# Reverse proxy for the UV-K5 emulator web UI (tools/webui.py). # # Shares 443 on the existing DN42 addresses via SNI, so no new IP is needed and it # coexists with dns.mckero.dn42 on the same socket. # # Certificate is the existing *.mckero.dn42 wildcard, which already covers this # name -- no new issuance required. server { listen 172.21.91.140:80; listen [fd3c:3f9b:6424:2::5]:80; server_name k6v3.mckero.dn42; return 301 https://$host$request_uri; } server { listen 172.21.91.140:443 ssl; listen [fd3c:3f9b:6424:2::5]:443 ssl; server_name k6v3.mckero.dn42; ssl_certificate /etc/letsencrypt/live/mckero-wildcard/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/mckero-wildcard/privkey.pem; # The emulator UI has no authentication of its own: anyone who reaches it can # drive the radio. Reachability is limited by the DN42-only bind plus the # iptables rules in uvk5-port/sim/tools/dn42_firewall.sh. location / { proxy_pass http://127.0.0.1:8080; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # /stream is an endless multipart/x-mixed-replace response. Buffering it # would hold frames back and the picture would arrive in bursts or stall # outright, so buffering is off and the read timeout is long enough that an # idle screen does not look like a dropped connection. proxy_buffering off; proxy_request_buffering off; proxy_read_timeout 3600s; proxy_send_timeout 3600s; # Latency is the whole point of this UI; Nagle would add delay to the # small, frequent keypress responses. tcp_nodelay on; } }