Skip to content

Nginx Reverse Proxy ​

Run IPA Harbor on an internal Docker network and proxy HTTP from nginx. Example hostname ipa_harbor on network my_network:

bash
docker run -d \
  -e KEYCHAIN_PASSPHRASE=$(openssl rand -base64 15 | tr -dc 'A-Za-z0-9' | head -c10) \
  -e ADMIN_INIT_PIN=$(openssl rand -base64 24 | tr -dc '0-9' | head -c8) \
  -e PORT=3080 \
  -e ALLOW_LAN_ACCESS=false \
  -e ALLOWED_DOMAINS=example.com \
  -e TRUST_PROXY=1 \
  -v ipa_data:/app/data \
  --hostname ipa_harbor \
  --network my_network \
  --name ipa-harbor \
  --restart unless-stopped \
  uuphy/ipa-harbor:latest

Nginx site block:

nginx
server {
    listen 80;
    server_name example.com;

    location = /robots.txt {
        add_header Content-Type text/plain;
        return 200 "User-agent: *\nDisallow: /\n";
    }

    location / {
        proxy_pass http://ipa_harbor:3080;

        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";

        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        proxy_read_timeout 3600s;
        proxy_send_timeout 3600s;
    }
}

WebSocket headers are required for download progress in the UI. Configure TLS on :443 similarly when you terminate HTTPS at nginx.