Simple reverse proxy to provide various web applications over a single HTTPS entry point.
5.2K
The GenHTTP Gateway provides a simple way to serve all your web applications over a single, HTTPS secured entry point. Compared to other reverse-proxy solutions such as Traefik, the gateway provides less features but is easier to configure for scenarios such as home servers.
| Tag | Description |
|---|---|
| latest | Multi architecture image to run on Linux (x64 / ARM32 / ARM64) or Windows (x64) |
| linux-x64 | Alpine based image to run on Linux x64 hosts |
| linux-arm32 | Image to run on ARMv7-based Linux hosts (such as the Raspberry Pi 2) |
| linux-arm64 | Image to run on ARMv8-based Linux hosts (such as the Raspberry Pi 4) |
| windows-x64 | Image for Windows 10 / Server 2019 based on Nano Server 2004 |
When starting the gateway via docker, an example configuration file will be created in the mounted configuration directory. Adjust this configuration file to your needs and restart the container.
docker run -d -p 80:80 \
-p 443:443 \
-v /data/gateway/config:/app/config \
-v /data/gateway/data:/app/data \
-v /etc/letsencrypt:/app/certs:ro \
--name gateway \
genhttp/gateway
Syntax for docker compositions:
services:
gateway:
image: genhttp/gateway
container_name: gateway
restart: always
volumes:
- /data/gateway/config:/app/config
- /data/gateway/data:/app/data
- /etc/letsencrypt:/app/certs:ro
ports:
- 80:80
- 443:443
Sample gateway.yaml configuration file:
# the server engine to run the gateway on
# - kestrel (default): ASP.NET Core Kestrel, supports HTTP/1.1, HTTP/2 and HTTP/3
# - internal: the built-in GenHTTP engine, supports HTTP/1.1 only
# - ioxide: io_uring based engine (experimental, linux x64 with kernel 6.1+ only)
engine: kestrel
# the ports to listen on for plain HTTP and for HTTPS
# (the secure port is only opened if at least one certificate is configured)
ports:
plain: 80
secure: 443
# the HTTP protocols to be supported on the secure port (http1, http2, http3)
# http3 requires the secure port to be reachable via UDP
protocols:
- http1
- http2
hosts:
domain1.com:
# domain1.com/...
default:
destination: http://10.0.0.2:8080
routes:
admin:
routes:
# domain1.com/admin/portainer/
portainer:
destination: http://10.0.0.2:9000
# domain1.com/admin/pi-hole/
pi-hole:
destination: http://10.0.0.3/admin/
# domain1.com/admin/files/
# directory browsing of files (requires the target path to be available through a volume)
files:
listing: /data/files/
# domain1.com/admin/content/
# static content to be served (requires the target path to be available through a volume)
content:
content:
directory: /data/content/
index: index.html # optional
# the certificate as issued by certbot, relative to /app/certs
security:
certificate:
pem: live/domain1.com/fullchain.pem
key: live/domain1.com/privkey.pem
The following volumes are available in this image:
| Volume | Description |
|---|---|
| /app/config | The configuration files of the gateway |
| /app/certs | The certificates to be used for SSL/TLS (e.g. /etc/letsencrypt) |
| /app/data | Additional data such as the .well-known folder |
For Windows volume paths, see the section below.
The gateway serves the .well-known folder from the data volume, so certbot can verify your domains using its webroot mode while the gateway is running:
certbot certonly --webroot -w /data/gateway/data/ -d domain1.com
The gateway reads the PEM files generated by certbot directly, so there is no need to convert them. Mount the whole /etc/letsencrypt directory as /app/certs (as shown above) and reference the files below live/ in your configuration:
security:
certificate:
pem: live/domain1.com/fullchain.pem
key: live/domain1.com/privkey.pem
Please note that the files in live/ are symbolic links into the archive/ folder. Mounting only /etc/letsencrypt/live will therefore not work, as the links cannot be resolved within the container.
Certificates are loaded when the gateway starts. To pick up renewed certificates, let certbot restart the container after a successful renewal:
certbot renew --deploy-hook "docker restart gateway"
To enable HTTP/3, add http3 to the list of protocols in your configuration and expose the secure port via UDP as well:
docker run ... -p 443:443 -p 443:443/udp ... genhttp/gateway
When running a Windows based image, the volume path format differs:
docker run -d -p 80:80 ^
-p 443:443 ^
-v C:\Data\Gateway\Config:C:/App/Config ^
-v C:\Data\Gateway\Data:C:/App/Data ^
-v C:\Data\Gateway\Certs:C:/App/Certs ^
genhttp/gateway
Content type
Image
Digest
sha256:210f2c1b4…
Size
50.6 MB
Last updated
3 days ago
docker pull genhttp/gateway