31 lines
911 B
Caddyfile
31 lines
911 B
Caddyfile
# Clusev reverse proxy — one template, both modes (driven by $SITE_ADDRESS).
|
|
#
|
|
# SITE_ADDRESS=:80 -> plain HTTP on the bare IP, no cert
|
|
# SITE_ADDRESS=https://clusev.host.tld -> auto Let's Encrypt, :443, auto-redirect
|
|
#
|
|
# Reverb (Pusher protocol) rides the same address over /app/* (WS) and /apps/*
|
|
# (event API), proxied to reverb:8080 — no extra exposed port, no mixed content.
|
|
{
|
|
# ACME_EMAIL is never empty at runtime: compose defaults it to admin@localhost
|
|
# in bare-IP mode, where no cert is issued so the address is simply unused.
|
|
email {$ACME_EMAIL}
|
|
}
|
|
|
|
{$SITE_ADDRESS} {
|
|
@reverb path /app/* /apps/*
|
|
reverse_proxy @reverb reverb:8080
|
|
|
|
reverse_proxy app:80
|
|
|
|
encode zstd gzip
|
|
|
|
header {
|
|
# conservative hardening; HSTS only meaningful under HTTPS
|
|
X-Content-Type-Options nosniff
|
|
X-Frame-Options DENY
|
|
Referrer-Policy strict-origin-when-cross-origin
|
|
-Server
|
|
}
|
|
}
|