# Reference config for the CENTRAL REVERSE PROXY MACHINE — not for this host. # This stack publishes plain HTTP on :5233; TLS terminates here. # # Replace notes-host.lan with the LAN address of the machine running the # markdown-to-caldav stack. upstream mdcaldav { server notes-host.lan:5233; } # --- Option A: its own hostname --------------------------------------------- server { listen 443 ssl; http2 on; server_name notes.example.com; ssl_certificate /etc/letsencrypt/live/notes.example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/notes.example.com/privkey.pem; # CalDAV bodies are small, but clients send large PROPFIND/REPORT XML. client_max_body_size 100M; location / { proxy_pass http://mdcaldav; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } # --- Option B: share a hostname with an existing Radicale ------------------- # # NOTE the absence of a trailing slash on proxy_pass. With a trailing slash # nginx replaces the /notes/ prefix with /, Radicale then generates hrefs # without the prefix, and clients walk to URLs that do not exist. Radicale # strips script_name itself, so send it the full path. # # server { # listen 443 ssl; # server_name dav.example.com; # # location /notes/ { # proxy_pass http://mdcaldav; # no trailing slash # proxy_set_header X-Script-Name /notes; # proxy_set_header Host $host; # proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # proxy_set_header X-Forwarded-Proto $scheme; # } # # location / { # proxy_pass http://existing-radicale.lan:5232; # } # }