1.4 KiB
1.4 KiB
External Proxy Mode
EXTERNAL_PROXY_MODE declares how a cloud reaches HTTPS when it is not using the bundled SSL stack.
Supported values:
none- Default for the bundled SSL stack (
docker-compose.devprod.yml) - Use when bundled Caddy terminates TLS for the cloud
- Default for the bundled SSL stack (
manual- Use for the no-SSL stack when some external reverse proxy exists, but it is not the repo-managed shared/global Caddy workflow
global-caddy- Use for the no-SSL stack when the cloud is registered into the repo-managed shared/global Caddy container
Why this exists
nossl alone is not enough to validate proxy/header alignment, because multiple topologies can sit in front of the same no-SSL stack.
This flag lets scripts distinguish:
- generic/manual external proxy usage
- repo-managed shared/global Caddy usage
Validation
Use:
./scripts/validate-proxy-alignment.sh --compose-file docker-compose.devprod.nossl.yml --env-file .env.devprod
For global-caddy mode, the validator additionally checks:
- Apache
RemoteIPHeaderis aligned withX-Forwarded-For - Nextcloud trusts forwarded proxy headers
- host bind settings are reachable from containerized shared/global Caddy
- Talk signaling upstream host is
host.docker.internal - Talk signaling upstream port matches the host-published
TALK_SIGNALING_PORT; the HPB container still listens internally onTALK_SIGNALING_CONTAINER_PORT(8081by default)