• 1 Post
  • 28 Comments
Joined 1 year ago
cake
Cake day: June 16th, 2023

help-circle



  • I think people are missing the point here. The biggest problem was not that the update was bricking the machines, that could’ve happened to Linux/macOS/BSD etc. The problem is that the solution to the problem is to MANUALLY access the machine, get into safe mode and type some commands. This is insane. And you should be able to EASILY disable automatic updates for apps like that on Windows Server.













  • Yep, definitely something wrong with the webserver 😅 Can you try this configuration?

    https://nextcloud.domain.com {
            reverse_proxy 192.168.1.182:443 {
                    header_up Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
                    header_up X-Forwarded-Proto {scheme}
                    header_up X-Forwarded-For {remote}
                    header_up X-Real-IP {remote}
            }
    }
    

    You said that “originally, the Nextcloud server handled HTTPS with Let’s Encrypt at domain.com” and now you are redirecting to 192.168.1.182 on port 443. Is this Nextcloud server still serving HTTPS with Let’s Encrypt for domain.com?

    I’m asking because if you are using Caddy in front of that HTTPS webserver as a reverse-proxy, you will need to override the Host header with the configured upstream address. Here’s the documentation. I think it would be something like this (?):

    https://nextcloud.domain.com {
            reverse_proxy domain.com:443 {
                    header_up Host {upstream_hostport}
                    header_up Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
                    header_up X-Forwarded-Proto {scheme}
                    header_up X-Forwarded-For {remote}
                    header_up X-Real-IP {remote}
            }
    }