Skip to content

HTTPS and reverse proxies

The container serves plain HTTP, which is fine on a trusted network. Every request carries a bearer token, so put it behind HTTPS before exposing it to the internet. Nothing about the app needs special proxy handling: no WebSockets, no long-lived streams (/mcp answers in plain JSON), and it works at the root of its own hostname. A subpath (example.com/todo) is not supported.

Set TRUST_PROXY so logs record the real client address.

Caddy

todo.example.com {
reverse_proxy yarukoto:8080
}

Traefik (labels on the yarukoto service)

labels:
- traefik.enable=true
- traefik.http.routers.yarukoto.rule=Host(`todo.example.com`)
- traefik.http.routers.yarukoto.entrypoints=websecure
- traefik.http.routers.yarukoto.tls.certresolver=letsencrypt
- traefik.http.services.yarukoto.loadbalancer.server.port=8080

nginx

server {
listen 443 ssl;
server_name todo.example.com;
# ssl_certificate / ssl_certificate_key as usual
location / {
proxy_pass http://127.0.0.1:8080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}

Nginx Proxy Manager and DSM’s reverse proxy need only the hostname and http://<host>:8080.