# CKEditor AI On-Premises SSL communication

CKEditor AI On-Premises serves plain HTTP on port `8000`. To serve it over HTTPS, run a load balancer or reverse proxy in front of the deployment and terminate TLS there. You need a TLS certificate and its private key for the domain that serves the deployment.

This article gives one configuration for `HAProxy` and one for `NGINX`. Any other proxy works if it meets the requirements below.

<a id="what-the-proxy-must-do">

## What the proxy must do

* **Terminate TLS** – install your certificate on the proxy and forward requests to the application port over HTTP. Both examples also set the `X-Forwarded-Proto` header.
* **Allow a response to stay open for 10 minutes** – a conversation message, a document processing request, and an MCP tool call can each take that long. Set the idle timeout and the read timeout to at least 600 seconds. With a shorter timeout, the proxy closes the connection before the response is complete. See [Request flow](architecture.md#request-flow) for details.
* **Do not buffer the response body** – CKEditor AI On-Premises streams its responses. A proxy that holds the response until it is complete shows the user nothing until then.

<a id="haproxy-example">

## `HAProxy` example

This configuration terminates TLS on port 443, redirects HTTP to HTTPS, and forwards requests to the application on port 8000. `HAProxy` forwards the response as it arrives, so it needs no buffering option.

```nginx
global
    daemon
    maxconn 256
    tune.ssl.default-dh-param 2048

defaults
    mode http
    timeout connect 5000ms
    timeout client 600000ms
    timeout server 600000ms

frontend http-in
    bind *:80
    bind *:443 ssl crt /etc/ssl/your_certificate.pem
    http-request set-header X-Forwarded-Proto https if { ssl_fc }
    http-request set-header X-Forwarded-Proto http if !{ ssl_fc }
    redirect scheme https if !{ ssl_fc }

    default_backend servers

backend servers
    server server1 127.0.0.1:8000 maxconn 32
```

<a id="nginx-example">

## `NGINX` example

This configuration terminates TLS on port 443 and streams responses to the client. `proxy_buffering off` is required. With buffering on, `NGINX` holds the whole response and releases it only when the deployment finishes, so the user sees nothing until then.

```nginx
events {
    worker_connections  1024;
}

http {
    server {
        server_name your.domain.name;

        listen 443 ssl;
        ssl_certificate /etc/ssl/your_cert.crt;
        ssl_certificate_key /etc/ssl/your_cert_key.key;

        location / {
            proxy_pass http://127.0.0.1:8000;

            proxy_set_header Upgrade $http_upgrade;
            proxy_set_header Connection "Upgrade";
            proxy_set_header Host $host;
            proxy_set_header X-Forwarded-Proto $scheme;
            proxy_http_version 1.1;

            proxy_read_timeout 600s;
            proxy_send_timeout 600s;
            proxy_buffering off;
        }
    }
}
```

---

Full index of the Cloud Services documentation: [llms.txt](../../../llms.txt)
