README: Fix default ports and ADMIN_PASSWORD boot rules
Format / gofmt (push) Successful in 15s
CI / Build (push) Successful in 30s
CI / Go Tests (push) Successful in 1m4s

Docs sync: align README with current ports/password rules.

Co-authored-by: s1d3sw1ped_bot <s1d3sw1ped+giteabot@gmail.com>
Co-committed-by: s1d3sw1ped_bot <s1d3sw1ped+giteabot@gmail.com>
This commit was merged in pull request #9.
This commit is contained in:
s1d3sw1ped_bot
2026-09-02 10:44:13 -05:00
committed by s1d3sw1ped_bot
parent 83c4f4163e
commit ac98b8e942
+15 -9
View File
@@ -1,6 +1,6 @@
# Helix Proxy # Helix Proxy
A pure-Go reverse proxy with embedded web UI. Supports proxy hosts, TCP/UDP streams, redirections, dead hosts, certificates (Let's Encrypt + custom), access lists, audit, and more. Single static binary. Single built-in admin (no multi-user registration; defaults to "password", first login forces a change which is then bcrypt-hashed and stored in the DB). A pure-Go reverse proxy with embedded web UI. Supports proxy hosts, TCP/UDP streams, redirections, dead hosts, certificates (Let's Encrypt + custom), access lists, audit, and more. Single static binary. Single built-in admin (no multi-user registration). Production requires `ADMIN_PASSWORD` on first boot (the well-known default `"password"` is rejected); development may leave it unset until you change it (bootstrap lock).
**Key features / differences from traditional setups**: **Key features / differences from traditional setups**:
- **Entirely replaces nginx**: pure Go reverse proxy (http) + TCP/UDP stream proxy engine. No nginx binary, no config files on disk for routing, live updates. - **Entirely replaces nginx**: pure Go reverse proxy (http) + TCP/UDP stream proxy engine. No nginx binary, no config files on disk for routing, live updates.
@@ -12,12 +12,14 @@ A pure-Go reverse proxy with embedded web UI. Supports proxy hosts, TCP/UDP stre
## Quick start (binary) ## Quick start (binary)
```bash ```bash
make # builds UI (placeholder) + Go binary with embed make # builds UI (placeholder) + Go binary with embed
./helix-proxy ADMIN_PASSWORD='choose-a-real-password' ./helix-proxy
# Admin UI + API on :81 # Defaults (overridable via env):
# Proxy on :8080 (or 80/443 when you have perms / run in docker) # Admin UI + API: 127.0.0.1:8081 (ADMIN_HOST / ADMIN_PORT)
# Proxy HTTP: :8080 (PROXY_HTTP_PORT)
# Proxy HTTPS: :18443 (PROXY_HTTPS_PORT)
``` ```
Visit http://localhost:81 Visit http://127.0.0.1:8081
Data (db, certs, logs, www html) lives in `./data` relative to where you ran the binary. Data (db, certs, logs, www html) lives in `./data` relative to where you ran the binary.
@@ -26,9 +28,13 @@ Data (db, certs, logs, www html) lives in `./data` relative to where you ran the
docker compose up -d docker compose up -d
# or # or
docker build -t helix-proxy:dev . docker build -t helix-proxy:dev .
docker run -p 81:81 -v $PWD/data:/app/data --workdir /app helix-proxy:dev docker run --env ADMIN_PASSWORD='choose-a-real-password' \
-e ADMIN_PORT=81 -e ADMIN_HOST=0.0.0.0 -e PROXY_HTTP_PORT=80 -e PROXY_HTTPS_PORT=443 \
-p 80:80 -p 81:81 -p 443:443 -v $PWD/data:/app/data --workdir /app helix-proxy:dev
``` ```
Without those env overrides the binary still defaults to admin `127.0.0.1:8081` and proxy `:8080` / `:18443` inside the container.
PUID/PGID + DISABLE_IPV6 example (see docker-compose.yml for full): PUID/PGID + DISABLE_IPV6 example (see docker-compose.yml for full):
```yaml ```yaml
# user: "0:0" # root to allow chown+drop inside # user: "0:0" # root to allow chown+drop inside
@@ -41,7 +47,7 @@ environment:
Binary auto-chowns data tree (if started root) then drops privs (unless PUID_NO_DROP); umask support via UMASK env. Files 0600, dirs 0755. Binary auto-chowns data tree (if started root) then drops privs (unless PUID_NO_DROP); umask support via UMASK env. Files 0600, dirs 0755.
Note: privilege drop happens early (before listeners); low-port binds require either root (with PUID_NO_DROP), capabilities, high ports in config, or external setuid wrapper. Note: privilege drop happens early (before listeners); low-port binds require either root (with PUID_NO_DROP), capabilities, high ports in config, or external setuid wrapper.
See docker-compose.yml for full example (exposes 80/81/443, volume for data/). See docker-compose.yml for a full example (publishes 80/443; admin stays on loopback unless you set `ADMIN_HOST` / publish the admin port).
## Paths (all overridable) ## Paths (all overridable)
- `data/db.bolt` (or `DATA_DIR`) - `data/db.bolt` (or `DATA_DIR`)
@@ -55,13 +61,13 @@ Core features implemented and verified:
- cwd-relative + env-overridable paths/storage (single `data/db.bolt` primary via bbolt) - cwd-relative + env-overridable paths/storage (single `data/db.bolt` primary via bbolt)
- pure-Go engine: proxy hosts (full: locations, advanced_config parser, ssl_forced, block_exploits, websocket, hsts, caching w/ HIT/MISS, access lists, custom certs, LE), streams (tcp/udp +ssl term), redirection hosts (full forward_http_code/preservePath/scheme + CRUD), dead hosts (per-dead custom content + CRUD) - pure-Go engine: proxy hosts (full: locations, advanced_config parser, ssl_forced, block_exploits, websocket, hsts, caching w/ HIT/MISS, access lists, custom certs, LE), streams (tcp/udp +ssl term), redirection hosts (full forward_http_code/preservePath/scheme + CRUD), dead hosts (per-dead custom content + CRUD)
- certificates: custom PEM (meta keys compat) + full Let's Encrypt issuance/renewal via lego (http-01). In PROXY_MODE=development *all* LE certs are self-signed test certs (domain-based sim tricks removed). - certificates: custom PEM (meta keys compat) + full Let's Encrypt issuance/renewal via lego (http-01). In PROXY_MODE=development *all* LE certs are self-signed test certs (domain-based sim tricks removed).
- single admin (defaults to "password"; first login forces change; hashed + stored in DB; no registration or multi-user) - single admin (`ADMIN_PASSWORD` required in production; default `"password"` refused; hashed + stored in DB; no registration or multi-user)
- audit (userId=1), settings (default_site + letsencrypt_email etc) - audit (userId=1), settings (default_site + letsencrypt_email etc)
- live reload on all CRUD, dual https/http + SNI, embedded Svelte SPA (full tabs, pickers, edits) - live reload on all CRUD, dual https/http + SNI, embedded Svelte SPA (full tabs, pickers, edits)
- single binary (go build embeds UI after make ui-build), docker multi-stage + full PUID/PGID/umask - single binary (go build embeds UI after make ui-build), docker multi-stage + full PUID/PGID/umask
- no nginx, no .conf files, no external processes for proxying - no nginx, no .conf files, no external processes for proxying
LE note: for real certs use a public DNS domain pointing at your server (port 80/http reachable). By default (production), real LE http-01 is used. Set PROXY_MODE=development and *all* letsencrypt cert requests will produce self-signed test certs instead (for dev/testing; see TESTING.md). Real LE will be used otherwise (requires valid email, port 80 reachable etc). LE note: for real certs use a public DNS domain pointing at your server (port 80/http reachable). By default (production), real LE http-01 is used. Set PROXY_MODE=development and *all* letsencrypt cert requests will produce self-signed test certs instead (for dev/testing). Real LE will be used otherwise (requires valid email, port 80 reachable etc).
## Development ## Development
- `make ui-build` (once real Svelte UI added to ui/) - `make ui-build` (once real Svelte UI added to ui/)