From c91b5d44acc582044bf76ab079294f182a39f4fe Mon Sep 17 00:00:00 2001 From: Louis Chmn Date: Fri, 14 Aug 2026 20:24:54 +0200 Subject: [PATCH] docs(proxy): Add instruction for fully local setups --- README.md | 42 +++++++++++++++++++++++++++++++++++++++--- 1 file changed, 39 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 7a1142a..b6bfae5 100644 --- a/README.md +++ b/README.md @@ -277,13 +277,13 @@ proxy to allow using a wildcard domain. ### Requirements - A domain name you can set wildcard DNS records for -- A reverse proxy like nginx or Apache +- A reverse proxy like Nginx or Apache - (optionally) a wildcard ssl certificate (can be acquiring using letsencrypt and dns verification) -### Setup +### DNS Setup -- Set a DNS record for `*.haze.exmaple.com` and `haze.example.com` pointing to +- Set a DNS record for `*.haze.example.com` and `haze.example.com` pointing to your development machine. - Set the `proxy` configuration with your domain and desired listen endpoint. - Set up a service to run `haze proxy` in the background as your own user. A @@ -296,6 +296,42 @@ proxy to allow using a wildcard domain. [this](https://community.letsencrypt.org/t/dns-providers-who-easily-integrate-with-lets-encrypt-dns-validation/86438) lists some DNS providers and supported ACME clients. +### Local Setup + +- Setup `dnsmasq` to resolve `*.haze.test` to your development machine. +- Generate a wildcard ssl certificate for `*.haze.test` using `mkcert`: +```bash +# Generate local wildcard certificate +mkcert -cert-file haze.test.crt -key-file haze.test.key '*.haze.test' +``` +- Set up a service to run `haze proxy` in the background as your own user. A + systemd user service is recommended (see [haze.service](./haze.service) for an + example). +- Setup a reverse proxy to proxy `*.haze.test` and `haze.test` to the `haze proxy`'s socket. Example for Nginx: +```nginx +upstream haze-handler { + server unix:/run/haze/haze.sock; +} + +server { + listen 80; + listen 443 ssl; + http2 on; + server_name *.haze.test; + + ssl_certificate /haze.test.crt; + ssl_certificate_key /haze.test.key; + + location / { + proxy_pass http://haze-handler; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + } +} +``` + ### Usage When the proxy is configured, generated URLs for the instances will use a