Choose a method
This page helps you pick how to run Goiabada in production.
Most people want Cloudflare Tunnel: no open port, no certificate to renew and no Nginx. Already run Nginx, or don’t use Cloudflare? Pick by what you have:
| Method | TLS | Exposed to the internet | Setup wizard | Database | Suits |
|---|---|---|---|---|---|
| Cloudflare Tunnel Least effort |
Cloudflare’s certificates | Nothing: cloudflared connects out |
Production with reverse proxy | MySQL, PostgreSQL, SQL Server or SQLite, in the Compose file | One server, with your domain on Cloudflare |
| Cloudflare + Nginx Some effort |
Cloudflare’s, and Let’s Encrypt’s on Nginx | Ports 80 and 443 | Production with reverse proxy | The same | A server already running Nginx, with your domain on Cloudflare |
| Reverse proxy Some effort |
Let’s Encrypt’s on Nginx | Ports 80 and 443 | Production with reverse proxy | The same | One server, without Cloudflare |
| Kubernetes Most effort |
cert-manager’s, on the Gateway | The Gateway’s load balancer | Kubernetes cluster | MySQL, PostgreSQL or SQL Server, run by you | Several replicas, on a cluster you already run |
| Native binaries Some effort |
Your reverse proxy’s, or each server’s own | Your proxy’s ports, or each server’s | Native binaries | MySQL, PostgreSQL or SQL Server run by you, or SQLite | A server without Docker |
The first three run the Docker Compose files the setup wizard writes, and differ only in what sits in front of them.
What every method needs
Section titled “What every method needs”- Two hostnames, one for the auth server and one for the admin console, such as
auth.example.comandadmin.example.com. Each server answers on its own. - One registrable domain for both.
auth.example.comandadmin.example.comwork;auth.example.comandadmin.example.netdon’t. The admin console’s sign-in ends with the auth server posting the answer back to the admin console, and a browser sends the admin console’s session cookie on that post only when both are on the same site. On two sites, every sign-in to the admin console stops at “This sign-in can’t be finished”. - HTTPS on both public URLs. Each server marks its cookies
Secureonly when its URL ishttps://. - An empty database on the first start, which the auth server seeds with the administrator and the admin console’s client, for the URLs you gave. Changing the URLs later means changing that client’s redirect URIs too: see Invalid redirect_uri.
What changes between methods
Section titled “What changes between methods”Every method runs the same two servers. The auth server answers sign-ins, tokens and the API on port 9090, and the admin console answers administrators on port 9091. Each serves plain HTTP by default, and something in front of it serves HTTPS: Cloudflare, Nginx, a Kubernetes Gateway, or the server itself with a certificate of its own.
Two things change from method to method, and each has a page:
- How Goiabada learns the client’s IP address through whatever is in front of it, which decides what the rate limiter counts: Client IP and proxy trust.
- How the admin console reaches the auth server. It calls the auth server’s API at
GOIABADA_AUTHSERVER_INTERNALBASEURL, and that hop carries its client secret and administrators’ tokens. The generated Compose files and Kubernetes manifests point it at the auth server’s container or Service over plain HTTP, inside the deployment’s own network; native binaries go through the public URL. Docker Compose, Kubernetes and the production checklist say when that’s enough and how to encrypt it.
Next steps
Section titled “Next steps”Setup wizardGenerate the files for the method you picked.
Cloudflare TunnelThe simplest way in: no open port, no certificate.
Production checklistWhat to check before going live.