Solved: Collabora CODE 26.04.2.2.1 (Docker) behind Nginx reverse proxy

I’m running Collabora CODE since age using docker-compose and all the time I used traefik and set extra_params=--o:ssl.enable=false --o:ssl.termination=true as described in Am I misunderstanding ssl.termination and the discovery endpoint? - #4 by darshan

the config is working up to 26.04.2.1.1 and stops working with 26.04.2.2.1.

I clearly see my ENV is valid

docker inspect -f '{{json .Config.Env}}' collabora|jq
[
  "extra_params=--o:ssl.enable=false --o:ssl.termination=true",
  "username={redacted},
  "password={redacted},
  "aliasgroup1=https://nc.mydomain.tld:443",
  "aliasgroup2=https://nc.myotherdomain.tld:443",
  "dictionaries=de_DE en_US es_ES ru",
  "PATH=/usr/bin:/bin",
  "LD_LIBRARY_PATH=/lib:/usr/lib:/lib/x86_64-linux-gnu:/usr/lib/x86_64-linux-gnu",
  "LC_CTYPE=C.UTF-8"
]

in the startup log I can see

wsd-00001-00001 2026-08-06 19:46:05.307031 [ coolwsd ] INF  SSL support: SSL is enabled.|wsd/COOLWSD.cpp:1938
wsd-00001-00001 2026-08-06 19:46:05.307040 [ coolwsd ] INF  SSL support: termination is disabled.|wsd/COOLWSD.cpp:1939

using curl I can confirm ../hosting/discovery is using https and self-signed cert.

reverting to 26.04.2.1.1 immediately makes it work :white_check_mark:

I seems with this upgrade TLS termination is broken, likely it is related to

Recent images (26.04.2.2.1 and later) are distroless: they have no shell and a minimal base. If you are upgrading from an older image, see Migrating to the distroless Docker image.

btw - new bot-protection CDN in front of the docs is terrible - it take many seconds until one can access the docs :frowning:

Update: using coolwsd.xml I could change both setting and TLS termination works..