1
0
Fork 0
mirror of https://codeberg.org/icewind/haze.git synced 2026-10-01 08:44:09 +02:00

spelling fixes in changelog and book

This commit is contained in:
Robin Appelman 2026-09-23 15:10:49 +02:00
commit 51d0279c41
14 changed files with 110 additions and 102 deletions

View file

@ -1,10 +1,10 @@
# HTTPS
The proxy can be setup to enable using https to access the running instances.
Besides the warm and fuzy feeling of knowing that nobody can snoop on the trafic
that is happening completely local inside your machine. Accessing the page over
https is required for some javascript features (such as service workers), as
they are only available in "secure contexts".
The proxy can be setup to enable using HTTPS to access the running instances.
Besides the warm and fuzzy feeling of knowing that nobody can snoop on the
traffic that is happening completely local inside your machine. Accessing the
page over HTTPS is required for some JavaScript features (such as service
workers), as they are only available in "secure contexts".
## Getting a wildcard certificate
@ -26,18 +26,18 @@ lists some DNS providers and supported ACME clients.
You can also create a self-signed wildcard certificate using a tool like
`mkcert`. This certificate will not be trusted by your browser and tools like
curl, but you can add manually add it to the trusted certificates on your
system, or bypass the certficate warning in the browser/curl every time.
system, or bypass the certificates warning in the browser/curl every time.
```bash
# Generate local wildcard certificate
mkcert -cert-file <path-to-your-certificats>haze.example.com.crt -key-file <path-to-your-certificats>haze.example.com.key '*.haze.example.com'
mkcert -cert-file <path-to-your-certificates>haze.example.com.crt -key-file <path-to-your-certificates>haze.example.com.key '*.haze.example.com'
```
## Using the certificate
### Without reverse proxy
The haze proxy can serve over https directly, to enable that add the following
The haze proxy can serve over HTTPS directly, to enable that add the following
to the `[proxy]` section of your `haze.toml`.
```toml
@ -64,8 +64,8 @@ server {
http2 on;
server_name *.haze.example.com;
ssl_certificate <path-to-your-certificats>/haze.example.com.crt;
ssl_certificate_key <path-to-your-certificats>/haze.example.com.key;
ssl_certificate <path-to-your-certificates>/haze.example.com.crt;
ssl_certificate_key <path-to-your-certificates>/haze.example.com.key;
location / {
proxy_pass http://haze-handler;