HTTPS on non standard port
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- docker, nginx, shell
- Domain
- devops, infrastructure, networking
Research direction
Start with the toolkit's doc/tls-proxy.md and the bin/init --tls entry point, then compare the overleaf.rc settings with the generated nginx configuration. Check how nginx.conf, the TLS port, and the container port are wired together, and reproduce the failure on port 33443. Done means the cause is identified and documented with a working non-standard HTTPS port configuration.
Written by the indexing model from the issue text.
Description
Hi,
I fail to configure HTTP on 33443 port.
I configured overeleaf.rc as follows:
### Overleaf RC ####
PROJECT_NAME=overleaf
# Sharelatex container
# Uncomment the OVERLEAF_IMAGE_NAME variable to use a user-defined image.
# OVERLEAF_IMAGE_NAME=sharelatex/sharelatex
OVERLEAF_IMAGE_NAME=tuetenk0pp/sharelatex-full
OVERLEAF_DATA_PATH=data/overleaf
SERVER_PRO=false
OVERLEAF_LISTEN_IP=127.0.0.1
#OVERLEAF_LISTEN_IP=0.0.0.0
#OVERLEAF_PORT=80
OVERLEAF_PORT=80
#OVERLEAF_SECURE=true
#OVERLEAF_SSL_KEY_PATH=/home/xxx/overleaf-toolkit/key.pem
#OVERLEAF_SSL_CRT_PATH=/home/xxx/overleaf-toolkit/cert.pem
# Sibling Containers
SIBLING_CONTAINERS_ENABLED=true
DOCKER_SOCKET_PATH=/var/run/docker.sock
# Mongo configuration
MONGO_ENABLED=true
MONGO_DATA_PATH=data/mongo
MONGO_IMAGE=mongo
MONGO_VERSION=6.0
# Redis configuration
REDIS_ENABLED=true
REDIS_DATA_PATH=data/redis
REDIS_IMAGE=redis:6.2
REDIS_AOF_PERSISTENCE=true
# Git-bridge configuration (Server Pro only)
GIT_BRIDGE_ENABLED=false
GIT_BRIDGE_DATA_PATH=data/git-bridge
# TLS proxy configuration (optional)
# See documentation in doc/tls-proxy.md
#NGINX_ENABLED=false
NGINX_ENABLED=true
NGINX_CONFIG_PATH=config/nginx/nginx.conf
#NGINX_HTTP_PORT=80
NGINX_HTTP_PORT=33080
# Replace these IP addresses with the external IP address of your host
#NGINX_HTTP_LISTEN_IP=127.0.1.1
NGINX_HTTP_LISTEN_IP=192.168.123.16
#NGINX_TLS_LISTEN_IP=127.0.1.1
NGINX_TLS_LISTEN_IP=192.168.123.16
TLS_PRIVATE_KEY_PATH=config/nginx/certs/overleaf_key.pem
TLS_CERTIFICATE_PATH=config/nginx/certs/overleaf_certificate.pem
#TLS_PORT=443
TLS_PORT=33443
# In Air-gapped setups, skip pulling images
# PULL_BEFORE_UPGRADE=false
# SIBLING_CONTAINERS_PULL=false
and nginx.con
events {}
http {
server {
listen 80 default_server;
#listen 33080 default_server;
server_name _;
#return 301 https://$host$request_uri;
return 301 https://$host:33443$request_uri;
}
server {
#listen 443 ssl;
listen 33443 ssl;
server_name 192.168.123.16 qualifiedname.domain.com internalname.lab;
ssl_certificate /certs/nginx_certificate.pem;
ssl_certificate_key /certs/nginx_key.pem;
# Intermediate Mozilla Config
# https://ssl-config.mozilla.org/#server=nginx&version=1.26.0&config=intermediate&openssl=1.1.1w&ocsp=false&guideline=5.7
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305;
ssl_prefer_server_ciphers off;
#ssl_prefer_server_ciphers on;
# config to enable HSTS(HTTP Strict Transport Security) https://developer.mozilla.org/en-US/docs/Security/HTTP_Strict_Transport_Security
# to avoid ssl stripping https://en.wikipedia.org/wiki/SSL_stripping#SSL_stripping
add_header Strict-Transport-Security "max-age=31536000; includeSubdomains;";
server_tokens off;
client_max_body_size 50M;
location / {
proxy_pass http://sharelatex:80;
#proxy_pass http://127.0.0.1:80;
#proxy_pass http://overleaf:80;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 3m;
proxy_send_timeout 3m;
}
}
}
Please can you help me to understand why this configuration is missworking?
obviously I initialize overleaf using bin/init --tls command.
Best Regards
- Dominant language
- Shell
- Stars
- 1.3k
- Forks
- 311
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from overleaf/toolkit
-
Container mongo Started - Error response from daemon on kernel 7.0.13May be free again A pull request for this issue was closed without being merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty 1/5 Under an hour Newbie friendliness 68/100
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
-
Difficulty 3/5 1-2 days Newbie friendliness 48/100
All issues in overleaf/toolkit
Similar issues
-
omarchy-menu-keybindings lua bind scan spins at 100% CPU when user config iterates a mocked hl APIOpen
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
omacom/omarchy#14302 · 1 comment ·
Maintainers usually reply within 1 day
-
Link Checker ReportPossibly taken @keraron claimed this today. Openautomated issue report
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
a2aproject/A2A#2297 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
mattpocock/skills#1165 ·
-
agent-research-finding agent-research-recommend chore ready-for-agent
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
jordansmall/spindrift#4487 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
bigstack-oss/cubecos#1708 ·
Maintainers usually reply within 1 day