Restrict unused backend endpoints
This commit is contained in:
@@ -63,6 +63,9 @@ The following examples assume that the reverse proxy runs on the Docker host.
|
|||||||
Replace `hub.example.com` with the public frontend domain. Keep
|
Replace `hub.example.com` with the public frontend domain. Keep
|
||||||
`FRONTEND_BIND=127.0.0.1:18080` in the frontend `.env`. The examples also assume
|
`FRONTEND_BIND=127.0.0.1:18080` in the frontend `.env`. The examples also assume
|
||||||
that Drivers Hub: Backend listens on `127.0.0.1:17777` and uses the `/api` prefix.
|
that Drivers Hub: Backend listens on `127.0.0.1:17777` and uses the `/api` prefix.
|
||||||
|
They do not publish the API documentation or the upstream service restart
|
||||||
|
endpoint. The restart endpoint does not manage a Docker container. All other
|
||||||
|
API routes remain available to the frontend and configured external services.
|
||||||
|
|
||||||
### Standalone Nginx
|
### Standalone Nginx
|
||||||
|
|
||||||
@@ -85,7 +88,13 @@ server {
|
|||||||
ssl_certificate /etc/letsencrypt/live/hub.example.com/fullchain.pem;
|
ssl_certificate /etc/letsencrypt/live/hub.example.com/fullchain.pem;
|
||||||
ssl_certificate_key /etc/letsencrypt/live/hub.example.com/privkey.pem;
|
ssl_certificate_key /etc/letsencrypt/live/hub.example.com/privkey.pem;
|
||||||
|
|
||||||
location ^~ /api/ {
|
# Do not publish API schemas or interactive API documentation.
|
||||||
|
# The upstream restart endpoint cannot restart this Docker container.
|
||||||
|
location ~ ^/api/(?:docs?(?:/|$)|redoc/?$|openapi\.json$|restart$) {
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /api/ {
|
||||||
proxy_pass http://127.0.0.1:17777;
|
proxy_pass http://127.0.0.1:17777;
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
@@ -119,6 +128,13 @@ Add this site block to the Caddyfile:
|
|||||||
|
|
||||||
```caddyfile
|
```caddyfile
|
||||||
hub.example.com {
|
hub.example.com {
|
||||||
|
# Do not publish API schemas or interactive API documentation.
|
||||||
|
# The upstream restart endpoint cannot restart this Docker container.
|
||||||
|
@blocked path /api/openapi.json /api/doc /api/doc/* /api/docs /api/docs/* /api/redoc /api/restart
|
||||||
|
handle @blocked {
|
||||||
|
respond 404
|
||||||
|
}
|
||||||
|
|
||||||
handle /api/* {
|
handle /api/* {
|
||||||
reverse_proxy 127.0.0.1:17777
|
reverse_proxy 127.0.0.1:17777
|
||||||
}
|
}
|
||||||
@@ -151,7 +167,13 @@ Use a domain or subdomain that has a valid TLS certificate in Plesk.
|
|||||||
5. Add this block to **Additional nginx directives**:
|
5. Add this block to **Additional nginx directives**:
|
||||||
|
|
||||||
```nginx
|
```nginx
|
||||||
location ^~ /api/ {
|
# Do not publish API schemas or interactive API documentation.
|
||||||
|
# The upstream restart endpoint cannot restart this Docker container.
|
||||||
|
location ~ ^/api/(?:docs?(?:/|$)|redoc/?$|openapi\.json$|restart$) {
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /api/ {
|
||||||
proxy_pass http://127.0.0.1:17777;
|
proxy_pass http://127.0.0.1:17777;
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
|||||||
Reference in New Issue
Block a user