Caddy
Use Caddy as a reverse proxy for Sharkord.
Caddy is the least work: it obtains and renews Let's Encrypt certificates on its own, and proxies WebSockets without extra configuration.
Assumptions
- Sharkord is running on this server with the default ports.
- You are on Ubuntu Server.
- A domain (for example
sharkord.yourdomain.com) already points at this server's public IP.
Adjust the steps if any of that differs.
Step 1: Install Dependencies
sudo apt update && sudo apt upgrade -y
sudo apt install -y wget ufw curl nanoStep 2: Install Caddy
wget "https://github.com/caddyserver/caddy/releases/download/v2.11.2/caddy_2.11.2_linux_amd64.tar.gz" -O /tmp/caddy.tar.gz
tar -xzf /tmp/caddy.tar.gz
sudo mv caddy /usr/local/bin/
sudo chmod +x /usr/local/bin/caddy
caddy versionOn arm64, download the linux_arm64 archive instead. Caddy is also in the Debian and Ubuntu repositories if you prefer apt install caddy, in which case skip step 4.
Step 3: Configure Caddy
sudo mkdir -p /etc/caddy
sudo nano /etc/caddy/CaddyfilePaste this, replacing sharkord.yourdomain.com with your domain:
sharkord.yourdomain.com {
reverse_proxy 127.0.0.1:4991
encode gzip
}Step 4: Create the Service
sudo nano /etc/systemd/system/caddy.service[Unit]
Description=Caddy Web Server
After=network.target
[Service]
ExecStart=/usr/local/bin/caddy run --config /etc/caddy/Caddyfile --adapter caddyfile
ExecReload=/usr/local/bin/caddy reload --config /etc/caddy/Caddyfile --adapter caddyfile
Restart=on-failure
User=root
Group=root
AmbientCapabilities=CAP_NET_BIND_SERVICE
[Install]
WantedBy=multi-user.targetStep 5: Start Caddy
sudo systemctl daemon-reload
sudo systemctl enable caddy
sudo systemctl start caddy
sudo systemctl status caddyStep 6: Tell Sharkord About the Proxy
No configuration needed. Sharkord trusts forwarded headers from loopback and from private networks by default, so a proxy on this machine is believed and the real client address is read from X-Forwarded-For.
Two exceptions are worth knowing: a CDN such as Cloudflare in front of this proxy has to be added by hand, and a network you do not fully control should be narrowed rather than trusted wholesale. Both are covered in Behind a Proxy.
Step 7: Configure the Firewall
sudo ufw statusIf it is active, open what Sharkord needs:
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 40000/tcp
sudo ufw allow 40000/udp
sudo ufw enable
sudo ufw reloadPort 4991 does not need to be open to the internet: Caddy reaches it over localhost. Port 40000 does, because voice and video bypass the proxy.
Step 8: Open It
Go to https://sharkord.yourdomain.com. Caddy issues the certificate on the first request and renews it on its own from then on.