From fd44052fe49708ff86100dd1279fddf14cf7584c Mon Sep 17 00:00:00 2001 From: MickLesk Date: Mon, 24 Aug 2026 08:04:23 +0200 Subject: [PATCH] netbox: serve on plain HTTP too, port 80 forced HTTPS redirect broke reverse proxies --- install/netbox-install.sh | 49 ++++++++++++++++++++++++++++++++++++++- 1 file changed, 48 insertions(+), 1 deletion(-) diff --git a/install/netbox-install.sh b/install/netbox-install.sh index e844da809..bc3db7d9d 100644 --- a/install/netbox-install.sh +++ b/install/netbox-install.sh @@ -59,8 +59,55 @@ sed -i -e 's/ALLOWED_HOSTS = \[\]/ALLOWED_HOSTS = ["*"]/' \ $STD /opt/netbox/upgrade.sh ln -s /opt/netbox/contrib/netbox-housekeeping.sh /etc/cron.daily/netbox-housekeeping -mv /opt/netbox/contrib/apache.conf /etc/apache2/sites-available/netbox.conf $STD openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/netbox.key -out /etc/ssl/certs/netbox.crt -subj "/C=US/O=NetBox/OU=Certificate/CN=localhost" +# Upstream's contrib/apache.conf redirects all port-80 traffic to HTTPS, which breaks +# reverse proxies that talk plain HTTP to the backend (they get a redirect instead of +# content). Serve NetBox directly on 80 too; 443 stays available for direct HTTPS access. +cat </etc/apache2/sites-available/netbox.conf + + ProxyPreserveHost On + + Alias /static /opt/netbox/netbox/static + + + Options FollowSymLinks MultiViews + AllowOverride None + Require all granted + + + + ProxyPass ! + + + RequestHeader set "X-Forwarded-Proto" expr=%{REQUEST_SCHEME} + ProxyPass / http://127.0.0.1:8001/ + ProxyPassReverse / http://127.0.0.1:8001/ + + + + ProxyPreserveHost On + + SSLEngine on + SSLCertificateFile /etc/ssl/certs/netbox.crt + SSLCertificateKeyFile /etc/ssl/private/netbox.key + + Alias /static /opt/netbox/netbox/static + + + Options FollowSymLinks MultiViews + AllowOverride None + Require all granted + + + + ProxyPass ! + + + RequestHeader set "X-Forwarded-Proto" expr=%{REQUEST_SCHEME} + ProxyPass / http://127.0.0.1:8001/ + ProxyPassReverse / http://127.0.0.1:8001/ + +EOF $STD a2enmod ssl proxy proxy_http headers rewrite $STD a2ensite netbox systemctl restart apache2