Skip to content

Reverse Proxy & TLS

SelfHosted Nostos does not include the Hosted Nostos account layer. A reverse proxy provides TLS, but TLS alone does not add application authentication.

For personal use, prefer a private LAN, VPN, or another access-control layer rather than exposing an unauthenticated SelfHosted instance directly to the public internet.

The standard Compose file maps host port 5099 to container port 8080.

/etc/caddy/Caddyfile
library.yourdomain.com {
reverse_proxy 127.0.0.1:5099
}
server {
listen 80;
server_name library.yourdomain.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name library.yourdomain.com;
ssl_certificate /etc/letsencrypt/live/library.yourdomain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/library.yourdomain.com/privkey.pem;
# The Nostos backend accepts uploads up to 4 GB.
client_max_body_size 4g;
location / {
proxy_pass http://127.0.0.1:5099;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# Avoid buffering long-lived streaming responses.
proxy_buffering off;
proxy_read_timeout 600s;
proxy_send_timeout 600s;
}
}

When Traefik shares the Docker network with the Nostos container, route to the container’s internal port 8080:

labels:
- "traefik.enable=true"
- "traefik.http.routers.nostos.rule=Host(`library.yourdomain.com`)"
- "traefik.http.routers.nostos.entrypoints=websecure"
- "traefik.http.routers.nostos.tls.certresolver=letsencrypt"
- "traefik.http.services.nostos.loadbalancer.server.port=8080"