Reverse Proxy Setup
Complete the initial server setup on your local network at http://your-server-address:11423 before exposing a public address.
A reverse proxy accepts HTTPS connections and forwards them to Norri’s HTTP listener. Norri does not need a separate HTTPS port. Users open an address such as https://norri.example.com, using the normal HTTPS port 443.
Caddy
For Caddy running directly on the same host as Norri:
norri.example.com {
reverse_proxy 127.0.0.1:11423
}
Replace the domain with one you control and configure DNS and access to Caddy for your deployment.
nginx
This example assumes you already have a certificate and key for your domain:
server {
listen 443 ssl;
server_name norri.example.com;
ssl_certificate /etc/letsencrypt/live/norri.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/norri.example.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:11423;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_buffering off;
proxy_read_timeout 3600s;
}
}
Preserve the request’s host, scheme, and client address. Disabling response buffering lets scan progress and other live events reach the browser promptly.
Docker networks
If the proxy runs in another container on the same Docker network, use norri:11423 as the upstream address. That is the internal container port. If the proxy runs on the host, use the published host port, 11423 by default.
127.0.0.1 inside a proxy container refers to that container, not to the Norri container or Docker host.
Trusted proxies
Set NORRI_TRUSTED_PROXIES to the address or dedicated network of your proxy so Norri can use the forwarded client address. Use the source address that Norri actually sees. A host proxy forwarded through a Docker bridge may appear as the bridge gateway rather than 127.0.0.1. For a proxy sharing Norri’s Docker network, use its address or a dedicated proxy subnet. Do not trust arbitrary internet clients.
First-run setup also validates the host and origin. For a deliberately trusted local hostname, configure NORRI_SETUP_HOSTS, including the port when applicable. See Environment Variables.
After changing Norri’s port
Update the proxy’s upstream address when the host port changes. A proxy connecting directly to the standard container’s internal 11423 port does not need to change. Record the new host port in Settings → General → Network. Test the public address after confirming that local access still works.
See Remote Access for VPN access and troubleshooting.