Local network

Opt-in. Leave it off when people open Synaplan on the same machine (http://127.0.0.1:8000) or through a public name that already has HTTPS.

Turn it on when the network has no route to the public internet and people open the app by this machine's address. Chat needs https://<address>/. The machine creates the certificate. The browser warns once; continue past that warning.

Any IPv4 address that network uses is accepted:

You pass Block
10.0.0.15 10.0.0.0/8
172.16.5.4 172.16.0.0/12
192.168.1.20 192.168.0.0/16
100.64.0.8 100.64.0.0/10 (shared / CGNAT)
169.254.1.20 169.254.0.0/16 (link-local)
any other IPv4 you assigned and do not announce closed site numbering

A public name stays on your own HTTPS proxy. This profile stays off for that install.

Turn it on

From a checkout of synaplan, with deploy/.env already copied from deploy/selfhost.env.example and SYNAPLAN_VERSION set:

deploy/scripts/local-tls.sh 10.0.0.15
deploy/scripts/prepare.sh
docker compose --env-file deploy/.env -f deploy/compose.yaml pull
deploy/scripts/validate-release.sh
docker compose --env-file deploy/.env -f deploy/compose.yaml up -d

Replace 10.0.0.15 with the address of this machine. A second interface is another argument:

deploy/scripts/local-tls.sh 10.0.0.15 192.168.1.20

The first address is the URL. The command:

  • writes deploy/data/tls/cert.pem and key.pem (mode 0600)
  • adds local-tls to COMPOSE_PROFILES
  • sets APP_URL, FRONTEND_URL and REALTIME_ALLOWED_ORIGINS to https://10.0.0.15

Colleagues open https://10.0.0.15/. Ports 80 and 443 must be free. SYNAPLAN_HTTP_BIND stays 127.0.0.1, so the network reaches the app through HTTPS. Live chat stays disconnected when those three URLs differ from the address in the browser.

https://10.0.0.15 is accepted and means the same address.

Certificate

Back up deploy/data/tls with the rest of deploy/data. Creating the certificate again makes every browser warn again. To skip the warning, install cert.pem as a trusted certificate on each computer.

Turn it off

Remove local-tls from COMPOSE_PROFILES. Point APP_URL, FRONTEND_URL and REALTIME_ALLOWED_ORIGINS at the HTTPS URL people actually open, then start the stack again.