Behind nginx¶
nginx can serve as a reverse proxy in front of YAAMon — useful when TLS termination, rate limiting, or coexistence with other services is needed.
Prerequisites¶
When running behind any reverse proxy, restrict YAAMon to localhost only:
# /etc/yaamon/config.yaml
server:
bind_address: 127.0.0.1
http_port: 8080
tls:
mode: disabled # nginx handles TLS
SSE requirement: YAAMon's live dashboard uses Server-Sent Events (SSE). nginx must have
proxy_buffering offon the proxied location or SSE messages will be buffered and the dashboard will not update in real time.
Variant 1 — Dedicated subdomain¶
Serve YAAMon at https://yaamon.example.com/. No base_path needed.
See examples/nginx/subdomain.conf for a complete example.
Key points:
location / {
proxy_pass http://127.0.0.1:8080;
proxy_buffering off; # required for SSE
proxy_cache off;
proxy_read_timeout 3600s; # SSE connections are long-lived
}
Variant 2 — Sub-path of an existing virtual host¶
Serve YAAMon at https://example.com/yaamon/ alongside other content.
Set base_path in YAAMon to match the nginx location prefix:
Then add to your existing nginx server {} block:
location /yaamon/ {
proxy_pass http://127.0.0.1:8081/yaamon/;
proxy_buffering off;
proxy_cache off;
proxy_read_timeout 3600s;
}
See examples/nginx/subfolder.conf for a complete example.
Trailing slash: Both the
locationblock andproxy_passURL must have a trailing slash so nginx strips the prefix correctly before forwarding to YAAMon.