who_need_help/deploy/nginx/README.md

2.3 KiB

Staging reverse proxy

whoneedhelp.imalto.site.conf is the HTTP vhost consumed by Certbot's Nginx installer on the VPN gateway. It forwards HTTP and LiveView WebSocket traffic to the workstation at 10.8.0.14:4010.

The workstation's ignored .env must use:

PHX_HOST=whoneedhelp.imalto.site
PHX_SCHEME=https
PHX_URL_PORT=443
TRAEFIK_TRUSTED_IPS=10.8.0.1/32

The last setting allows forwarded headers only from the observed VPN address of the gateway. Do not replace it with Traefik's insecure forwarded-header mode.

The checked server currently uses the standard Ubuntu Nginx/Certbot layout. After copying the vhost to /home/simple/whoneedhelp.imalto.site.conf, install and enable it with root privileges:

sudo install -o root -g root -m 0644 \
  /home/simple/whoneedhelp.imalto.site.conf \
  /etc/nginx/sites-available/whoneedhelp.imalto.site
sudo ln -s \
  /etc/nginx/sites-available/whoneedhelp.imalto.site \
  /etc/nginx/sites-enabled/whoneedhelp.imalto.site
sudo nginx -t
sudo systemctl reload nginx
sudo certbot --nginx --redirect -d whoneedhelp.imalto.site
sudo nginx -t

If validation fails before certificate issuance, remove only the new symlink and file, validate the previous configuration, and reload:

sudo rm -f /etc/nginx/sites-enabled/whoneedhelp.imalto.site
sudo rm -f /etc/nginx/sites-available/whoneedhelp.imalto.site
sudo nginx -t
sudo systemctl reload nginx

Observed staging deployment

Verified on 2026-07-18:

  • whoneedhelp.imalto.site resolves to the VPN gateway 77.110.101.144.
  • Plain HTTP redirects to HTTPS.
  • HTTPS responds over HTTP/2 with a valid Let's Encrypt certificate whose SAN is whoneedhelp.imalto.site; the observed expiry is 2026-10-16.
  • /healthz/live and /healthz/ready return HTTP 200.
  • The public homepage and fingerprinted CSS, JavaScript, and logo assets return HTTP 200 with zero browser console errors or warnings.
  • A direct WSS handshake through Nginx returns 101 Switching Protocols.
  • Nginx and certbot.timer are active.

The server also reports pre-existing protocol-option and duplicate-server-name warnings in unrelated enabled vhosts. Its complete configuration test still reports success. The staging domain publishes no AAAA record, so this bootstrap vhost intentionally declares only the observed IPv4 listener.