# Mirror Gateway Assets This directory holds the reverse-proxy configuration and TLS material for the managed mirror profile: - `conf.d/*.conf` – nginx configuration shipped with the profile. - `tls/` – place environment-specific certificates and private keys (`mirror-primary.{crt,key}`, `mirror-community.{crt,key}`, etc.). - `secrets/` – populate Basic Auth credential stores (`*.htpasswd`) that gate each mirror domain. Generate with `htpasswd -B`. The Compose bundle mounts these paths read-only. Populate `tls/` with the actual certificates before invoking `docker compose config` or `docker compose up`.