65 lines
1.7 KiB
Caddyfile
65 lines
1.7 KiB
Caddyfile
{
|
|
admin off
|
|
email {$TLS_CONTACT}
|
|
|
|
# Stock Caddy only proxies HTTP. The pinned caddy-l4 module also handles the
|
|
# PostgreSQL SSLRequest handshake, terminates TLS, then proxies cleartext only
|
|
# over the private Docker network.
|
|
layer4 {
|
|
:5432 {
|
|
@postgres postgres
|
|
route @postgres {
|
|
postgres_tls
|
|
tls
|
|
proxy postgres:5432
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
# One host name for everything. Each service has its own port, and a certificate is for a name, not a
|
|
# port, so all of them share the one Caddy obtains for {$DATA_DOMAIN}.
|
|
#
|
|
# 443 S3 API path-style: https://<name>/<bucket>/<key>, the root of the host
|
|
# 5432 PostgreSQL TLS terminated by the Layer 4 listener above
|
|
# 9443 MinIO console
|
|
# 5443 pgAdmin
|
|
#
|
|
# The S3 API is the one on the standard port because it is what other systems call: its host
|
|
# appears in signed requests, and MinIO serves buckets from the root, so it cannot share the root
|
|
# with another application. Opening https://<name>/ in a browser shows MinIO's XML error; that is
|
|
# the API answering, not a fault.
|
|
#
|
|
# This site block is also what makes Caddy obtain and renew the certificate the Layer 4 PostgreSQL
|
|
# listener presents.
|
|
{$DATA_DOMAIN} {
|
|
reverse_proxy minio:9000
|
|
|
|
log {
|
|
output stdout
|
|
format json
|
|
}
|
|
}
|
|
|
|
# Browser-based MinIO console. MINIO_BROWSER_REDIRECT_URL must carry this port, or MinIO sends the
|
|
# browser back to the S3 API's address.
|
|
{$DATA_DOMAIN}:9443 {
|
|
reverse_proxy minio:9001
|
|
|
|
log {
|
|
output stdout
|
|
format json
|
|
}
|
|
}
|
|
|
|
# Multi-user PostgreSQL administration UI. Authentication is handled by
|
|
# pgAdmin; database permissions remain the responsibility of PostgreSQL roles.
|
|
{$DATA_DOMAIN}:5443 {
|
|
reverse_proxy pgadmin:5050
|
|
|
|
log {
|
|
output stdout
|
|
format json
|
|
}
|
|
}
|