SWAG (Nginx) how do I set all HTTPS traffic to go to port 8123

I need to send all HTTPS traffic to mydomain.duckdns.org to go through to Homeassistant (effectively port 8123).

Currently a call to https://mydomain.duckdns.org shows the SWAG page.

I’ve added this to HA config:

http:
  use_x_forwarded_for: true    
  trusted_proxies:
    - 172.16.0.2

I’ve then updated the homeassistant.subdomain.conf file with the local IP of the HA server:

server {
    listen 443 ssl;
#    listen 443 quic;
    listen [::]:443 ssl;
#    listen [::]:443 quic;

    server_name ha.*;

    include /config/nginx/ssl.conf;

    client_max_body_size 0;

    # enable for ldap auth (requires ldap-location.conf in the location block)
    #include /config/nginx/ldap-server.conf;

    # enable for Authelia (requires authelia-location.conf in the location block)
    #include /config/nginx/authelia-server.conf;

    # enable for Authentik (requires authentik-location.conf in the location block)
    #include /config/nginx/authentik-server.conf;

    # enable for Tinyauth (requires tinyauth-location.conf in the location block)
    #include /config/nginx/tinyauth-server.conf;

    location / {
        # enable the next two lines for http auth
        #auth_basic "Restricted";
        #auth_basic_user_file /config/nginx/.htpasswd;

        # enable for ldap auth (requires ldap-server.conf in the server block)
        #include /config/nginx/ldap-location.conf;

        # enable for Authelia (requires authelia-server.conf in the server block)
        #include /config/nginx/authelia-location.conf;

        # enable for Authentik (requires authentik-server.conf in the server block)
        #include /config/nginx/authentik-location.conf;

        # enable for Tinyauth (requires tinyauth-server.conf in the server block)
        #include /config/nginx/tinyauth-location.conf;

        include /config/nginx/proxy.conf;
        include /config/nginx/resolver.conf;
        set $upstream_app 192.168.1.10;
        set $upstream_port 8123;
        set $upstream_proto http;
        proxy_pass $upstream_proto://$upstream_app:$upstream_port;

    }

    location ~ ^/(api|local|media)/ {
        include /config/nginx/proxy.conf;
        include /config/nginx/resolver.conf;
        set $upstream_app 192.168.1.10;
        set $upstream_port 8123;
        set $upstream_proto http;
        proxy_pass $upstream_proto://$upstream_app:$upstream_port;
    }
}

That is typically done in your firewall / router…

I have solved this by ditching the homeassistant subfolder/domain confs in Nginx and instead using the ‘general’ conf to just drive all secure traffic to HA’s IP address. I believe duckdns can’t handle subfolder setups, so this seemed the easy solution as I don’t need Nginx for anything else.

(Nginx is a firewall)

From personal experience, for anyone looking into HTTPS‑ing their HA setup: try to stretch this change out over a longer time and ONLY turn off the non‑HTTPS route once you’ve daily-used the new path yourself for weeks or months. And. Test. Everything.

There is always that one weird HA app you only use 2× a year which, by the time you need it at 3AM, has had a broken config or settings flow for two months because of stopgaps such as hard‑coded ports or incompatibilities when they need to serve a URL (if you do that via duckdns) vs. a raw IP addresses.

Looking at you, “GuestRoom‑Heating‑Prewarm-Turn-Off‑Only‑When‑Inlaws‑Event‑In‑Calendar” app*.

* Not a real app but I hope the point gets across. Test for weeks, don’t rush it.