Reverse Proxy & TLS
Before exposing Nostos
Section titled “Before exposing Nostos”SelfHosted Nostos does not include the Hosted Nostos account layer. A reverse proxy provides TLS, but TLS alone does not add application authentication.
For personal use, prefer a private LAN, VPN, or another access-control layer rather than exposing an unauthenticated SelfHosted instance directly to the public internet.
The standard Compose file maps host port 5099 to container port 8080.
library.yourdomain.com { reverse_proxy 127.0.0.1:5099}server { listen 80; server_name library.yourdomain.com; return 301 https://$host$request_uri;}
server { listen 443 ssl http2; server_name library.yourdomain.com;
ssl_certificate /etc/letsencrypt/live/library.yourdomain.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/library.yourdomain.com/privkey.pem;
# The Nostos backend accepts uploads up to 4 GB. client_max_body_size 4g;
location / { proxy_pass http://127.0.0.1:5099; proxy_http_version 1.1;
proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme;
# Avoid buffering long-lived streaming responses. proxy_buffering off; proxy_read_timeout 600s; proxy_send_timeout 600s; }}Traefik
Section titled “Traefik”When Traefik shares the Docker network with the Nostos container, route to the container’s internal port 8080:
labels: - "traefik.enable=true" - "traefik.http.routers.nostos.rule=Host(`library.yourdomain.com`)" - "traefik.http.routers.nostos.entrypoints=websecure" - "traefik.http.routers.nostos.tls.certresolver=letsencrypt" - "traefik.http.services.nostos.loadbalancer.server.port=8080"