Troubleshooting:Service Troubleshooting: Difference between revisions
Appearance
Minor update - troubleshooting guide: Service Troubleshooting (7 sections) (troubleshooting) |
Updated documentation from markdown files |
||
| (2 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
This guide covers troubleshooting for reverse proxy services on the VPS. Public HTTPS is handled by '''Caddy''' (<code>/etc/caddy/Caddyfile</code>). | |||
This guide covers troubleshooting for reverse proxy services. | |||
== Common Issues == | == Common Issues == | ||
| Line 8: | Line 6: | ||
'''Causes''': | '''Causes''': | ||
* | * Backend not running (Docker on VPS or service on NAS) | ||
* Caddy misconfigured or not reloaded after Caddyfile change | |||
* Wrong port number | * Wrong port number | ||
| Line 16: | Line 16: | ||
'''Solutions''': | '''Solutions''': | ||
<pre class="lang-bash"> | <pre class="lang-bash"> | ||
# Test from VPS to NAS | |||
ping 10.8.0.2 | ping 10.8.0.2 | ||
curl http://10.8.0.2:PORT_NUMBER | curl http://10.8.0.2:PORT_NUMBER | ||
# Test VPS-local Docker service | |||
curl -sI http://127.0.0.1:PORT_NUMBER | |||
# Check Caddy logs | |||
journalctl -u caddy -n 50 | |||
# Check if service is listening (from Synology NAS or via SSH) | |||
netstat -tlnp | grep PORT_NUMBER | netstat -tlnp | grep PORT_NUMBER | ||
</pre> | </pre> | ||
| Line 36: | Line 41: | ||
'''Solutions''': | '''Solutions''': | ||
<pre class="lang-bash"> | <pre class="lang-bash"> | ||
# Check DNS | |||
nslookup newservice.jb-vpn.uk | nslookup newservice.jb-vpn.uk | ||
# Verify port 80 is open | |||
curl -I http://newservice.jb-vpn.uk | curl -I http://newservice.jb-vpn.uk | ||
# Check firewall | |||
sudo iptables -L -n -v | grep 80 | sudo iptables -L -n -v | grep 80 | ||
# Validate Caddy config | |||
caddy validate --config /etc/caddy/Caddyfile | |||
</pre> | </pre> | ||
| Line 49: | Line 57: | ||
'''Causes''': | '''Causes''': | ||
* Wrong | * Wrong upstream URL in Caddyfile | ||
* Missing headers | * Missing proxy headers | ||
* Service requires specific path | * Service requires specific path | ||
'''Solutions''': | '''Solutions''': | ||
* Check | * Check Caddy: <code>journalctl -u caddy -n 50</code> | ||
* Verify | * Verify backend directly: <code>curl http://127.0.0.1:PORT</code> (VPS) or <code>curl http://10.8.0.2:PORT</code> (NAS via VPN) | ||
* | * Validate and reload: <code>caddy validate --config /etc/caddy/Caddyfile && systemctl reload caddy</code> | ||
=== Issue: Connection Timeout === | === Issue: Connection Timeout === | ||
| Line 73: | Line 81: | ||
'''Solutions''': | '''Solutions''': | ||
<pre class="lang-bash"> | <pre class="lang-bash"> | ||
# Check VPN | |||
ip addr show tun0 | ip addr show tun0 | ||
ping 10.8.0.2 | ping 10.8.0.2 | ||
cat /var/log/openvpn-status.log | |||
# Check routing | |||
ip route | grep 10.8.0. | ip route | grep 10.8.0.0 | ||
# Test connectivity | |||
curl -v http://10.8.0.2:PORT_NUMBER | curl -v http://10.8.0.2:PORT_NUMBER | ||
</pre> | </pre> | ||
| Line 87: | Line 96: | ||
<pre class="lang-bash"> | <pre class="lang-bash"> | ||
# Caddy | |||
systemctl status | caddy validate --config /etc/caddy/Caddyfile | ||
systemctl status caddy | |||
systemctl reload caddy | |||
journalctl -u caddy -n 50 | |||
# OpenVPN (for NAS-backed services) | |||
systemctl status openvpn-server@server.service | |||
ip addr show tun0 | |||
cat /var/log/openvpn-status.log | |||
# Test public endpoint | |||
curl -I https://service.jb-vpn.uk | |||
# Docker stacks on VPS | |||
cd /var/www/wiki.jb && docker compose ps | |||
</pre> | |||
= | == Service-specific guides == | ||
* '''Plex''': [[Troubleshooting:Plex Troubleshooting|Troubleshooting:Plex Troubleshooting]] — auth, custom access URLs, Caddy pitfalls | |||
* '''Nginx (legacy)''': [[Documentation:Nginx-Troubleshooting|Troubleshooting:Nginx Troubleshooting]] — host/WebApp internal nginx only | |||
== Related Documentation == | == Related Documentation == | ||
* [ | * [[Services:Current Services|Services:Current Services]] — service inventory | ||
* [[Documentation:Components|System:Components]] — Caddy, VPN, Docker components | |||
[[Category:Documentation]] | [[Category:Documentation]] | ||
[[Category:Documentation/Troubleshooting]] | [[Category:Documentation/Troubleshooting]] | ||
Latest revision as of 10:44, 7 July 2026
This guide covers troubleshooting for reverse proxy services on the VPS. Public HTTPS is handled by Caddy (/etc/caddy/Caddyfile).
Common Issues
[edit]Issue: 502 Bad Gateway
[edit]Causes:
- Backend not running (Docker on VPS or service on NAS)
- Caddy misconfigured or not reloaded after Caddyfile change
- Wrong port number
- Service not accessible via VPN
Solutions:
# Test from VPS to NAS ping 10.8.0.2 curl http://10.8.0.2:PORT_NUMBER # Test VPS-local Docker service curl -sI http://127.0.0.1:PORT_NUMBER # Check Caddy logs journalctl -u caddy -n 50 # Check if service is listening (from Synology NAS or via SSH) netstat -tlnp | grep PORT_NUMBER
Issue: SSL Certificate Failed
[edit]Causes:
- DNS not pointing to VPS
- Port 80 blocked
- Rate limiting from Let's Encrypt
Solutions:
# Check DNS nslookup newservice.jb-vpn.uk # Verify port 80 is open curl -I http://newservice.jb-vpn.uk # Check firewall sudo iptables -L -n -v | grep 80 # Validate Caddy config caddy validate --config /etc/caddy/Caddyfile
Issue: Service Not Loading
[edit]Causes:
- Wrong upstream URL in Caddyfile
- Missing proxy headers
- Service requires specific path
Solutions:
- Check Caddy:
journalctl -u caddy -n 50
- Verify backend directly:
curl http://127.0.0.1:PORT(VPS) orcurl http://10.8.0.2:PORT(NAS via VPN)
- Validate and reload:
caddy validate --config /etc/caddy/Caddyfile && systemctl reload caddy
Issue: Connection Timeout
[edit]Causes:
- VPN tunnel down
- Service not accessible
- Firewall blocking
Solutions:
# Check VPN ip addr show tun0 ping 10.8.0.2 cat /var/log/openvpn-status.log # Check routing ip route | grep 10.8.0.0 # Test connectivity curl -v http://10.8.0.2:PORT_NUMBER
Diagnostic Commands
[edit]# Caddy caddy validate --config /etc/caddy/Caddyfile systemctl status caddy systemctl reload caddy journalctl -u caddy -n 50 # OpenVPN (for NAS-backed services) systemctl status openvpn-server@server.service ip addr show tun0 cat /var/log/openvpn-status.log # Test public endpoint curl -I https://service.jb-vpn.uk # Docker stacks on VPS cd /var/www/wiki.jb && docker compose ps
Service-specific guides
[edit]- Plex: Troubleshooting:Plex Troubleshooting — auth, custom access URLs, Caddy pitfalls
- Nginx (legacy): Troubleshooting:Nginx Troubleshooting — host/WebApp internal nginx only
Related Documentation
[edit]- Services:Current Services — service inventory
- System:Components — Caddy, VPN, Docker components