Operations

Reverse proxy and HTTPS

Put TraDoc behind Caddy, Traefik or Nginx without exposing its internal ports.

The proxy terminates TLS and forwards HTTP and SSE requests to TraDoc. It must preserve long-lived /api/events connections and accept imports up to the configured limit.

Principles

  • Expose only proxy ports 80 and 443.
  • Keep TraDoc on a private Docker network or internal interface.
  • Use an automatically renewed certificate.
  • Forward Host, X-Forwarded-Proto and the client address correctly.
  • Disable caching for API routes and exports.
  • Set the proxy timeout above useful long-running operations.

Origins

If the frontend and API share one domain, leave ALLOWED_ORIGINS empty. If you genuinely separate origins, add only the required HTTPS URLs.

Authentication

For public exposure, add upstream authentication; TraDoc does not provide multi-user accounts.