Nginx Configuration
Serving soketi behind a web server such as Nginx can allow you to access the soketi server via a specific hostname, such as socket.example.com. If you wish, you may also choose to allow Nginx to negotiate your SSL connections instead of providing your SSL certificate information to soketi.
An example Nginx configuration is provided below; however, small adjustments may be required or desired for your specific server environment:
1
server {
2
listen 6002 ssl http2;
3
listen [::]:6002 ssl http2;
4
server_name socket.example.com;
5
server_tokens off;
6
root /home/forge/default/public;
7
​
8
# FORGE SSL (DO NOT REMOVE!)
9
ssl_certificate /path/to/ssl/certificate.crt;
10
ssl_certificate_key /path/to/ssl/key.key;
11
​
12
ssl_protocols TLSv1.2 TLSv1.3;
13
ssl_ciphers TLS13-AES-256-GCM-SHA384:TLS13-CHACHA20-POLY1305-SHA256:TLS_AES_256_GCM_SHA384:TLS-AES-256-GCM-SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS-CHACHA20-POLY1305-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA;
14
ssl_prefer_server_ciphers on;
15
ssl_dhparam /etc/nginx/dhparams.pem;
16
​
17
add_header X-Frame-Options "SAMEORIGIN";
18
add_header X-XSS-Protection "1; mode=block";
19
add_header X-Content-Type-Options "nosniff";
20
​
21
index index.html index.htm index.php;
22
​
23
charset utf-8;
24
​
25
location / {
26
proxy_pass http://127.0.0.1:6001;
27
proxy_read_timeout 60;
28
proxy_connect_timeout 60;
29
proxy_redirect off;
30
​
31
proxy_http_version 1.1;
32
proxy_set_header Upgrade $http_upgrade;
33
proxy_set_header Connection 'upgrade';
34
proxy_set_header Host $host;
35
proxy_cache_bypass $http_upgrade;
36
}
37
​
38
access_log off;
39
error_log /var/log/nginx/socket.example.com.log error;
40
}
Copied!
Copy link