Deployment troubleshooting
Start with the authenticated Settings diagnostics and a redacted support bundle, then verify each trust boundary independently.
Cookies are not Secure
Confirm the proxy's immediate address is in TRESTLE_TRUSTED_PROXIES and that it replaces X-Forwarded-Proto with https. Trestle ignores that header from every other peer.
Login reports an origin error
Preserve the public Host header and scheme. Do not rewrite browser origins or expose Trestle on a second public hostname without a deliberate routing policy.
SSE connects but events arrive late
Disable proxy buffering and extend the upstream read timeout. Clients must reconnect with Last-Event-ID and handle replay duplicates.
Uploads fail at the proxy
Increase the proxy body limit above Trestle's configured upload maximum plus multipart overhead. A proxy rejection occurs before Trestle can return its structured error.
Wrong client address in logs
Ensure every trusted hop is listed and every untrusted edge replaces forwarded headers. Trestle walks the chain from the immediate peer and stops at the first untrusted address.
Support bundle
Download it from Settings. It includes build identity, platform, listener, storage mode, timeout and trusted-proxy configuration, but excludes credentials, tokens, database contents and file paths.