Files
fkrebs 17b6fc6fcb CT 108 decommissioned: Zoraxy replaced by Traefik v3 on CT 109
Traefik v3 now handles all *.nuclide.systems traffic (ports 80/443).
ACME DNS-01 via Cloudflare, HTTP/2, Keep-Alive fix for Immich.
CT 108 backup: vzdump-lxc-108-2026_05_28-00_46_45.tar.zst on UNAS.
2026-05-28 00:49:28 +02:00

111 lines
5.9 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Zoraxy Reverse Proxy — DECOMMISSIONED 2026-05-28
> **CT 108 destroyed 2026-05-28.** Replaced by **Traefik v3** on CT 109 (`192.168.1.8`). Backup at `unas:/dump/vzdump-lxc-108-2026_05_28-00_46_45.tar.zst`. All `*.nuclide.systems` traffic now routes through Traefik. See `/docs/infra/portmap.md` and the Traefik stack at `/opt/stacks/traefik/` on CT 109.
---
> ~~Zoraxy is a Go-based reverse proxy + ACME daemon running as a **systemd service** on **LXC 108** (`zoraxy`, 192.168.1.4). Config lives in JSON files at `/opt/zoraxy/conf/proxy/`. Changes take effect after `systemctl restart zoraxy`.~~
## Current route table
Audited 2026-05-23; updated 2026-05-26 (mcp.nuclide.systems removed, ai/chat backends swapped, arcane.nuclide.systems removed). 20 active public routes have:
- `EnableAutoHTTPS: true` — Zoraxy requests LE certs for `*.nuclide.systems`
- `EnableWebsocketCustomHeaders: true` — preserves WS upgrade headers through the proxy
- `DisableHopByHopHeaderRemoval: true` — keeps hop-by-hop headers intact for upstream
`SkipWebSocketOriginCheck` is enabled on routes that use WebSocket heavily (n8n, Coder, Gotify, Immich, abs, ai, chat, ha, nc, ocpp, s3, shepard*). Disabled on git, hoarder, id, memos (not needed).
| Domain | Upstream | SkipWSOrigin | Notes |
|--------|----------|:---:|-------|
| abs.nuclide.systems | 192.168.1.40:13003 | ✓ | Audiobookshelf |
| ai.nuclide.systems | 192.168.1.40:14003 | ✓ | Bifrost LLM gateway (LiteLLM decommissioned 2026-05-26) |
| ~~arcane.nuclide.systems~~ | ~~192.168.1.8:10002~~ | — | **DECOMMISSIONED 2026-05-26** — replaced by Portainer |
| chat.nuclide.systems | 192.168.1.40:14002 | ✓ | Open WebUI (LobeChat decommissioned 2026-05-26) |
| dev.nuclide.systems | 192.168.1.40:7080 | ✓ | Coder (CT 104; migrated from CT 111 2026-05-26) |
| git.nuclide.systems | 192.168.1.40:3000 | — | Gitea (CT 104; migrated from CT 111 2026-05-26) |
| gotify.nuclide.systems | 192.168.1.40:10003 | ✓ | Gotify push notifications |
| ha.nuclide.systems | 192.168.1.60:8123 | ✓ | Home Assistant (VM 100) |
| hoarder.nuclide.systems | 192.168.1.40:17001 | — | Karakeep bookmarks |
| id.nuclide.systems | 192.168.1.8:11000 | — | Pocket-ID OIDC (CT 109; migrated from CT 110 2026-05-26) |
| immich.nuclide.systems | 192.168.1.40:12000 | ✓ | Immich photos |
| ~~mcp.nuclide.systems~~ | ~~192.168.1.40:8080~~ | — | **DECOMMISSIONED 2026-05-26** — mcp-gateway removed; MCP now at `https://ai.nuclide.systems/mcp` (Bifrost) |
| memos.nuclide.systems | 192.168.1.40:17000 | — | Memos notes |
| n8n.nuclide.systems | 192.168.1.40:16000 | ✓ | n8n workflows |
| nc.nuclide.systems | 192.168.1.41:11000 | ✓ | Nextcloud AIO (CT 105) |
| ocpp.nuclide.systems | 192.168.1.60:8887 | ✓ | OCPP charger endpoint (HAOS) |
| s3.nuclide.systems | 192.168.1.40:10004 | ✓ | Garage S3 (web endpoint) |
| shepard.nuclide.systems | 192.168.1.49:80 | ✓ | Shepard frontend (CT 101) |
| shepard-api.nuclide.systems | 192.168.1.49:8080 | ✓ | Shepard API (CT 101) |
| shepard-auth.nuclide.systems | 192.168.1.49:8082 | ✓ | Shepard auth (CT 101) |
| flux.nuclide.systems | 192.168.1.40:17002 | — | Miniflux RSS reader (OIDC via Pocket-ID) |
| traccar.nuclide.systems | 192.168.1.40:15000 | ✓ | Traccar GPS |
| vault.nuclide.systems | 192.168.1.40:11001 | ✓ | Vaultwarden |
**Intentionally LAN-only (no Zoraxy route)**: Dozzle (:10001), Homarr (:7575), Wetty (:4090), docs-server (:13080), paperless (:15003), paperless-ai (:15002), immich-tools. `immich-tools.nuclide.systems` is listed in portmap but route has not been created — defer until needed.
`root.config` — ProxyType=0 internal dashboard fallback (127.0.0.1:5487), no ACME.
## Admin UI
```
http://192.168.1.4:8000
```
Zoraxy runs with `-noauth=true` — no login required on the LAN.
## Adding a new route
### Via admin UI
1. **Reverse Proxy → Create Proxy Rules → New Proxy Rule**
2. Enter the domain, set the upstream IP:port
3. **TLS → Enable Auto HTTPS** — tick it
4. **Header Rewrite Rules** → enable **Disable Hop-by-Hop Removal** and **WebSocket Custom Headers**
5. Save, allow 12 minutes for LE cert issuance
### Via JSON (preferred for scripted changes)
Config files live at `/opt/zoraxy/conf/proxy/<domain>.config` on CT 108.
Minimum template for a new public route:
```json
{
"ProxyType": 1,
"RootOrMatchingDomain": "example.nuclide.systems",
"ActiveOrigins": [{"OriginIpOrDomain": "192.168.1.40:PORT", "Weight": 1}],
"TlsOptions": {"EnableAutoHTTPS": true},
"HeaderRewriteRules": {"DisableHopByHopHeaderRemoval": true},
"EnableWebsocketCustomHeaders": true,
"AccessFilterUUID": "default"
}
```
After editing, restart Zoraxy:
```bash
ssh root@192.168.1.4 'systemctl restart zoraxy'
```
## Backup / restore
All configs are backed up at `/tmp/zoraxy-backup-2026-05-21/` on CT 108 (22 files from the 2026-05-21 audit). To restore a single route:
```bash
ssh root@192.168.1.4 'cp /tmp/zoraxy-backup-2026-05-21/<domain>.config /opt/zoraxy/conf/proxy/ && systemctl restart zoraxy'
```
## Decommissioned routes
`.DECOMMISSIONED-*` files in `/opt/zoraxy/conf/proxy/` are ignored by Zoraxy. Current:
- `daytona.nuclide.systems.config.DECOMMISSIONED-2026-05-20`
- `id.daytona.nuclide.systems.config.DECOMMISSIONED-2026-05-20`
- `mcp.nuclide.systems.config` — removed 2026-05-26 (mcp-gateway decommissioned; MCP now via Bifrost at `ai.nuclide.systems/mcp`)
- `arcane.nuclide.systems.config` — removed 2026-05-26 (Arcane decommissioned; replaced by Portainer at `http://192.168.1.8:9000` LAN-only)
## Auth posture
No routes have `ForwardAuthURL` set (no Tinyauth/auth middleware). Pocket-ID (`id.nuclide.systems`) is the OIDC IdP; apps that require auth implement it themselves (Open WebUI, Coder, Gitea, Nextcloud). Public-facing routes like `ha.nuclide.systems` and `ocpp.nuclide.systems` have no proxy-level auth — upstream apps handle it.
**Pending**: Tinyauth or similar on unauthenticated-but-sensitive routes (gotify). Planned for CT 109 deployment.