Document and version-control the HTTPS front end

The UI is served at https://k6v6.mckero.dn42/ with nginx terminating TLS and the
server itself now bound to loopback, so it is not directly reachable.

No new address and no new certificate: 443 is shared with the other vhosts on
these DN42 addresses and separated by SNI, and the existing *.mckero.dn42 wildcard
already covers the name. Only DN42 addresses are bound, so the public 443
listeners on this host are untouched.

docs/reverse-proxy.md records the settings that are not optional, because each has
a failure mode that is easy to misread:
  proxy_buffering off  -- otherwise the frame stream arrives in bursts
  X-Forwarded-For      -- otherwise every log line is attributed to 127.0.0.1
  long read timeout    -- a paused guest emits nothing at all
  tcp_nodelay          -- Nagle would delay exactly the latency-critical requests

Two pitfalls hit while setting it up are written down. "http2 on;" needs nginx
1.25.1+ and this host runs 1.22.1, and because nginx -t was run before the symlink
existed it passed, then reload failed and left nginx stopped, briefly taking the
other sites down. Separately, a newly added listen address needs a reload to be
bound: after the failed reload, v6 requests failed with nothing in the error log
until a second reload created the socket.

deploy/nginx-k6v6.conf keeps a copy in the repo, since nothing here
version-controls /etc.

Verified: HTTP 200 on both families with the certificate validating (no -k), 7
frames in a 20 KB stream sample, log entries attributed to real client addresses.
This commit is contained in:
mckero committed 2026-08-28 11:39:17 +01:00
1 parent f2c5c6b31b
commit a4a8f21d50
3 files changed
+194 -2

No files matched your search

+11 -2
View File
@@ -67,6 +67,8 @@ keypresses silently stop working. Run the test after touching that code;
armv7m_systick.*.patched SysTick with the poll-boost property added
assets/
calibration.bin 512-byte dump from a real radio
deploy/ nginx vhost for the HTTPS front end
docs/reverse-proxy.md how https://k6v6.mckero.dn42/ is served
docs/screenshots/ LCD captures used in this README
tools/ run, screenshot, inject keys, probe state
keypad_test.py keypad regression test, boots its own instance
@@ -187,8 +189,15 @@ Two constraints worth knowing before you use it:
### Reaching it from elsewhere
`--host ::` makes it reachable off-box, which with no authentication means the
port must be filtered by source address. `tools/dn42_firewall.sh` restricts it to
The deployment here runs the server on loopback and puts nginx in front of it for
TLS, at `https://k6v6.mckero.dn42/`. See
[docs/reverse-proxy.md](docs/reverse-proxy.md) for the vhost, including the two
settings that matter for this app: `proxy_buffering off` (or the frame stream
arrives in bursts) and `X-Forwarded-For` (or every log line is attributed to
127.0.0.1).
Binding directly with `--host ::` also works, but with no authentication the port
then has to be filtered by source address. `tools/dn42_firewall.sh` restricts it to
DN42:
tools/dn42_firewall.sh apply 8080 # DN42 + loopback only