Operations

Reverse proxy HTTPS

Ready-to-adapt examples for Caddy, Nginx, and Traefik, both inside and outside Docker.

Choose the example that matches the proxy location. The name nasdash works only if both containers share the same Docker network. A proxy installed on the host typically uses 127.0.0.1:2504.

Caddy installed on the host

Publish NasDash only on the loopback interface:

services:
  nasdash:
    ports:
      - "127.0.0.1:2504:2504"

Then in Caddyfile:

Caddyfile
nasdash.example.com {
  encode zstd gzip
  reverse_proxy 127.0.0.1:2504
}

Caddy obtains the certificate if the public DNS points to the server and the ports required for the challenge are accessible.

Nginx installed on the host

server {
    listen 443 ssl http2;
    server_name nasdash.example.com;

    ssl_certificate     /etc/letsencrypt/live/nasdash.example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/nasdash.example.com/privkey.pem;

    location / {
        proxy_pass http://127.0.0.1:2504;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
    }
}

Certificate management is not handled by NasDash. Test the Nginx configuration before reloading.

Caddy in the same Compose

services:
  nasdash:
    image: ghcr.io/lucas-lepajollec/nasdash:latest
    expose:
      - "2504"
    networks: [web]

  caddy:
    image: caddy:2-alpine
    ports:
      - "80:80"
      - "443:443"
      - "443:443/udp"
    volumes:
      - ./Caddyfile:/etc/caddy/Caddyfile:ro
      - caddy-data:/data
      - caddy-config:/config
    networks: [web]

networks:
  web:

volumes:
  caddy-data:
  caddy-config:
Caddyfile
nasdash.example.com {
  reverse_proxy nasdash:2504
}

Traefik in the same Compose

The example assumes an external network proxy already used by Traefik and a resolver named letsencrypt:

services:
  nasdash:
    image: ghcr.io/lucas-lepajollec/nasdash:latest
    networks: [proxy]
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.nasdash.rule=Host(`nasdash.example.com`)"
      - "traefik.http.routers.nasdash.entrypoints=websecure"
      - "traefik.http.routers.nasdash.tls=true"
      - "traefik.http.routers.nasdash.tls.certresolver=letsencrypt"
      - "traefik.http.services.nasdash.loadbalancer.server.port=2504"

networks:
  proxy:
    external: true

Checks after publishing

curl -I https://nasdash.example.com/api/health

Also verify login, logout, service links, widget loading, and the absence of mixed content. Never add NasDash secrets to the proxy labels if its inspection is accessible to other users.