clusev/docker/caddy/Caddyfile

34 lines
1.1 KiB
Caddyfile

# Clusev reverse proxy — one template, both modes (driven by $SITE_ADDRESS).
#
# SITE_ADDRESS=:80 -> plain HTTP on the bare IP, no cert
# SITE_ADDRESS=https://clusev.host.tld -> auto Let's Encrypt, :443, auto-redirect
#
# Fully automatic: Caddy issues + renews the certificate and redirects HTTP->HTTPS with
# no script, cron or reload. The domain is the single install knob (APP_DOMAIN); to
# change it later, re-run install.sh with the new domain. Reverb (Pusher protocol) rides
# the same address over /app/* (WS) and /apps/* (event API), proxied to reverb:8080 —
# no extra exposed port, no mixed content.
{
# ACME_EMAIL is never empty at runtime: compose defaults it to admin@localhost
# in bare-IP mode, where no cert is issued so the address is simply unused.
email {$ACME_EMAIL}
}
{$SITE_ADDRESS} {
@reverb path /app/* /apps/*
reverse_proxy @reverb reverb:8080
reverse_proxy app:80
encode zstd gzip
header {
# conservative hardening; HSTS only meaningful under HTTPS
X-Content-Type-Options nosniff
X-Frame-Options DENY
Referrer-Policy strict-origin-when-cross-origin
-Server
}
}