fix(docs): correct nginx X-Forwarded-Proto and certbot instructions flavor (backport to release/2.34) by nickvigilante · Pull Request #28171 · coder/coder · GitHub
Skip to content

fix(docs): correct nginx X-Forwarded-Proto and certbot instructions flavor (backport to release/2.34) - #28171

Merged
nickvigilante merged 1 commit into
release/2.34from
backport/28086-to-2.34
Aug 14, 2026
Merged

fix(docs): correct nginx X-Forwarded-Proto and certbot instructions flavor (backport to release/2.34)#28171
nickvigilante merged 1 commit into
release/2.34from
backport/28086-to-2.34

Conversation

@nickvigilante

Copy link
Copy Markdown
Contributor

Backport of #28086 to release/2.34 (ESR).

Cherry-picked b0e93b6e3b59 from main via git cherry-pick -x. Docs-only change; applied cleanly with no conflicts.

The backport label on the original merged PR did not produce a 2.34 backport, so this is created by hand. 2.34 is listed in scripts/release_channels/esr_versions.txt, so it is a valid backport target.

This PR was created with AI assistance (Coder Agents).

…#28086)

## What

Two fixes to the nginx reverse-proxy tutorial.

### `X-Forwarded-Proto` (line 137)
The config set:
```nginx
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
```
`$http_x_forwarded_proto` is the value of a client-supplied request
header, which a client can spoof and which is usually empty for a direct
request. In an nginx TLS-terminating reverse proxy this should be
`$scheme`, which nginx sets from the actual connection (`https`). Using
the raw client header can break Coder's scheme detection and
secure-cookie handling.

### Certbot link flavor (line 57)
The Certbot instructions link used `?ws=apache` in an nginx guide;
changed to `?ws=nginx` so readers get nginx instructions.

Surfaced by the runtime drift sweep; verified against `main`.

Linear:
[DOCS-642](https://linear.app/codercom/issue/DOCS-642/docs-fix-reverse-proxy-nginx-x-forwarded-proto-dollarscheme-certbot)

> This PR was created with AI assistance (Coder Agents).

(cherry picked from commit b0e93b6)
@github-actions

Copy link
Copy Markdown
Contributor

@github-actions

Copy link
Copy Markdown
Contributor

@nickvigilante nickvigilante changed the title docs: correct nginx X-Forwarded-Proto and certbot instructions flavor (backport to release/2.34) fix(docs): correct nginx X-Forwarded-Proto and certbot instructions flavor (backport to release/2.34) Aug 14, 2026
@nickvigilante
nickvigilante marked this pull request as ready for review August 14, 2026 17:27
@nickvigilante
nickvigilante enabled auto-merge (squash) August 14, 2026 17:28
@nickvigilante
nickvigilante merged commit 2c9745a into release/2.34 Aug 14, 2026
59 checks passed
@nickvigilante
nickvigilante deleted the backport/28086-to-2.34 branch August 14, 2026 17:34
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 14, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants