After the one-click install, SoxAI listens on plain HTTP on your server's IP address. This page shows two independent paths to add a real domain with HTTPS:
Gateway must be grey-cloud; console/API are fine behind CDN
No limit — nginx timeout configurable
Both options require nginx on your server to route traffic to the Docker containers. The difference is where TLS terminates and whether Cloudflare sits in front.
Use this option if you want Cloudflare DDoS protection and CDN for the console and API. The gateway sub-domain bypasses Cloudflare (grey-cloud) to avoid the CDN proxy timeout on streaming AI responses.
The gateway sub-domain bypasses Cloudflare (grey-cloud), so clients connect directly to your server and expect a publicly trusted certificate. Issue one with acme.sh:
# Install acme.shcurl https://get.acme.sh | sh -s[email protected]source ~/.bashrc # or open a new terminal if you use zsh# Bootstrap nginx so the HTTP-01 challenge can completemkdir -p /var/www/acmecat > /etc/nginx/conf.d/acme.conf <<'EOF'server { listen 80; server_name gateway.yourdomain.com; location /.well-known/acme-challenge/ { root /var/www/acme; } location / { return 444; }}EOFnginx -s reload# Issue the certificate~/.acme.sh/acme.sh --issue \ -d gateway.yourdomain.com \ --webroot /var/www/acme# Install it so nginx auto-reloads on renewalmkdir -p /etc/nginx/ssl~/.acme.sh/acme.sh --install-cert -d gateway.yourdomain.com \ --fullchain-file /etc/nginx/ssl/gateway-fullchain.crt \ --key-file /etc/nginx/ssl/gateway.key \ --reloadcmd "nginx -s reload"# Verify renewal cron is installedcrontab -l | grep acme# Expected: 0 0 * * * "/root/.acme.sh"/acme.sh --cron ...# Test the renewal pipeline end-to-end (dry-run, no real renewal)~/.acme.sh/acme.sh --renew -d gateway.yourdomain.com --force --dry-run
Alternative — DNS-01 challenge: If port 80 is not reachable, use the Cloudflare DNS API instead:
For the orange-cloud sub-domains (console and api), use a Cloudflare Origin Certificate. This is a free certificate issued by Cloudflare's CA and trusted by Cloudflare's CDN edge — no Let's Encrypt needed for these two domains.
In Cloudflare dashboard go to SSL/TLS → Origin Server → Create Certificate
Leave the defaults (RSA 2048, 15-year validity, covers *.yourdomain.com and yourdomain.com)
Copy the certificate and key into files on your server:
In Cloudflare DNS → Records, create three A records pointing to your server's public IP:
Name
Type
Content
Proxy status
console
A
YOUR_SERVER_IP
Proxied (orange cloud)
api
A
YOUR_SERVER_IP
Proxied (orange cloud)
gateway
A
YOUR_SERVER_IP
DNS only (grey cloud)
Why grey-cloud the gateway? Cloudflare's CDN proxy has a 100-second proxy timeout on free, Pro, and Business plans. AI streaming responses (SSE) routinely exceed this — the request gets cut off mid-stream. Grey-cloud sends traffic directly to your server where nginx has a 600s timeout.
Cloudflare plan
Proxy timeout
Free / Pro / Business
100 seconds
Enterprise
6000 seconds
Even with the gateway on grey-cloud, console and API still get CDN acceleration and DDoS protection.
Go to SSL/TLS → Overview and select Full (strict). This makes Cloudflare verify the Origin Certificate on your server before completing the connection.
Use this option if you are not using a CDN proxy — your DNS records point directly to your server (any DNS provider, records without CDN proxy). TLS terminates on your server with Let's Encrypt certificates.
mkdir -p /etc/nginx/ssl# If you used HTTP-01 (three separate -d flags):~/.acme.sh/acme.sh --install-cert \ -d console.yourdomain.com \ --fullchain-file /etc/nginx/ssl/soxai-fullchain.crt \ --key-file /etc/nginx/ssl/soxai.key \ --reloadcmd "nginx -s reload"# If you used DNS-01 with a wildcard cert (*.yourdomain.com), the -d must# match the primary domain used at --issue time:# ~/.acme.sh/acme.sh --install-cert \# -d "*.yourdomain.com" \# --fullchain-file /etc/nginx/ssl/soxai-fullchain.crt \# --key-file /etc/nginx/ssl/soxai.key \# --reloadcmd "nginx -s reload"
The --reloadcmd flag tells acme.sh to reload nginx automatically after every renewal, so the new certificate takes effect without manual intervention.
502 Bad Gateway — nginx can't reach the Docker container. Check containers are running:
cd /opt/soxai && docker compose ps
Streaming cuts off at exactly 100 seconds (Option A) — the CDN proxy timeout is firing. Confirm that gateway.yourdomain.com is set to DNS only (grey cloud), not proxied.
ERR_SSL_PROTOCOL_ERROR (Option A) — Cloudflare SSL/TLS mode is set to Flexible (origin receives plain HTTP). Change it to Full (strict).
Certificate not renewing (Option B) — ensure port 80 is reachable and run a forced renewal: