Commit 0c68f866ef
Verified · cmc
Layout: unified · split
linux/nginx/etc/nginx/conf.d/piped.conf added +74
| @@ -0,0 +1,74 @@ | ||
| 1 | # Piped -- Host-based router on 127.0.0.1:8077 | |
| 2 | # | |
| 3 | # WHY THIS EXISTS: the Cloudflare tunnel routes all three Piped hostnames to | |
| 4 | # localhost:8077 -- | |
| 5 | # piped.krz.sh -> :8077 | |
| 6 | # pipedapi.krz.sh -> :8077 (should be the backend) | |
| 7 | # pipedproxy.krz.sh -> :8077 (should be the media proxy) | |
| 8 | # so the API and media-proxy hostnames landed on the frontend and Piped was | |
| 9 | # broken. The frontend advertises BACKEND_HOSTNAME=pipedapi.krz.sh to browsers, | |
| 10 | # so every API call failed. | |
| 11 | # | |
| 12 | # The tidier fix is two edits in the Cloudflare dashboard (point pipedapi at | |
| 13 | # :8078 and pipedproxy at :8079). This file fixes it server-side instead, and | |
| 14 | # is harmless if the dashboard is corrected later -- the tunnel would simply | |
| 15 | # reach the containers directly and these blocks would go unused. | |
| 16 | # | |
| 17 | # Ports: frontend :8076 (moved from :8077), backend :8078, media proxy :8079. | |
| 18 | # | |
| 19 | # NOTE: custom.d/basic.conf is deliberately NOT included. Its Permissions-Policy | |
| 20 | # sets fullscreen=(), which would stop videos going fullscreen. | |
| 21 | ||
| 22 | # Frontend. default_server so the Tor onion for piped (which targets :8077 with | |
| 23 | # a .onion Host header) also lands here. | |
| 24 | server { | |
| 25 | listen 127.0.0.1:8077 default_server; | |
| 26 | server_name piped.krz.sh; | |
| 27 | ||
| 28 | location / { | |
| 29 | proxy_pass http://127.0.0.1:8076; | |
| 30 | proxy_set_header Host $host; | |
| 31 | proxy_set_header X-Real-IP $remote_addr; | |
| 32 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |
| 33 | proxy_set_header X-Forwarded-Proto $scheme; | |
| 34 | proxy_http_version 1.1; | |
| 35 | } | |
| 36 | } | |
| 37 | ||
| 38 | # Backend API. | |
| 39 | server { | |
| 40 | listen 127.0.0.1:8077; | |
| 41 | server_name pipedapi.krz.sh; | |
| 42 | ||
| 43 | location / { | |
| 44 | proxy_pass http://127.0.0.1:8078; | |
| 45 | proxy_set_header Host $host; | |
| 46 | proxy_set_header X-Real-IP $remote_addr; | |
| 47 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |
| 48 | proxy_set_header X-Forwarded-Proto $scheme; | |
| 49 | proxy_http_version 1.1; | |
| 50 | # The backend emits its own CORS headers; do not add or override any | |
| 51 | # here or the browser will reject the API responses. | |
| 52 | proxy_read_timeout 120; | |
| 53 | } | |
| 54 | } | |
| 55 | ||
| 56 | # Media proxy. Streams video, so no buffering and generous timeouts. | |
| 57 | server { | |
| 58 | listen 127.0.0.1:8077; | |
| 59 | server_name pipedproxy.krz.sh; | |
| 60 | ||
| 61 | location / { | |
| 62 | proxy_pass http://127.0.0.1:8079; | |
| 63 | proxy_set_header Host $host; | |
| 64 | proxy_set_header X-Real-IP $remote_addr; | |
| 65 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | |
| 66 | proxy_set_header X-Forwarded-Proto $scheme; | |
| 67 | proxy_http_version 1.1; | |
| 68 | ||
| 69 | proxy_buffering off; | |
| 70 | proxy_request_buffering off; | |
| 71 | proxy_read_timeout 300; | |
| 72 | proxy_send_timeout 300; | |
| 73 | } | |
| 74 | } | |
linux/nginx/etc/nginx/nginx.conf +13 −1
| @@ -41,7 +41,19 @@ events { | ||
| 41 | 41 | # Default: logs/error.log error |
| 42 | 42 | # https://nginx.org/en/docs/ngx_core_module.html#error_log |
| 43 | 43 | # error_log /var/log/nginx/error.log warn; |
| 44 | error_log /dev/null emerg; | |
| 44 | # | |
| 45 | # emerg-only, to stderr -> systemd captures it into journald, which is RAM-only | |
| 46 | # on this host (Storage=volatile), so nothing lands on disk and nothing survives | |
| 47 | # a reboot. | |
| 48 | # | |
| 49 | # This was /dev/null, which discarded the one class of message that says the | |
| 50 | # server is broken. That cost real diagnostic time twice on 2026-08-03: a reload | |
| 51 | # that silently failed to rebind sockets, and the certbot failures. emerg | |
| 52 | # messages are startup/bind/shutdown faults and carry no visitor data, so | |
| 53 | # keeping them costs nothing in privacy terms. | |
| 54 | # | |
| 55 | # Read with: journalctl -u nginx | |
| 56 | error_log stderr emerg; | |
| 45 | 57 | |
| 46 | 58 | # The file storing the process ID of the main process |
| 47 | 59 | # Default: logs/nginx.pid |