mirror of
https://github.com/MCKero6423/uv-k5-v3-emulator.git
synced 2026-10-02 03:15:36 +00:00
Document and version-control the HTTPS front end
The UI is served at https://k6v6.mckero.dn42/ with nginx terminating TLS and the server itself now bound to loopback, so it is not directly reachable. No new address and no new certificate: 443 is shared with the other vhosts on these DN42 addresses and separated by SNI, and the existing *.mckero.dn42 wildcard already covers the name. Only DN42 addresses are bound, so the public 443 listeners on this host are untouched. docs/reverse-proxy.md records the settings that are not optional, because each has a failure mode that is easy to misread: proxy_buffering off -- otherwise the frame stream arrives in bursts X-Forwarded-For -- otherwise every log line is attributed to 127.0.0.1 long read timeout -- a paused guest emits nothing at all tcp_nodelay -- Nagle would delay exactly the latency-critical requests Two pitfalls hit while setting it up are written down. "http2 on;" needs nginx 1.25.1+ and this host runs 1.22.1, and because nginx -t was run before the symlink existed it passed, then reload failed and left nginx stopped, briefly taking the other sites down. Separately, a newly added listen address needs a reload to be bound: after the failed reload, v6 requests failed with nothing in the error log until a second reload created the socket. deploy/nginx-k6v6.conf keeps a copy in the repo, since nothing here version-controls /etc. Verified: HTTP 200 on both families with the certificate validating (no -k), 7 frames in a 20 KB stream sample, log entries attributed to real client addresses.
This commit is contained in:
1 parent
f2c5c6b31b
commit
a4a8f21d50
3 files changed
+194
-2
No files matched your search
@@ -0,0 +1,49 @@
|
||||
# Reverse proxy for the UV-K5 emulator web UI (tools/webui.py).
|
||||
#
|
||||
# Shares 443 on the existing DN42 addresses via SNI, so no new IP is needed and it
|
||||
# coexists with dns.mckero.dn42 on the same socket.
|
||||
#
|
||||
# Certificate is the existing *.mckero.dn42 wildcard, which already covers this
|
||||
# name -- no new issuance required.
|
||||
|
||||
server {
|
||||
listen 172.21.91.140:80;
|
||||
listen [fd3c:3f9b:6424:2::5]:80;
|
||||
server_name k6v6.mckero.dn42;
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 172.21.91.140:443 ssl;
|
||||
listen [fd3c:3f9b:6424:2::5]:443 ssl;
|
||||
server_name k6v6.mckero.dn42;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/mckero-wildcard/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/mckero-wildcard/privkey.pem;
|
||||
|
||||
# The emulator UI has no authentication of its own: anyone who reaches it can
|
||||
# drive the radio. Reachability is limited by the DN42-only bind plus the
|
||||
# iptables rules in uvk5-port/sim/tools/dn42_firewall.sh.
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:8080;
|
||||
proxy_http_version 1.1;
|
||||
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
|
||||
# /stream is an endless multipart/x-mixed-replace response. Buffering it
|
||||
# would hold frames back and the picture would arrive in bursts or stall
|
||||
# outright, so buffering is off and the read timeout is long enough that an
|
||||
# idle screen does not look like a dropped connection.
|
||||
proxy_buffering off;
|
||||
proxy_request_buffering off;
|
||||
proxy_read_timeout 3600s;
|
||||
proxy_send_timeout 3600s;
|
||||
|
||||
# Latency is the whole point of this UI; Nagle would add delay to the
|
||||
# small, frequent keypress responses.
|
||||
tcp_nodelay on;
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user