Configure Nginx for the Service Portal

This article shows an example of configuring Nginx to access a Service Portal at a designated domain name using a reverse proxy.

Attention

Before you start, you need to enable and activate a Service Portal.

We also recommend configuring Nginx for HUMMIX with a reverse proxy based on the instructions in the Configure Nginx to use HUMMIX behind a reverse proxy article.

The following data is used in the example:

  • /_portal/orders. Name of the workspace with an activated portal.
  • portal-hummixclient.domain.com. The Service Portal domain name.
  • hummixclient.domain.com. The HUMMIX application domain name.
  • 192.168.1.10. IP address of the server with the HUMMIX application.

Here is an example of reverse proxy configuration to access a Service Portal at a designated domain with Nginx:

server { 
   listen 80; 
   server_name portal-hummixclient.domain.com; 
   return 301 https://$server_name$request_uri; 
}
 
server { 
listen 443 ssl http2; 
server_name portal-hummixclient.domain.com;
ssl_certificate /etc/letsencrypt/live/portal-hummixclient.domain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/portal-hummixclient.domain.com/privkey.pem;
 
proxy_http_version                 1.1;
proxy_cache_bypass                 $http_upgrade;
 
proxy_set_header Upgrade           $http_upgrade;
proxy_set_header Connection        "upgrade";
proxy_set_header Host              $host;
proxy_set_header X-Real-IP         $remote_addr;
proxy_set_header X-Forwarded-For   $proxy_add_x_forwarded_for;
 
proxy_set_header Accept-Encoding "";
sub_filter_types *;
sub_filter_once off;
sub_filter 'hummixclient.domain.com' 'portal-hummixclient.domain.com';
 
location / {
    return 301 /_portal/orders;
}
location = /index.html {
    return 301 /_portal/orders;
}
location /_portal/orders {
    proxy_pass                         http://192.168.1.10/_portal/orders;
}
location ~* ^.+.(jpg|jpeg|gif|png|svg|ico|js|woff|woff|woff2|css|po)$ {
    proxy_pass                         http://192.168.1.10;
}
location /ws {
    proxy_pass                         http://192.168.1.10;
}
location /api {
    proxy_pass                         http://192.168.1.10;
}
location /s3hummix {
    proxy_pass                         http://192.168.1.10;
}
location /guard {
    proxy_pass                         http://192.168.1.10;
}
location /assets {
    proxy_pass                         http://192.168.1.10;
}
}

During installation or reconfiguration, in the Enter host field, specify hummixclient.domain.com as the external domain that HUMMIX will be available at and enable SSL termination.

Note

Note

The following parameters are required for the web sockets in the application to work correctly:

  • proxy_http_version 1.1.
  • proxy_set_header Upgrade $http_upgrade.
  • proxy_set_header Connection "upgrade".

The sub_filter directive will only work if ngx_http_sub_module is enabled in Nginx.