Behind a proxy
Put Caddy, nginx or another proxy in front of Nifty.
On this page
Let the proxy handle HTTPS and pass requests to Nifty on 127.0.0.1:4000, its default. Tell Nifty two things in
/etc/nifty.env:
NIFTY_ORIGIN=https://notes.example.com
NIFTY_TRUSTED_PROXIES=127.0.0.1
NIFTY_ORIGINis the address you open Nifty at. Always set it: Nifty answers only to that name, and a new server's setup trusts requests from this machine without it.NIFTY_TRUSTED_PROXIESnames the proxy, so Nifty sees each visitor's address. Without it, every visitor counts as the proxy, so one visitor hitting a rate limit (too many sign-in attempts, say) blocks everyone. It takes addresses or CIDRs, comma separated.
Then sudo systemctl restart nifty. install.sh --origin https://notes.example.com writes both for you.
Caddy
Caddy gets its own certificate and redirects http://:
notes.example.com {
reverse_proxy 127.0.0.1:4000
}
nginx
server {
listen 443 ssl;
server_name notes.example.com;
# ssl_certificate and ssl_certificate_key here
client_max_body_size 51m;
proxy_read_timeout 120s;
location / {
proxy_pass http://127.0.0.1:4000;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
}
client_max_body_size: documents can be 50 MB; nginx refuses anything over 1 MB by default.proxy_read_timeout: an AI reply can take up to 90 seconds.- Redirect
http://to HTTPS in a secondserverblock.
A proxy on another machine
Set NIFTY_LISTEN to an address the proxy can reach (10.0.0.5:4000), name the proxy in NIFTY_TRUSTED_PROXIES,
and pass the original Host header through. Keep that port closed to everything else: traffic between them is plain
HTTP.