Commit 0c68f866ef
Verified · cmc
Layout: unified · split
linux/nginx/etc/nginx/conf.d/piped.conf added +74
| @@ -0,0 +1,74 @@ | |||
| 1 | # Piped -- Host-based router on 127.0.0.1:8077 | ||
| 2 | # | ||
| 3 | # WHY THIS EXISTS: the Cloudflare tunnel routes all three Piped hostnames to | ||
| 4 | # localhost:8077 -- | ||
| 5 | # piped.krz.sh -> :8077 | ||
| 6 | # pipedapi.krz.sh -> :8077 (should be the backend) | ||
| 7 | # pipedproxy.krz.sh -> :8077 (should be the media proxy) | ||
| 8 | # so the API and media-proxy hostnames landed on the frontend and Piped was | ||
| 9 | # broken. The frontend advertises BACKEND_HOSTNAME=pipedapi.krz.sh to browsers, | ||
| 10 | # so every API call failed. | ||
| 11 | # | ||
| 12 | # The tidier fix is two edits in the Cloudflare dashboard (point pipedapi at | ||
| 13 | # :8078 and pipedproxy at :8079). This file fixes it server-side instead, and | ||
| 14 | # is harmless if the dashboard is corrected later -- the tunnel would simply | ||
| 15 | # reach the containers directly and these blocks would go unused. | ||
| 16 | # | ||
| 17 | # Ports: frontend :8076 (moved from :8077), backend :8078, media proxy :8079. | ||
| 18 | # | ||
| 19 | # NOTE: custom.d/basic.conf is deliberately NOT included. Its Permissions-Policy | ||
| 20 | # sets fullscreen=(), which would stop videos going fullscreen. | ||
| 21 | |||
| 22 | # Frontend. default_server so the Tor onion for piped (which targets :8077 with | ||
| 23 | # a .onion Host header) also lands here. | ||
| 24 | server { | ||
| 25 | listen 127.0.0.1:8077 default_server; | ||
| 26 | server_name piped.krz.sh; | ||
| 27 | |||
| 28 | location / { | ||
| 29 | proxy_pass http://127.0.0.1:8076; | ||
| 30 | proxy_set_header Host $host; | ||
| 31 | proxy_set_header X-Real-IP $remote_addr; | ||
| 32 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | ||
| 33 | proxy_set_header X-Forwarded-Proto $scheme; | ||
| 34 | proxy_http_version 1.1; | ||
| 35 | } | ||
| 36 | } | ||
| 37 | |||
| 38 | # Backend API. | ||
| 39 | server { | ||
| 40 | listen 127.0.0.1:8077; | ||
| 41 | server_name pipedapi.krz.sh; | ||
| 42 | |||
| 43 | location / { | ||
| 44 | proxy_pass http://127.0.0.1:8078; | ||
| 45 | proxy_set_header Host $host; | ||
| 46 | proxy_set_header X-Real-IP $remote_addr; | ||
| 47 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | ||
| 48 | proxy_set_header X-Forwarded-Proto $scheme; | ||
| 49 | proxy_http_version 1.1; | ||
| 50 | # The backend emits its own CORS headers; do not add or override any | ||
| 51 | # here or the browser will reject the API responses. | ||
| 52 | proxy_read_timeout 120; | ||
| 53 | } | ||
| 54 | } | ||
| 55 | |||
| 56 | # Media proxy. Streams video, so no buffering and generous timeouts. | ||
| 57 | server { | ||
| 58 | listen 127.0.0.1:8077; | ||
| 59 | server_name pipedproxy.krz.sh; | ||
| 60 | |||
| 61 | location / { | ||
| 62 | proxy_pass http://127.0.0.1:8079; | ||
| 63 | proxy_set_header Host $host; | ||
| 64 | proxy_set_header X-Real-IP $remote_addr; | ||
| 65 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | ||
| 66 | proxy_set_header X-Forwarded-Proto $scheme; | ||
| 67 | proxy_http_version 1.1; | ||
| 68 | |||
| 69 | proxy_buffering off; | ||
| 70 | proxy_request_buffering off; | ||
| 71 | proxy_read_timeout 300; | ||
| 72 | proxy_send_timeout 300; | ||
| 73 | } | ||
| 74 | } | ||
linux/nginx/etc/nginx/nginx.conf +13 −1
| @@ -41,7 +41,19 @@ events { | |||
| 41 | # Default: logs/error.log error | 41 | # Default: logs/error.log error |
| 42 | # https://nginx.org/en/docs/ngx_core_module.html#error_log | 42 | # https://nginx.org/en/docs/ngx_core_module.html#error_log |
| 43 | # error_log /var/log/nginx/error.log warn; | 43 | # error_log /var/log/nginx/error.log warn; |
| 44 | error_log /dev/null emerg; | 44 | # |
| 45 | # emerg-only, to stderr -> systemd captures it into journald, which is RAM-only | ||
| 46 | # on this host (Storage=volatile), so nothing lands on disk and nothing survives | ||
| 47 | # a reboot. | ||
| 48 | # | ||
| 49 | # This was /dev/null, which discarded the one class of message that says the | ||
| 50 | # server is broken. That cost real diagnostic time twice on 2026-08-03: a reload | ||
| 51 | # that silently failed to rebind sockets, and the certbot failures. emerg | ||
| 52 | # messages are startup/bind/shutdown faults and carry no visitor data, so | ||
| 53 | # keeping them costs nothing in privacy terms. | ||
| 54 | # | ||
| 55 | # Read with: journalctl -u nginx | ||
| 56 | error_log stderr emerg; | ||
| 45 | 57 | ||
| 46 | # The file storing the process ID of the main process | 58 | # The file storing the process ID of the main process |
| 47 | # Default: logs/nginx.pid | 59 | # Default: logs/nginx.pid |