GuidesProduction setup
Configure the reverse proxy
The reverse proxy sends each app hostname to the Ferry proxy and keeps the Host header.
map $http_upgrade $connection_upgrade {
default upgrade;
'' close;
}
server {
listen 443 ssl;
server_name *.apps.example.com;
ssl_certificate /etc/ssl/apps.example.com/fullchain.pem;
ssl_certificate_key /etc/ssl/apps.example.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_buffering off;
proxy_read_timeout 1h;
}
}This is an example with nginx. Each other reverse proxy must do the same four things.
What the reverse proxy must do
| Task | Lines of the example |
|---|---|
Send the hostnames to 127.0.0.1:8080: *.apps.example.com, your custom domains, and the dashboard host if you set --dashboard-host. | server_name, proxy_pass |
| Keep the original Host header. The Ferry proxy reads it to find the service. | proxy_set_header Host $host; |
Hold the TLS certificates: a wildcard certificate for *.apps.example.com and one for each custom domain. | listen 443 ssl;, ssl_certificate, ssl_certificate_key |
| Pass the upgrade headers and do not buffer the responses. Then WebSockets and streamed logs continue to work. | map, proxy_http_version 1.1;, Upgrade, Connection, proxy_buffering off; |
proxy_read_timeout 1h; lets a connection stay open for one hour with no data.