Tuesday, May 18, 2021

How to Proxy Secure WebSockets (WSS) in a Subfolder with Apache mod_proxy_wstunnel

Routing secure WebSocket connections (wss://) originating from a specific URL subfolder (such as /websocket1) to a local backend daemon (running on an internal TCP port like 2085) requires configuring Apache's mod_proxy_wstunnel.

Prerequisites: Enable Apache modules: proxy, proxy_http, proxy_wstunnel, and rewrite.

Apache VirtualHost Configuration

# Enable proxy tunneling for WebSockets
RewriteEngine On

# Detect WebSocket upgrade request headers for /websocket1
RewriteCond %{REQUEST_URI} ^/websocket1 [NC]
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteRule ^/websocket1/(.*)$ ws://127.0.0.1:2085/$1 [P,L]

# Normal HTTP proxy fallback (if needed):
ProxyPass /websocket1 http://127.0.0.1:2085/
ProxyPassReverse /websocket1 http://127.0.0.1:2085/

Reload Apache to apply:

sudo systemctl reload apache2

1 comment:

  1. I've tried similar configurations while managing my WebSpaceKit server and it helped streamline multiple WebSocket services behind HTTPS without conflicts.

    ReplyDelete

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...