Secure websocket and proxy forward with nginx

Viewed 186

I have following setup on Digitalocean droplets:

  • Databases
  • API
  • Nats.io (Pub/Sub and Websocket)

Currently, i already setup my configuration for Nginx and Nats, SSL certificate that i'm use was Certbot from Letsencrypt. Nats was placed on docker container with run command mounting my custom config and Letsencrypt SSL certificate into container, and Nginx was placed on the host droplets.

nats-server.conf

websocket {
        port: 6969

        tls {
          cert_file: "/usr/etc/nats/fullchain.pem"
          key_file: "/usr/etc/nats/privkey.pem"
        }

        allowed_origins [
            MY_DOMAIN_LIST
        ]

        authorization {
            timeout: 3.0
        }
    }

/etc/nginx/sites-available/my-domain

server {
        server_name my-domain.com;

    # Reverse Proxy for API
    location / {
        proxy_pass http://172.22.0.1:8002;
        proxy_set_header Host $host;
        proxy_set_header  X-Real-IP $remote_addr;
        proxy_set_header  X-Forwarded-Proto https;
        proxy_set_header  X-Forwarded-For $remote_addr;
        proxy_set_header  X-Forwarded-Host $remote_addr;
    }

    # Reverse proxy for Nats
    location /ws {
        proxy_ssl_certificate /etc/letsencrypt/live/my-domain.com/fullchain.pem;
        proxy_ssl_certificate_key /etc/letsencrypt/live/my-domain.com/privkey.pem;
        proxy_ssl_protocols           TLSv1 TLSv1.1 TLSv1.2;

        proxy_ssl_session_reuse on;

        resolver 8.8.8.8;
        proxy_pass http://172.22.0.1:2222;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "Upgrade";
        proxy_set_header Host $host;
    }

        listen 443 ssl; # managed by Certbot
        ssl_certificate /etc/letsencrypt/live/my-domain.com/fullchain.pem; # managed by Certbot
        ssl_certificate_key /etc/letsencrypt/live/my-domain.com/privkey.pem; # managed by Certbot
        include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
        ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

    }

With config above, my API can be access with https protocol, but client can't be connected to websocket. I've already tried to comment tls config and add no_tls: true on nats-server.conf and remove these statement from nginx config, client can access the websocket. Websocket port was pointed to local port 2222 on host machine.

proxy_ssl_certificate /etc/letsencrypt/live/my-domain.com/fullchain.pem;
proxy_ssl_certificate_key /etc/letsencrypt/live/my-domain.com/privkey.pem;
proxy_ssl_protocols           TLSv1 TLSv1.1 TLSv1.2;

proxy_ssl_session_reuse on;

resolver 8.8.8.8;

Nats server logs not return an error when using SSL certificate from Letsencrypt, the only different if not using SSL was there was an warning message don't use this on production.

enter image description here

Is there something wrong with the Nginx configuration, SSL Certificate or Nats server configuration ? I'm trying connect to websocket using nats.ws and their said TLS and client certificates not supported, can be that was the problem ?

0 Answers
Related