Skip to content

feat: TLS edge in ota-web for the cabinet and the API

Danila requested to merge feat/tls-edge into main

Browsers auto-upgrade protok.online to https, so plain-HTTP ports were unreachable from a normal browser. ota-web now terminates TLS with the host's lego certificate: :8443 serves the SPA, :8444 reverse-proxies to ota-api (streaming, 4 GB bodies, Range passthrough); plain HTTP on those ports answers 301 to https. ota-api no longer publishes a host port and trusts X-Forwarded-Proto/Host (ForwardedHeaders:Enabled) so manifest and package URLs handed to head units are https. Without a certificate the container generates a self-signed pair for local runs. README and the board runbook use the https URLs.

Merge request reports