{ admin off email {$TLS_CONTACT} # Stock Caddy only proxies HTTP. The pinned caddy-l4 module also handles the # PostgreSQL SSLRequest handshake, terminates TLS, then proxies cleartext only # over the private Docker network. layer4 { :5432 { @postgres postgres route @postgres { postgres_tls tls proxy postgres:5432 } } } } # One host name for everything. Each service has its own port, and a certificate is for a name, not a # port, so all of them share the one Caddy obtains for {$DATA_DOMAIN}. # # 443 S3 API path-style: https:////, the root of the host # 5432 PostgreSQL TLS terminated by the Layer 4 listener above # 9443 MinIO console # 5443 pgAdmin # # The S3 API is the one on the standard port because it is what other systems call: its host # appears in signed requests, and MinIO serves buckets from the root, so it cannot share the root # with another application. Opening https:/// in a browser shows MinIO's XML error; that is # the API answering, not a fault. # # This site block is also what makes Caddy obtain and renew the certificate the Layer 4 PostgreSQL # listener presents. {$DATA_DOMAIN} { reverse_proxy minio:9000 log { output stdout format json } } # Browser-based MinIO console. MINIO_BROWSER_REDIRECT_URL must carry this port, or MinIO sends the # browser back to the S3 API's address. {$DATA_DOMAIN}:9443 { reverse_proxy minio:9001 log { output stdout format json } } # Multi-user PostgreSQL administration UI. Authentication is handled by # pgAdmin; database permissions remain the responsibility of PostgreSQL roles. {$DATA_DOMAIN}:5443 { reverse_proxy pgadmin:5050 log { output stdout format json } }