{ servers { listener_wrappers { proxy_protocol tls } trusted_proxies static 127.0.0.1/32 ::1/128 } http_port 8080 https_port 8443 } # Replace example.com with your domain. Requires web service on the same compose network. example.com { reverse_proxy web:80 { header_up X-Real-IP {remote_host} } header { X-Content-Type-Options "nosniff" X-Frame-Options "DENY" Referrer-Policy "strict-origin-when-cross-origin" Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" } } # API on same host (optional second site block) api.example.com { reverse_proxy main:8300 { header_up X-Real-IP {remote_host} } }