docs: correct nginx X-Forwarded-Proto and certbot instructions flavor by nickvigilante · Pull Request #28086 · coder/coder · GitHub
Skip to content

docs: correct nginx X-Forwarded-Proto and certbot instructions flavor - #28086

Merged
nickvigilante merged 1 commit into
mainfrom
vigilante/docs-642-docs-fix-reverse-proxy-nginx-x-forwarded-proto-scheme
Aug 14, 2026
Merged

docs: correct nginx X-Forwarded-Proto and certbot instructions flavor#28086
nickvigilante merged 1 commit into
mainfrom
vigilante/docs-642-docs-fix-reverse-proxy-nginx-x-forwarded-proto-scheme

Conversation

@nickvigilante

Copy link
Copy Markdown
Contributor

What

Two fixes to the nginx reverse-proxy tutorial.

X-Forwarded-Proto (line 137)

The config set:

proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;

$http_x_forwarded_proto is the value of a client-supplied request header, which a client can spoof and which is usually empty for a direct request. In an nginx TLS-terminating reverse proxy this should be $scheme, which nginx sets from the actual connection (https). Using the raw client header can break Coder's scheme detection and secure-cookie handling.

Certbot link flavor (line 57)

The Certbot instructions link used ?ws=apache in an nginx guide; changed to ?ws=nginx so readers get nginx instructions.

Surfaced by the runtime drift sweep; verified against main.

Linear: DOCS-642

This PR was created with AI assistance (Coder Agents).

reverse-proxy-nginx.md set X-Forwarded-Proto from $http_x_forwarded_proto, a client-controlled (spoofable) header. In an nginx TLS-terminating reverse proxy it should be $scheme, which nginx derives from the actual connection. Also point the Certbot instructions link at the nginx flavor (ws=nginx) instead of apache. Fixes DOCS-642.

> This PR was created with AI assistance (Coder Agents).
@linear-code

linear-code Bot commented Aug 12, 2026

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown
Contributor

Docs preview

Check off each page once it's been reviewed. If a page changes in a later push, its checkbox clears automatically so it gets a fresh look. Pages not yet wired into the docs navigation aren't listed here.

@BobbyHo BobbyHo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

nickvigilante added a commit that referenced this pull request Aug 14, 2026
## Summary

High-confidence textual subset of the DOCS-637 **P2/P3** drift batch (31
findings total). These 8 fixes are pure typo / grammar / syntax
corrections verified directly against the doc source, so they carry no
risk of misreconstructed command output.

## Changes (6 files)

| Page | Fix |
|------|-----|
| `docs/admin/templates/extending-templates/variables.md` | Remove
doubled word: "file in in the template directory" → "file in the
template directory". |
| `docs/admin/networking/port-forwarding.md` | Grammar: heading "From an
coder_app resource" → "From a coder_app resource". |
| `docs/user-guides/workspace-access/index.md` | Malformed heading
"Through with the CLI" → "Through the CLI". |
| `docs/about/contributing/modules.md` | Conventional-commit example
missing the required space: `feat(git-clone):add` → `feat(git-clone):
add`. |
| `docs/ai-coder/tasks-migration.md` | Add missing closing double-quotes
on Terraform `source`/`version` in two snippets that would fail
`terraform` parsing. |
| `docs/admin/users/idp-sync.md` | Role Sync section said "group sync
settings" (copy-paste from the Group Sync section); remove an invalid
trailing comma from a JSON output example. |

## Deferred (remaining ~23 P2/P3 items, not in this PR)

The rest of the batch is stale **command-output** samples (column/schema
changes, sample values) and items that need a content decision (e.g.
`--psk` now deprecated in favor of `--key`; `--address` deprecated; an
undocumented retention flag). Those need live-output reconstruction or a
call on direction, so they're left for follow-up work, consistent with
the issue's "handle after the P0/P1 fixes land" guidance. One catalog
row (`reverse-proxy-nginx.md:57`, certbot `ws=apache`) is already
handled by #28086 and is excluded here.

Linear: https://linear.app/codercom/issue/DOCS-646

> This PR was created with AI assistance (Coder Agents).
@nickvigilante
nickvigilante marked this pull request as ready for review August 14, 2026 16:47
@nickvigilante
nickvigilante merged commit b0e93b6 into main Aug 14, 2026
52 of 53 checks passed
@nickvigilante
nickvigilante deleted the vigilante/docs-642-docs-fix-reverse-proxy-nginx-x-forwarded-proto-scheme branch August 14, 2026 16:48
@github-actions

Copy link
Copy Markdown
Contributor

nickvigilante added a commit that referenced this pull request Aug 14, 2026
…#28086) (#28160)

Backport of #28086

Original PR: #28086 — docs: correct nginx X-Forwarded-Proto and certbot
instructions flavor
Merge commit: b0e93b6
Requested by: @nickvigilante

Co-authored-by: Nick Vigilante <nickvigilante@users.noreply.github.com>
nickvigilante added a commit that referenced this pull request Aug 14, 2026
…lavor (backport to release/2.34) (#28171)

Backport of #28086 to `release/2.34` (ESR).

Cherry-picked `b0e93b6e3b59` from `main` via `git cherry-pick -x`.
Docs-only change; applied cleanly with no conflicts.

The `backport` label on the original merged PR did not produce a 2.34
backport, so this is created by hand. 2.34 is listed in
`scripts/release_channels/esr_versions.txt`, so it is a valid backport
target.

- Original PR: #28086
- Tracking: DOCS-651

> This PR was created with AI assistance (Coder Agents).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants