Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
72 changes: 30 additions & 42 deletions configs/nginx/nginx.conf
Original file line number Diff line number Diff line change
@@ -1,61 +1,49 @@
# =====================================================================
# OpenELIS internal reverse proxy — HTTP-only build for Dokploy
#
# Dokploy's Traefik terminates public TLS (Let's Encrypt) and forwards
# plain HTTP to this container on port 80. This proxy then stitches the
# app together: / -> React frontend | /api/ -> Tomcat backend (8443).
# The nginx->backend hop stays HTTPS internally with the self-signed
# certs from the certgen service (nginx does not verify upstream certs).
# =====================================================================

worker_processes 1;

events { worker_connections 1024; }

http {
server {
listen 80;
server_name _;
##### Comment to run on HTTP
return 301 https://$host$request_uri;

##### Uncomment to run on HTTP
# location / {
# proxy_pass http://frontend.openelis.org;
# proxy_redirect off;

# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_set_header X-Forwarded-Proto $scheme;
# }
# location /api/ {
# proxy_pass https://oe.openelis.org:8443/api/;
# proxy_redirect off;

# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_set_header X-Forwarded-Host $server_name;
# proxy_set_header X-Forwarded-Proto $scheme;
# }
# TLS is terminated at Traefik. Trust its X-Forwarded-Proto so the
# app generates correct https URLs; default to https if the header
# is missing (it will always be present in normal operation).
map $http_x_forwarded_proto $fwd_proto {
default $http_x_forwarded_proto;
"" https;
}

server {
listen [::]:443 ssl;
listen 443 ssl default;
server_name __;

ssl_certificate /etc/nginx/certs/${OE_NGINX_CERT};
ssl_certificate_key /etc/nginx/keys/${OE_NGINX_KEY};
listen 80;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep the proxy listening on HTTPS for compose users

In the default docker-compose deployment, the proxy service still publishes 443:443 and the README's documented entry point is https://localhost/, but this config now only binds nginx to port 80. Anyone running the repository as documented, without an external Traefik/Dokploy TLS terminator, will get connection failures on HTTPS instead of the OpenELIS frontend. Please either retain the SSL listener for the compose path or split/update the deployment config so the HTTP-only listener is only used behind Traefik.

Useful? React with 👍 / 👎.

server_name _;

proxy_set_header X-Forwarded-For $proxy_protocol_addr; # To forward the original client's IP address
proxy_set_header X-Forwarded-Proto $scheme; # to forward the original protocol (HTTP or HTTPS)
proxy_set_header Host $host; # to forward the original host requested by the client
absolute_redirect off;

absolute_redirect off;
proxy_set_header X-Forwarded-Proto $fwd_proto;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header Host $host;

location / {
proxy_pass http://frontend.openelis.org;
proxy_redirect off;
proxy_pass http://frontend.openelis.org;
proxy_redirect off;
}

location /api/ {
proxy_pass https://oe.openelis.org:8443/api/;
proxy_redirect off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $server_name;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto $fwd_proto;
}
}
}