Running Behind a Reverse Proxy
Production reverse proxy setups for Nginx, Caddy, and Traefik with WebSocket and Range streaming support
Running kv-file behind a reverse proxy provides HTTPS encryption (SSL/TLS), custom domain names, and automated certificate renewals.
[!IMPORTANT] kv-file relies on WebSockets (
/api/v1/ws) for real-time filesystem updates and HTTP Range headers (206 Partial Content) for instant video seeking. Your reverse proxy must pass upgrade headers and allow large request bodies for file uploads.
1. Nginx
Add the following server block to /etc/nginx/sites-available/kv-file.conf:
server {
listen 80;
server_name files.example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name files.example.com;
# SSL Certificates
ssl_certificate /etc/letsencrypt/live/files.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/files.example.com/privkey.pem;
# Allow unlimited upload sizes for large media & ISOs
client_max_body_size 0;
location / {
proxy_pass http://127.0.0.1:8866;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# WebSocket support for real-time inotify push events
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
# Disable buffering for low-latency streaming
proxy_buffering off;
proxy_read_timeout 86400s;
proxy_send_timeout 86400s;
}
}Test and reload Nginx:
sudo nginx -t
sudo systemctl reload nginx2. Caddy
Caddy enables automatic HTTPS via Let’s Encrypt with a two-line configuration. Add to /etc/caddy/Caddyfile:
files.example.com {
reverse_proxy 127.0.0.1:8866 {
# WebSockets and streaming are supported natively in Caddy
}
}Reload Caddy:
sudo systemctl reload caddy3. Traefik (Docker Compose)
When deploying kv-file with Traefik as a container ingress, configure router labels in your docker-compose.yml:
version: '3.8'
services:
kv-file:
image: ghcr.io/vndangkhoa/kv-file:latest
container_name: kv-file
restart: unless-stopped
volumes:
- /opt/kv-file/data:/data
- /mnt/storage:/storage
labels:
- "traefik.enable=true"
- "traefik.http.routers.kv-file.rule=Host(`files.example.com`)"
- "traefik.http.routers.kv-file.entrypoints=websecure"
- "traefik.http.routers.kv-file.tls.certresolver=letsencrypt"
- "traefik.http.services.kv-file.loadbalancer.server.port=8866"4. Key Proxy Checklist
Ensure your proxy satisfies these requirements:
- WebSocket Upgrade Headers:
Upgrade $http_upgradeandConnection "upgrade"on/api/v1/ws. - Client Max Body Size: Set to
0(or10G+) to prevent413 Request Entity Too Largeon bulk file uploads. - HTTP Range Requests: Enable
proxy_buffering offso streaming media requests (bytes=...) stream without buffering the entire media file.