Reverse Proxy Configuration (Nginx, Caddy, Traefik)
Placing RUSEON Core behind a reverse proxy allows centralized TLS certificate termination (Let's Encrypt), domain routing, and integration into existing enterprise web infrastructure.
1. Caddy (Recommended)
Caddy automatically handles Let's Encrypt SSL certificates and provides native HTTP/2, HTTP/3, and WebSocket support with zero boilerplate:
caddy
docs.example.com {
reverse_proxy 127.0.0.1:8080 {
# Disable response buffering for instant HLS and WHEP stream delivery
flush_interval -1
}
}2. Nginx Production Configuration
For Nginx, ensure WebSocket upgrades and non-buffering directives are explicitly configured:
nginx
server {
listen 80;
server_name ruseon.example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name ruseon.example.com;
ssl_certificate /etc/letsencrypt/live/ruseon.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/ruseon.example.com/privkey.pem;
# Maximum upload size for firmware and archive exports
client_max_body_size 50M;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_http_version 1.1;
# WebSocket headers
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
# Standard proxy headers
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# Disable buffering for live HLS and WHEP signaling
proxy_buffering off;
proxy_read_timeout 86400s;
proxy_send_timeout 86400s;
}
}3. Traefik (Docker Compose Integration)
If using Traefik as an ingress controller:
yaml
services:
ruseon:
image: ghcr.io/rusegal/ruseon-core:latest
labels:
- "traefik.enable=true"
- "traefik.http.routers.ruseon.rule=Host(`ruseon.example.com`)"
- "traefik.http.routers.ruseon.entrypoints=websecure"
- "traefik.http.routers.ruseon.tls.certresolver=letsencrypt"
- "traefik.http.services.ruseon.loadbalancer.server.port=8080"Important Note on WebRTC Media Traffic
The reverse proxy handles HTTPS signaling (WHEP) and HLS streams. However, the actual WebRTC media packets travel directly over UDP:
- Ensure the UDP port range (
50000-50100) is open on your firewall and routed directly to the RUSEON server host. - Configure
webrtc.public_ipinconfig.yamlwith your server's public IPv4/IPv6 address so clients receive valid ICE candidates.