Reverse Proxy & TLS
Put ScanDrix behind nginx or Caddy with correct TLS, websockets, and webhook path routing.
Terminate TLS at your proxy and forward traffic to the ScanDrix services. Two routes matter: the web app and the webhook ingress path.
nginx
nginx
server {
listen 443 ssl http2;
server_name scandrix.example.com;
ssl_certificate /etc/letsencrypt/live/scandrix.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/scandrix.example.com/privkey.pem;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Content-Type-Options nosniff always;
add_header X-Frame-Options DENY always;
add_header Referrer-Policy strict-origin-when-cross-origin always;
client_max_body_size 8m;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_read_timeout 60s;
}
}
Keep X-Forwarded-For/X-Forwarded-Proto headers — ScanDrix uses them for rate limiting (per-client IP) and secure-cookie decisions. If your proxy chains another layer, trust only the immediate hop so clients can't spoof IPs.
Caddy
code
scandrix.example.com {
reverse_proxy 127.0.0.1:8080
}
Caddy provisions and renews certificates automatically.
Webhook path
Your Git provider must reach the ingress path publicly:
code
https://scandrix.example.com/api/webhooks/<provider>
- No auth middleware may strip the request body or content-type header.
- Signature headers (
X-Hub-Signature-256,X-Gitlab-Token, …) must pass through unmodified. - Do not cache or transform POSTs on this path.
Splitting dashboard from ingress
Higher-security setups serve:
scandrix.example.com→ web dashboard (SSO-enforced, VPN or allow-list optional)hooks.scandrix.example.com→ webhook ingress only (public, narrow WAF rules)
Both can proxy to the same services; record both base URLs in .env (PUBLIC_APP_URL, WEBHOOK_BASE_URL).
Checklist
- TLS 1.2+ only, HSTS enabled
-
X-Forwarded-*headers set - Webhook path public, body not buffered
- Upload limit ≥ 8 MB (diff attachments)
- Timeouts ≥ 60 s for streaming dashboard responses
- Access/error logs shipping — webhook delivery debugging starts here