Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -116,6 +116,9 @@ server {

location /exapps/ {
proxy_pass http://127.0.0.1:8780/exapps/;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
Expand All @@ -125,6 +128,42 @@ server {
}
```

The `proxy_http_version` and the `Upgrade`/`Connection` headers let WebSocket connections through to ExApps;
nginx drops them otherwise.

If you point `proxy_pass` at a container or DNS name instead of an IP (for example `appapi-harp` on a
user-defined Docker network), do not write the name into `proxy_pass` directly: nginx resolves it once at startup
and refuses to start whenever that container is absent (`host not found in upstream`), which takes every site on
that nginx down. Put the upstream in a variable, which nginx resolves per request, and give it a resolver. Use
this block instead of the one above, not next to it:

```nginx
server {
listen 80;
server_name nextcloud.com;

resolver 127.0.0.11 valid=30s; # Docker's embedded DNS; use your own resolver outside Docker

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

maybe this is not required to be set?

# no /exapps/ suffix: with a variable, nginx would send every request to exactly that path
set $harp_upstream http://appapi-harp:8780;

location /exapps/ {
Comment thread
coderabbitai[bot] marked this conversation as resolved.
proxy_pass $harp_upstream;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_read_timeout 1800s;
}
}
```

`127.0.0.11` only answers inside containers on a user-defined network (such as a Compose network), not on the
default `bridge` network and not for nginx on the host. nginx's `resolver` also ignores `/etc/hosts`, so names
added with `--add-host` or `extra_hosts` do not resolve this way; keep the plain `proxy_pass` form for those.

### Caddy Example

```caddyfile
Expand Down
Loading