895658a115
- zoraxy.md: fix arcane upstream to CT109 (192.168.1.8:10002), add SkipWebSocketOriginCheck column, note missing routes (dozzle, etc.) - arcane.md: reflect CT109 migration complete, expand agent table to all 8 environments, fix MANAGER_API_URL and DB paths - ct-inventory.md: CT103 RAM 512→4096+swap; CT109 footnote complete - proxmox-memory-audit.md: CT103 bump, add CT109+CT113 rows, fix sum - portmap.md: add Wetty row, fix arcane backend, WAL-G scrape target, homepage decommissioned, dozzle LAN-only note - mcp-gateway.md: add gitea/paperless/proxmox, count 26→29 servers - RESUME.md: check off WAL-G, Loki, Zoraxy audit; CT109 in key state table; session ×4 completed items block Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
104 lines
4.8 KiB
Markdown
104 lines
4.8 KiB
Markdown
# Zoraxy Reverse Proxy
|
||
|
||
> Zoraxy is a Go-based reverse proxy + ACME daemon running as a **systemd service** on **LXC 108** (`zoraxy`, 192.168.1.4). Config lives in JSON files at `/opt/zoraxy/conf/proxy/`. Changes take effect after `systemctl restart zoraxy`.
|
||
|
||
## Current route table
|
||
|
||
Audited 2026-05-23. All 22 public routes have:
|
||
- `EnableAutoHTTPS: true` — Zoraxy requests LE certs for `*.nuclide.systems`
|
||
- `EnableWebsocketCustomHeaders: true` — preserves WS upgrade headers through the proxy
|
||
- `DisableHopByHopHeaderRemoval: true` — keeps hop-by-hop headers intact for upstream
|
||
|
||
`SkipWebSocketOriginCheck` is enabled on routes that use WebSocket heavily (n8n, Coder, Gotify, Immich, Arcane, abs, ai, chat, ha, mcp, nc, ocpp, s3, shepard*). Disabled on git, hoarder, id, memos (not needed).
|
||
|
||
| Domain | Upstream | SkipWSOrigin | Notes |
|
||
|--------|----------|:---:|-------|
|
||
| abs.nuclide.systems | 192.168.1.40:13003 | ✓ | Audiobookshelf |
|
||
| ai.nuclide.systems | 192.168.1.40:14000 | ✓ | LiteLLM gateway |
|
||
| arcane.nuclide.systems | **192.168.1.8:10002** | ✓ | Arcane (moved to CT 109 2026-05-23) |
|
||
| chat.nuclide.systems | 192.168.1.40:14001 | ✓ | LobeHub |
|
||
| dev.nuclide.systems | 192.168.1.42:7080 | ✓ | Coder (CT 111) |
|
||
| git.nuclide.systems | 192.168.1.42:3000 | — | Gitea (CT 111) |
|
||
| gotify.nuclide.systems | 192.168.1.40:10003 | ✓ | Gotify push notifications |
|
||
| ha.nuclide.systems | 192.168.1.60:8123 | ✓ | Home Assistant (VM 100) |
|
||
| hoarder.nuclide.systems | 192.168.1.40:17001 | — | Karakeep bookmarks |
|
||
| id.nuclide.systems | 192.168.1.5:11000 | — | Pocket-ID OIDC (CT 110) |
|
||
| immich.nuclide.systems | 192.168.1.40:12000 | ✓ | Immich photos |
|
||
| mcp.nuclide.systems | 192.168.1.40:8080 | ✓ | MCP gateway |
|
||
| memos.nuclide.systems | 192.168.1.40:17000 | — | Memos notes |
|
||
| n8n.nuclide.systems | 192.168.1.40:16000 | ✓ | n8n workflows |
|
||
| nc.nuclide.systems | 192.168.1.41:11000 | ✓ | Nextcloud AIO (CT 105) |
|
||
| ocpp.nuclide.systems | 192.168.1.60:8887 | ✓ | OCPP charger endpoint (HAOS) |
|
||
| s3.nuclide.systems | 192.168.1.40:10004 | ✓ | Garage S3 (web endpoint) |
|
||
| shepard.nuclide.systems | 192.168.1.49:80 | ✓ | Shepard frontend (CT 101) |
|
||
| shepard-api.nuclide.systems | 192.168.1.49:8080 | ✓ | Shepard API (CT 101) |
|
||
| shepard-auth.nuclide.systems | 192.168.1.49:8082 | ✓ | Shepard auth (CT 101) |
|
||
| traccar.nuclide.systems | 192.168.1.40:15000 | ✓ | Traccar GPS |
|
||
| vault.nuclide.systems | 192.168.1.40:11001 | ✓ | Vaultwarden |
|
||
|
||
**Missing routes** (services listed in portmap but no Zoraxy config exists): `dozzle.nuclide.systems`, `immich-tools.nuclide.systems`, `paperless.nuclide.systems`, `paperless-ai.nuclide.systems`. These are either LAN-only or the routes were never created.
|
||
|
||
`root.config` — ProxyType=0 internal dashboard fallback (127.0.0.1:5487), no ACME.
|
||
|
||
## Admin UI
|
||
|
||
```
|
||
http://192.168.1.4:8000
|
||
```
|
||
|
||
Zoraxy runs with `-noauth=true` — no login required on the LAN.
|
||
|
||
## Adding a new route
|
||
|
||
### Via admin UI
|
||
|
||
1. **Reverse Proxy → Create Proxy Rules → New Proxy Rule**
|
||
2. Enter the domain, set the upstream IP:port
|
||
3. **TLS → Enable Auto HTTPS** — tick it
|
||
4. **Header Rewrite Rules** → enable **Disable Hop-by-Hop Removal** and **WebSocket Custom Headers**
|
||
5. Save, allow 1–2 minutes for LE cert issuance
|
||
|
||
### Via JSON (preferred for scripted changes)
|
||
|
||
Config files live at `/opt/zoraxy/conf/proxy/<domain>.config` on CT 108.
|
||
|
||
Minimum template for a new public route:
|
||
|
||
```json
|
||
{
|
||
"ProxyType": 1,
|
||
"RootOrMatchingDomain": "example.nuclide.systems",
|
||
"ActiveOrigins": [{"OriginIpOrDomain": "192.168.1.40:PORT", "Weight": 1}],
|
||
"TlsOptions": {"EnableAutoHTTPS": true},
|
||
"HeaderRewriteRules": {"DisableHopByHopHeaderRemoval": true},
|
||
"EnableWebsocketCustomHeaders": true,
|
||
"AccessFilterUUID": "default"
|
||
}
|
||
```
|
||
|
||
After editing, restart Zoraxy:
|
||
|
||
```bash
|
||
ssh root@192.168.1.4 'systemctl restart zoraxy'
|
||
```
|
||
|
||
## Backup / restore
|
||
|
||
All configs are backed up at `/tmp/zoraxy-backup-2026-05-21/` on CT 108 (22 files from the 2026-05-21 audit). To restore a single route:
|
||
|
||
```bash
|
||
ssh root@192.168.1.4 'cp /tmp/zoraxy-backup-2026-05-21/<domain>.config /opt/zoraxy/conf/proxy/ && systemctl restart zoraxy'
|
||
```
|
||
|
||
## Decommissioned routes
|
||
|
||
`.DECOMMISSIONED-*` files in `/opt/zoraxy/conf/proxy/` are ignored by Zoraxy. Current:
|
||
- `daytona.nuclide.systems.config.DECOMMISSIONED-2026-05-20`
|
||
- `id.daytona.nuclide.systems.config.DECOMMISSIONED-2026-05-20`
|
||
|
||
## Auth posture
|
||
|
||
No routes have `ForwardAuthURL` set (no Tinyauth/auth middleware). Pocket-ID (`id.nuclide.systems`) is the OIDC IdP; apps that require auth implement it themselves (LobeHub, Coder, Gitea, Nextcloud). Public-facing routes like `ha.nuclide.systems` and `ocpp.nuclide.systems` have no proxy-level auth — upstream apps handle it.
|
||
|
||
**Pending**: Tinyauth or similar on unauthenticated-but-sensitive routes (arcane, gotify). Planned for CT 109 deployment.
|