Go to file
nexxo a25e9c2fe6 Run Traefik as a service that fetches its own routes
Binary plus systemd unit, no Docker on the hypervisor: nftables stays the only
owner of the host's firewall rules and a Docker daemon would bring its own
chain.

The names were read out of SshTraefikWriter::render() rather than guessed, which
is what the handoff asks for in as many words. The route endpoint emits
entryPoints ["websecure"] and certResolver "letsencrypt", so the static config
declares exactly those. Name them differently here and the routers point at
nothing while Traefik still reports a clean start — a failure with no symptom
at the place it happens.

An ordering problem this plan had not resolved: the http provider needs the
durable host token, and that token only exists after POST /host/register, two
sections later. Rather than reorder the section keys — they are the contract
with the platform plan — the static config is written twice. Here with an empty
token, so the service stands and holds 80 and 443, and again in Task 9 with the
real one. The proof does not disappear, it moves to where it can be given.

That proof asks the endpoint directly with the same token and URL the config
carries, instead of counting Traefik's routers. A fresh host has no customers,
so its table is legitimately empty, and "zero routers" would mean both "fine"
and "never fetched".

Ports are checked separately from the service. "Running" and "listening" are two
claims, and Traefik starts cleanly even when a typo means an entryPoint was
never created.

The binary is checksummed against the release's own checksums file, for the same
reason the ISO is: what listens on 80 and 443 and holds every customer's
certificate does not get taken off the network unverified. The version is
discovered at runtime, because a pinned number becomes a 404 mid-takeover.

acme.json is created at 600 before Traefik ever runs. It holds the private keys
of every customer certificate, and Traefik refuses wider permissions — rightly.
The unit runs with CAP_NET_BIND_SERVICE and nothing else, ProtectSystem=strict,
NoNewPrivileges: this is the one process on the box reachable from the open
internet.

Verified without hardware: dash-clean, the generated config parses as YAML, and
it carries web/websecure/traefik as entryPoints, letsencrypt as the resolver,
the Bearer header on the http provider, web redirecting to websecure, and 640 on
the config with 600 on acme.json and the token file. Step 2 unticked — it wants a
fetched route set, and that is Task 9's to show.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-30 20:13:54 +02:00
.gitea/workflows feat(deploy): releases you can pin to, and a version that tells the truth 2026-07-26 15:21:38 +02:00
.npm chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
app Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
bin Make the private hostnames look like nothing is there, and close the way past the proxy 2026-07-27 11:26:48 +02:00
bootstrap Stop the 503 page appearing during an update 2026-07-29 17:50:15 +02:00
config Verify webhooks against the secret of the mode we are in 2026-07-30 12:13:55 +02:00
database Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
deploy Run Traefik as a service that fetches its own routes 2026-07-30 20:13:54 +02:00
docker Give the readiness probe long enough for a restart to finish 2026-07-27 14:46:47 +02:00
docs Run Traefik as a service that fetches its own routes 2026-07-30 20:13:54 +02:00
lang Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
public One wordmark, one typeface, and the address the server actually issues 2026-07-29 14:30:44 +02:00
resources Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
routes Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
storage chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
tests Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
.dockerignore chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.editorconfig chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.env.example Verify webhooks against the secret of the mode we are in 2026-07-30 12:13:55 +02:00
.gitattributes chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
.gitignore Keep exported invoices out of the repository 2026-07-29 09:56:00 +02:00
.npmrc chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
CLAUDE.md R24: a modal is never taller than the screen 2026-07-29 23:33:57 +02:00
README.md chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
VERSION Release v1.3.62 2026-07-30 17:38:57 +02:00
artisan chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
composer.json Render an invoice, with the arithmetic held to integer cents 2026-07-29 01:41:46 +02:00
composer.lock Render an invoice, with the arithmetic held to integer cents 2026-07-29 01:41:46 +02:00
docker-compose.yml Stop root workers breaking every page, and let the panel be closed 2026-07-29 15:43:54 +02:00
package-lock.json Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
package.json Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
phpunit.xml Tell a read-only token apart from one that can write 2026-07-30 13:56:28 +02:00
postcss.config.js feat(portal): design foundation — Tailwind v3, tokens, self-hosted fonts 2026-07-25 00:43:01 +02:00
tailwind.config.js Rebuild the public site as a document, and read prices from the catalogue 2026-07-27 03:52:25 +02:00
vite.config.js feat(ops): update page, automatic 419 recovery, CI workflow 2026-07-26 00:58:27 +02:00

README.md

Laravel Logo

Build Status Total Downloads Latest Stable Version License

About Laravel

Laravel is a web application framework with expressive, elegant syntax. We believe development must be an enjoyable and creative experience to be truly fulfilling. Laravel takes the pain out of development by easing common tasks used in many web projects, such as:

Laravel is accessible, powerful, and provides tools required for large, robust applications.

Learning Laravel

Laravel has the most extensive and thorough documentation and video tutorial library of all modern web application frameworks, making it a breeze to get started with the framework.

In addition, Laracasts contains thousands of video tutorials on a range of topics including Laravel, modern PHP, unit testing, and JavaScript. Boost your skills by digging into our comprehensive video library.

You can also watch bite-sized lessons with real-world projects on Laravel Learn, where you will be guided through building a Laravel application from scratch while learning PHP fundamentals.

Agentic Development

Laravel's predictable structure and conventions make it ideal for AI coding agents like Claude Code, Cursor, and GitHub Copilot. Install Laravel Boost to supercharge your AI workflow:

composer require laravel/boost --dev

php artisan boost:install

Boost provides your agent 15+ tools and skills that help agents build Laravel applications while following best practices.

Contributing

Thank you for considering contributing to the Laravel framework! The contribution guide can be found in the Laravel documentation.

Code of Conduct

In order to ensure that the Laravel community is welcoming to all, please review and abide by the Code of Conduct.

Security Vulnerabilities

If you discover a security vulnerability within Laravel, please send an e-mail to Taylor Otwell via taylor@laravel.com. All security vulnerabilities will be promptly addressed.

License

The Laravel framework is open-sourced software licensed under the MIT license.