1
0
Fork 0
mirror of https://codeberg.org/icewind/haze.git synced 2026-10-01 08:44:09 +02:00

feat(proxy): Support direct TLS connection

This allows runing haze proxy without a reverse proxy while still having
the possiblity to use HTTPS.

Signed-off-by: Louis Chmn <louis@chmn.me>
This commit is contained in:
Louis Chmn 2026-09-16 22:31:16 +02:00
commit 048bbe8de5
5 changed files with 87 additions and 11 deletions

View file

@ -299,14 +299,16 @@ By default, instances can be accessed by their IP. In order to get more
memorable URLs and allow supporting https, haze comes with a builtin reverse
proxy to allow using a wildcard domain.
### Requirements
### DNS Setup
#### Requirements
- A domain name you can set wildcard DNS records for
- A reverse proxy like Nginx or Apache
- (optionally) a wildcard ssl certificate (can be acquiring using letsencrypt
and dns verification)
### DNS Setup
#### Steps
- Set a DNS record for `*.haze.example.com` and `haze.example.com` pointing to
your development machine.
@ -334,8 +336,23 @@ mkcert -cert-file <path-to-your-certificats>haze.test.crt -key-file <path-to-you
- Set up a service to run `haze proxy` in the background as your own user. A
systemd user service is recommended (see [haze.service](./haze.service) for an
example).
- Setup a reverse proxy to proxy `*.haze.test` and `haze.test` to the
`haze proxy`'s socket. Example for Nginx:
- Either point haze at the certificate directly:
```toml
[proxy]
address = "haze.test"
https = true
listen = "0.0.0.0:443"
cert = "<path-to-your-certificats>/haze.test.crt"
key = "<path-to-your-certificats>/haze.test.key"
```
Binding to port 443 as a regular user requires either
`sudo setcap cap_net_bind_service=+ep $(which haze)` or
`sysctl net.ipv4.ip_unprivileged_port_start=443`.
- Or, if you already have another web server, setup it up to proxy `*.haze.test`
and `haze.test` to the `haze proxy`'s socket. Example for Nginx:
```nginx
upstream haze-handler {
@ -467,9 +484,11 @@ read_only = true
[proxy] # optional
address = "haze.example.com" # base domain
https = true # Is the proxy behind a https terminating proxy
https = true # Whether the instances are reachable over https
listen = "/run/haze/haze.sock" # either a unix socket path
#listen = "127.0.0.1:8080" # or a socket address
cert = "/path/to/haze.test.crt" # optional - PEM encoded certificate chain
key = "/path/to/haze.test.key" # optional - PEM encoded private key
# presets allow for easy usage of commonly used setups
[[preset]]