server {
    listen %%interface%%:%%port%% default_server;

    include /etc/nginx/includes/server_params.conf;
    include /etc/nginx/includes/proxy_params.conf;
    # Set Hass.io Ingress header
    proxy_set_header X-Hassio-Ingress "YES";

    location / {
        # Only allow from Hass.io supervisor
        allow   172.30.32.2;
        deny    all;

        proxy_pass http://esphome;
    }
}