UBUNTU reverse proxy server based on node-rebird
963
This image provides an UBUNTU reverse proxy server based on node-rebird.
It has a built in option to generate SSL certificates with letsencrypt.
The server works by default on ports 80/443, and forwards the http request to the right application/port by parsing the URL's domain. If the domain has not been identified, the server shows error 404.
Assuming that your user has the docker privileges, here is an example for creating and running the container:
docker run -i -t \
-p 80:80 \
-p 443:443 \
-v /path/to/proxy-list.json:/root/proxy-list.json \
--name MyProxyContainer mbinunn/ubuntu_node_based_reverse_proxy_with_letsencrypt
By default, the reverse-proxy server will not show a log of the http requests.
If you want to show the log, use:
docker run -i -t \
-p 80:80 \
-p 443:443 \
-v /path/to/proxy-list.json:/root/proxy-list.json \
-e SHOW_LOG=1 \
--name MyProxyContainer mbinunn/ubuntu_node_based_reverse_proxy_with_letsencrypt
By default, the reverse-proxy server will automatically send the x-forwarded-header to the target ip.
If you don't want to send, use:
docker run -i -t \
-p 80:80 \
-p 443:443 \
-v /path/to/proxy-list.json:/root/proxy-list.json \
-e DISABLE_XFWD=1 \
--name MyProxyContainer mbinunn/ubuntu_node_based_reverse_proxy_with_letsencrypt
NOTE:
The above commands will start the container in the interactive mode, so that you'll see the proxy server response.
If you want to run the server in detached mode, use the -d switch instead of -i.
Also consider using --restart=always to run the container continously when running in production.
You should implement the proxy-list.json file and use it with the -v switch. The file should look like this:
[
{"domain":"mydomain.com", "ssl":1, "target_ip":"localhost" , "target_port":3000},
{"domain":"example1.com", "ssl":0, "target_ip":"192.168.0.1" , "target_port":8000},
{"domain":"example2.com", "ssl":0, "target_ip":"HOST_IP" , "target_port":8080},
{"domain":"app-api.com" , "ssl":1, "target_ip":"api.app.com" , "target_port":4444}
]
NOTES:
-When "ssl" is 1, the domain will be queried on port 443. Otherwise it'll be queried on port 80.
-If using "HOST_IP" as the value of target_ip, it'll automatically calculate the container's host machine IP address. There is no need to calualte host IP by yourself.
Use the following command to generate an SSL certificate for a domain:
docker exec -i -t -u root MyProxyContainer bash -c "/root/ssl-cert-generate.sh MY_NEW_DOMAIN.com"
(you'll have to enter an e-mail when doing this for the first time)
Use the following command to renew all the existing certificates:
docker exec -i -t -u root MyProxyContainer bash -c "/root/ssl-renew.sh"
SHOW_LOG = Pass this variable only if you want to show the log, otherwise do not pass it
DISABLE_XFWD = Pass this variable only if you want to prevent x-forwarded header from being sent, otherwise do not pass it
ROOT_PASSWD = Initializes the root password of UBUNTU
After making changes, installing software or changing startup.sh, save your own image by using the following command:
docker commit MyProxyContainer my_own_proxy_image:v1
See my source code on https://github.com/mbinnun/Dockers/tree/main/ubuntu-node-based-reverse-proxy-with-letsencrypt
Content type
Image
Digest
Size
194.1 MB
Last updated
over 5 years ago
docker pull mbinunn/ubuntu_node_based_reverse_proxy_with_letsencrypt