# allprox — Caddy reverse proxy # # Maps domains to local IPs and hosts an authenticated portal (web UI). # Edit the domain names below to match your DNS, and set the upstream # IP:port values in the installer's .env (APP1_UPSTREAM, APP2_UPSTREAM, ...). # Duplicate a "Proxied services" block to add more services. # # Authentication: # * Today: basic_auth (a single admin account; hash set via PORTAL_AUTH_HASH). # * Later: Authelia SSO — replace the basic_auth blocks with the forward_auth # block shown below (see https://www.authelia.com/integration/proxies/caddy/). { # For public domains with automatic HTTPS, set your ACME email here: # email you@example.com } # --------------------------------------------------------------------------- # Web UI — authenticated portal (change the domain to your own) # --------------------------------------------------------------------------- portal.example.com { # `tls internal` issues a self-signed cert for LAN use. Remove this line # and set the ACME email above when exposing a real public domain. tls internal basic_auth { admin {$PORTAL_AUTH_HASH} } # Authelia SSO (later): replace the basic_auth block above with: # forward_auth authelia:9091 { # uri /api/authz/forward-auth # copy_headers Remote-User Remote-Groups Remote-Email Remote-Name # } root * /srv/portal file_server } # --------------------------------------------------------------------------- # Authelia portal — the SSO login page (proxy to the authelia container). # With Authelia running, users are redirected here to sign in. # --------------------------------------------------------------------------- auth.example.com { tls internal reverse_proxy authelia:9091 } # --------------------------------------------------------------------------- # Proxied services — copy a block per service. The local IP:port comes from # the {$APPx_UPSTREAM} variable in .env. # --------------------------------------------------------------------------- app1.example.com { tls internal # basic_auth { admin {$PORTAL_AUTH_HASH} } # or the Authelia forward_auth block reverse_proxy {$APP1_UPSTREAM} } app2.example.com { tls internal # basic_auth { admin {$PORTAL_AUTH_HASH} } reverse_proxy {$APP2_UPSTREAM} }