Files
docs/services/zoraxy.md
T
fkrebs 0def5c0be9 docs: rewrite zoraxy.md — full route table, audit status, config guide
Replaces outdated setup-only guide with current state:
- Full 22-route table with upstream IPs (audited 2026-05-21)
- All routes confirmed ACME+WS+Hop enabled
- JSON template for adding new routes
- Auth posture section with open items (Tinyauth pending CT 109)
- Backup/restore instructions

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-21 09:52:25 +02:00

100 lines
4.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Zoraxy Reverse Proxy
> Zoraxy is a Go-based reverse proxy + ACME daemon running as a **systemd service** on **LXC 108** (`zoraxy`, 192.168.1.4). Config lives in JSON files at `/opt/zoraxy/conf/proxy/`. Changes take effect after `systemctl restart zoraxy`.
## Current route table
Audited and fully configured 2026-05-21. All 22 public routes have:
- `EnableAutoHTTPS: true` — Zoraxy requests LE certs for `*.nuclide.systems`
- `EnableWebsocketCustomHeaders: true` — preserves WS upgrade headers through the proxy
- `DisableHopByHopHeaderRemoval: true` — keeps hop-by-hop headers intact for upstream
| Domain | Upstream | Notes |
|--------|----------|-------|
| abs.nuclide.systems | 192.168.1.40:13003 | Absolut (abs) |
| ai.nuclide.systems | 192.168.1.40:14000 | LiteLLM gateway |
| arcane.nuclide.systems | 192.168.1.40:10002 | Arcane Manager |
| chat.nuclide.systems | 192.168.1.40:14001 | LobeHub |
| dev.nuclide.systems | 192.168.1.42:7080 | Coder (CT 111) |
| git.nuclide.systems | 192.168.1.42:3000 | Gitea (CT 111) |
| gotify.nuclide.systems | 192.168.1.40:10003 | Gotify push notifications |
| ha.nuclide.systems | 192.168.1.60:8123 | Home Assistant (VM 100) |
| hoarder.nuclide.systems | 192.168.1.40:17001 | Karakeep bookmarks |
| id.nuclide.systems | 192.168.1.5:11000 | Pocket-ID OIDC (CT 110) |
| immich.nuclide.systems | 192.168.1.40:12000 | Immich photos |
| mcp.nuclide.systems | 192.168.1.40:8080 | MCP gateway |
| memos.nuclide.systems | 192.168.1.40:17000 | Memos notes |
| n8n.nuclide.systems | 192.168.1.40:16000 | n8n workflows |
| nc.nuclide.systems | 192.168.1.41:11000 | Nextcloud AIO (CT 105) |
| ocpp.nuclide.systems | 192.168.1.60:8887 | OCPP charger endpoint (HAOS) |
| s3.nuclide.systems | 192.168.1.40:10004 | Garage S3 (web endpoint) |
| shepard.nuclide.systems | 192.168.1.49:80 | Shepard frontend (CT 101) |
| shepard-api.nuclide.systems | 192.168.1.49:8080 | Shepard API (CT 101) |
| shepard-auth.nuclide.systems | 192.168.1.49:8082 | Shepard auth (CT 101) |
| traccar.nuclide.systems | 192.168.1.40:15000 | Traccar GPS |
| vault.nuclide.systems | 192.168.1.40:11001 | Vaultwarden |
`root.config` — ProxyType=0 internal dashboard fallback (127.0.0.1:5487), no ACME.
## Admin UI
```
http://192.168.1.4:8000
```
Zoraxy runs with `-noauth=true` — no login required on the LAN.
## Adding a new route
### Via admin UI
1. **Reverse Proxy → Create Proxy Rules → New Proxy Rule**
2. Enter the domain, set the upstream IP:port
3. **TLS → Enable Auto HTTPS** — tick it
4. **Header Rewrite Rules** → enable **Disable Hop-by-Hop Removal** and **WebSocket Custom Headers**
5. Save, allow 12 minutes for LE cert issuance
### Via JSON (preferred for scripted changes)
Config files live at `/opt/zoraxy/conf/proxy/<domain>.config` on CT 108.
Minimum template for a new public route:
```json
{
"ProxyType": 1,
"RootOrMatchingDomain": "example.nuclide.systems",
"ActiveOrigins": [{"OriginIpOrDomain": "192.168.1.40:PORT", "Weight": 1}],
"TlsOptions": {"EnableAutoHTTPS": true},
"HeaderRewriteRules": {"DisableHopByHopHeaderRemoval": true},
"EnableWebsocketCustomHeaders": true,
"AccessFilterUUID": "default"
}
```
After editing, restart Zoraxy:
```bash
ssh root@192.168.1.4 'systemctl restart zoraxy'
```
## Backup / restore
All configs are backed up at `/tmp/zoraxy-backup-2026-05-21/` on CT 108 (22 files from the 2026-05-21 audit). To restore a single route:
```bash
ssh root@192.168.1.4 'cp /tmp/zoraxy-backup-2026-05-21/<domain>.config /opt/zoraxy/conf/proxy/ && systemctl restart zoraxy'
```
## Decommissioned routes
`.DECOMMISSIONED-*` files in `/opt/zoraxy/conf/proxy/` are ignored by Zoraxy. Current:
- `daytona.nuclide.systems.config.DECOMMISSIONED-2026-05-20`
- `id.daytona.nuclide.systems.config.DECOMMISSIONED-2026-05-20`
## Auth posture
No routes have `ForwardAuthURL` set (no Tinyauth/auth middleware). Pocket-ID (`id.nuclide.systems`) is the OIDC IdP; apps that require auth implement it themselves (LobeHub, Coder, Gitea, Nextcloud). Public-facing routes like `ha.nuclide.systems` and `ocpp.nuclide.systems` have no proxy-level auth — upstream apps handle it.
**Pending**: Tinyauth or similar on unauthenticated-but-sensitive routes (arcane, gotify). Planned for CT 109 deployment.