/** * tls-server.cjs — production HTTPS entrypoint for TradeAC. * * Serves the compiled Next.js app (tac-app/.next) over HTTPS with the * self-signed certificate generated by the container entrypoint * (entrypoint.sh) when SERVER_TLS=true. * * It reuses Next's normal production server (next({ dev: false }) + * getRequestHandler()), so middleware, server actions, and all routes behave * exactly like `next start` — just over TLS. */ "use strict"; const fs = require("node:fs"); const https = require("node:https"); const path = require("node:path"); const next = require("next"); const port = Number(process.env.PORT || 3000); const host = process.env.HOSTNAME || "0.0.0.0"; const tlsKeyPath = process.env.TLS_KEY || "/tmp/tls/key.pem"; const tlsCertPath = process.env.TLS_CERT || "/tmp/tls/cert.pem"; const tlsHost = process.env.TLS_HOST || "localhost"; async function main() { const app = next({ dev: false, dir: path.join(__dirname, "tac-app"), hostname: host, port, }); const handle = app.getRequestHandler(); await app.prepare(); const key = fs.readFileSync(tlsKeyPath); const cert = fs.readFileSync(tlsCertPath); const server = https.createServer({ key, cert }, (req, res) => handle(req, res)); server.listen(port, host, () => { console.log(`> TradeAC HTTPS (self-signed) ready on https://${tlsHost}:${port}`); }); const shutdown = () => { server.close(() => process.exit(0)); setTimeout(() => process.exit(0), 2000).unref(); }; process.on("SIGTERM", shutdown); process.on("SIGINT", shutdown); } main().catch((err) => { console.error("Failed to start HTTPS server:", err); process.exit(1); });