Files
tac-exp-dev/tls-server.cjs

56 lines
1.6 KiB
JavaScript

/**
* tls-server.cjs — production HTTPS entrypoint for TradeAC.
*
* Serves the compiled Next.js app (tac-app/.next) over HTTPS with the
* self-signed certificate generated by the container entrypoint
* (entrypoint.sh) when SERVER_TLS=true.
*
* It reuses Next's normal production server (next({ dev: false }) +
* getRequestHandler()), so middleware, server actions, and all routes behave
* exactly like `next start` — just over TLS.
*/
"use strict";
const fs = require("node:fs");
const https = require("node:https");
const path = require("node:path");
const next = require("next");
const port = Number(process.env.PORT || 3000);
const host = process.env.HOSTNAME || "0.0.0.0";
const tlsKeyPath = process.env.TLS_KEY || "/tmp/tls/key.pem";
const tlsCertPath = process.env.TLS_CERT || "/tmp/tls/cert.pem";
const tlsHost = process.env.TLS_HOST || "localhost";
async function main() {
const app = next({
dev: false,
dir: path.join(__dirname, "tac-app"),
hostname: host,
port,
});
const handle = app.getRequestHandler();
await app.prepare();
const key = fs.readFileSync(tlsKeyPath);
const cert = fs.readFileSync(tlsCertPath);
const server = https.createServer({ key, cert }, (req, res) => handle(req, res));
server.listen(port, host, () => {
console.log(`> TradeAC HTTPS (self-signed) ready on https://${tlsHost}:${port}`);
});
const shutdown = () => {
server.close(() => process.exit(0));
setTimeout(() => process.exit(0), 2000).unref();
};
process.on("SIGTERM", shutdown);
process.on("SIGINT", shutdown);
}
main().catch((err) => {
console.error("Failed to start HTTPS server:", err);
process.exit(1);
});