Comment on Can't access some services behind reverse proxy
samuraiapocalypse@lemmy.zip 5 days agoOK, I noticed I had service1.duckdns.org --> Caddy IP configured in my local DNS for pihole, but didn’t have an entry for service2. I added service2.duckdns.org --> Caddy IP. Not exactly sure how that works but now I can see errors in the logs for it in Caddy, and it’s still sending me a 502.
I’m not really sure where to start troubleshooting based on the log entry:
{"level":"error","ts":1791273870.8226678,"logger":"http.log.access.log1","msg":"handled request","request": {"remote_ip":"192.168.0.183","remote_port":"53434","client_ip":"192.168.0.183","proto":"HTTP/2.0","method":"GET","host":"service2.duckdns.org", "uri":"/","headers":{"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-Site":["none"],"Sec-Fetch-User":["?1"],"Te":["trailers"], "User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:155.0) Gecko/20100101 Firefox/155.0"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"], "Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Dest":["document"],"Dnt":["1"],"Priority":["u=0, i"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Gpc":["1"]}, "tls":{"resumed":false,"version":772,"cipher_suite":4867,"proto":"h2","server_name":"service2.duckdns.org"}},"bytes_read":0,"user_id":"","duration":0.001651465,"size":0,"status":502, "resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
grorbabrag@lemmy.world 5 days ago
Yea, no, that log entry doesn’t really shed any light on the issue.
However, your comment regarding having configured ActualBudget to serve the certificate might be hinting at what’s wrong.
Since your chain is
client > caddy > actualyou should be following the guide by actualbudget regarding operating behind a reverse proxy, so actual should not be serving the certificate.samuraiapocalypse@lemmy.zip 4 days ago
Thanks for the explanation! I removed the entries for the certs in Actual and now it seems to be working. Solved a problem and learned something new!
grorbabrag@lemmy.world 4 days ago
Sweet, just keep in mind that the connection between caddy and actual is just a plain HTTP one. Since your connection is in your local network that’s fine, but if you were to change that then be mindful that you are placing an implicit trust on the networking between caddy and actual.