Files
xenia-pos-local/nginx-proxy
bonaminandClaude Opus 5.5 2b9f841bbd feat(proxy): https://<LAN IP>:8443 for the native app (backend-managed cert, LAN only)
- new :8443 server (both copies byte-identical): TLS with the backend's
  data/tls key+cert, LAN-only allow list, proxies the whole waiter
  origin incl. /api/ws/ upgrades
- compose: backend healthcheck; proxy waits for backend healthy (TLS files
  exist) and mounts ${DATA_PATH}/tls read-only; publishes 8443;
  TLS_PORT passed to the backend so it advertises the published port

Verified on an isolated stack: served key == advertised pin, identity and
WebSocket over TLS, proxy starts only after the backend is healthy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 17:41:25 +03:00
..