@cryptotaxi247 / netdata-1 / commits / 7ab81f6a3

Add other web servers to proxy instructions (#5027)

* Add other web servers to proxy instructions Made the proxy instructions more generic and added links to the other "running behind" docs. * Add proxy instructions for more web servers apparently netlify doesn't like underscores in headings * Update netdata-security.md

Chris Akritidis committed Dec 28, 2018 at 10:56 UTC 7ab81f6a3620ec683698f10776387847edf682bd
1 file changed +6 -6
docs/netdata-security.md
+6 -6
@@ -89,17 +89,17 @@ In Netdata v1.9+ there is also access list support, like this:
89
90 #### Use an authenticating web server in proxy mode
91
92 -Use **one nginx** (or one apache) server to provide authentication in front of **all your Netdata servers**. So, you will be accessing all your Netdata with URLs like `http://nginx.host/netdata/{NETDATA_HOSTNAME}/` and authentication will be shared among all of them (you will sign-in once for all your servers). Check [this wiki page for more information on configuring nginx for such a setup](Running-behind-nginx.md#netdata-via-nginx).
92 +Use one web server to provide authentication in front of **all your Netdata servers**. So, you will be accessing all your Netdata with URLs like `http://{HOST}/netdata/{NETDATA_HOSTNAME}/` and authentication will be shared among all of them (you will sign-in once for all your servers). Instructions are provided on how to set the proxy configuration to have Netdata run behind [nginx](Running-behind-nginx.md#netdata-via-nginx), [Apache](Running-behind-apache.md), [lighthttpd](Running-behind-lighttpd.md#netdata-via-lighttpd-v14x) and [Caddy](Running-behind-caddy.md#netdata-via-caddy).
93
94 -To use this method, you should firewall protect all your Netdata servers, so that only the nginx IP will allowed to directly access Netdata. To do this, run this on each of your servers (or use your firewall manager):
94 +To use this method, you should firewall protect all your Netdata servers, so that only the web server IP will allowed to directly access Netdata. To do this, run this on each of your servers (or use your firewall manager):
95
96 ```sh
97 -NGINX_IP="1.2.3.4"
98 -iptables -t filter -I INPUT -p tcp --dport 19999 \! -s ${NGINX_IP} -m conntrack --ctstate NEW -j DROP
97 +PROXY_IP="1.2.3.4"
98 +iptables -t filter -I INPUT -p tcp --dport 19999 \! -s ${PROXY_IP} -m conntrack --ctstate NEW -j DROP
99 ```
100 -_commands to allow direct access to Netdata from an nginx proxy_
100 +_commands to allow direct access to Netdata from a web server proxy_
101
102 -The above will prevent anyone except your nginx server to access a Netdata dashboard running on the host.
102 +The above will prevent anyone except your web server to access a Netdata dashboard running on the host.
103
104 For Netdata v1.9+ you can also use `netdata.conf`:
105