@pernia dawg how is i supposed to make the mitra frontend work with nexus.asbestos.cafe when relayd is handling the reverse proxy and the mitra web is a static website god fucking DAMMIT
in reply to meso

@caohuak hlep

relayd.conf:

ext_inet="23.131.76.109"

table <mitra_server> { 127.0.0.1 }
table <httpd_static> { 127.0.0.1 }

http protocol mitra {
tls ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"
# tls ecdhe "X25519,P-256,P-384,secp521r1" # relayd default+secp521r1
tls ecdhe X25519

return error

tls keypair "nexus.asbestos.cafe"

match request header append "X-Forwarded-For" value "$REMOTE_ADDR"
match request header append "Connection" value "upgrade"
# pass request quick header "Host" value "nexus.asbestos.cafe" forward to <mitra_server>

pass request quick header "Host" value "nexus.asbestos.cafe" path "/activities*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/actor*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/ap*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/api*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/collections*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/feeds*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/media*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/metrics*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/nodeinfo*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/oauth*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/objects*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/users*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/.well-known*" forward to <mitra_server>

pass request quick header "Host" value "nexus.asbestos.cafe" forward to <httpd_static>
}

relay wwwtls {
listen on $ext_inet port https tls # Comment to disable listening on IPv4
protocol mitra

# forward to <mitra_server> port 8383 check tcp timeout 500 # Adjust timeout accordingly when relayd returns 502 while Mitra is running without problems.
# When serving multiple services, add the forwards here.
# Example:
# forward to <httpd_static> port 8080 check tcp timeout 500

forward to <mitra_server> port 8383 check tcp timeout 500
forward to <httpd_static> port 8080 check tcp timeout 500
}

httpd.conf:
server "nexus.asbestos.cafe" {
listen on 127.0.0.1 port 8080
root "/nexus.asbestos.cafe/latest"
}

in reply to YBG pern

@caohuak nigga I had to ask the clanker 30 times for a config and it gave me a wrong one every time and then it made up a reason why it's wrong and why the new one is fixed but it wasn't and then it stopped giving me configs it just answered heres the config but there was none it got tired of giving me results for this and then sent me in the end I looked at pleroma's relayd config and adapted it to mitra, but then I realized I needed the god damn web client so I asked the clanker another 30 times how to make it forward all backend requests to mitra and all the rest to the frontend static site and it struggled with my nginx example with the regex so in the end ig it said fuck it and spammed all the endpoints on separate rules
in reply to meso

@meso @CaohuaK ❄️ @YBG pern I believe this the main problem all rest looks ok > match request header append "Connection" value "upgrade" it fires on every request that matches, so a plain GET /activities arrives at Mitra with Connection: upgrade attached. Which is wrong for a non upgrade request.
The match ... append line is a hack that pollutes every request with a wrong header and doesn't actually enable the internal mode switch relayd needs. One line I suggest to replace is

http protocol mitra {
    ...
    http websockets
    ...
}

The client already sends those headers. A WebSocket handshake starts as a normal HTTP GET with:

GET /activities HTTP/1.1
Host: nexus.asbestos.cafe
Connection: Upgrade
Upgrade: websocket
Sec-WebSocket-Key: ...

relayd doesn't need to add Connection: upgrade as the browser/client puts it there itself. The match ... append line was fighting a problem that didn't exist.
⇧