Sign inSign up

genhttp/gateway

By genhttp

•Updated 3 days ago

Simple reverse proxy to provide various web applications over a single HTTPS entry point.

Image
Networking
Integration & delivery
Web servers
1

5.2K

genhttp/gateway repository overview

⁠Introduction

The GenHTTP Gateway provides a simple way to serve all your web applications over a single, HTTPS secured entry point. Compared to other reverse-proxy solutions such as Traefik⁠, the gateway provides less features but is easier to configure for scenarios such as home servers.

⁠Tags

TagDescription
latestMulti architecture image to run on Linux (x64 / ARM32 / ARM64) or Windows (x64)
linux-x64Alpine based image to run on Linux x64 hosts
linux-arm32Image to run on ARMv7-based Linux hosts (such as the Raspberry Pi 2)
linux-arm64Image to run on ARMv8-based Linux hosts (such as the Raspberry Pi 4)
windows-x64Image for Windows 10 / Server 2019 based on Nano Server 2004

⁠Initial Setup

When starting the gateway via docker, an example configuration file will be created in the mounted configuration directory. Adjust this configuration file to your needs and restart the container.

docker run -d -p 80:80 \
              -p 443:443 \
              -v /data/gateway/config:/app/config \
              -v /data/gateway/data:/app/data \
              -v /etc/letsencrypt:/app/certs:ro \
              --name gateway \
              genhttp/gateway

Syntax for docker compositions:

services:

  gateway:
    image: genhttp/gateway
    container_name: gateway
    restart: always
    volumes:
      - /data/gateway/config:/app/config
      - /data/gateway/data:/app/data
      - /etc/letsencrypt:/app/certs:ro
    ports:
      - 80:80
      - 443:443

Sample gateway.yaml configuration file:

# the server engine to run the gateway on
# - kestrel (default): ASP.NET Core Kestrel, supports HTTP/1.1, HTTP/2 and HTTP/3
# - internal: the built-in GenHTTP engine, supports HTTP/1.1 only
# - ioxide: io_uring based engine (experimental, linux x64 with kernel 6.1+ only)
engine: kestrel

# the ports to listen on for plain HTTP and for HTTPS
# (the secure port is only opened if at least one certificate is configured)
ports:
  plain: 80
  secure: 443

# the HTTP protocols to be supported on the secure port (http1, http2, http3)
# http3 requires the secure port to be reachable via UDP
protocols:
  - http1
  - http2

hosts:

  domain1.com:    

    # domain1.com/...
    default:
      destination: http://10.0.0.2:8080

    routes:

      admin:

        routes:

          # domain1.com/admin/portainer/
          portainer:
            destination: http://10.0.0.2:9000

          # domain1.com/admin/pi-hole/
          pi-hole:
            destination: http://10.0.0.3/admin/

          # domain1.com/admin/files/
          # directory browsing of files (requires the target path to be available through a volume)
          files:
            listing: /data/files/
          
          # domain1.com/admin/content/
          # static content to be served (requires the target path to be available through a volume)
          content:
            content:
              directory: /data/content/
              index: index.html # optional

    # the certificate as issued by certbot, relative to /app/certs
    security:
      certificate:
        pem: live/domain1.com/fullchain.pem
        key: live/domain1.com/privkey.pem

⁠Volumes

The following volumes are available in this image:

VolumeDescription
/app/configThe configuration files of the gateway
/app/certsThe certificates to be used for SSL/TLS (e.g. /etc/letsencrypt)
/app/dataAdditional data such as the .well-known folder

For Windows volume paths, see the section below.

⁠SSL / Let's Encrypt

The gateway serves the .well-known folder from the data volume, so certbot can verify your domains using its webroot mode while the gateway is running:

certbot certonly --webroot -w /data/gateway/data/ -d domain1.com

The gateway reads the PEM files generated by certbot directly, so there is no need to convert them. Mount the whole /etc/letsencrypt directory as /app/certs (as shown above) and reference the files below live/ in your configuration:

security:
  certificate:
    pem: live/domain1.com/fullchain.pem
    key: live/domain1.com/privkey.pem

Please note that the files in live/ are symbolic links into the archive/ folder. Mounting only /etc/letsencrypt/live will therefore not work, as the links cannot be resolved within the container.

Certificates are loaded when the gateway starts. To pick up renewed certificates, let certbot restart the container after a successful renewal:

certbot renew --deploy-hook "docker restart gateway"
⁠HTTP/3

To enable HTTP/3, add http3 to the list of protocols in your configuration and expose the secure port via UDP as well:

docker run ... -p 443:443 -p 443:443/udp ... genhttp/gateway

⁠Volumes on Windows

When running a Windows based image, the volume path format differs:

docker run -d -p 80:80 ^
              -p 443:443 ^
              -v C:\Data\Gateway\Config:C:/App/Config ^
              -v C:\Data\Gateway\Data:C:/App/Data ^
              -v C:\Data\Gateway\Certs:C:/App/Certs ^
              genhttp/gateway

Tag summary

Content type

Image

Digest

sha256:210f2c1b4…

Size

50.6 MB

Last updated

3 days ago

docker pull genhttp/gateway