33 lines
1.7 KiB
Markdown
33 lines
1.7 KiB
Markdown
# Nginx Proxy Manager (temporary, on the Synology)
|
|
|
|
Running here until the NUC homeserver exists — see
|
|
[../../docs/todo.md](../../docs/todo.md) for the full local-DNS + reverse-proxy
|
|
plan (Pi-hole/LAN DNS points internal hostnames at this box's IP; NPM routes
|
|
each hostname to the right backend service/port).
|
|
|
|
Deploy via Container Manager's **Project** feature (paste/import this
|
|
compose file — same as however Pi-hole was set up there) or over SSH with
|
|
`docker compose up -d` from this directory.
|
|
|
|
## Port note
|
|
|
|
Ports 80/443 are already taken on this Synology by DSM's own internal nginx
|
|
(`netstat -tulpn | grep :443` showed `nginx: worker` — likely Web Station or
|
|
the Login Portal's HTTP→HTTPS redirect feature); 8080/8443/81 turned out to
|
|
also already be in use by other running packages. Rather than chase down and
|
|
touch existing DSM config for a temporary deployment, NPM is remapped to
|
|
host ports **9080/9443/9081** instead — meaning proxied HTTPS URLs need an
|
|
explicit `:9443` and the admin UI is at `http://<synology-ip>:9081` until
|
|
this moves to the NUC, where a clean `80:80`/`443:443`/`81:81` mapping will
|
|
work with no conflict. Revert the compose file's `ports:` section at that
|
|
point.
|
|
|
|
## Notes
|
|
|
|
- No MariaDB container — NPM's built-in SQLite database is enough for this
|
|
scale and keeps the footprint light on the DS223j's 1GB RAM.
|
|
- Admin UI: `http://<synology-ip>:81` — default login is `admin@example.com`
|
|
/ `changeme` on first run; change both immediately.
|
|
- TLS certs: plan is Let's Encrypt via DNS-01 using INWX's API (an `acme.sh`
|
|
plugin exists for this) once that part of the plan is implemented — see
|
|
[../../docs/todo.md](../../docs/todo.md).
|