Reverse Proxy Configuration
When hosting Trailarr behind a reverse proxy (like Nginx, Apache, Caddy, Traefik, etc.), certain configurations are necessary to ensure that the application functions correctly. This includes proper routing of requests and handling of headers.
There are two common scenarios for reverse proxy setups:
https://trailarr.mydomain.com/(Sub-domain)https://mydomain.com/trailarr/(Sub-directory)
Sub-domain Reverse Proxy Configuration
When hosting the application behind a reverse proxy in a sub-domain (e.g., https://trailarr.mydomain.com/), the following configurations can be used as examples.
These are example configurations for common reverse proxies, adjust them as needed for your specific setup.
No special configuration is needed in Trailarr for sub-domain setups, but ensure that your reverse proxy forwards the necessary headers.
Sub-directory Reverse Proxy Configuration
When hosting the application behind a reverse proxy in a sub-directory (e.g., https://mydomain.com/trailarr/), additional configuration is required to ensure proper routing and resource loading.
URL Base Setting
-
Make sure to set the
URL Basein the General Settings of the application to match the sub-directory path used in the reverse proxy. For example, if your application is accessible athttps://mydomain.com/trailarr/, set theURL Baseto/trailarr. -
You can set the
URL_BASEenvironment variable instead. Trailarr reads it at startup, and shows the value in the General Settings.
The new value applies immediately
v0.11.4
A change to URL Base applies to the next request. Reload the page in your browser to load the app with the new base path. Before v0.11.4, the setting applied only after an application restart, and the API returned a 405 Method Not Allowed error until then.
How to remove the URL Base
The application does not accept an empty value for a setting, so you cannot remove the URL Base in the WebUI. Use one of these two methods:
- v0.11.4 Set
URL_BASE=(empty) in yourdocker-compose.yml. Then restart the container. From v0.11.4, a variable set for the container has priority over the stored value. - Open the
.envfile in yourconfig/folder, remove the value set forURL_BASE, and restart the application.
Example Configurations
Warning
Remember to replace these with actual values:
http://192.168.1.231:7889-> Trailarr internal IP and porttrailarr.mydomain.com-> Your Sub-Domain/trailarr/-> Your Sub-Directory path -> set the same forURL Basesetting in Trailarr
Recommended headers
The following headers preserve information about the original request that would otherwise be lost when the proxy forwards it:
| Header | Purpose |
|---|---|
X-Forwarded-For |
Original client IP address — added automatically by most proxies |
X-Forwarded-Proto |
Original protocol (http or https) |
X-Forwarded-Host |
Original host name (mysuperapp.com) |
X-Forwarded-Prefix |
Sub-directory prefix (/trailarr) — see the note below |
Trailarr uses X-Forwarded-Prefix to select the correct frontend when the proxy removes the sub-directory prefix before it sends the request (the Apache and Traefik examples below). A proxy that keeps the prefix (the Nginx and Caddy examples below) does not need the header, but the header does no harm. If you are not sure, set the header in both cases.
Nginx
server {
server_name trailarr.mydomain.com;
location / {
proxy_pass http://192.168.1.231:7889;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
}
}
server {
server_name mydomain.com;
location /trailarr/ {
proxy_pass http://192.168.1.231:7889;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Prefix /trailarr;
}
}
Apache
<VirtualHost *:80>
ServerName mydomain.com
ProxyPreserveHost On
ProxyPass "/trailarr/" "http://192.168.1.231:7889/"
ProxyPassReverse "/trailarr/" "http://192.168.1.231:7889/"
RequestHeader set X-Forwarded-Proto "%{REQUEST_SCHEME}s"
RequestHeader set X-Forwarded-Host "%{HTTP_HOST}s"
RequestHeader set X-Forwarded-Prefix "/trailarr"
</VirtualHost>
Caddy
Traefik
http:
routers:
trailarr:
rule: "PathPrefix(`/trailarr`)"
service: trailarr-service
middlewares:
- strip-trailarr
- trailarr-headers
services:
trailarr-service:
loadBalancer:
servers:
- url: "http://192.168.1.231:7889"
middlewares:
strip-trailarr:
stripPrefix:
prefixes:
- "/trailarr"
trailarr-headers:
headers:
customRequestHeaders:
X-Forwarded-Prefix: "/trailarr"
Additional Notes
- Forward the
X-Forwarded-Prefixheader from reverse proxy to Trailarr. Recommended — ensures the correct frontend is served when accessed through the proxy. - Restart the reverse proxy to apply its new configuration. Trailarr applies a new
URL Baseimmediately, but a restart of Trailarr does no harm. - With
URL Baseset, Trailarr is accessible at both the local URL (http://your-ip:7889/) and the sub-directory URL (https://mydomain.com/trailarr/). -
You may need to clear your browser cache or perform a hard refresh to load the resources correctly.
Tip
Ctrl + Shift + Ito open Developer Tools -> right-click theRefreshbutton -> selectEmpty Cache and Hard Reload -
If you encounter any issues, and want to revert back to root-only access, find the
.envfile inconfig/folder and remove the value set forURL_BASE, then restart the application.
Success
If you are using a different reverse proxy, and successfully configured it to work with Trailarr in a sub-directory, please consider sharing your configuration by opening a new issue or a pull request on our GitHub repository and we will update the documentation accordingly.
How It Works
When URL Base is set, Trailarr does the following:
- Keeps the root
index.htmlwith<base href="/">so the app remains accessible at the local IP and port (http://your-ip:7889/). - Creates a
/{url_base}/subfolder inside the frontend build directory containing a separateindex.htmlpatched with<base href="/{url_base}/">. This makes the app also accessible athttp://your-ip:7889/{url_base}/and via the reverse proxy sub-directory URL. - Removes the
/{url_base}prefix from API, WebSocket, health and image requests that arrive with the prefix. This applies to direct local access athttp://your-ip:7889/{url_base}/api/..., and to a reverse proxy that keeps the prefix. The proxy does not have to remove the prefix. - Reads the
X-Forwarded-Prefixheader (sent by the reverse proxy) to decide whichindex.htmlto serve when the proxy strips the prefix before forwarding — ensuring Angular loads with the correct base path. - Keeps the login session cookie at the root path (
/), so the same session works at the local URL and at the sub-directory URL.
Both access methods work at the same time — no trade-off between local and proxied access. Trailarr reads the URL Base for each request, so a change to the setting applies without a restart.
Login Problems in a Sub-directory Setup
Versions before v0.11.4 had three problems with a sub-directory setup (#663). If you see one of them, update to v0.11.4 or later.
- The login page returns a
405 Method Not Allowederror. The API prefix was removed only for aURL Basethat was set when the app started. - The login is successful, but every page shows a
401 Unauthorizederror. The session cookie was limited to theURL Basepath, so the browser did not send it for other paths. - The app goes to the root URL after login, and the sub-directory prefix is lost. The redirect used an absolute path and did not include the base path.
If you cannot sign in and cannot open the Settings page, open the .env file in your config/ folder. Remove the value set for URL_BASE. Then restart the application. Trailarr is available at the root URL again.
Bypassing Authentication via Reverse Proxy
If your reverse proxy already handles authentication (e.g. SSO, OAuth, basic auth at the proxy level) and you want Trailarr to skip its own login screen, configure the proxy to inject the X-API-KEY header with your Trailarr API key on every forwarded request. Trailarr will accept the key, issue a session automatically, and the login page will not be shown.
Finding your API key
Your API key is shown in Settings → About → API Key. Click the key to copy it.
Security note
Anyone who can send an X-API-KEY header directly to Trailarr will bypass authentication. Make sure Trailarr's port is not accessible from outside your network — only the reverse proxy should be able to reach it.
Set the header on all forwarded requests
The WebSocket connection gives you live task and download updates. The browser cannot add a header to that connection. Trailarr solves this with a session: the first request with the key gets a session cookie. The WebSocket then uses that cookie. Set the header for the full location block, and not only for the page URL.
Add the following to your existing reverse proxy configuration (in addition to any other headers already set):