mirror of
https://codeberg.org/icewind/haze.git
synced 2026-10-01 08:44:09 +02:00
feat(proxy): Support direct TLS connection
This allows runing haze proxy without a reverse proxy while still having the possiblity to use HTTPS. Signed-off-by: Louis Chmn <louis@chmn.me>
This commit is contained in:
parent
7121474198
commit
048bbe8de5
5 changed files with 87 additions and 11 deletions
29
README.md
29
README.md
|
|
@ -299,14 +299,16 @@ By default, instances can be accessed by their IP. In order to get more
|
|||
memorable URLs and allow supporting https, haze comes with a builtin reverse
|
||||
proxy to allow using a wildcard domain.
|
||||
|
||||
### Requirements
|
||||
### DNS Setup
|
||||
|
||||
#### Requirements
|
||||
|
||||
- A domain name you can set wildcard DNS records for
|
||||
- A reverse proxy like Nginx or Apache
|
||||
- (optionally) a wildcard ssl certificate (can be acquiring using letsencrypt
|
||||
and dns verification)
|
||||
|
||||
### DNS Setup
|
||||
#### Steps
|
||||
|
||||
- Set a DNS record for `*.haze.example.com` and `haze.example.com` pointing to
|
||||
your development machine.
|
||||
|
|
@ -334,8 +336,23 @@ mkcert -cert-file <path-to-your-certificats>haze.test.crt -key-file <path-to-you
|
|||
- Set up a service to run `haze proxy` in the background as your own user. A
|
||||
systemd user service is recommended (see [haze.service](./haze.service) for an
|
||||
example).
|
||||
- Setup a reverse proxy to proxy `*.haze.test` and `haze.test` to the
|
||||
`haze proxy`'s socket. Example for Nginx:
|
||||
- Either point haze at the certificate directly:
|
||||
|
||||
```toml
|
||||
[proxy]
|
||||
address = "haze.test"
|
||||
https = true
|
||||
listen = "0.0.0.0:443"
|
||||
cert = "<path-to-your-certificats>/haze.test.crt"
|
||||
key = "<path-to-your-certificats>/haze.test.key"
|
||||
```
|
||||
|
||||
Binding to port 443 as a regular user requires either
|
||||
`sudo setcap cap_net_bind_service=+ep $(which haze)` or
|
||||
`sysctl net.ipv4.ip_unprivileged_port_start=443`.
|
||||
|
||||
- Or, if you already have another web server, setup it up to proxy `*.haze.test`
|
||||
and `haze.test` to the `haze proxy`'s socket. Example for Nginx:
|
||||
|
||||
```nginx
|
||||
upstream haze-handler {
|
||||
|
|
@ -467,9 +484,11 @@ read_only = true
|
|||
|
||||
[proxy] # optional
|
||||
address = "haze.example.com" # base domain
|
||||
https = true # Is the proxy behind a https terminating proxy
|
||||
https = true # Whether the instances are reachable over https
|
||||
listen = "/run/haze/haze.sock" # either a unix socket path
|
||||
#listen = "127.0.0.1:8080" # or a socket address
|
||||
cert = "/path/to/haze.test.crt" # optional - PEM encoded certificate chain
|
||||
key = "/path/to/haze.test.key" # optional - PEM encoded private key
|
||||
|
||||
# presets allow for easy usage of commonly used setups
|
||||
[[preset]]
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue