Reverse proxy HTTPS
Ready-to-adapt examples for Caddy, Nginx, and Traefik, both inside and outside Docker.
Choose the example that matches the proxy location. The name nasdash works only if both containers share the same Docker network. A proxy installed on the host typically uses 127.0.0.1:2504.
Caddy installed on the host
Publish NasDash only on the loopback interface:
services:
nasdash:
ports:
- "127.0.0.1:2504:2504"Then in Caddyfile:
nasdash.example.com {
encode zstd gzip
reverse_proxy 127.0.0.1:2504
}Caddy obtains the certificate if the public DNS points to the server and the ports required for the challenge are accessible.
Nginx installed on the host
server {
listen 443 ssl http2;
server_name nasdash.example.com;
ssl_certificate /etc/letsencrypt/live/nasdash.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/nasdash.example.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:2504;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}Certificate management is not handled by NasDash. Test the Nginx configuration before reloading.
Caddy in the same Compose
services:
nasdash:
image: ghcr.io/lucas-lepajollec/nasdash:latest
expose:
- "2504"
networks: [web]
caddy:
image: caddy:2-alpine
ports:
- "80:80"
- "443:443"
- "443:443/udp"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile:ro
- caddy-data:/data
- caddy-config:/config
networks: [web]
networks:
web:
volumes:
caddy-data:
caddy-config:nasdash.example.com {
reverse_proxy nasdash:2504
}Traefik in the same Compose
The example assumes an external network proxy already used by Traefik and a resolver named letsencrypt:
services:
nasdash:
image: ghcr.io/lucas-lepajollec/nasdash:latest
networks: [proxy]
labels:
- "traefik.enable=true"
- "traefik.http.routers.nasdash.rule=Host(`nasdash.example.com`)"
- "traefik.http.routers.nasdash.entrypoints=websecure"
- "traefik.http.routers.nasdash.tls=true"
- "traefik.http.routers.nasdash.tls.certresolver=letsencrypt"
- "traefik.http.services.nasdash.loadbalancer.server.port=2504"
networks:
proxy:
external: trueChecks after publishing
curl -I https://nasdash.example.com/api/healthAlso verify login, logout, service links, widget loading, and the absence of mixed content. Never add NasDash secrets to the proxy labels if its inspection is accessible to other users.