Restrict unused backend endpoints
This commit is contained in:
@@ -63,6 +63,9 @@ The following examples assume that the reverse proxy runs on the Docker host.
|
||||
Replace `hub.example.com` with the public frontend domain. Keep
|
||||
`FRONTEND_BIND=127.0.0.1:18080` in the frontend `.env`. The examples also assume
|
||||
that Drivers Hub: Backend listens on `127.0.0.1:17777` and uses the `/api` prefix.
|
||||
They do not publish the API documentation or the upstream service restart
|
||||
endpoint. The restart endpoint does not manage a Docker container. All other
|
||||
API routes remain available to the frontend and configured external services.
|
||||
|
||||
### Standalone Nginx
|
||||
|
||||
@@ -85,7 +88,13 @@ server {
|
||||
ssl_certificate /etc/letsencrypt/live/hub.example.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/hub.example.com/privkey.pem;
|
||||
|
||||
location ^~ /api/ {
|
||||
# Do not publish API schemas or interactive API documentation.
|
||||
# The upstream restart endpoint cannot restart this Docker container.
|
||||
location ~ ^/api/(?:docs?(?:/|$)|redoc/?$|openapi\.json$|restart$) {
|
||||
return 404;
|
||||
}
|
||||
|
||||
location /api/ {
|
||||
proxy_pass http://127.0.0.1:17777;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
@@ -119,6 +128,13 @@ Add this site block to the Caddyfile:
|
||||
|
||||
```caddyfile
|
||||
hub.example.com {
|
||||
# Do not publish API schemas or interactive API documentation.
|
||||
# The upstream restart endpoint cannot restart this Docker container.
|
||||
@blocked path /api/openapi.json /api/doc /api/doc/* /api/docs /api/docs/* /api/redoc /api/restart
|
||||
handle @blocked {
|
||||
respond 404
|
||||
}
|
||||
|
||||
handle /api/* {
|
||||
reverse_proxy 127.0.0.1:17777
|
||||
}
|
||||
@@ -151,7 +167,13 @@ Use a domain or subdomain that has a valid TLS certificate in Plesk.
|
||||
5. Add this block to **Additional nginx directives**:
|
||||
|
||||
```nginx
|
||||
location ^~ /api/ {
|
||||
# Do not publish API schemas or interactive API documentation.
|
||||
# The upstream restart endpoint cannot restart this Docker container.
|
||||
location ~ ^/api/(?:docs?(?:/|$)|redoc/?$|openapi\.json$|restart$) {
|
||||
return 404;
|
||||
}
|
||||
|
||||
location /api/ {
|
||||
proxy_pass http://127.0.0.1:17777;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
|
||||
Reference in New Issue
Block a user