[Self-Hosted]Admin Interface Is Not Accessible When Running on a Non-Standard Port (non-443)

(#618) Bug Fixed self-hosting

Summary

When I change the externally exposed port (FLUXER_PUBLIC_PORT) from the default one in the environment variables (for example, to 5366), I can no longer access the admin interface correctly. Visiting: https://domain.com:5366/admin/ automatically redirects me to: https://domain.com/oauth2/authorize?... During this redirect, the port information (:5366) is lost. If I manually add the port back after the redirect, for example: https://domain.com:5366/oauth2/authorize?... the page then reports that the redirect URL is not registered (see Screenshot 2).

Steps to reproduce

  1. Change the exposed port (FLUXER_PUBLIC_PORT) from the default value to a non-standard port (e.g. 5366) via environment variables.
  2. Access https://domain.com:5366/admin/.
  3. Observe that the request is redirected to https://domain.com/oauth2/authorize?... without the port.
  4. Manually add the port back to the redirected URL.
  5. Observe the "redirect URL not registered" error.

Environment

Version: BUILD_VERSION 2026.616.45607 OS: Docker 27.5.1 on unRAID 7.2.4, with Pangolin 1.19.2 as reverse proxy before Fluxer's Caddy Device: iPad, iPhone and Windows PC Browser: FireFox 151.3.2

Logs or screenshots

image image
  • 609051840-8c6bd494-0f54-44a5-ae9b-a8f501d68321.jpeg

    609051840-8c6bd494-0f54-44a5-ae9b-a8f501d68321.jpeg

    1206×2534 | 105 kB

  • 609051841-5ef68d39-9b33-4200-a1d4-5c82fe10884b.jpeg

    609051841-5ef68d39-9b33-4200-a1d4-5c82fe10884b.jpeg

    1206×2622 | 147 kB

Merged posts

These posts were merged into this one. Their comments are now part of the conversation below, marked with where they came from.

Report details

Summary

Setting FLUXER_PUBLIC_PORT in .env to something other than 80 prevents being able to access the admin page. For example, if FLUXER_PUBLIC_PORT is set to 8080, Accessing https://chat.example.com:8080/admin, attempts to load https://chat.example.com/oauth2/ which fails to load. Stuck showing "Starting Authentication..." I've found a fix, I've changed the following in the docker-compose.yml, changing
admin:
    <<: *fluxer-service
    image: ${FLUXER_REGISTRY:-ghcr.io/${FLUXER_REGISTRY_OWNER:-fluxerapp}}/fluxer-admin:${FLUXER_IMAGE_TAG:-v1}
    environment:
      <<: *fluxer-env
      FLUXER_ADMIN_HOST: 0.0.0.0
      FLUXER_ADMIN_PORT: "8080"
      FLUXER_ADMIN_BASE_PATH: /admin
      FLUXER_API_ENDPOINT: http://api:8080
      FLUXER_ADMIN_ENDPOINT: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}/admin
      FLUXER_APP_ENDPOINT: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}
      FLUXER_MEDIA_ENDPOINT: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}/media
      FLUXER_STATIC_CDN_ENDPOINT: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}
      FLUXER_ADMIN_OAUTH_REDIRECT_URI: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}/admin/oauth2_callback
    depends_on:
      api: {condition: service_healthy}
to
admin:
    <<: *fluxer-service
    image: ${FLUXER_REGISTRY:-ghcr.io/${FLUXER_REGISTRY_OWNER:-fluxerapp}}/fluxer-admin:${FLUXER_IMAGE_TAG:-v1}
    environment:
      <<: *fluxer-env
      FLUXER_ADMIN_HOST: 0.0.0.0
      FLUXER_ADMIN_PORT: "8080"
      FLUXER_ADMIN_BASE_PATH: /admin
      FLUXER_API_ENDPOINT: http://api:8080
      FLUXER_ADMIN_ENDPOINT: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}/admin
      FLUXER_APP_ENDPOINT: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}:${FLUXER_PUBLIC_PORT}
      FLUXER_MEDIA_ENDPOINT: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}/media
      FLUXER_STATIC_CDN_ENDPOINT: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}
      FLUXER_ADMIN_OAUTH_REDIRECT_URI: ${FLUXER_PUBLIC_SCHEME:-https}://${FLUXER_DOMAIN}:${FLUXER_PUBLIC_PORT}/admin/oauth2_callback
    depends_on:
      api: {condition: service_healthy}
By adding ${FLUXER_PUBLIC_PORT} to botht he app endpoint and oauth redirect, the admin page appears to work normally.

Steps to reproduce

Follow instructions at https://docs.fluxer.app/operator/get-started/, but when prompted to customize .env, Set FLUXER_PUBLIC_PORT to something non-default like 8080. After setup, attempt to access the admin page at https://chat.example.com:8080/admin, and see it fails.

Environment

Fluxer on Arch Container running Docker.

3 comments

Sign in with Fluxer to comment and vote.
Comment by @Sinterdial
RexSystem 1 vote originally by @Sinterdial on GitHub OP
solved by adding port in admin container's env
Deleted comment
Removed by moderator Rex: Removed a general status note that was posted on many GitHub threads. It no longer applies here.
Comment by @ajsnyde
RexSystem 1 vote Merged from #685 originally by @ajsnyde on GitHub
I'm also having issues that may be related to this when using flux on a non-default port. I feels related, but when initially creating an admin account on an instance, the networking tab shows a 200: image But immediately shows a 401({"code":"UNAUTHORIZED","message":"Unauthorized."}) for any related login etc and refreshes the page back to the 'create an admin' prompt: image I can't use the new admin user, but the email shows as already used in subsequent account creation forms. Relevant logs:
api-1               | {"level":"warn","time":"2026-09-08T15:12:23.254Z","service":"fluxer-api","env":"production","domain":"asdf.asdf","code":"ESERVFAIL","error":{"type":"Error","message":"queryMx ESERVFAIL asdf.asdf","stack":"Error: queryMx ESERVFAIL asdf.asdf\n    at QueryReqWrap.onresolve [as oncomplete] (node:internal/dns/promises:297:17)","code":"ESERVFAIL","syscall":"queryMx","hostname":"asdf.asdf"},"msg":"Email DNS lookup failed with a transient error, allowing request"}
api-1               | {"level":"info","time":"2026-09-08T15:12:23.422Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/register","status":200,"durationMs":529,"msg":"Request completed"}
seaweedfs-1         | I0908 15:10:18.199722 master_server.go:348 snapshot taken to persist TopologyId 61d770ff-257d-4471-b397-796e6fd399df
api-1               | {"level":"info","time":"2026-09-08T15:12:23.462Z","service":"fluxer-api","env":"production","method":"GET","path":"/v1/admin/instance/config","status":401,"durationMs":6,"msg":"Request completed"}
seaweedfs-1         | I0908 15:10:18.277268 volume_grpc_client_to_master.go:71 Volume server start with seed master nodes: [192.168.240.6:9333]
I have FLUXER_EMAIL_ENABLED=false in the .env, so I'm surprised to see the server presumably checking the DNS of the supplied email.
  • 647973850-291e4b07-e89a-4cf5-a7a5-5b7b7554dafb.png

    647973850-291e4b07-e89a-4cf5-a7a5-5b7b7554dafb.png

    1265×1022 | 257 kB

  • 647974376-76f4628e-7637-40e7-a6f9-2bc833d817f6.png

    647974376-76f4628e-7637-40e7-a6f9-2bc833d817f6.png

    2559×1014 | 639 kB

Comment by @naelstrof
RexSystem 1 vote Merged from #685 originally by @naelstrof on GitHub
This has since been fixed, there's a new article on the setup instructions here: https://docs.fluxer.app/operator/reverse-proxy/ Or perhaps, I didn't understand what reverse proxy meant when I initially followed the instructions. Anyway, I took my completely stock installation and added the following to the .env:
COMPOSE_FILE=docker-compose.yml:docker-compose.proxy.yml
FLUXER_EDGE_BIND=0.0.0.0:8080
Then I just pointed my reverse proxy to that port, and it works as expected.