Sign up (with export icon)

CKEditor AI On-Premises SSL communication

Show the table of contents

CKEditor AI On-Premises serves plain HTTP on port 8000. To serve it over HTTPS, run a load balancer or reverse proxy in front of the deployment and terminate TLS there. You need a TLS certificate and its private key for the domain that serves the deployment.

This article gives one configuration for HAProxy and one for NGINX. Any other proxy works if it meets the requirements below.

What the proxy must do

Copy link
  • Terminate TLS – install your certificate on the proxy and forward requests to the application port over HTTP. Both examples also set the X-Forwarded-Proto header.
  • Allow a response to stay open for 10 minutes – a conversation message, a document processing request, and an MCP tool call can each take that long. Set the idle timeout and the read timeout to at least 600 seconds. With a shorter timeout, the proxy closes the connection before the response is complete. See Request flow for details.
  • Do not buffer the response body – CKEditor AI On-Premises streams its responses. A proxy that holds the response until it is complete shows the user nothing until then.

HAProxy example

Copy link

This configuration terminates TLS on port 443, redirects HTTP to HTTPS, and forwards requests to the application on port 8000. HAProxy forwards the response as it arrives, so it needs no buffering option.

global
    daemon
    maxconn 256
    tune.ssl.default-dh-param 2048

defaults
    mode http
    timeout connect 5000ms
    timeout client 600000ms
    timeout server 600000ms

frontend http-in
    bind *:80
    bind *:443 ssl crt /etc/ssl/your_certificate.pem
    http-request set-header X-Forwarded-Proto https if { ssl_fc }
    http-request set-header X-Forwarded-Proto http if !{ ssl_fc }
    redirect scheme https if !{ ssl_fc }

    default_backend servers

backend servers
    server server1 127.0.0.1:8000 maxconn 32
Copy code

NGINX example

Copy link

This configuration terminates TLS on port 443 and streams responses to the client. proxy_buffering off is required. With buffering on, NGINX holds the whole response and releases it only when the deployment finishes, so the user sees nothing until then.

events {
    worker_connections  1024;
}

http {
    server {
        server_name your.domain.name;

        listen 443 ssl;
        ssl_certificate /etc/ssl/your_cert.crt;
        ssl_certificate_key /etc/ssl/your_cert_key.key;

        location / {
            proxy_pass http://127.0.0.1:8000;

            proxy_set_header Upgrade $http_upgrade;
            proxy_set_header Connection "Upgrade";
            proxy_set_header Host $host;
            proxy_set_header X-Forwarded-Proto $scheme;
            proxy_http_version 1.1;

            proxy_read_timeout 600s;
            proxy_send_timeout 600s;
            proxy_buffering off;
        }
    }
}
Copy code