61 lines
1.2 KiB
Caddyfile
61 lines
1.2 KiB
Caddyfile
{
|
|
admin off
|
|
email {$TLS_CONTACT}
|
|
|
|
# Stock Caddy only proxies HTTP. The pinned caddy-l4 module also handles the
|
|
# PostgreSQL SSLRequest handshake, terminates TLS, then proxies cleartext only
|
|
# over the private Docker network.
|
|
layer4 {
|
|
:5432 {
|
|
@postgres postgres
|
|
route @postgres {
|
|
postgres_tls
|
|
tls
|
|
proxy postgres:5432
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
# Besides providing a useful status response, this site block tells Caddy to
|
|
# obtain and renew the certificate used by the Layer 4 PostgreSQL listener.
|
|
{$POSTGRES_DOMAIN} {
|
|
respond "PostgreSQL is available on port 5432 with TLS required.\n" 200
|
|
|
|
log {
|
|
output stdout
|
|
format json
|
|
}
|
|
}
|
|
|
|
# S3 API. Keep this on its own hostname: S3 request signatures include the host.
|
|
{$MINIO_API_DOMAIN} {
|
|
reverse_proxy minio:9000
|
|
|
|
log {
|
|
output stdout
|
|
format json
|
|
}
|
|
}
|
|
|
|
# Browser-based MinIO console, separated from the S3 API hostname.
|
|
{$MINIO_CONSOLE_DOMAIN} {
|
|
reverse_proxy minio:9001
|
|
|
|
log {
|
|
output stdout
|
|
format json
|
|
}
|
|
}
|
|
|
|
# Multi-user PostgreSQL administration UI. Authentication is handled by
|
|
# pgAdmin; database permissions remain the responsibility of PostgreSQL roles.
|
|
{$PGADMIN_DOMAIN} {
|
|
reverse_proxy pgadmin:5050
|
|
|
|
log {
|
|
output stdout
|
|
format json
|
|
}
|
|
}
|