running #Gunicorn exposed to the internet is not recommended because it sucks at #slowloris DoS attack handling; instead they recommend using #nginx, and provide a recommended configuration, including Unix-domain sockets (#uds).
on 02023-02-01how to get #nginx to proxy Unix-domain sockets (#uds): location / { proxy_pass http://datasette; proxy_set_header Host $host; } upstream datasette { server unix:/tmp/datasette.sock; }
You can also bind #Gunicorn to Unix-domain sockets (#uds) for secure reverse proxying. Gunicorn does try to remove the socket before exiting, but of course if it gets killed or crashes this will fail. In manual testing, though, I don’t see the behavior reported in this answer where you need to manually remove the socket file to get it to restart.
on 02023-02-01