1
0
Fork 0
mirror of https://codeberg.org/icewind/haze.git synced 2026-10-01 08:44:09 +02:00

Merge pull request 'docs(proxy): Add instruction for fully local setups' (#37) from artonge/haze:artonge/docs/proxy_setup into main

Reviewed-on: https://codeberg.org/icewind/haze/pulls/37
This commit is contained in:
Robin Appelman 2026-08-15 02:08:32 +02:00
commit 33c94449c2

View file

@ -277,13 +277,13 @@ proxy to allow using a wildcard domain.
### Requirements ### Requirements
- A domain name you can set wildcard DNS records for - A domain name you can set wildcard DNS records for
- A reverse proxy like nginx or Apache - A reverse proxy like Nginx or Apache
- (optionally) a wildcard ssl certificate (can be acquiring using letsencrypt - (optionally) a wildcard ssl certificate (can be acquiring using letsencrypt
and dns verification) and dns verification)
### Setup ### DNS Setup
- Set a DNS record for `*.haze.exmaple.com` and `haze.example.com` pointing to - Set a DNS record for `*.haze.example.com` and `haze.example.com` pointing to
your development machine. your development machine.
- Set the `proxy` configuration with your domain and desired listen endpoint. - Set the `proxy` configuration with your domain and desired listen endpoint.
- Set up a service to run `haze proxy` in the background as your own user. A - Set up a service to run `haze proxy` in the background as your own user. A
@ -296,6 +296,42 @@ proxy to allow using a wildcard domain.
[this](https://community.letsencrypt.org/t/dns-providers-who-easily-integrate-with-lets-encrypt-dns-validation/86438) [this](https://community.letsencrypt.org/t/dns-providers-who-easily-integrate-with-lets-encrypt-dns-validation/86438)
lists some DNS providers and supported ACME clients. lists some DNS providers and supported ACME clients.
### Local Setup
- Setup `dnsmasq` to resolve `*.haze.test` to your development machine.
- Generate a wildcard ssl certificate for `*.haze.test` using `mkcert`:
```bash
# Generate local wildcard certificate
mkcert -cert-file <path-to-your-certificats>haze.test.crt -key-file <path-to-your-certificats>haze.test.key '*.haze.test'
```
- Set up a service to run `haze proxy` in the background as your own user. A
systemd user service is recommended (see [haze.service](./haze.service) for an
example).
- Setup a reverse proxy to proxy `*.haze.test` and `haze.test` to the `haze proxy`'s socket. Example for Nginx:
```nginx
upstream haze-handler {
server unix:/run/haze/haze.sock;
}
server {
listen 80;
listen 443 ssl;
http2 on;
server_name *.haze.test;
ssl_certificate <path-to-your-certificats>/haze.test.crt;
ssl_certificate_key <path-to-your-certificats>/haze.test.key;
location / {
proxy_pass http://haze-handler;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
```
### Usage ### Usage
When the proxy is configured, generated URLs for the instances will use a When the proxy is configured, generated URLs for the instances will use a