Repository navigation
Releases: tetrixdev/proxy-nginx
Releases · tetrixdev/proxy-nginx
Release list
v1.3.0 - ACME exception for IP-whitelisted domains
What's New
ACME Challenge Exception for IP-Whitelisted Domains
When using --whitelist, the domain script now automatically adds a location block that allows Let's Encrypt HTTP-01 challenges through, even when other traffic is blocked.
# This now works! SSL certificates with IP whitelist
docker exec proxy-nginx /scripts/domain.sh upsert \
--domain=private.example.com \
--upstream=myapp-nginx \
--whitelist="100.64.0.0/10"
docker exec -it proxy-nginx certbot --nginx -d private.example.comRemoved
- TransIP DNS-01 plugin removed - The ACME exception makes DNS-01 unnecessary for most use cases. HTTP-01 works even with IP whitelisting.
Why This Change
After investigation, we found that DNS-01 challenge is not needed for IP-whitelisted domains if nginx is configured correctly. The /.well-known/acme-challenge/ path now bypasses the IP whitelist, allowing Let's Encrypt to verify domain ownership.
Benefits:
- Simpler setup (no DNS provider credentials needed)
- Works with any DNS provider
- Fully automatic renewal via standard HTTP-01
🤖 Generated with Claude Code
v1.2.0 - TransIP DNS-01 Plugin
What's New
TransIP DNS-01 Plugin for Wildcard SSL Certificates
This release adds built-in support for wildcard SSL certificates using TransIP DNS.
New features:
certbot-dns-transipplugin pre-installed- New
/scripts/transip-setup.shscript for credential management and wildcard cert requests - Supports domains behind firewalls (Tailscale-only apps)
- Automatic renewal via existing certbot cron
Usage:
# Configure TransIP credentials (one-time)
docker exec proxy-nginx /scripts/transip-setup.sh setup \
--login=your-username \
--key-file=/path/to/private-key.pem
# Request wildcard certificate
docker exec proxy-nginx /scripts/transip-setup.sh wildcard --domain=example.com
# Check status
docker exec proxy-nginx /scripts/transip-setup.sh statusRequirements:
- Domain must be registered/managed at TransIP
- TransIP API access enabled with private key
See README for full documentation.
v1.1.0 - Domain Management Scripts
New Features
- Domain management scripts -
/scripts/domain.shfor programmatic nginx config management - Basic auth helper -
/scripts/htpasswd.shfor user management - IP whitelisting - Support for CIDR notation (
--whitelist="100.64.0.0/10") - Configurable limits -
--max-body-sizeand--websocket-timeoutoptions - Lowercase normalization - Domains like
Example.COMauto-converted toexample.com - Port support - Domain names with ports (e.g.,
example.com:8080)
Usage
# Add a domain
docker exec proxy-nginx /scripts/domain.sh upsert \
--domain=app.example.com \
--upstream=myapp-nginx
# With IP whitelist (Tailscale only)
docker exec proxy-nginx /scripts/domain.sh upsert \
--domain=staging.example.com \
--upstream=staging-nginx \
--whitelist="100.64.0.0/10"
# Delete a domain
docker exec proxy-nginx /scripts/domain.sh delete --domain=old.example.com
# List managed domains
docker exec proxy-nginx /scripts/domain.sh listFull Changelog
v1.0.0
Initial Release
Production-ready nginx reverse proxy for Laravel applications.
Features
- SSL/TLS termination with Let's Encrypt (certbot + auto-renewal)
- SSE streaming optimization (
ssl_buffer_size 1400) - WebSocket support with dynamic connection upgrade
- Maintenance page fallback on 502/503 errors
- Default server block that blocks direct IP access
- One-line installer script
- Docker image published to ghcr.io/tetrixdev/proxy-nginx
Quick Start
curl -fsSL https://raw.githubusercontent.com/tetrixdev/proxy-nginx/main/install.sh | bashDocumentation
See README.md for full documentation.