Reverse proxy with Apache HTTP Server


For this you will need the Apache HTTP Server.

That is a fairly popular package so your distro will probably have it.


sudo apt install apache2


sudo pacman -S apache


sudo zypper install apache2

Install modules

You'll also need to install additional modules for Apache HTTP Server. You can do that with the following command:

sudo a2enmod proxy_http md ssl headers proxy_wstunnel

Configure GoToSocial

We're going to have Apache handle LetsEncrypt certificates, so you need to turn off built-in LetsEncrypt support in your GoToSocial config.

First open the file in your text editor:

sudoedit /gotosocial/config.yaml

Then set letsencrypt-enabled: false.

If GoToSocial is already running, restart it.

sudo systemctl restart gotosocial.service

Or if you don't have a systemd service just restart it manually.

Set up Apache HTTP Server with LetsEncrypt SSL

Now we'll configure Apache HTTP Server to serve GoToSocial requests.

First we'll write a configuration for Apache HTTP Server and put it in /etc/apache2/sites-available:

sudo mkdir -p /etc/apache2/sites-available/
sudoedit /etc/apache2/sites-available/

In the above sudoedit command, replace with the hostname of your GoToSocial server.

The file you're about to create should look a bit like this:

MDomain auto
MDCertificateAgreement accepted
<VirtualHost *:80 >
<VirtualHost *:443>
  SSLEngine On
  ProxyPreserveHost On
  ProxyPassMatch ^/(api/v1/streaming.*)$ ws://localhost:8080/$1
  ProxyPass / http://localhost:8080/
  ProxyPassReverse / http://localhost:8080/
  RequestHeader set "X-Forwarded-Proto" expr=https

Again, replace occurrences of in the above config file with the hostname of your GtS server. If your domain name is, then would be the correct value.

You should also change http://localhost:8080 to the correct address and port of your GtS server. For example, if you're running GoToSocial on another machine with the local ip of and on port 8080 then would be the correct value.

ProxyPreserveHost On is essential: It guarantees that the proxy and the GoToSocial speak of the same Server name. If not, GoToSocial will build the wrong authentication headers, and all attempts at federation will be rejected with 401 Unauthorized.

The line ProxyPassMatch ^/(api/v1/streaming.*)$ ws://localhost:8080/$1 ensures that Websocket streaming connections also work. See the websocket document for more information on this.

Save and close the config file.

Now we'll need to link the file we just created to the folder that Apache HTTP Server reads configurations for active sites from.

sudo mkdir /etc/apache2/sites-enabled
sudo ln -s /etc/apache2/sites-available/ /etc/apache2/sites-enabled/

In the above ln command, replace with the hostname of your GoToSocial server.

Now check for configuration errors.

sudo apachectl -t

If everything is fine you should get this as output:

Syntax OK

Everything working? Great! Then restart Apache HTTP Server to load your new config file.

sudo systemctl restart apache2

Now, monitor the logs to see when the new LetsEncrypt certificate arrives (tail -F /var/log/apache2/error.log), and then reload Apache one last time with the above systemctl restart command. After that you should be good to go!

Apache HTTP Server needs to be restart (or reloaded), every time mod_md gets a new certificate; see the module's docs for more information.

Depending on your version of Apache HTTP Server, you may see the following error: error (specific information not available): acme problem urn:ietf:params:acme:error:invalidEmail: Error creating new account :: contact email "webmaster@localhost" has invalid domain : Domain name needs at least one dot

If this happens, you'll need to do one (or all) of the below:

  1. Update /etc/apache2/sites-enabled/000-default.conf and change the ServerAdmin value to a valid email address (then reload Apache HTTP Server).
  2. Add the line MDContactEmail below the MDomain line in /etc/apache2/sites-available/, replacing with a valid email address, and with your GtS host name.