Behind a TLS-terminating proxy

With Cloudflare, Traefik or a host nginx terminating TLS in front, choose one:

  • point it at https://…:443, with the bundled nginx's certificate, or
  • switch the bundled nginx to plain HTTP on port 80 with the shipped override. Port 80 then proxies instead of redirecting, and 443 is not published:
.env
COMPOSE_FILE=docker-compose.prod.yml:docker-compose.behind-proxy.yml
  • Keep port 80 reachable only from the terminator: nothing on it is encrypted.
  • SECURE_COOKIES stays true; the browser still talks HTTPS.
  • nginx still strips the client-IP headers the terminator adds, so it rate-limits the terminator's address. Rate-limit per client at the terminator.

Edit this page on GitHub