# Nginx Proxy Manager – Media Cluster Alle TLS en reverse proxy-instellingen gaan via de **NPM Web GUI**. Bewerk nooit handmatig `/etc/nginx/` of `/data/nginx/`. ## Master proxy host | Veld | Waarde | |------|--------| | Domain | `master.media.example.com` | | Scheme | `http` | | Forward Host | IP of hostname van de Master Docker-host | | Forward Port | `3000` | | Websockets | **Aan** (node control channel) | | Block Common Exploits | Aan | | SSL | Let's Encrypt + Force SSL + HTTP/2 | ### Advanced (optioneel) ```nginx proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_read_timeout 86400s; ``` ## Media Node proxy host Per node een apart Proxy Host: | Veld | Waarde | |------|--------| | Domain | `node01.media.example.com` | | Scheme | `http` | | Forward Host | LAN-IP van de media-node | | Forward Port | `8080` | | Block Common Exploits | Aan | | SSL | Let's Encrypt + Force SSL + HTTP/2 | ### Advanced (verplicht voor streaming) ```nginx proxy_buffering off; proxy_request_buffering off; proxy_http_version 1.1; proxy_read_timeout 86400s; proxy_send_timeout 86400s; send_timeout 86400s; # Voorkom logging van playback-tokens access_log off; ``` ## Firewall op de Media Node Alleen NPM mag poort 8080 bereiken: ```bash # Voorbeeld: NPM = 192.168.1.5, Node = 192.168.1.50 sudo ufw allow from 192.168.1.5 to any port 8080 proto tcp sudo ufw deny 8080/tcp ``` Expose **geen** WAN-poort rechtstreeks naar de media-node.