Reverse Proxy & TLS

Put ScanDrix behind nginx or Caddy with correct TLS, websockets, and webhook path routing.

Terminate TLS at your proxy and forward traffic to the ScanDrix services. Two routes matter: the web app and the webhook ingress path.

nginx

nginx
server {
    listen 443 ssl http2;
    server_name scandrix.example.com;

    ssl_certificate     /etc/letsencrypt/live/scandrix.example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/scandrix.example.com/privkey.pem;

    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
    add_header X-Content-Type-Options nosniff always;
    add_header X-Frame-Options DENY always;
    add_header Referrer-Policy strict-origin-when-cross-origin always;

    client_max_body_size 8m;

    location / {
        proxy_pass http://127.0.0.1:8080;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_read_timeout 60s;
    }
}

Keep X-Forwarded-For/X-Forwarded-Proto headers — ScanDrix uses them for rate limiting (per-client IP) and secure-cookie decisions. If your proxy chains another layer, trust only the immediate hop so clients can't spoof IPs.

Caddy

code
scandrix.example.com {
    reverse_proxy 127.0.0.1:8080
}

Caddy provisions and renews certificates automatically.

Webhook path

Your Git provider must reach the ingress path publicly:

code
https://scandrix.example.com/api/webhooks/<provider>
  • No auth middleware may strip the request body or content-type header.
  • Signature headers (X-Hub-Signature-256, X-Gitlab-Token, …) must pass through unmodified.
  • Do not cache or transform POSTs on this path.

Splitting dashboard from ingress

Higher-security setups serve:

  • scandrix.example.com → web dashboard (SSO-enforced, VPN or allow-list optional)
  • hooks.scandrix.example.com → webhook ingress only (public, narrow WAF rules)

Both can proxy to the same services; record both base URLs in .env (PUBLIC_APP_URL, WEBHOOK_BASE_URL).

Checklist

  • TLS 1.2+ only, HSTS enabled
  • X-Forwarded-* headers set
  • Webhook path public, body not buffered
  • Upload limit ≥ 8 MB (diff attachments)
  • Timeouts ≥ 60 s for streaming dashboard responses
  • Access/error logs shipping — webhook delivery debugging starts here