Managed Collabora Online hosting

Collaboration and identityOn-prem or sovereign site

In-browser editing of Word, Excel and PowerPoint files beside Nextcloud, on your own hardware or in the Pilae region you choose, so no document passes through someone else's cloud. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about Collabora Online

Licence
MPL-2.0
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
www.collaboraonline.com

Running Collabora Online in production: what it takes

  1. Deploy beside Nextcloud

    A pinned Collabora Online build we have run, on its own hostname on the private network, with TLS ending at the proxy in front of it and WebSocket connections passed through.

  2. Allow-list in both directions

    Collabora names the Nextcloud it serves, and Nextcloud names the Collabora servers that may fetch and save files. A WOPI proof key lets Nextcloud tell a request from Collabora apart from one sent by a browser on the same address.

  3. Size for documents open at once

    We size CPU and memory for your busiest hour, set a memory ceiling, and watch memory per document through its metrics endpoint in the first weeks.

  4. Restore it together with Nextcloud

    Documents live in Nextcloud and are backed up there. The Collabora configuration and fonts go offsite daily, encrypted. Once a month we restore Nextcloud and Collabora together into a scratch environment and edit a document.

  5. Upgrade when nobody is editing

    Collabora releases separately from Nextcloud. The Pilae Agent tests each build on a copy, waits for your approval and applies it in your window. A restart saves open documents first, but it interrupts everyone editing, so it happens outside working hours.

What Collabora Online is, and who runs it

Self-hosted Collabora Online for Word, Excel and PowerPoint files

Collabora Online is the LibreOffice engine run on a server and drawn in the browser. People open a Word, Excel or PowerPoint file from Nextcloud and edit it in place, several at once, with comments and tracked changes. The file keeps its format: a .docx is saved back as a .docx.

It is what turns Nextcloud from file storage into a replacement for the documents half of Microsoft 365. Without it, people download a file, edit it on the desktop and let the sync client carry it back. We run it beside your Nextcloud: on a dedicated machine in the same Pilae Cloud region, or on your own hardware next to it. In a sovereign workplace it is the piece that keeps documents edited where they are stored.

Collabora Online in production: sizing, allow-lists and fonts

Every open document runs in its own isolated process, so the server is sized by how many documents are open at once, not by how many people have accounts. It gets its own hostname on your private network and names the one Nextcloud allowed to use it. Left at its default, Collabora locks on to whichever host happens to connect first. Fonts are the other quiet failure: a document set in a typeface the server does not have reflows, so we install the ones you license and log the ones that are missing.

Collabora holds a document only while people edit it, and saves it back to Nextcloud after 30 seconds idle or every five minutes. So the backup that matters is Nextcloud’s. Ours covers the configuration and fonts, daily, encrypted, to an offsite location in your chosen country, and once a month we restore the pair into a scratch environment and edit a document there. Probes check the discovery endpoint every 60 seconds and alerts reach an engineer.

Collabora releases on its own schedule, not Nextcloud’s, so each of its upgrades is a separate change for the Pilae Agent: tried on a copy, applied in your window once you approve it, and recorded in the console.

Collabora Online licence and editions

Collabora develops the code on its own Gerrit server and mirrors it read-only on GitHub. Each major version of the supported build is supported for three years, and that is the build we run in production. Our operation is priced on request. Talk to us about moving document editing off Microsoft 365.

Collabora Online's source is primarily MPL-2.0, with some bundled components under other open-source licences. The free Development Edition, CODE, is a rolling release without long-term support, and Collabora does not recommend it for production. Its branding package is not open source. For production we deploy the supported build, which Collabora Productivity sells as a per-user subscription with long-term support, security updates and an SLA, and which Nextcloud also offers as a paid add-on to Nextcloud Enterprise. The subscription is held in your name, and we price it with you before you commit.

Collabora Online system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
4 vCPU · 8 GBA starting size for around forty concurrent users. Collabora's own rule of thumb is ten concurrent users per CPU thread and 50 MB of memory per user, plus 1 GB for the system. Large spreadsheets take more, so we keep headroom.
WOPI host
Nextcloud + richdocumentsCollabora stores no documents. It opens what Nextcloud hands it through the richdocuments app and saves it back there.
DNS and TLS
1 hostname · WebSocketSeparate from the Nextcloud hostname, behind a proxy that passes WebSocket connections. Browsers reach both hostnames, and the two servers reach each other over the private network.
Fonts
Carlito, Caladea + yoursCarlito and Caladea stand in for Calibri and Cambria at the same metrics, so line breaks hold. Aptos and corporate typefaces are not bundled, and are installed where their licence allows server use.
Subscription
Per user, from CollaboraHeld in your name. The free development edition is not supported for production, so we do not run it there.

Migrating from Microsoft 365 for the web to Collabora Online

There is no import step. Collabora Online opens Word, Excel and PowerPoint files as they are and saves them back in the same format, so the files move with the storage, from OneDrive or SharePoint into Nextcloud. What does not come across is what Microsoft 365 builds around the editor: Copilot, Loop components, and co-editing with people still on Microsoft 365. Macros stay off by default. Layout fidelity is high but not identical: Calibri and Cambria have metric-compatible substitutes, while documents set in Aptos or a corporate typeface reflow until those fonts are installed. So the effort sits in a few difficult files, not in the bulk. We find them first and decide, file by file, whether they move or stay on desktop Office.

  1. Find the difficult files

    Macro-enabled workbooks, heavily designed templates, files set in fonts the server does not have, and spreadsheets with external data. They decide the timeline, not the file count.

  2. Round-trip a sample

    A sample of your heaviest documents is opened and saved in Collabora, then reopened in desktop Office. You see the list of what changed before anyone is asked to switch.

  3. Set fonts and formats

    Licensed typefaces go on the server where their licence allows it, and Nextcloud creates new files as .docx, .xlsx and .pptx instead of its default OpenDocument formats.

  4. Switch the default, keep desktop Office

    Browser editing moves to Collabora on the agreed date. Desktop Office keeps working through the Nextcloud sync client for the files that need it, so the exceptions block nobody.

What we set in coolwsd.xml, and why

<!-- coolwsd.xml · acme · zur1 (excerpt) -->
<config>
    <server_name>office.acme.internal</server_name>
    <memproportion>70.0</memproportion>
    <per_document>
        <idlesave_duration_secs>30</idlesave_duration_secs>
        <autosave_duration_secs>300</autosave_duration_secs>
        <limit_load_secs>100</limit_load_secs>
    </per_document>
    <ssl>
        <enable>false</enable>
        <termination>true</termination>
    </ssl>
    <security>
        <enable_macros_execution>false</enable_macros_execution>
    </security>
    <storage>
        <wopi allow="true">
            <max_file_size>209715200</max_file_size>
            <alias_groups mode="groups">
                <group>
                    <host allow="true">https://files.acme.internal:443</host>
                </group>
            </alias_groups>
        </wopi>
    </storage>
    <remote_font_config>
        <url>https://fonts.acme.internal/fonts.json</url>
    </remote_font_config>
    <fonts_missing>
        <handling>both</handling>
    </fonts_missing>
</config>
An example excerpt. The alias group names the one Nextcloud allowed to open documents here, where the default locks on to whichever host happens to connect first. TLS ends at the proxy in front, macros stay off, files over 200 MB are refused, and fonts come from a list you control. The file lives in your repository.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running Collabora Online

Pricing is on request: a fixed price for onboarding, then a monthly price for Collabora Online, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

Collabora Online: common questions

Is Collabora Online open source?

Yes. The code is primarily MPL-2.0, with some bundled components under other open-source licences, and Collabora states that all of the code is open source. The CODE branding package is not, and an image can be built without it. What Collabora Productivity sells is the supported build: long-term support, security updates and an SLA, per user. The free Development Edition, CODE, is a rolling release without that support, and Collabora does not recommend it for production.

Where are the documents while someone edits them?

In Nextcloud, on storage you name. Collabora fetches a working copy when a document is opened, holds it in an isolated process while people edit, and saves it back after 30 seconds idle or every five minutes. The two run on the same site, so the working copy never leaves it: dedicated machines in the Pilae region that holds your Nextcloud, in ISO 27001-certified datacentres, or your own hardware.

Will files from Microsoft Office look the same?

Ordinary documents keep their layout. Differences show in complex layouts, in fonts the server does not have and in macro-enabled files, whose macros stay off by default. We round-trip a sample of your heaviest files before rollout and give you the list, and desktop Office stays available through the sync client for the files that need it.

How do people sign in?

Through Nextcloud. Collabora Online has no user accounts of its own. People sign in to Nextcloud through Keycloak or your own identity provider, such as Microsoft Entra ID, and Nextcloud hands Collabora an access token for the one document being opened. The admin console stays on the private network with its own credentials.

Who counts as a user for the Collabora subscription?

Everyone with an account who can create, edit or collaborate on documents, by Collabora's definition. People without an account that you share a document with, to co-edit or review, are not charged. We count with you from your directory before the proposal. Nextcloud Enterprise customers can also buy it as an add-on through Nextcloud.

Also in collaboration and identity

Back to apps

Bring us your Collabora Online. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.