hf-storage-data/Caddyfile

61 lines
1.2 KiB
Caddyfile

{
admin off
email {$TLS_CONTACT}
# Stock Caddy only proxies HTTP. The pinned caddy-l4 module also handles the
# PostgreSQL SSLRequest handshake, terminates TLS, then proxies cleartext only
# over the private Docker network.
layer4 {
:5432 {
@postgres postgres
route @postgres {
postgres_tls
tls
proxy postgres:5432
}
}
}
}
# Besides providing a useful status response, this site block tells Caddy to
# obtain and renew the certificate used by the Layer 4 PostgreSQL listener.
{$POSTGRES_DOMAIN} {
respond "PostgreSQL is available on port 5432 with TLS required.\n" 200
log {
output stdout
format json
}
}
# S3 API. Keep this on its own hostname: S3 request signatures include the host.
{$MINIO_API_DOMAIN} {
reverse_proxy minio:9000
log {
output stdout
format json
}
}
# Browser-based MinIO console, separated from the S3 API hostname.
{$MINIO_CONSOLE_DOMAIN} {
reverse_proxy minio:9001
log {
output stdout
format json
}
}
# Multi-user PostgreSQL administration UI. Authentication is handled by
# pgAdmin; database permissions remain the responsibility of PostgreSQL roles.
{$PGADMIN_DOMAIN} {
reverse_proxy pgadmin:5050
log {
output stdout
format json
}
}