# Use HTTPS on Reverse Proxys (/node & /rnode)

**URL:** <https://discourse.openondemand.org/t/use-https-on-reverse-proxys-node-rnode/2404>\
**Category:** Get Help\
**Created:** [December 13, 2022, 3:23pm UTC](https://discourse.openondemand.org/t/use-https-on-reverse-proxys-node-rnode/2404 "2022-12-13T15:23:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jgibbens](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jgibbens/32/1400_2.png) [@jgibbens](https://discourse.openondemand.org/u/jgibbens)\
**Post date:** [December 13, 2022, 3:23pm UTC](https://discourse.openondemand.org/t/use-https-on-reverse-proxys-node-rnode/2404/1 "2022-12-13T15:23:17Z")

</div>

I’m able to to use the OOD builtin Reverse Proxy to hit an upstream host via HTTP with no issues.  
For example, a simple NGINX server is running on node04.  
[https://head.cluster/rnode/node04.cluster/80](https://head.cluster/rnode/node04.cluster/80) → works  
[https://head.cluster/rnode/node04.cluster/443](https://head.cluster/rnode/node04.cluster/443) → Fails with expected ‘The plain HTTP request was sent to HTTPS port’

I’m having trouble figuring out where to set a forced HTTPS protocol within the HTTPD & LUA configs that I believe are relevant to what OOD is doing. I see the /rnode Location block within ood-portal.conf and more in node\_proxy.lua, but I’m not sure on where to make the proper change. I also don’t want to make all upstream connections use HTTPS, just a few that require it.

I’ve set up my own NGINX instance with Reverse Proxy as a sanity test that works. I really want to leverage the built in OID auth and host/port mapping that comes with OOD Reverse Proxy though. Any tips would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![travert](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/travert/32/3074_2.png) [@travert](https://discourse.openondemand.org/u/travert)\
**Post date:** [December 13, 2022, 6:14pm UTC](https://discourse.openondemand.org/t/use-https-on-reverse-proxys-node-rnode/2404/2 "2022-12-13T18:14:16Z")

</div>

Hello and welcome!

I think the main document you will want to be using for this is the `ood_portaly.yml` file here:  
[https://osc.github.io/ood-documentation/latest/reference/files/ood-portal-yml.html](https://osc.github.io/ood-documentation/latest/reference/files/ood-portal-yml.html)

This can help you set things up for OIDC auth.

For the question around using HTTPS vs HTTP you’ll have to hack the code that is currently used for the reverse proxy here:

> <https://github.com/OSC/ondemand/blob/2ac63ceb6dc5e3ced3e349ac0aad9e6dc8fc6f2f/mod_ood_proxy/lib/ood/proxy.lua#L8>

So that you force `http` based on the `port` and similar for `https` instead of using the either or.

---

<div class="post-metadata">

**Author:** ![jgibbens](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jgibbens/32/1400_2.png) [@jgibbens](https://discourse.openondemand.org/u/jgibbens)\
**Post date:** [December 14, 2022, 7:32pm UTC](https://discourse.openondemand.org/t/use-https-on-reverse-proxys-node-rnode/2404/3 "2022-12-14T19:32:14Z")

</div>

Thanks for verifying the location within LUA → /opt/ood/mod\_ood\_proxy/lib/ood/proxy.lua

For posterity, I changed the following:  
`local protocol = (r.headers_in['Upgrade'] and "ws://" or "http://")`  
To:

```auto
  -- find protocol used by parsing the request headers
  -- Check if an upstream port was set for reverse proxies.
  local upstreamPort = nil
  local isUpstreamPortSet = (r.subprocess_env['MATCH_PORT'] and 'true' or 'false')
  if isUpstreamPortSet == 'true' then
    upstreamPort = r.subprocess_env['MATCH_PORT']
  end

  -- Default to ws:// or http:// protocols to upstream hosts
  local protocol = (r.headers_in['Upgrade'] and "ws://" or "http://")
  if upstreamPort then
    -- If specified port was used, then use secure protocols
    if upstreamPort == '8443' then
      protocol = (r.headers_in['Upgrade'] and "wss://" or "https://")
    end
  end

```

You also have to edit /etc/httpd/conf.d/ood-portal.conf and add ‘SSLProxyEngine on’ within the VirtualHost block.

```auto
  SSLEngine On
  SSLProxyEngine on

```

That was the first LUA I’ve ever been forced to touch, so someone else could do better. It appears to work though (10 mins of testing), and only changes to secure protocols when a specific port is set (8443 in this example).  
Other, previously added apps still seem to work (NoVNC desktops, etc…)

Thanks again!

---

<div class="post-metadata">

**Author:** ![travert](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/travert/32/3074_2.png) [@travert](https://discourse.openondemand.org/u/travert)\
**Post date:** [December 14, 2022, 7:48pm UTC](https://discourse.openondemand.org/t/use-https-on-reverse-proxys-node-rnode/2404/4 "2022-12-14T19:48:36Z")

</div>

Thanks for posting your solution! Let us know if you have anymore questions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [June 12, 2023, 7:48pm UTC](https://discourse.openondemand.org/t/use-https-on-reverse-proxys-node-rnode/2404/5 "2023-06-12T19:48:56Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
