Reverse proxy
Publish SwissKnife over HTTPS without removing headers required by FFmpeg WASM.
SwissKnife has no authentication. A reverse proxy mainly terminates TLS. The critical requirement is not a cookie but SharedArrayBuffer, which FFmpeg WASM needs.
The product nginx.conf sends these headers:
Cross-Origin-Opener-Policy: same-originCross-Origin-Embedder-Policy: require-corpCross-Origin-Resource-Policy: same-origin
If the proxy removes or replaces them, the audio/video engine cannot load. Canvas image conversions may still work.
The examples use swissknife.example.com and 127.0.0.1:2501. Change the hostname, and change the port only if your host mapping is no longer 2501.
Restrict Docker binding
To accept traffic only from a proxy on the same host:
services:
swissknife:
ports:
- "127.0.0.1:2501:2501"Caddy on the host
swissknife.example.com {
encode zstd gzip
reverse_proxy 127.0.0.1:2501
}Caddy normally forwards upstream response headers. Verify in browser developer tools that COOP and COEP remain present on / and /ffmpeg/ffmpeg-core.wasm.
Nginx on the host
server {
listen 443 ssl http2;
server_name swissknife.example.com;
ssl_certificate /etc/letsencrypt/live/swissknife.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/swissknife.example.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:2501;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_hide_header Cross-Origin-Opener-Policy;
proxy_hide_header Cross-Origin-Embedder-Policy;
proxy_hide_header Cross-Origin-Resource-Policy;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
add_header Cross-Origin-Resource-Policy "same-origin" always;
}
}When Nginx overrides response headers, it does not always retain upstream add_header values. The block above sets them explicitly. Test the configuration before reloading.
Do not enable COEP on the docs
This documentation and the presentation site do not need require-corp. Do not copy these headers outside the conversion application.