# Installing Yunohost in an lxc behind a reverse proxy

**URL:** https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578
**Category:** Tutorials
**Tags:** install, english
**Created:** [July 25, 2024, 8:33pm UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578 "2024-07-25T20:33:22Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![PseudoMotivated](https://forum.yunohost.org/user_avatar/forum.yunohost.org/pseudomotivated/32/10326_2.png) [@PseudoMotivated](https://forum.yunohost.org/u/PseudoMotivated)
#### Post date: [July 25, 2024, 8:33pm UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578/1 "2024-07-25T20:33:22Z")

</div>

Hello,  
I recently installed Yunohost (again), and this time in an lxc behind a reverse proxy. While trying to do it I found there wasn’t a whole lot of good documentation for that. So I thought I’d do it myself and maybe help whoever comes searching next. So after digging in threads, reading docs and a whole lot of googling, I present this mess of a [tutorial](https://github.com/PseudoMotivated/Yunohost-in-lxc-behind-nginx-reverse-proxy).

I tried to post it here but there were too many links apparently.

---

<div class="post-metadata">

### Author: ![wbk](https://forum.yunohost.org/letter_avatar_proxy/v4/letter/w/e0b2c6/32.png) [@wbk](https://forum.yunohost.org/u/wbk)
#### Post date: [July 26, 2024, 12:44am UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578/2 "2024-07-26T00:44:48Z")

</div>

Hi PseudoMotivated,

Welcome to the forums!

Nice of you to write the tutorial 🙂

Are you happy with the setup?

---

<div class="post-metadata">

### Author: ![Aleks](https://forum.yunohost.org/user_avatar/forum.yunohost.org/aleks/32/1704_2.png) [@Aleks](https://forum.yunohost.org/u/Aleks)
#### Post date: [July 26, 2024, 1:38am UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578/3 "2024-07-26T01:38:35Z")

</div>

Thanks for sharing 👍

Github README support mermaid diagram, zomg 😮

Here are my notes on an SNI-based approach (with the goal of being to be able to host several machines being a single IP, or expose a YunoHost that cannot be easily exposed through traditional means using another external YunoHost)

> **[GitHub - alexAubin/snibasedforwarding: SNI-based forwarding with nginx](https://github.com/alexAubin/snibasedforwarding)**
>
> SNI-based forwarding with nginx. Contribute to alexAubin/snibasedforwarding development by creating an account on GitHub.

> <https://github.com/YunoHost/yunohost/pull/1697>
>
> \## The problem
> 
> For various scenarios, it would be nice to be able to have SNI…-based forwarding of HTTPS traffic (ie without decrypting the traffic) to another machine. For example:
> \- hosting several Yunohost behind a single IP (or a single YunoHot + other stuff like NAS / whatever, behind a single IP)
> \- more advanced case such as having a VPN on a YunoHost server on whatever provider, but which serves a purpose of "exposing" a Yunohost server which otherwise cannot be exposed because behind too many layers of networks etc
> 
> \## Solution
> 
> Introduce a new setting to "enable SNI based forwarding" + configure a mapping of domain:IPv4
> 
> The whole thing tweaks nginx's configuration and use nginx's ssl\_preread stuff : https://nginx.org/en/docs/stream/ngx\_stream\_ssl\_preread\_module.html
> 
> !\[2023-08-11-230653\_1366x768\_scrot\](https://github.com/YunoHost/yunohost/assets/4533074/806f5789-3809-4cd9-8217-96e72e7a5bc0)
> 
> 
> 
> \## PR Status
> 
> Somewhat tested but should be propreply re-tested
> 
> Also we should : 
> \- check that the SNI-forwarded domains are not YunoHost domains
> \- technical tweak to add in nginx regenconf to forget about old .forward80.conf (cf FIXME in code)
> \- ??? think about other funky cases idk
> 
> \## How to test
> 
> ...

The remaining part of the PR is kind of tricky because implementing fail2ban on the proxied server aint trivial in this approach, because all traffic (in terms of IP layer, the one on which fail2ban/iptables act) appears as coming from the reverse proxy so eh

---

<div class="post-metadata">

### Author: ![jarod5001](https://forum.yunohost.org/user_avatar/forum.yunohost.org/jarod5001/32/5323_2.png) [@jarod5001](https://forum.yunohost.org/u/jarod5001)
#### Post date: [July 26, 2024, 12:50pm UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578/4 "2024-07-26T12:50:20Z")

</div>

I have, a long time ago, written a tutorial on how to run yunohost 4 inside an lxc container with another lxc container running a docker app (azuracast). All this in a virtualbox VM under windows, proxied by my main yunohost server (an old laptop).  
All was working great, but I deleted the VM after a while since I didn’t need the containers.  
I also had to move my blog from Hugo to something else, because I had very little time on pc and preferred other solution to easily write on phone (meanwhile my blog is showing “under construction”). The idea of writing on github seems very interesting.

---

<div class="post-metadata">

### Author: ![PseudoMotivated](https://forum.yunohost.org/user_avatar/forum.yunohost.org/pseudomotivated/32/10326_2.png) [@PseudoMotivated](https://forum.yunohost.org/u/PseudoMotivated)
#### Post date: [July 27, 2024, 10:01pm UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578/5 "2024-07-27T22:01:46Z")

</div>

Yes absolutely!

Pretty much indistiguishable from baremetal performance, and so far minimal issues.

However there is only one thing I’ve yet to figure out how to solve and that is forwarding the real IP address of client to the final destination. As in the webmin interface all logs show that it thinks its talking to 127.0.0.1.  
Which can be bad, however my threatmodel allows for it, though if anyone has any suggestions it would be much appreciated 🙂

---

<div class="post-metadata">

### Author: ![PseudoMotivated](https://forum.yunohost.org/user_avatar/forum.yunohost.org/pseudomotivated/32/10326_2.png) [@PseudoMotivated](https://forum.yunohost.org/u/PseudoMotivated)
#### Post date: [July 30, 2024, 9:42pm UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578/6 "2024-07-30T21:42:41Z")

</div>

Hello,  
I also noticed this issue, and I believe that I fixed it in this revision because when I test with the ynh app ifconfig it now tells me my real IP instead of the reverse proxy containers IP as it did with the previous revision of the guide. I have however not retested this new version beginning to end as I did the previous one and therefore put it in a different branch. What I did is enabled proxy\_protocol for the containers proxy devices, and in the nginx configs. I then added a config to the yunohost nginx to get the clients ip from the reverse proxy. It wasn’t a totally obscure fix, and it seems to work as far as I can tell. Here is the [revised version](https://github.com/PseudoMotivated/Yunohost-in-lxc-behind-nginx-reverse-proxy/blob/real-ip/README.md)

---

<div class="post-metadata">

### Author: ![Aleks](https://forum.yunohost.org/user_avatar/forum.yunohost.org/aleks/32/1704_2.png) [@Aleks](https://forum.yunohost.org/u/Aleks)
#### Post date: [July 30, 2024, 9:47pm UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578/7 "2024-07-30T21:47:47Z")

</div>

Yes, the “proxy protocol” / X-Real-IP thing in nginx is “half” of the solution

The real issue is that in an ideal world, you would like the proxied yunohost to handle fail2ban on its own. But the whole X-Real-IP thing happens on the HTTP layer, whereas iptable acts on the IP layer … and on the IP layer, every packet appears as sent from the reverseproxy “front” …

so even if an attacker is doing nasty stuff from, say, IP 66.66.66.66 … nginx will indeed log the right IP because of the proxy protocol / X-Real-IP-whatever … hence fail2ban will indeed end up banning this IP … but all the packets actually arrive from 192.168.x.y (the reverseproxy front) so banning the IP has no effect.

---

<div class="post-metadata">

### Author: ![PseudoMotivated](https://forum.yunohost.org/user_avatar/forum.yunohost.org/pseudomotivated/32/10326_2.png) [@PseudoMotivated](https://forum.yunohost.org/u/PseudoMotivated)
#### Post date: [July 30, 2024, 10:00pm UTC](https://forum.yunohost.org/t/installing-yunohost-in-an-lxc-behind-a-reverse-proxy/30578/8 "2024-07-30T22:00:17Z")

</div>

I see, in that case then I don’t see any possible solutions. I guess unless fail2ban ran directly on the host or the proxy. To be frank I am in way over my head here anyways, but if I do find some way to work around this I will try to improve the guide to integrate it.
