Comment on Can't access some services behind reverse proxy
grorbabrag@lemmy.world 6 days ago
Seems weird that you’re not seeing any logs for service2 in caddy, especially if it’s caddy serving the 502. I’d expect at least a message from caddy complaining about being unable to reach the upstream service in that case.
Verify that the 502 is coming from caddy and not potentially some other gateway that’s part of service2.
samuraiapocalypse@lemmy.zip 5 days ago
OK, I noticed I had service1.duckdns.org --> Caddy IP configured in my local DNS for pihole, but didn’t have an entry for service2. I added service2.duckdns.org --> Caddy IP. Not exactly sure how that works but now I can see errors in the logs for it in Caddy, and it’s still sending me a 502.
I’m not really sure where to start troubleshooting based on the log entry:
grorbabrag@lemmy.world 5 days ago
Yea, no, that log entry doesn’t really shed any light on the issue.
However, your comment regarding having configured ActualBudget to serve the certificate might be hinting at what’s wrong.
Since your chain is
client > caddy > actualyou should be following the guide by actualbudget regarding operating behind a reverse proxy, so actual should not be serving the certificate.samuraiapocalypse@lemmy.zip 4 days ago
Thanks for the explanation! I removed the entries for the certs in Actual and now it seems to be working. Solved a problem and learned something new!
grorbabrag@lemmy.world 4 days ago
Sweet, just keep in mind that the connection between caddy and actual is just a plain HTTP one. Since your connection is in your local network that’s fine, but if you were to change that then be mindful that you are placing an implicit trust on the networking between caddy and actual.