GuidesProduction setup
Behind another reverse proxy
If another program owns ports 80 and 443, run the Ferry proxy on a local port behind it.
Use this setup in two cases:
- A reverse proxy or a cloud load balancer has ports 80 and 443 on the server: nginx, Caddy or Traefik, for example.
- TLS must stop at another place.
Start ferryd on a local port
ferryd --data-dir /var/lib/ferry \
--base-domain apps.example.com \
--proxy-addr 127.0.0.1:8080 \
--public-port 80In this setup, Ferry does not do HTTPS itself. Leave out --https-addr and --acme-email.
| Flag | Effect |
|---|---|
--proxy-addr 127.0.0.1:8080 | Only the reverse proxy can reach the Ferry proxy. No person can go around it. |
--public-port 80 | The port in the URLs that Ferry prints and resolves: ferry open, the dashboard, ${{service.NAME.url}}. Ferry leaves port 80 out, thus the URLs are http://<name>.apps.example.com. |
Then configure the reverse proxy, and read the limits of this setup.