CKEditor AI On-Premises SSL communication
CKEditor AI On-Premises serves plain HTTP on port 8000. To serve it over HTTPS, run a load balancer or reverse proxy in front of the deployment and terminate TLS there. You need a TLS certificate and its private key for the domain that serves the deployment.
This article gives one configuration for HAProxy and one for NGINX. Any other proxy works if it meets the requirements below.
- Terminate TLS – install your certificate on the proxy and forward requests to the application port over HTTP. Both examples also set the
X-Forwarded-Protoheader. - Allow a response to stay open for 10 minutes – a conversation message, a document processing request, and an MCP tool call can each take that long. Set the idle timeout and the read timeout to at least 600 seconds. With a shorter timeout, the proxy closes the connection before the response is complete. See Request flow for details.
- Do not buffer the response body – CKEditor AI On-Premises streams its responses. A proxy that holds the response until it is complete shows the user nothing until then.
This configuration terminates TLS on port 443, redirects HTTP to HTTPS, and forwards requests to the application on port 8000. HAProxy forwards the response as it arrives, so it needs no buffering option.
global
daemon
maxconn 256
tune.ssl.default-dh-param 2048
defaults
mode http
timeout connect 5000ms
timeout client 600000ms
timeout server 600000ms
frontend http-in
bind *:80
bind *:443 ssl crt /etc/ssl/your_certificate.pem
http-request set-header X-Forwarded-Proto https if { ssl_fc }
http-request set-header X-Forwarded-Proto http if !{ ssl_fc }
redirect scheme https if !{ ssl_fc }
default_backend servers
backend servers
server server1 127.0.0.1:8000 maxconn 32
Copy codeThis configuration terminates TLS on port 443 and streams responses to the client. proxy_buffering off is required. With buffering on, NGINX holds the whole response and releases it only when the deployment finishes, so the user sees nothing until then.
events {
worker_connections 1024;
}
http {
server {
server_name your.domain.name;
listen 443 ssl;
ssl_certificate /etc/ssl/your_cert.crt;
ssl_certificate_key /etc/ssl/your_cert_key.key;
location / {
proxy_pass http://127.0.0.1:8000;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "Upgrade";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_read_timeout 600s;
proxy_send_timeout 600s;
proxy_buffering off;
}
}
}
Copy code