hf-storage-data/Caddyfile

65 lines
1.7 KiB
Caddyfile

{
admin off
email {$TLS_CONTACT}
# Stock Caddy only proxies HTTP. The pinned caddy-l4 module also handles the
# PostgreSQL SSLRequest handshake, terminates TLS, then proxies cleartext only
# over the private Docker network.
layer4 {
:5432 {
@postgres postgres
route @postgres {
postgres_tls
tls
proxy postgres:5432
}
}
}
}
# One host name for everything. Each service has its own port, and a certificate is for a name, not a
# port, so all of them share the one Caddy obtains for {$DATA_DOMAIN}.
#
# 443 S3 API path-style: https://<name>/<bucket>/<key>, the root of the host
# 5432 PostgreSQL TLS terminated by the Layer 4 listener above
# 9443 MinIO console
# 5443 pgAdmin
#
# The S3 API is the one on the standard port because it is what other systems call: its host
# appears in signed requests, and MinIO serves buckets from the root, so it cannot share the root
# with another application. Opening https://<name>/ in a browser shows MinIO's XML error; that is
# the API answering, not a fault.
#
# This site block is also what makes Caddy obtain and renew the certificate the Layer 4 PostgreSQL
# listener presents.
{$DATA_DOMAIN} {
reverse_proxy minio:9000
log {
output stdout
format json
}
}
# Browser-based MinIO console. MINIO_BROWSER_REDIRECT_URL must carry this port, or MinIO sends the
# browser back to the S3 API's address.
{$DATA_DOMAIN}:9443 {
reverse_proxy minio:9001
log {
output stdout
format json
}
}
# Multi-user PostgreSQL administration UI. Authentication is handled by
# pgAdmin; database permissions remain the responsibility of PostgreSQL roles.
{$DATA_DOMAIN}:5443 {
reverse_proxy pgadmin:5050
log {
output stdout
format json
}
}