t/solved-collabora-code-26-04-2-2-1-docker-behind-nginx-reverse-proxy/4894/1 "2026-07-23T11:57:15Z")

</div>

Hello,

I would like to share my findings in case it helps someone else.

## Environment

- Ubuntu 24.04.4 LTS

- Docker Engine Community 29.6.1

- Docker Compose

- Nextcloud ( Docker image: nextcloud:34.0.1-apache)

- Collabora CODE 26.04.2.2.1 (Docker image: collabora/code:26.04.2.2.1)

- Nginx reverse proxy

Collabora configuration:

collabora:

image: collabora/code:26.04.2.2.1

environment:

cert\_domain: collabora[.]example[.]com

domain: nextcloud\\.example\\.com

extra\_params: --o:ssl.enable=false --o:ssl.termination=true

Nginx configuration:

location / {

proxy\_pass [http://collabora:9980](http://collabora:9980);

}

Symptoms

--------

Nextcloud Office reported that it could not connect to the Collabora server.

Accessing the Collabora URL through nginx returned:

502 Bad Gateway

Nginx logs contained:

upstream prematurely closed connection while reading response header from upstream

Investigation

-------------

The container appeared healthy:

docker inspect collabora --format=‘{{.State.Health.Status}}’

Result:

healthy

Collabora logs showed:

Ready to accept connections on port 9980.

Network connectivity was fine:

nc -vz collabora 9980

Result:

Connected to collabora 9980

However:

curl [http] ://collabora:9980/hosting/discovery

returned:

Empty reply from server

I then tested HTTPS directly:

curl -vk [https] ://collabora:9980/hosting/discovery

This returned a valid WOPI discovery XML document and established a TLS connection using a self-signed certificate generated by Collabora.

Root Cause

----------

Although the container was configured with:

extra\_params: --o:ssl.enable=false --o:ssl.termination=true

CODE 26.04.2.2.1 was still serving HTTPS on port 9980.

Because nginx was configured with:

proxy\_pass [http]://collabora:9980;

there was a protocol mismatch:

Nginx (HTTP) → Collabora (HTTPS)

which caused:

- Empty reply from server

- upstream prematurely closed connection

- 502 Bad Gateway

Solution

--------

I changed the nginx upstream to HTTPS:

> location / {
> 
> proxy\_pass [https]://collabora:9980;
> 
> proxy\_http\_version 1.1;
> 
> proxy\_ssl\_verify off;
> 
> proxy\_set\_header Host $host;
> 
> proxy\_set\_header X-Forwarded-Proto https;
> 
> proxy\_set\_header X-Forwarded-For $proxy\_add\_x\_forwarded\_for;
> 
> proxy\_set\_header X-Real-IP $remote\_addr;
> 
> proxy\_set\_header Upgrade $http\_upgrade;
> 
> proxy\_set\_header Connection “upgrade”;
> 
> proxy\_read\_timeout 3600;
> 
> proxy\_connect\_timeout 3600;
> 
> }

Result

------

After restarting nginx:

- [https] ://collabora.example.com/ worked correctly

- /hosting/discovery was reachable

- Nextcloud reported:

“Collabora Online server is reachable”

- Documents opened successfully in Collabora Online

One thing that confused me during troubleshooting:

CODE 26.04.2.2.1 appeared to be serving HTTPS on port 9980 even though I had configured:

--o:ssl.enable=false --o:ssl.termination=true

The issue was resolved by changing the nginx upstream from HTTP to HTTPS, so I’m wondering whether I misunderstood how these parameters are intended to work, or whether something has changed in recent releases.

Thank you.

---

<div class="post-metadata">

**Author:** ![wwe](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/wwe/32/534_2.png) [@wwe](https://forum.collaboraonline.com/u/wwe)\
**Post date:** [August 6, 2026, 8:02pm UTC](https://forum.collaboraonline.com/t/solved-collabora-code-26-04-2-2-1-docker-behind-nginx-reverse-proxy/4894/2 "2026-08-06T20:02:59Z")

</div>

I’m running Collabora CODE since age using docker-compose and all the time I used traefik and set `extra_params=--o:ssl.enable=false --o:ssl.termination=true` as described in [Am I misunderstanding ssl.termination and the discovery endpoint? - #4 by darshan](https://forum.collaboraonline.com/t/am-i-misunderstanding-ssl-termination-and-the-discovery-endpoint/3970/4)

the config is working up to 26.04.2.1.1 and stops working with 26.04.2.2.1.

I clearly see my ENV is valid

```json
docker inspect -f '{{json .Config.Env}}' collabora|jq
[
  "extra_params=--o:ssl.enable=false --o:ssl.termination=true",
  "username={redacted},
  "password={redacted},
  "aliasgroup1=https://nc.mydomain.tld:443",
  "aliasgroup2=https://nc.myotherdomain.tld:443",
  "dictionaries=de_DE en_US es_ES ru",
  "PATH=/usr/bin:/bin",
  "LD_LIBRARY_PATH=/lib:/usr/lib:/lib/x86_64-linux-gnu:/usr/lib/x86_64-linux-gnu",
  "LC_CTYPE=C.UTF-8"
]

```

in the startup log I can see

```auto
wsd-00001-00001 2026-08-06 19:46:05.307031 [coolwsd] INF SSL support: SSL is enabled.|wsd/COOLWSD.cpp:1938
wsd-00001-00001 2026-08-06 19:46:05.307040 [coolwsd] INF SSL support: termination is disabled.|wsd/COOLWSD.cpp:1939

```

using curl I can confirm `../hosting/discovery` is using https and self-signed cert.

reverting to 26.04.2.1.1 immediately makes it work ✅

I seems with this upgrade TLS termination is broken, likely it is related to

> Recent images (26.04.2.2.1 and later) are distroless: they have no shell and a minimal base. If you are upgrading from an older image, see [Migrating to the distroless Docker image](https://sdk.collaboraonline.com/docs/installation/Distroless_migration.html).

btw - new bot-protection CDN in front of the docs is terrible - it take many seconds until one can access the docs ☹

Update: using coolwsd.xml I could change both setting and TLS termination works..

---

<div class="post-metadata">

**Author:** ![markus](https://avatars.discourse-cdn.com/v4/letter/m/b782af/32.png) [@markus](https://forum.collaboraonline.com/u/markus)\
**Post date:** [August 7, 2026, 8:40pm UTC](https://forum.collaboraonline.com/t/solved-collabora-code-26-04-2-2-1-docker-behind-nginx-reverse-proxy/4894/3 "2026-08-07T20:40:04Z")

</div>

> [@ikumi](#):
>
> Collabora CODE 26.04.2.2.1

> [@wwe](#):
>
> (..) and stops working with 26.04.2.2.1

I don’t use `--o:ssl.enable=false` or `--o:ssl.termination=true`, but I had a similar problem with `--o:logging.disable_server_audit=true`. That option had no effect in [`cp-26.04.2-2`](https://github.com/CollaboraOnline/online.mirror/tree/cp-26.04.2-2).

However, this was then fixed in [`cp-26.04.2-3`](https://github.com/CollaboraOnline/online.mirror/tree/cp-26.04.2-3):

- [https://github.com/CollaboraOnline/online/issues/16019](https://github.com/CollaboraOnline/online/issues/16019)
- [https://gerrit.collaboraoffice.com/c/online/+/7274](https://gerrit.collaboraoffice.com/c/online/+/7274)

---

<div class="post-metadata">

**Author:** ![wwe](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/wwe/32/534_2.png) [@wwe](https://forum.collaboraonline.com/u/wwe)\
**Post date:** [August 8, 2026, 8:55pm UTC](https://forum.collaboraonline.com/t/solved-collabora-code-26-04-2-2-1-docker-behind-nginx-reverse-proxy/4894/4 "2026-08-08T20:55:55Z")

</div>

Yes I confirm this is solved with 26.04.2.4.1..  
it’s a shame I missed this image was shipped already 16d ago 🤦‍♂️

---

<div class="post-metadata">

**Author:** ![system](https://europe1.discourse-cdn.com/flex013/uploads/collaboraonline/original/1X/326930fc3c4344f7b3daaa009c34a90206dee4be.png) [@system](https://forum.collaboraonline.com/u/system)\
**Post date:** [September 7, 2026, 8:56pm UTC](https://forum.collaboraonline.com/t/solved-collabora-code-26-04-2-2-1-docker-behind-nginx-reverse-proxy/4894/5 "2026-09-07T20:56:08Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
