fix(scriberr): serve over HTTPS via the fleet TLS caddy so the browser recorder works

The in-browser recorder calls getUserMedia, which browsers refuse on http://
origins, so it sat at "Initializing recorder...". scriberr.nh3.phasefinal.com
is now fronted by the fleet TLS caddy on nh3-dev (wildcard cert) and added to
Scriberr's ALLOWED_ORIGINS; the Homepage link points at it. The plain
http://10.251.50.54:8080 URL keeps working except for recording.
This commit is contained in:
vh
2026-10-01 13:07:18 -07:00
parent 474f78811c
commit abcf4c3166
5 changed files with 53 additions and 4 deletions
+8 -2
View File
@@ -5,8 +5,14 @@ speaker diarization) with NVIDIA Parakeet/Canary also selectable; SQLite for
state; optional summarisation and transcript chat against any OpenAI-compatible
endpoint.
- **Host:** `fv-ml1` (10.251.50.54) — GPU1
- **URL:** http://10.251.50.54:8080
- **Host:** `fv-ml1` (10.251.50.54) — GPU 3
- **URL:** **https://scriberr.nh3.phasefinal.com** (since 2026-10-01). The fleet TLS caddy on nh3-dev
(`~/.config/caddy-fleet/Caddyfile`, wildcard `*.nh3.phasefinal.com`) reverse-proxies it to
fv-ml1:8080. Use this name for **recording**: the browser recorder calls `getUserMedia`, which
browsers refuse on `http://` origins, and the page then sits at "Initializing recorder..."
(console: "Failed to initialize recorder"). The name must also be in `SCRIBERR_ALLOWED_ORIGINS`,
or Scriberr's CORS check rejects the app's own API calls (`playbooks/scriberr-https-origin.yaml`).
The plain http://10.251.50.54:8080 still works for everything except recording.
- **Upstream:** https://github.com/rishikanthc/Scriberr
## The image is built locally, and that is not incidental