1
0
Fork 0
mirror of https://codeberg.org/icewind/haze.git synced 2026-10-01 16:54:08 +02:00

spelling fixes in changelog and book

This commit is contained in:
Robin Appelman 2026-09-23 15:10:49 +02:00
commit e52f978bea
14 changed files with 110 additions and 102 deletions

View file

@ -1,7 +1,7 @@
# Proxy
By default, instances can be accessed by their IP. In order to get more
memorable URLs and allow supporting https. haze comes with a builtin reverse
memorable URLs and allow supporting HTTPS. haze comes with a builtin reverse
proxy to allow using a wildcard domain.
## Setup
@ -10,17 +10,17 @@ proxy to allow using a wildcard domain.
`haze.example.com` pointing to your development machine.
- Set the `proxy` configuration with your domain and desired listen endpoint.
- Set up a service to run `haze proxy` in the background as your own user. A
systemd user service is recommended (see
SystemD user service is recommended (see
[haze.service](<[./haze.service](https://codeberg.org/icewind/haze/src/branch/main/haze.service)>)
for an example).
- If you're already running a reverse proxy, configure your reverse proxy of
choice to proxy `*.haze.example.com` and `haze.example.com` to the proxy's
listen endpoint.
- (Optionally) [setup https](./https.html) for the proxy.
- (Optionally) [setup HTTPS](./https.html) for the proxy.
### Configuration
Add the following configuration to the `haze.toml` config file:
Add the following configuration to the `haze.toml` configuration file:
```toml
[proxy]
@ -34,13 +34,13 @@ listen = "127.0.0.1:8080" # the port+ip to listen on
If you have no other http(s) servers on your development machine, you can setup
things without a reverse proxy.
Simply configure the proxy to listen on port `80` (or `443` when using http).
Simply configure the proxy to listen on port `80` (or `443` when using HTTPS).
Binding to port 80 or443 as a regular user requires either giving the haze
binary the `net_bind_service` capability with
`sudo setcap cap_net_bind_service=+ep $(which haze)` (this will have to be done
every time your upgrade haze) or configure your system to allow unpriviled users
to bind on the low port numbers. Using
every time your upgrade haze) or configure your system to allow unprivileged
users to bind on the low port numbers. Using
`sysctl net.ipv4.ip_unprivileged_port_start=80` and writing
```
@ -56,7 +56,7 @@ probably want to setup a reverse proxy to allow them to all be served on your
machine.
The setup for this will depend on your reverse proxy of the choice, the
following example config is for `nginx`.
following example configuration is for `nginx`.
```nginx
upstream haze-handler {

View file

@ -1,12 +1,12 @@
# DNS
Since the domain name used for the instance is dynamic, a wildcard dns record is
Since the domain name used for the instance is dynamic, a wildcard DNS record is
required.
## With your domain's DNS provider
If you own a domain you would like to use, you can create a wildcard domain
withing the DNS settings of your DNS provider. For example creating a record an
within the DNS settings of your DNS provider. For example creating a record an
`A` record for `*.haze.example.com` with a value of `127.0.0.1` and a similar
one for `haze.example.com`.
@ -15,8 +15,8 @@ one for `haze.example.com`.
If you do not own a "real" domain for using with haze, you can setup `dnsmasq`
locally to achieve the same goal instead.
How to install and enable `dnsmasq` will depend on your distro of choice and
should be documented by it's documentation.
How to install and enable `dnsmasq` will depend on your Linux distribution of
choice and should be documented by it's documentation.
Once setup, a configuration line like

View file

@ -1,10 +1,10 @@
# HTTPS
The proxy can be setup to enable using https to access the running instances.
Besides the warm and fuzy feeling of knowing that nobody can snoop on the trafic
that is happening completely local inside your machine. Accessing the page over
https is required for some javascript features (such as service workers), as
they are only available in "secure contexts".
The proxy can be setup to enable using HTTPS to access the running instances.
Besides the warm and fuzzy feeling of knowing that nobody can snoop on the
traffic that is happening completely local inside your machine. Accessing the
page over HTTPS is required for some JavaScript features (such as service
workers), as they are only available in "secure contexts".
## Getting a wildcard certificate
@ -26,18 +26,18 @@ lists some DNS providers and supported ACME clients.
You can also create a self-signed wildcard certificate using a tool like
`mkcert`. This certificate will not be trusted by your browser and tools like
curl, but you can add manually add it to the trusted certificates on your
system, or bypass the certficate warning in the browser/curl every time.
system, or bypass the certificates warning in the browser/curl every time.
```bash
# Generate local wildcard certificate
mkcert -cert-file <path-to-your-certificats>haze.example.com.crt -key-file <path-to-your-certificats>haze.example.com.key '*.haze.example.com'
mkcert -cert-file <path-to-your-certificates>haze.example.com.crt -key-file <path-to-your-certificates>haze.example.com.key '*.haze.example.com'
```
## Using the certificate
### Without reverse proxy
The haze proxy can serve over https directly, to enable that add the following
The haze proxy can serve over HTTPS directly, to enable that add the following
to the `[proxy]` section of your `haze.toml`.
```toml
@ -64,8 +64,8 @@ server {
http2 on;
server_name *.haze.example.com;
ssl_certificate <path-to-your-certificats>/haze.example.com.crt;
ssl_certificate_key <path-to-your-certificats>/haze.example.com.key;
ssl_certificate <path-to-your-certificates>/haze.example.com.crt;
ssl_certificate_key <path-to-your-certificates>/haze.example.com.key;
location / {
proxy_pass http://haze-handler;