mirror of
https://codeberg.org/icewind/haze.git
synced 2026-10-01 16:54:08 +02:00
spelling fixes in changelog and book
This commit is contained in:
parent
307dba81ec
commit
e52f978bea
14 changed files with 110 additions and 102 deletions
|
|
@ -1,7 +1,7 @@
|
|||
# Proxy
|
||||
|
||||
By default, instances can be accessed by their IP. In order to get more
|
||||
memorable URLs and allow supporting https. haze comes with a builtin reverse
|
||||
memorable URLs and allow supporting HTTPS. haze comes with a builtin reverse
|
||||
proxy to allow using a wildcard domain.
|
||||
|
||||
## Setup
|
||||
|
|
@ -10,17 +10,17 @@ proxy to allow using a wildcard domain.
|
|||
`haze.example.com` pointing to your development machine.
|
||||
- Set the `proxy` configuration with your domain and desired listen endpoint.
|
||||
- Set up a service to run `haze proxy` in the background as your own user. A
|
||||
systemd user service is recommended (see
|
||||
SystemD user service is recommended (see
|
||||
[haze.service](<[./haze.service](https://codeberg.org/icewind/haze/src/branch/main/haze.service)>)
|
||||
for an example).
|
||||
- If you're already running a reverse proxy, configure your reverse proxy of
|
||||
choice to proxy `*.haze.example.com` and `haze.example.com` to the proxy's
|
||||
listen endpoint.
|
||||
- (Optionally) [setup https](./https.html) for the proxy.
|
||||
- (Optionally) [setup HTTPS](./https.html) for the proxy.
|
||||
|
||||
### Configuration
|
||||
|
||||
Add the following configuration to the `haze.toml` config file:
|
||||
Add the following configuration to the `haze.toml` configuration file:
|
||||
|
||||
```toml
|
||||
[proxy]
|
||||
|
|
@ -34,13 +34,13 @@ listen = "127.0.0.1:8080" # the port+ip to listen on
|
|||
If you have no other http(s) servers on your development machine, you can setup
|
||||
things without a reverse proxy.
|
||||
|
||||
Simply configure the proxy to listen on port `80` (or `443` when using http).
|
||||
Simply configure the proxy to listen on port `80` (or `443` when using HTTPS).
|
||||
|
||||
Binding to port 80 or443 as a regular user requires either giving the haze
|
||||
binary the `net_bind_service` capability with
|
||||
`sudo setcap cap_net_bind_service=+ep $(which haze)` (this will have to be done
|
||||
every time your upgrade haze) or configure your system to allow unpriviled users
|
||||
to bind on the low port numbers. Using
|
||||
every time your upgrade haze) or configure your system to allow unprivileged
|
||||
users to bind on the low port numbers. Using
|
||||
`sysctl net.ipv4.ip_unprivileged_port_start=80` and writing
|
||||
|
||||
```
|
||||
|
|
@ -56,7 +56,7 @@ probably want to setup a reverse proxy to allow them to all be served on your
|
|||
machine.
|
||||
|
||||
The setup for this will depend on your reverse proxy of the choice, the
|
||||
following example config is for `nginx`.
|
||||
following example configuration is for `nginx`.
|
||||
|
||||
```nginx
|
||||
upstream haze-handler {
|
||||
|
|
|
|||
|
|
@ -1,12 +1,12 @@
|
|||
# DNS
|
||||
|
||||
Since the domain name used for the instance is dynamic, a wildcard dns record is
|
||||
Since the domain name used for the instance is dynamic, a wildcard DNS record is
|
||||
required.
|
||||
|
||||
## With your domain's DNS provider
|
||||
|
||||
If you own a domain you would like to use, you can create a wildcard domain
|
||||
withing the DNS settings of your DNS provider. For example creating a record an
|
||||
within the DNS settings of your DNS provider. For example creating a record an
|
||||
`A` record for `*.haze.example.com` with a value of `127.0.0.1` and a similar
|
||||
one for `haze.example.com`.
|
||||
|
||||
|
|
@ -15,8 +15,8 @@ one for `haze.example.com`.
|
|||
If you do not own a "real" domain for using with haze, you can setup `dnsmasq`
|
||||
locally to achieve the same goal instead.
|
||||
|
||||
How to install and enable `dnsmasq` will depend on your distro of choice and
|
||||
should be documented by it's documentation.
|
||||
How to install and enable `dnsmasq` will depend on your Linux distribution of
|
||||
choice and should be documented by it's documentation.
|
||||
|
||||
Once setup, a configuration line like
|
||||
|
||||
|
|
|
|||
|
|
@ -1,10 +1,10 @@
|
|||
# HTTPS
|
||||
|
||||
The proxy can be setup to enable using https to access the running instances.
|
||||
Besides the warm and fuzy feeling of knowing that nobody can snoop on the trafic
|
||||
that is happening completely local inside your machine. Accessing the page over
|
||||
https is required for some javascript features (such as service workers), as
|
||||
they are only available in "secure contexts".
|
||||
The proxy can be setup to enable using HTTPS to access the running instances.
|
||||
Besides the warm and fuzzy feeling of knowing that nobody can snoop on the
|
||||
traffic that is happening completely local inside your machine. Accessing the
|
||||
page over HTTPS is required for some JavaScript features (such as service
|
||||
workers), as they are only available in "secure contexts".
|
||||
|
||||
## Getting a wildcard certificate
|
||||
|
||||
|
|
@ -26,18 +26,18 @@ lists some DNS providers and supported ACME clients.
|
|||
You can also create a self-signed wildcard certificate using a tool like
|
||||
`mkcert`. This certificate will not be trusted by your browser and tools like
|
||||
curl, but you can add manually add it to the trusted certificates on your
|
||||
system, or bypass the certficate warning in the browser/curl every time.
|
||||
system, or bypass the certificates warning in the browser/curl every time.
|
||||
|
||||
```bash
|
||||
# Generate local wildcard certificate
|
||||
mkcert -cert-file <path-to-your-certificats>haze.example.com.crt -key-file <path-to-your-certificats>haze.example.com.key '*.haze.example.com'
|
||||
mkcert -cert-file <path-to-your-certificates>haze.example.com.crt -key-file <path-to-your-certificates>haze.example.com.key '*.haze.example.com'
|
||||
```
|
||||
|
||||
## Using the certificate
|
||||
|
||||
### Without reverse proxy
|
||||
|
||||
The haze proxy can serve over https directly, to enable that add the following
|
||||
The haze proxy can serve over HTTPS directly, to enable that add the following
|
||||
to the `[proxy]` section of your `haze.toml`.
|
||||
|
||||
```toml
|
||||
|
|
@ -64,8 +64,8 @@ server {
|
|||
http2 on;
|
||||
server_name *.haze.example.com;
|
||||
|
||||
ssl_certificate <path-to-your-certificats>/haze.example.com.crt;
|
||||
ssl_certificate_key <path-to-your-certificats>/haze.example.com.key;
|
||||
ssl_certificate <path-to-your-certificates>/haze.example.com.crt;
|
||||
ssl_certificate_key <path-to-your-certificates>/haze.example.com.key;
|
||||
|
||||
location / {
|
||||
proxy_pass http://haze-handler;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue