Restrict unused backend endpoints

This commit is contained in:
2026-08-25 13:33:12 +00:00
parent ec50d3eea8
commit b956829560
+24 -2
View File
@@ -63,6 +63,9 @@ The following examples assume that the reverse proxy runs on the Docker host.
Replace `hub.example.com` with the public frontend domain. Keep
`FRONTEND_BIND=127.0.0.1:18080` in the frontend `.env`. The examples also assume
that Drivers Hub: Backend listens on `127.0.0.1:17777` and uses the `/api` prefix.
They do not publish the API documentation or the upstream service restart
endpoint. The restart endpoint does not manage a Docker container. All other
API routes remain available to the frontend and configured external services.
### Standalone Nginx
@@ -85,7 +88,13 @@ server {
ssl_certificate /etc/letsencrypt/live/hub.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/hub.example.com/privkey.pem;
location ^~ /api/ {
# Do not publish API schemas or interactive API documentation.
# The upstream restart endpoint cannot restart this Docker container.
location ~ ^/api/(?:docs?(?:/|$)|redoc/?$|openapi\.json$|restart$) {
return 404;
}
location /api/ {
proxy_pass http://127.0.0.1:17777;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
@@ -119,6 +128,13 @@ Add this site block to the Caddyfile:
```caddyfile
hub.example.com {
# Do not publish API schemas or interactive API documentation.
# The upstream restart endpoint cannot restart this Docker container.
@blocked path /api/openapi.json /api/doc /api/doc/* /api/docs /api/docs/* /api/redoc /api/restart
handle @blocked {
respond 404
}
handle /api/* {
reverse_proxy 127.0.0.1:17777
}
@@ -151,7 +167,13 @@ Use a domain or subdomain that has a valid TLS certificate in Plesk.
5. Add this block to **Additional nginx directives**:
```nginx
location ^~ /api/ {
# Do not publish API schemas or interactive API documentation.
# The upstream restart endpoint cannot restart this Docker container.
location ~ ^/api/(?:docs?(?:/|$)|redoc/?$|openapi\.json$|restart$) {
return 404;
}
location /api/ {
proxy_pass http://127.0.0.1:17777;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;