SSL and reverse proxies
Serve the control plane over HTTPS with the bundled Caddy configuration or your own proxy, and keep WebSockets and client IPs working.
Self-hosted
Bundled: Caddy with automatic HTTPS
DOMAIN=orchestration.example.com docker compose -f docker-compose.yml -f docker-compose.production.yml up -d --buildCaddy obtains and renews certificates for DOMAIN, and port 4000 is no longer exposed directly. Point the
domain's DNS at the server and open ports 80 and 443.
Verification status
The production Compose file was run with DOMAIN=localhost (Caddy's local certificate), not yet with a public
domain and Let's Encrypt.
Your own proxy
Any TLS-terminating proxy works (nginx, Traefik, a cloud load balancer), as long as it:
- forwards WebSockets — the dashboard's live updates (
/api/v1/live) and workers (/api/v1/worker/ws) use them; - passes
X-Forwarded-For/X-Forwarded-Proto, withTRUST_PROXY=trueon the control plane so rate limits and the audit log see real client IPs; - does not time out long-lived WebSocket connections too early.
Then set PUBLIC_URL, WEB_URL and CORS_ORIGINS to the https:// address. Pairing links, OAuth
redirect URIs and emails use PUBLIC_URL.
Workers
Workers connect outbound to the HTTPS address. They need no certificate of their own and no inbound port.