Skip to content

feat: support direct TLS termination - #25

Merged
darwin67 merged 2 commits into
mainfrom
self-host
Aug 7, 2026
Merged

darwin67 merged 2 commits into
mainfrom
self-host

Conversation

@darwin67

@darwin67 darwin67 commented Aug 7, 2026

Copy link
Copy Markdown
Member

Allow production releases to serve HTTPS directly when readable certificate and key paths are configured, while retaining HTTP for upstream TLS termination and internal health traffic. Validate listener ports and database pool size at startup, document NLB TCP passthrough and certificate operations, and exercise the production image, migrations, HTTP, and TLS in CI.

Allow production releases to serve HTTPS directly when readable certificate and key paths are configured, while retaining HTTP for upstream TLS termination and internal health traffic. Validate listener ports and database pool size at startup, document NLB TCP passthrough and certificate operations, and exercise the production image, migrations, HTTP, and TLS in CI.
@github-actions github-actions Bot added the feat label Aug 7, 2026
Bind production HTTP and direct TLS listeners explicitly on IPv4 so container and NLB target reachability is not host-dependent. Exercise IPv4 in the image smoke test and clarify that HTTPS_PORT is the internal listener behind public HTTPS port 443.
@darwin67
darwin67 marked this pull request as ready for review August 7, 2026 18:31
@darwin67
darwin67 merged commit 2ada73f into main Aug 7, 2026
10 checks passed
@darwin67
darwin67 deleted the self-host branch August 7, 2026 18:33
@chaba2-bot chaba2-bot Bot mentioned this pull request Aug 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant