Reverse proxy
The proxy settings the hub depends on, with Caddy and nginx examples.
Terminate TLS in the proxy you already run and forward to 127.0.0.1:3000. The hub relies on six
things from it.
- Don't buffer
text/event-stream. The live stream (/api/live/stream) sendsX-Accel-Buffering: no, which nginx honours. Caddy and Traefik stream by default. - Forward the host and client address. Keep the original
Host(or setX-Forwarded-Host), and append the client address toX-Forwarded-For. See Client addresses. - Serve the hub over HTTPS. Some same-origin checks rely on
Sec-Fetch-Site, which browsers send only to secure origins. On plainhttp://<LAN address>, the data export and the raw-payload viewer answer 403. - Leave
/api/v1/*alone. Don't add CORS or caching headers in the proxy. The hub setsAccess-Control-Allow-Origin: *,ETagandCache-Controlitself. - Never redirect
/api/osrs-data/*. The plugin turns a 301 or 302 into a body-less GET and doesn't follow 307 or 308, so data is lost without any error. Redirect http to https for the UI only, or tell players to use thehttps://URL exactly as the wizard shows it. - Keep
/metricsoff the internet. It is token-protected, but only your monitoring needs it: answer 404 to everyone else.
Examples
hub.example.com {
# /metrics only for the Prometheus server (drop the allow-list to block it entirely).
@metrics_blocked {
path /metrics /metrics/*
not remote_ip 10.0.0.5
}
respond @metrics_blocked 404
reverse_proxy 127.0.0.1:3000
}Client addresses
The hub rate-limits pairing and failed API authentications per client IP. To find the client's address,
it reads X-Forwarded-For, counting TRUST_PROXY_HOPS entries from the right: one per proxy that
appends to the header.
| Setup | TRUST_PROXY_HOPS |
|---|---|
| One proxy on the VM (Caddy, nginx) | 1 (the default) |
| Cloudflare → cloudflared → Traefik | 2 |
| Nothing in front of the hub | 0 |
Get this number right
Too low, and every client looks like your proxy: one integration with a bad key then locks every API client out for about a minute. Too high, and the hub trusts an address the client wrote itself.