localhost resolves to ::1 first; backend/Vite only bind IPv4, causing intermittent 502s when nginx tried the IPv6 loopback address. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
84 lines
3.0 KiB
Nginx Configuration File
84 lines
3.0 KiB
Nginx Configuration File
# ── LAN-only app access (staff) ──────────────────────────────────────────
|
|
# https://local-summit.mydentalofficemanagement.com
|
|
# DNS A record points at this office's private LAN IP; cert is a real
|
|
# Let's Encrypt cert (issued via certbot + Cloudflare DNS-01), so no CA
|
|
# needs to be installed on any staff PC. Restricted to the office subnet.
|
|
server {
|
|
listen 443 ssl;
|
|
server_name local-summit.mydentalofficemanagement.com;
|
|
|
|
ssl_certificate /etc/letsencrypt/live/local-summit.mydentalofficemanagement.com/fullchain.pem;
|
|
ssl_certificate_key /etc/letsencrypt/live/local-summit.mydentalofficemanagement.com/privkey.pem;
|
|
|
|
allow 192.168.0.0/24;
|
|
deny all;
|
|
|
|
client_max_body_size 50m;
|
|
|
|
# API requests → backend (Authorization header must be explicit or it gets stripped)
|
|
location /api/ {
|
|
proxy_pass http://127.0.0.1:5000;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header Authorization $http_authorization;
|
|
}
|
|
|
|
# Socket.IO → backend (WebSocket upgrade)
|
|
location /socket.io/ {
|
|
proxy_pass http://127.0.0.1:5000;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
proxy_set_header Connection "upgrade";
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
}
|
|
|
|
# Everything else → Vite dev server
|
|
location / {
|
|
proxy_pass http://127.0.0.1:3000;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
proxy_set_header Connection "upgrade";
|
|
proxy_set_header Host $host;
|
|
}
|
|
}
|
|
|
|
# ── Public Twilio webhooks only ──────────────────────────────────────────
|
|
# https://summit.mydentalofficemanagement.com, reached via Cloudflare Tunnel.
|
|
# Cloudflare terminates TLS at its edge and cloudflared forwards plain HTTP
|
|
# to this block, so no certificate is needed here. Nothing except the
|
|
# Twilio webhook path is exposed on this hostname.
|
|
server {
|
|
listen 80;
|
|
server_name summit.mydentalofficemanagement.com;
|
|
|
|
client_max_body_size 50m;
|
|
|
|
location /api/twilio/ {
|
|
proxy_pass http://127.0.0.1:5000;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
}
|
|
|
|
location / {
|
|
return 403;
|
|
}
|
|
}
|
|
|
|
# Catch-all: reject anything not matching the two hostnames above
|
|
# (e.g. plain http://<ip> or an unrecognized Host header).
|
|
server {
|
|
listen 80 default_server;
|
|
listen 443 ssl default_server;
|
|
server_name _;
|
|
|
|
ssl_certificate /etc/letsencrypt/live/local-summit.mydentalofficemanagement.com/fullchain.pem;
|
|
ssl_certificate_key /etc/letsencrypt/live/local-summit.mydentalofficemanagement.com/privkey.pem;
|
|
|
|
return 403;
|
|
}
|