How to Configure TLS/SSL with Nginx Reverse Proxy for Production Deployment in MobileAudit
To configure TLS/SSL for MobileAudit production deployment, generate SSL certificates in the nginx/ssl/ directory, mount them via docker-compose.prod.yaml, and use the pre-configured nginx/app_tls.conf to terminate TLS at the Nginx reverse proxy while forwarding plain HTTP traffic to the Django web service on internal port 8000.
MobileAudit is a Django-based security testing framework that requires HTTPS encryption for production environments. According to the mpast/mobileaudit repository source code, the project provides a production-ready Nginx configuration that handles TLS termination and reverse proxies requests to the backend application. This guide explains the exact file paths, Docker Compose mappings, and security configurations required to enable TLS/SSL for secure production deployment.
Step 1: Generate TLS Certificates
MobileAudit expects SSL certificates in the nginx/ssl/ directory at the project root. Create this directory if it does not exist, then generate a self-signed certificate for testing or place CA-signed certificates here for production use.
Execute the following OpenSSL command to create a 4096-bit RSA self-signed certificate valid for 365 days:
openssl req -x509 -nodes -days 365 \
-newkey rsa:4096 \
-subj "/C=ES/ST=Madrid/L=Madrid/O=Example/OU=IT/CN=localhost" \
-keyout nginx/ssl/nginx.key \
-out nginx/ssl/nginx.crt
For production environments using trusted certificates, replace nginx.crt and nginx.key with your CA-signed or Let's Encrypt certificate files, ensuring the filenames match the paths referenced in nginx/app_tls.conf.
Step 2: Configure Nginx TLS Termination
The repository provides nginx/app_tls.conf, which contains the complete Nginx reverse proxy configuration with TLS support. This file defines an upstream server pointing to the Django application and enforces modern TLS protocols and security headers.
Key directives implemented in nginx/app_tls.conf include:
- Upstream definition: The
upstream appblock resolves toweb:8000, targeting the Django service within the Docker internal network. - TLS protocols:
ssl_protocols TLSv1.2 TLSv1.3ensures only secure protocol versions are accepted, excluding older vulnerable versions. - Certificate configuration:
ssl_certificateandssl_certificate_keypoint to/etc/nginx/ssl/nginx.crtand/etc/nginx/ssl/nginx.keyrespectively. - Security headers: Includes
Strict-Transport-Security "max-age=63072000; includeSubdomains"to enforce HSTS. - Proxy settings: The
location /block forwards all traffic tohttp://app/with 500-second timeouts for connect, read, and send operations. - Static file serving: Directories
/static/and/media/are served directly viaaliasdirectives pointing to/app/app/static/and/app/app/media/, offloading the Django application.
Step 3: Wire the Configuration into Docker Compose
The docker-compose.prod.yaml file orchestrates the production stack, mounting the TLS configuration and certificates into the Nginx container while keeping the Django application internal.
In docker-compose.prod.yaml, the service definitions configure the following:
services:
web:
build: .
env_file: ./.env.example
expose:
- "8000"
nginx:
image: nginx:stable-bullseye
ports:
- "443:443"
volumes:
- ./nginx/app_tls.conf:/etc/nginx/conf.d/app_tls.conf
- ./nginx/ssl:/etc/nginx/ssl
- ./nginx/logs:/var/log/nginx
depends_on:
- web
This configuration exposes only port 443 to the host, while the web service remains internal on port 8000. The volume mounts ensure Nginx accesses the TLS configuration at /etc/nginx/conf.d/app_tls.conf and certificates at /etc/nginx/ssl/.
Step 4: Start the Production Stack
With certificates in place and configurations verified, launch the production environment using the production-specific Docker Compose file:
docker-compose -f docker-compose.prod.yaml up -d
This command starts the Django application, PostgreSQL database, RabbitMQ message queue, Celery workers, and Nginx reverse proxy with TLS termination enabled. The depends_on directive ensures the web service initializes before Nginx attempts to proxy connections.
Architecture Overview
MobileAudit's production architecture terminates TLS at the Nginx layer, keeping internal traffic unencrypted between the reverse proxy and Django application. The traffic flow follows this pattern:
- Client requests arrive at
https://<host>:443with TLS encryption - Nginx validates certificates, applies security headers, and decrypts the traffic
- Proxy pass forwards plain HTTP to
http://app/(resolving toweb:8000) - Django processes the request and returns the response through the reverse proxy
- Static and media files are served directly by Nginx without hitting the Django application
Summary
Configuring TLS/SSL for MobileAudit production deployment requires coordinating three key components from the mpast/mobileaudit repository:
- Place certificates in
nginx/ssl/asnginx.crtandnginx.key(or update paths innginx/app_tls.conf) - Use
nginx/app_tls.confto enforce TLSv1.2/TLSv1.3 protocols, strong cipher suites, and HSTS headers at the reverse proxy - Deploy via
docker-compose.prod.yamlto mount configurations and expose only port 443 publicly, keeping the Django application on internal port 8000
This setup ensures encrypted client connections while allowing the Django web service to operate over plain HTTP internally, following the security model implemented in the source code.
Frequently Asked Questions
Where should SSL certificate files be stored in the MobileAudit project?
Store the nginx.crt and nginx.key files in the nginx/ssl/ directory at the project root. The docker-compose.prod.yaml volume mapping ./nginx/ssl:/etc/nginx/ssl mounts this directory to /etc/nginx/ssl/ inside the Nginx container, allowing the nginx/app_tls.conf configuration to reference them at /etc/nginx/ssl/nginx.crt and /etc/nginx/ssl/nginx.key.
Can I use Let's Encrypt or other CA-signed certificates instead of self-signed ones?
Yes, simply replace the self-signed files in nginx/ssl/ with your CA-signed certificate and private key, maintaining the filenames nginx.crt and nginx.key. If you use different filenames, update the ssl_certificate and ssl_certificate_key directives in nginx/app_tls.conf to match your certificate file paths.
Which ports need to be exposed for secure production deployment?
Only port 443 needs to be exposed publicly for HTTPS traffic, as configured in docker-compose.prod.yaml under the nginx service ports mapping "443:443". The Django web service uses port 8000 internally but should not be exposed directly to the host; Nginx handles all external traffic and proxies it to the application container.
How do I verify that the TLS configuration is working correctly?
After running docker-compose -f docker-compose.prod.yaml up -d, test the deployment by accessing https://localhost/ (or your domain) in a browser, or use curl -k https://localhost/ to bypass certificate warnings for self-signed certs. Verify that the dashboard loads over HTTPS and that the certificate details match the files placed in nginx/ssl/.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →