Running behind a reverse proxy§
Warpgate doesn't need any specific configuration except in the following case:
- When using single sign-on, make sure your reverse proxy supplies the correct
Host(orX-Forwarded-Host) andX-Forwarded-Protoheaders - this allows Warpgate to construct correct redirect URLs. - Set
http.trust_x_forwarded_headerstotruein the config file.
Example for NGINX:
server {
server_name warpgate.acme.inc;
listen *:443 http2 ssl;
ssl_certificate ...;
ssl_certificate_key ...;
location / {
proxy_pass https://192.168.10.1:8888;
proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
}
}
TCP PROXY protocol§
v0.27+
When Warpgate sits behind a TCP (layer-4) load balancer such as HAProxy or an AWS Network Load Balancer, the client's real IP address would otherwise be lost. Warpgate can read it from a HAProxy PROXY protocol (v1/v2) header on any listener. Enable it per listener with proxy_protocol: true:
ssh:
listen: '[::]:2222'
+ proxy_protocol: true
Only enable this when the upstream load balancer actually prepends a PROXY header.