From 6ea650f999e0a3c574cf0485545f7ec07fdf8c7a Mon Sep 17 00:00:00 2001 From: "Andrey A." <56412611+aantti@users.noreply.github.com> Date: Tue, 17 Mar 2026 11:32:42 +0100 Subject: [PATCH] fix: revise and update proxy how-to (#43853) --- .../self-hosting/self-hosted-proxy-https.mdx | 24 ++++--------------- 1 file changed, 5 insertions(+), 19 deletions(-) diff --git a/apps/docs/content/guides/self-hosting/self-hosted-proxy-https.mdx b/apps/docs/content/guides/self-hosting/self-hosted-proxy-https.mdx index 25723468ba8..cb040b48ab4 100644 --- a/apps/docs/content/guides/self-hosting/self-hosted-proxy-https.mdx +++ b/apps/docs/content/guides/self-hosting/self-hosted-proxy-https.mdx @@ -31,21 +31,7 @@ If you already run [HAProxy](https://www.haproxy.com/), [Traefik](https://traefi -### Step 1: Remove public port bindings for API gateway - -Comment out Kong's host port mappings in `docker-compose.yml` so that it's not exposed to the Internet: - -```yaml -kong: - # ... - ports: - # - ${KONG_HTTP_PORT}:8000/tcp - # - ${KONG_HTTPS_PORT}:8443/tcp -``` - -Kong remains accessible to other containers on the internal Docker network. - -### Step 2: Update environment variables +### Step 1: Update environment variables Update the URL configuration in your `.env` file to use your HTTPS domain: @@ -62,7 +48,7 @@ PROXY_DOMAIN=your-domain.example.com CERTBOT_EMAIL=admin@your-domain.example.com ``` -### Step 3: Start the reverse proxy +### Step 2: Start the reverse proxy Pick one of the options below and use the corresponding Docker Compose overlay. @@ -102,7 +88,7 @@ HTTP-to-HTTPS redirects are handled automatically by the `jonasal/nginx-certbot` -### Step 4: Verify HTTPS connection +### Step 3: Verify HTTPS connection ```sh curl -I https:///auth/v1/ @@ -137,13 +123,13 @@ openssl req -x509 -nodes -days 365 -newkey rsa:2048 \ ### Step 2: Configure Kong for SSL -Comment out Kong's HTTP port mapping in `docker-compose.yml`: +Comment out Kong's **HTTP** port mapping in `docker-compose.yml`: ```yaml kong: # ... ports: - # - ${KONG_HTTP_PORT}:8000/tcp + #- ${KONG_HTTP_PORT}:8000/tcp ``` Uncomment the certificate volume mounts and SSL environment variables in `docker-compose.yml`: