Skip to content

Releases: tetrixdev/proxy-nginx

v1.3.0 - ACME exception for IP-whitelisted domains

Choose a tag to compare

@jfbauer jfbauer released this 06 Apr 07:22
837e120

What's New

ACME Challenge Exception for IP-Whitelisted Domains

When using --whitelist, the domain script now automatically adds a location block that allows Let's Encrypt HTTP-01 challenges through, even when other traffic is blocked.

# This now works! SSL certificates with IP whitelist
docker exec proxy-nginx /scripts/domain.sh upsert \
  --domain=private.example.com \
  --upstream=myapp-nginx \
  --whitelist="100.64.0.0/10"

docker exec -it proxy-nginx certbot --nginx -d private.example.com

Removed

  • TransIP DNS-01 plugin removed - The ACME exception makes DNS-01 unnecessary for most use cases. HTTP-01 works even with IP whitelisting.

Why This Change

After investigation, we found that DNS-01 challenge is not needed for IP-whitelisted domains if nginx is configured correctly. The /.well-known/acme-challenge/ path now bypasses the IP whitelist, allowing Let's Encrypt to verify domain ownership.

Benefits:

  • Simpler setup (no DNS provider credentials needed)
  • Works with any DNS provider
  • Fully automatic renewal via standard HTTP-01

🤖 Generated with Claude Code

v1.2.0 - TransIP DNS-01 Plugin

Choose a tag to compare

@jfbauer jfbauer released this 05 Apr 20:08
8bd3cce

What's New

TransIP DNS-01 Plugin for Wildcard SSL Certificates

This release adds built-in support for wildcard SSL certificates using TransIP DNS.

New features:

  • certbot-dns-transip plugin pre-installed
  • New /scripts/transip-setup.sh script for credential management and wildcard cert requests
  • Supports domains behind firewalls (Tailscale-only apps)
  • Automatic renewal via existing certbot cron

Usage:

# Configure TransIP credentials (one-time)
docker exec proxy-nginx /scripts/transip-setup.sh setup \
  --login=your-username \
  --key-file=/path/to/private-key.pem

# Request wildcard certificate
docker exec proxy-nginx /scripts/transip-setup.sh wildcard --domain=example.com

# Check status
docker exec proxy-nginx /scripts/transip-setup.sh status

Requirements:

  • Domain must be registered/managed at TransIP
  • TransIP API access enabled with private key

See README for full documentation.

v1.1.0 - Domain Management Scripts

Choose a tag to compare

@jfbauer jfbauer released this 05 Apr 14:14
522a931

New Features

  • Domain management scripts - /scripts/domain.sh for programmatic nginx config management
  • Basic auth helper - /scripts/htpasswd.sh for user management
  • IP whitelisting - Support for CIDR notation (--whitelist="100.64.0.0/10")
  • Configurable limits - --max-body-size and --websocket-timeout options
  • Lowercase normalization - Domains like Example.COM auto-converted to example.com
  • Port support - Domain names with ports (e.g., example.com:8080)

Usage

# Add a domain
docker exec proxy-nginx /scripts/domain.sh upsert \
  --domain=app.example.com \
  --upstream=myapp-nginx

# With IP whitelist (Tailscale only)
docker exec proxy-nginx /scripts/domain.sh upsert \
  --domain=staging.example.com \
  --upstream=staging-nginx \
  --whitelist="100.64.0.0/10"

# Delete a domain
docker exec proxy-nginx /scripts/domain.sh delete --domain=old.example.com

# List managed domains
docker exec proxy-nginx /scripts/domain.sh list

Full Changelog

v1.0.0...v1.1.0

v1.0.0

Choose a tag to compare

@jfbauer jfbauer released this 28 Mar 13:03

Initial Release

Production-ready nginx reverse proxy for Laravel applications.

Features

  • SSL/TLS termination with Let's Encrypt (certbot + auto-renewal)
  • SSE streaming optimization (ssl_buffer_size 1400)
  • WebSocket support with dynamic connection upgrade
  • Maintenance page fallback on 502/503 errors
  • Default server block that blocks direct IP access
  • One-line installer script
  • Docker image published to ghcr.io/tetrixdev/proxy-nginx

Quick Start

curl -fsSL https://raw.githubusercontent.com/tetrixdev/proxy-nginx/main/install.sh | bash

Documentation

See README.md for full documentation.