Ory Hydra 는 Public API(4444) 와 Admin API(4445) 를 평문 HTTP 로 연다. 공식 배포 예제[1]는 그 앞에 Nginx 를 두어 Public API 만 HTTPS 로 공개하고 Admin API 는 막는다. 이 문서는 그 Nginx 를 설치하고 Let's Encrypt 인증서를 붙이는 절차다. Hydra 는 Ory Hydra v26.2.0 설치 가이드 대로 127.0.0.1:4444 · 127.0.0.1:4445 에 떠 있다고 본다.
urls.self.issuer 와 같은 공개 도메인 — 예시는 oauth2.example.com. DNS 가 이 서버를 가리켜야 한다.dnf install -y nginx
systemctl enable --now nginx
firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --reload
certbot 은 snap 으로 설치한다 — Let's Encrypt 인증서 발행.
snap install --classic certbot
ln -s /snap/bin/certbot /usr/bin/certbot
RHEL 계열 Nginx 는 /etc/nginx/conf.d/*.conf 를 읽는다. Debian 계열의 sites-available · sites-enabled 구조를 쓰려면 그 경로에 두고 심볼릭 링크를 건다.
/etc/nginx/conf.d/oauth2.example.com.conf
upstream hydra_public {
server 127.0.0.1:4444;
}
server {
listen 80;
server_name oauth2.example.com;
# certbot 이 이 블록에 443 설정을 추가한다
}
인증서를 받으면서 HTTPS 블록을 자동으로 만들게 한다.
nginx -t && systemctl reload nginx
certbot --nginx -d oauth2.example.com
certbot 이 만든 443 블록에 프록시 설정을 넣는다. 최종 형태는 다음과 같다.
upstream hydra_public {
server 127.0.0.1:4444;
}
server {
listen 80;
server_name oauth2.example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
http2 on;
server_name oauth2.example.com;
ssl_certificate /etc/letsencrypt/live/oauth2.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/oauth2.example.com/privkey.pem;
include /etc/letsencrypt/options-ssl-nginx.conf;
location / {
proxy_pass http://hydra_public;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
--endpoint http://127.0.0.1:4445 로 한다. 외부에서 써야 하면 별도 호스트명에 allow 내부망 IP; deny all; 과 클라이언트 인증서를 걸어 연다.X-Forwarded-Proto 가 있어야 Hydra 가 자신을 https 로 인식해 리다이렉트 URL 을 올바르게 만든다.nginx -t && systemctl reload nginx
curl -s https://oauth2.example.com/health/ready
# {"status":"ok"}
curl -s https://oauth2.example.com/.well-known/openid-configuration | jq -r .issuer
# https://oauth2.example.com
curl -s -o /dev/null -w '%{http_code}\n' https://oauth2.example.com/admin/clients
# 404 — Admin API 가 밖으로 나가지 않는다
위 버전과 저장소는 오래된 것이라 저장소가 존재하지 않을 수 있다.
yum install -y nginx certbot python3-certbot-nginx
cd /etc/nginx/sites-available/
vim oauth2.example.com
# server {
# listen 80;
# server_name oauth2.example.com;
# }
ln -s /etc/nginx/sites-available/oauth2.example.com /etc/nginx/sites-enabled/oauth2.example.com
Ory Hydra — Deploy example (Nginx upstream 4444 공개, 4445 제한). 2026-09-20 확인. https://www.ory.com/docs/hydra/self-hosted/deploy-hydra-example ↩︎