From 90111df03f7d6a415d09697f290eefdc88efa906 Mon Sep 17 00:00:00 2001 From: Claude Date: Sat, 21 Mar 2026 03:07:20 +0000 Subject: [PATCH] Fix Open WebUI FQDN auth and Kiwix 502 on cold start - Add WEBUI_URL to .env template and open-webui compose env so sessions work correctly when served behind Caddy (or any reverse proxy) - Fix Caddyfile.example to pass X-Forwarded-Proto/Host headers for Open WebUI - Wrap kiwix-serve command in a wait loop so the container stays healthy while ZIM files are still downloading (avoids 502 from Caddy) https://claude.ai/code/session_012gDnantBmFTWZGCiKyjazx --- laptop_full_setup.sh | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/laptop_full_setup.sh b/laptop_full_setup.sh index ddc04d8..6046dd7 100755 --- a/laptop_full_setup.sh +++ b/laptop_full_setup.sh @@ -701,6 +701,11 @@ if [[ ! -f "$BASE/.env" ]]; then # Local AI Stack — API Tokens # Edit this file, then restart: bash $BASE/start.sh +# Open WebUI — set to your public FQDN when behind a reverse proxy (Caddy etc.) +# Without this, sessions/cookies break when accessed via domain name. +# Example: WEBUI_URL=https://webui.yourdomain.com +WEBUI_URL= + # Gitea — generate at http://$LOCAL_IP:3001/user/settings/applications GITEA_TOKEN=your-gitea-token-here @@ -777,6 +782,7 @@ ${OLLAMA_VOLUME_LINE} - RAG_WEB_SEARCH_ENGINE=searxng - SEARXNG_QUERY_URL=http://searxng:8080/search?q=&format=json - WEBUI_AUTH=false + - WEBUI_URL=${WEBUI_URL:-} depends_on: ollama: condition: service_healthy @@ -876,7 +882,8 @@ ${OLLAMA_VOLUME_LINE} - "0.0.0.0:8181:8080" volumes: - $KIWIX_DIR:/data - command: "*.zim" + entrypoint: ["sh", "-c"] + command: ["until ls /data/*.zim 2>/dev/null; do echo 'kiwix: waiting for ZIM files…'; sleep 60; done && exec kiwix-serve /data/*.zim"] # ── Gitea — Self-hosted Git ───────────────────────────────────────────────── gitea: @@ -1080,7 +1087,12 @@ write_if_new "$BASE/Caddyfile.example" << CADDY # Caddy2 reverse proxy — copy to your proxy machine # Replace yourdomain.com with your actual domain -webui.yourdomain.com { reverse_proxy $(hostname).local:3000 } +webui.yourdomain.com { + reverse_proxy $(hostname).local:3000 { + header_up X-Forwarded-Proto {scheme} + header_up X-Forwarded-Host {host} + } +} invokeai.yourdomain.com { reverse_proxy $(hostname).local:9090 } search.yourdomain.com { reverse_proxy $(hostname).local:8888 } git.yourdomain.com { reverse_proxy $(hostname).local:3001 }