2.3 KiB
Staging reverse proxy
whoneedhelp.imalto.site.conf is the HTTP vhost consumed by Certbot's Nginx
installer on the VPN gateway. It forwards HTTP and LiveView WebSocket traffic
to the workstation at 10.8.0.14:4010.
The workstation's ignored .env must use:
PHX_HOST=whoneedhelp.imalto.site
PHX_SCHEME=https
PHX_URL_PORT=443
TRAEFIK_TRUSTED_IPS=10.8.0.1/32
The last setting allows forwarded headers only from the observed VPN address of the gateway. Do not replace it with Traefik's insecure forwarded-header mode.
The checked server currently uses the standard Ubuntu Nginx/Certbot layout.
After copying the vhost to /home/simple/whoneedhelp.imalto.site.conf, install
and enable it with root privileges:
sudo install -o root -g root -m 0644 \
/home/simple/whoneedhelp.imalto.site.conf \
/etc/nginx/sites-available/whoneedhelp.imalto.site
sudo ln -s \
/etc/nginx/sites-available/whoneedhelp.imalto.site \
/etc/nginx/sites-enabled/whoneedhelp.imalto.site
sudo nginx -t
sudo systemctl reload nginx
sudo certbot --nginx --redirect -d whoneedhelp.imalto.site
sudo nginx -t
If validation fails before certificate issuance, remove only the new symlink and file, validate the previous configuration, and reload:
sudo rm -f /etc/nginx/sites-enabled/whoneedhelp.imalto.site
sudo rm -f /etc/nginx/sites-available/whoneedhelp.imalto.site
sudo nginx -t
sudo systemctl reload nginx
Observed staging deployment
Verified on 2026-07-18:
whoneedhelp.imalto.siteresolves to the VPN gateway77.110.101.144.- Plain HTTP redirects to HTTPS.
- HTTPS responds over HTTP/2 with a valid Let's Encrypt certificate whose SAN
is
whoneedhelp.imalto.site; the observed expiry is 2026-10-16. /healthz/liveand/healthz/readyreturn HTTP 200.- The public homepage and fingerprinted CSS, JavaScript, and logo assets return HTTP 200 with zero browser console errors or warnings.
- A direct WSS handshake through Nginx returns
101 Switching Protocols. - Nginx and
certbot.timerare active.
The server also reports pre-existing protocol-option and duplicate-server-name warnings in unrelated enabled vhosts. Its complete configuration test still reports success. The staging domain publishes no AAAA record, so this bootstrap vhost intentionally declares only the observed IPv4 listener.