Conversation
@pernia dawg how is i supposed to make the mitra frontend work with nexus.asbestos.cafe when relayd is handling the reverse proxy and the mitra web is a static website god fucking DAMMIT
2
0
0
@pernia CC @silverpill is there maybe a list of endpoints that mitra's backend handles so i can only route those to the app and the rest to the static website/httpd
1
0
0

@meso @pernia Yes, take a look at this nginx config: https://codeberg.org/silverpill/mitra/src/branch/main/contrib/nginx/mitra-alt-fe.conf#L46

It's better to serve mitra-web with mitra though, because it adds some useful redirects.

1
0
1

@meso mitra serves the frontend 4 u.

thats what the web_client_dir in config is for. you build mitra-web, it puts files into a dist/ and you move the files to your web_client_dir

3
0
1

@silverpill @meso about that.

i talked to the clanker and found out i had to add (/|$) at the end of location ~ ^/(activities|actor|ap|api|collections|feeds|media|metrics|nodeinfo|oauth|objects|users|\.well-known) for that config to make chanfe work on a subdomain (served by nginx).

chanfe wouldn't pass requests to mitra because the regex was wrong (i think thats what the clanker said anyway), and so it wouldn't display timelines/posts etc.

2
0
1

@meso i think pleroma does this as well thats y it juz works cuz it comes with the fe

1
1
0
@pernia how 2 federate dawg this shit aint workin
1
0
0
@pernia unc how the fuck do i federate ts It aint federatin lil bro 😭
1
1
1

@meso @silverpill i rember i set up plerome and bloat on chudbsd with relayd once. considering the nginx configs r basically the same too i bet the relayd is gonna look similar

0
0
1

@meso @pernia It might be caused by a misconfiguration in relayd or httpd, when I try to access your profile or posts directly, I just get a 404 error code.

2
0
0
@meso@new.asbestos.cafe @pernia@cum.salon even if it didn't you can use relayd as a reverse proxy for httpd with tables
0
0
1
@caohuak @pernia hlep

relayd.conf:

ext_inet="23.131.76.109"

table <mitra_server> { 127.0.0.1 }
table <httpd_static> { 127.0.0.1 }

http protocol mitra {
tls ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"
# tls ecdhe "X25519,P-256,P-384,secp521r1" # relayd default+secp521r1
tls ecdhe X25519

return error

tls keypair "nexus.asbestos.cafe"

match request header append "X-Forwarded-For" value "$REMOTE_ADDR"
match request header append "Connection" value "upgrade"
# pass request quick header "Host" value "nexus.asbestos.cafe" forward to <mitra_server>

pass request quick header "Host" value "nexus.asbestos.cafe" path "/activities*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/actor*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/ap*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/api*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/collections*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/feeds*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/media*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/metrics*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/nodeinfo*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/oauth*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/objects*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/users*" forward to <mitra_server>
pass request quick header "Host" value "nexus.asbestos.cafe" path "/.well-known*" forward to <mitra_server>

pass request quick header "Host" value "nexus.asbestos.cafe" forward to <httpd_static>
}

relay wwwtls {
listen on $ext_inet port https tls # Comment to disable listening on IPv4
protocol mitra

# forward to <mitra_server> port 8383 check tcp timeout 500 # Adjust timeout accordingly when relayd returns 502 while Mitra is running without problems.
# When serving multiple services, add the forwards here.
# Example:
# forward to <httpd_static> port 8080 check tcp timeout 500

forward to <mitra_server> port 8383 check tcp timeout 500
forward to <httpd_static> port 8080 check tcp timeout 500
}

httpd.conf:
server "nexus.asbestos.cafe" {
listen on 127.0.0.1 port 8080
root "/nexus.asbestos.cafe/latest"
}
3
0
0
@caohuak @pernia this is interesting if you go on the web interface and click on my profile it leads to it but not if you just type https://nexus.asbestos.cafe/@meso
0
0
0

@meso @pernia >pass request quick header "Host" value "nexus.asbestos.cafe" forward to <httpd_static>

This line seems to redirect all other paths directly to httpd since # pass request quick header "Host" value "nexus.asbestos.cafe" forward to <mitra_server> is commented.

1
0
1
@caohuak @pernia isn't that the goal. For the back end endpoints to be redirected to the thing running on port 8383 and everything else to 8080 where the static website is hosted
2
0
0
@caohuak @pernia I'll try to host it like pernia said, with mitra serving the frontend
1
0
0

@meso @caohuak yea bro i'm gettin a fucking HEADACHE lookin @ ur config.

i might need to set some shit up for it but i could test it myself tomorrow as well

1
0
1

@meso
Yeah but there seems to be something a bit off with this config file. I'm not exactly sure what it is, though, since it's been a while since I've used httpd and relayd. I'll give it a shot when I have some time.
@pernia

0
0
1
@pernia @caohuak nigga I had to ask the clanker 30 times for a config and it gave me a wrong one every time and then it made up a reason why it's wrong and why the new one is fixed but it wasn't and then it stopped giving me configs it just answered heres the config but there was none it got tired of giving me results for this and then sent me in the end I looked at pleroma's relayd config and adapted it to mitra, but then I realized I needed the god damn web client so I asked the clanker another 30 times how to make it forward all backend requests to mitra and all the rest to the frontend static site and it struggled with my nginx example with the regex so in the end ig it said fuck it and spammed all the endpoints on separate rules
2
0
0

@meso @caohuak 🥀

thats just rape... thats rape of meso...

1
1
3
@pernia @caohuak @meso theyre raping meso in front of chunc niggawilt
0
3
2

@meso @caohuak @pernia I believe this the main problem all rest looks ok > match request header append "Connection" value "upgrade" it fires on every request that matches, so a plain GET /activities arrives at Mitra with Connection: upgrade attached. Which is wrong for a non upgrade request.
The match ... append line is a hack that pollutes every request with a wrong header and doesn't actually enable the internal mode switch relayd needs. One line I suggest to replace is

http protocol mitra {
    ...
    http websockets
    ...
}

The client already sends those headers. A WebSocket handshake starts as a normal HTTP GET with:

GET /activities HTTP/1.1
Host: nexus.asbestos.cafe
Connection: Upgrade
Upgrade: websocket
Sec-WebSocket-Key: ...

relayd doesn't need to add Connection: upgrade as the browser/client puts it there itself. The match ... append line was fighting a problem that didn't exist.
1
0
1
@zer0unplanned @pernia @caohuak yeah sorry the logic for that was total ai slop I was really tired last night and was trying to get it to work before 7666 nukes this instance out of existence
1
0
0

@meso @pernia I don't think the issue is with relayd, but rather with the httpd configuration. After checking carefully, I found that it doesn't return index.html when other paths aren't found.

1
0
1
@meso @caohuak @pernia 7666? isn't that a users handle here?
2
0
1
@pernia @caohuak @meso There's a troll mf impersonating you as I saw today.
0
0
1

@pernia @meso I haven't used this nginx config for a long time but the regex looks correct. Maybe there is clash between mitra and chanfe paths? @harblinger

1
0
1
@zer0unplanned @pernia @caohuak @meso to be clear i gave him a bunch of free kvm boxes on my actual company as i decommission the old lain.la vmware stack. which yes is happening today.
1
1
1
@meso @pernia @caohuak Steal the Pleroma relayd and httpd configs I made and let Mitra serve the frontend. Both configs are kinda annoying to get working right. What you basically want is httpd redirect to https and relayd forward all https traffic to Mitra's local http port. There is an example configuration on how to host a static website along Pleroma, which could be modified to host the frontend.
0
0
1

looks like default mitra-web being served https://nexus.asbestos.cafe/
but relayd can't connect/select Mitra on 8383:
>/api/v2/instance returns an OpenBSD relayd 502 whose body says “session failed”. In current relayd source that message comes from backend connection setup failing, so I’d check whether http://127.0.0.1:8383/api/v2/instance works locally and whether relayctl show summary reports the Mitra backend as up.

@meso

curl -sv --max-time 10 -H 'Host: nexus.asbestos.cafe' \
http://127.0.0.1:8383/api/v2/instance
doas relayctl show summary

is Mitra actually up?

1
0
1
@harblinger @silverpill no service set up yet. you want me to turn it on and you try to see somethin
1
0
0

yeah might as well, noticed something with the TLS setup too, but that can wait

1
0
0
@harblinger it's up

2026-09-23T18:31:26 mitra_workers::periodic_tasks [INFO] find_extraneous_posts query executed: 10.25ms
2026-09-23T18:31:26 mitra_activitypub::deliverer [WARN] failed to deliver activity to https://netzsphaere.xyz/users/whirly/inbox: HTTP error 400: [400] "Invalid HTTP Signature"
2026-09-23T18:31:26 mitra_activitypub::queues [INFO] delivery job (attempt #4): 789.96ms, 0 delivered, 1 errors, 0 skipped
2026-09-23T18:31:26 mitra_activitypub::queues [INFO] reachability statuses update
2
0
1

cool, yeah it might be the cert issue, I could navigate with the browser but got this when using curl:

$ curl https://nexus.asbestos.cafe/api/v2/instance
curl: (60) SSL certificate OpenSSL verify result: unable to get local issuer certificate (20)
More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the webpage mentioned above.

>the server sends only the leaf certificate, without the Let’s Encrypt intermediate. Check that relayd’s certificate file contains the full chain.

and since I don't know how to do that here's astra's response to how do I do that:

  grep -c 'BEGIN CERTIFICATE' /etc/ssl/nexus.asbestos.cafe.crt

  1 means it contains only one certificate. For his Let’s Encrypt setup, the file should contain the site certificate followed by the intermediate certificate—normally 2 certificates.

  One wrinkle: relayd prefers /etc/ssl/nexus.asbestos.cafe:443.crt if that exists, so check that file too. relayd documentation

  If he uses OpenBSD’s acme-client, check the domain block in /etc/acme-client.conf. The relevant setting should be:

  domain full chain certificate "/etc/ssl/nexus.asbestos.cafe.crt"

  The distinction is full chain certificate, which writes the site certificate plus intermediates, versus certificate, which writes only the site certificate. The output path must match whichever file relayd
  actually loads. acme-client documentation
0
0
0
@meso @harblinger
>Error code: SEC_ERROR_UNKNOWN_ISSUER

Did you deploy a staging LE cert or something?
1
0
1
@meso @harblinger And the example config has both the staging endpoint and the normal endpoint. So it's possible you deleted the wrong one.
1
0
0

I am but a channel
Astra speaks through me
>Can you paste the domain "nexus.asbestos.cafe" { ... } block from /etc/acme-client.conf? Looking for whether it says domain certificate or domain full chain certificate, and which path it writes to. relayd is currently serving only the site certificate, without the intermediate.

1
0
1

@harblinger

relayd.conf

ext_inet="23.131.76.109"

table <mitra_server> { 127.0.0.1 }
table <httpd_static> { 127.0.0.1 }

http protocol mitra {
    tls ciphers "ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4"
#    tls ecdhe "X25519,P-256,P-384,secp521r1" # relayd default+secp521r1
    tls ecdhe X25519

    return error

    tls keypair "nexus.asbestos.cafe"

    match request header append "X-Forwarded-For" value "$REMOTE_ADDR"
    match request header append "Connection" value "upgrade"
#    pass request quick header "Host" value "nexus.asbestos.cafe" forward to <mitra_server>

    pass request quick header "Host" value "nexus.asbestos.cafe" path "/activities*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/actor*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/ap*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/api*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/collections*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/feeds*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/media*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/metrics*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/nodeinfo*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/oauth*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/objects*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/users*" forward to <mitra_server>
    pass request quick header "Host" value "nexus.asbestos.cafe" path "/.well-known*" forward to <mitra_server>

    pass request quick header "Host" value "nexus.asbestos.cafe" forward to <httpd_static>
}

relay wwwtls {
    listen on $ext_inet port https tls # Comment to disable listening on IPv4
    protocol mitra

#    forward to <mitra_server> port 8383 check tcp timeout 500 # Adjust timeout accordingly when relayd returns 502 while Mitra is running without problems.
    # When serving multiple services, add the forwards here.
    # Example:
#    forward to <httpd_static> port 8080 check tcp timeout 500

    forward to <mitra_server> port 8383 check tcp timeout 500 
    forward to <httpd_static> port 8080 check tcp timeout 500
}

httpd.conf


server "nexus.asbestos.cafe" {
	listen on 127.0.0.1 port 8080
	root "/nexus.asbestos.cafe/latest"
}

server "*" {
        listen on * port 80

        location "/.well-known/acme-challenge/*" {
                root "/acme"
                request strip 2
        }

        location * {
                block return 302 "https://$HTTP_HOST$REQUEST_URI"
        }
}
0
0
0
@meso @harblinger Nevermind, you serve the wrong certificate :D You are serving the certificate without the rest of the PKI chain, ie. not the full chain certificate.

RTFM: https://docs.pleroma.social/backend/installation/openbsd_en/#configuring-acme-client
1
0
0
@phnt @harblinger domain nexus.asbestos.cafe {
alternative names { nexus.asbestos.cafe }
domain key "/etc/ssl/private/nexus.asbestos.cafe.key"
domain certificate "/etc/ssl/nexus.asbestos.cafe.crt"
domain full chain certificate "/etc/ssl/nexus.asbestos.cafe.fullchain.pem"
sign with letsencrypt
challengedir "/srv/www/acme"
}

wdym king...
3
0
0
@meso @harblinger Yeah, that's the issue. relayd is dumb and it only wants to pickup .crt certificates with the name you put in the "tls keypair" directive. Rename the .crt file to something else and the .pem file to nexus.asbestos.cafe.crt.
0
0
0
@phnt @harblinger aw FUCK is pem the one im not supposed to do. im used to nginx i think it fucks with pems
1
0
0
  Tell him to replace this in relayd.conf:

  tls keypair "nexus.asbestos.cafe"

  with:

  tls keypair "nexus.asbestos.cafe" cert "/etc/ssl/nexus.asbestos.cafe.fullchain.pem"

  That explicitly selects the full chain while retaining the existing private-key lookup. Documentation

  Then validate:

  doas relayd -n

  If successful, reload:

  doas rcctl reload relayd
1
0
0
@harblinger dawg i may be retarded but i think the clanker is making this shit up cuz relayd -n returns errors
0
0
0
@meso @harblinger You are getting the OpenBSD™ experience. I've told you it wasn't a good idea to use it, I've spent like a month making the Pleroma guide usable and figuring out the config.
2
0
2
@phnt @harblinger dawg its good until you start using like, relayd or some shit. then its gay as fuck. whoever made relayd should be stoned
1
0
0
@meso @harblinger tls keypair "example.com" cert "/etc/ssl/example.com.pem" is only supported in OpenBSD-current, not in a release yet puniko_laugh
2
0
0
@meso @harblinger It's not a bad system but not amazing either (especially if you don't RTFM). It has some very neat features and some things that are almost useless. But at least it upgrades between releases easily and without issues.
0
0
0

@i @phnt @meso @harblinger i mean theres also nginx in packages

1
0
1
@pernia @i @phnt @meso @harblinger yeah if i wanted to use not httpd id use nginx cuz i know how to use it
1
0
1