Skip to content

Reverse proxy: Let's Encrypt automation and config safety #30

Description

@halfcyan

Part of the Ultramarine Server roadmap (Outline: Server):

easy reverse proxy management (caddy or nginx; nginx proxy manager as the reference)
let's encrypt for dashboard (reverse proxy stuff)

Current state

Caddy management exists on both sides: tetra's reverse_proxy module manages site snippets (list/render/write/delete/reload), and the dashboard has a proxy page with site CRUD and reload. TLS and safety are missing.

Tasks

  • Let's Encrypt/ACME path for hosted sites (Caddy automatic HTTPS, or explicit ACME config where needed)
  • HTTPS for the dashboard itself through the same machinery
  • Validate config (caddy validate or equivalent) before write/reload; roll back on failure
  • Surface per-site TLS status (issued/expiry) so the dashboard can display it
  • Sensible behavior for LAN-only hosts with no public domain (self-signed/internal CA — explore)
  • Tests + docs (docs/agent-protocol.md, troubleshooting)

Dashboard consumer tracked in Ultramarine-Linux/dashboard#6.

Related: #29 (apps manage proxy snippets as companion files).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions