Skip to the content

Documentation

Put Docustay behind your own address

Serve a self-hosted Docustay on your own domain with HTTPS, using Caddy, nginx or Traefik, and set the address that goes into emails.

The web container listens on port 8080 (change it with DOCUSTAY_PORT in .env). Everything people use goes through that one port. Put a reverse proxy in front of it to get your own domain and HTTPS.

Tell Docustay its address

Set the address people will type, with no trailing slash, in .env, then restart:

KEYSTONE_PUBLIC_URL=https://sign.example.com

This is the start of every signing link and reset link in an email. If it is wrong, the links in emails will not open.

Caddy

Caddy gets and renews the certificate for you.

sign.example.com {
  reverse_proxy localhost:8080
}

nginx

server {
  listen 443 ssl http2;
  server_name sign.example.com;
  ssl_certificate     /etc/letsencrypt/live/sign.example.com/fullchain.pem;
  ssl_certificate_key /etc/letsencrypt/live/sign.example.com/privkey.pem;
  client_max_body_size 50m;                        # uploaded documents
  location / {
    proxy_pass http://127.0.0.1:8080;
    proxy_set_header Host $host;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Forwarded-For $remote_addr;
  }
}

Traefik (labels on the web service)

services:
  web:
    labels:
      - traefik.enable=true
      - traefik.http.routers.docustay.rule=Host(`sign.example.com`)
      - traefik.http.routers.docustay.tls.certresolver=letsencrypt
      - traefik.http.services.docustay.loadbalancer.server.port=3000

Check

  • Open https://sign.example.com/login. The sign-in page should load over HTTPS with no certificate warning.
  • Send yourself a document and open the link in the email. It must start with your address.
  • If you use embedded signing, list your own website under Settings → Documents → Embedding.

Keep the proxy honest

Pass X-Forwarded-Proto and X-Forwarded-For as shown. Docustay uses the first to know a request was secure and the second for the address in the audit trail. Do not expose ports 5432 (database), 8333 (file store) or 3000 (web) directly.

CtrlI