Reverse proxy
The proxy does TLS and puts everything under one address: the web app, the API, and the WebSocket for the editor.
server {
listen 443 ssl;
server_name pdm.example.com;
# ssl_certificate …; ssl_certificate_key …;
# the web app
root /srv/classcad-pdm/packages/web/dist;
location / {
try_files $uri /index.html;
}
# the API and its OpenAPI page; uploads are streamed through
location /api/ {
proxy_pass http://127.0.0.1:3333;
client_max_body_size 2g;
proxy_request_buffering off;
}
location /doc {
proxy_pass http://127.0.0.1:3333;
}
# the editor on the server: a WebSocket to the scheduler
location /classcad/ {
proxy_pass http://127.0.0.1:9091/;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_read_timeout 1d;
}
}
With that:
- the web app finds the API at
/api/v1, the default, and no CORS setting is needed; - the editor connects to
wss://pdm.example.com/classcad/(EDITOR_CC_URL); - the API stays on
127.0.0.1:3333, and the scheduler's status routes stay inside.
Workers and engines don't go through the proxy. They talk to the API and the scheduler directly, and PUBLIC_API_URL must be an address the engines can reach, usually http://127.0.0.1:3333/api/v1 on the same server.