SwissKnife Docs
Get started

Reverse proxy

Publish SwissKnife over HTTPS without removing headers required by FFmpeg WASM.

SwissKnife has no authentication. A reverse proxy mainly terminates TLS. The critical requirement is not a cookie but SharedArrayBuffer, which FFmpeg WASM needs.

The product nginx.conf sends these headers:

  • Cross-Origin-Opener-Policy: same-origin
  • Cross-Origin-Embedder-Policy: require-corp
  • Cross-Origin-Resource-Policy: same-origin

If the proxy removes or replaces them, the audio/video engine cannot load. Canvas image conversions may still work.

The examples use swissknife.example.com and 127.0.0.1:2501. Change the hostname, and change the port only if your host mapping is no longer 2501.

Restrict Docker binding

To accept traffic only from a proxy on the same host:

services:
  swissknife:
    ports:
      - "127.0.0.1:2501:2501"

Caddy on the host

Caddyfile
swissknife.example.com {
  encode zstd gzip
  reverse_proxy 127.0.0.1:2501
}

Caddy normally forwards upstream response headers. Verify in browser developer tools that COOP and COEP remain present on / and /ffmpeg/ffmpeg-core.wasm.

Nginx on the host

server {
    listen 443 ssl http2;
    server_name swissknife.example.com;

    ssl_certificate     /etc/letsencrypt/live/swissknife.example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/swissknife.example.com/privkey.pem;

    location / {
        proxy_pass http://127.0.0.1:2501;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_hide_header Cross-Origin-Opener-Policy;
        proxy_hide_header Cross-Origin-Embedder-Policy;
        proxy_hide_header Cross-Origin-Resource-Policy;
        add_header Cross-Origin-Opener-Policy "same-origin" always;
        add_header Cross-Origin-Embedder-Policy "require-corp" always;
        add_header Cross-Origin-Resource-Policy "same-origin" always;
    }
}

When Nginx overrides response headers, it does not always retain upstream add_header values. The block above sets them explicitly. Test the configuration before reloading.

Do not enable COEP on the docs

This documentation and the presentation site do not need require-corp. Do not copy these headers outside the conversion application.

On this page