Operations
Reverse proxy and HTTPS
Put TraDoc behind Caddy, Traefik or Nginx without exposing its internal ports.
The proxy terminates TLS and forwards HTTP and SSE requests to TraDoc. It must preserve long-lived /api/events connections and accept imports up to the configured limit.
Principles
- Expose only proxy ports
80and443. - Keep TraDoc on a private Docker network or internal interface.
- Use an automatically renewed certificate.
- Forward
Host,X-Forwarded-Protoand the client address correctly. - Disable caching for API routes and exports.
- Set the proxy timeout above useful long-running operations.
Origins
If the frontend and API share one domain, leave ALLOWED_ORIGINS empty. If you genuinely separate origins, add only the required HTTPS URLs.
Authentication
For public exposure, add upstream authentication; TraDoc does not provide multi-user accounts.