63 lines
2.2 KiB
Caddyfile
63 lines
2.2 KiB
Caddyfile
# allprox — Caddy reverse proxy
|
|
#
|
|
# Maps domains to local IPs and hosts an authenticated portal (web UI).
|
|
# Edit the domain names below to match your DNS, and set the upstream
|
|
# IP:port values in the installer's .env (APP1_UPSTREAM, APP2_UPSTREAM, ...).
|
|
# Duplicate a "Proxied services" block to add more services.
|
|
#
|
|
# Authentication:
|
|
# * Today: basic_auth (a single admin account; hash set via PORTAL_AUTH_HASH).
|
|
# * Later: Authelia SSO — replace the basic_auth blocks with the forward_auth
|
|
# block shown below (see https://www.authelia.com/integration/proxies/caddy/).
|
|
{
|
|
# For public domains with automatic HTTPS, set your ACME email here:
|
|
# email you@example.com
|
|
}
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Web UI — authenticated portal (change the domain to your own)
|
|
# ---------------------------------------------------------------------------
|
|
portal.example.com {
|
|
# `tls internal` issues a self-signed cert for LAN use. Remove this line
|
|
# and set the ACME email above when exposing a real public domain.
|
|
tls internal
|
|
|
|
basic_auth {
|
|
admin {$PORTAL_AUTH_HASH}
|
|
}
|
|
|
|
# Authelia SSO (later): replace the basic_auth block above with:
|
|
# forward_auth authelia:9091 {
|
|
# uri /api/authz/forward-auth
|
|
# copy_headers Remote-User Remote-Groups Remote-Email Remote-Name
|
|
# }
|
|
|
|
root * /srv/portal
|
|
file_server
|
|
}
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Authelia portal — the SSO login page (proxy to the authelia container).
|
|
# With Authelia running, users are redirected here to sign in.
|
|
# ---------------------------------------------------------------------------
|
|
auth.example.com {
|
|
tls internal
|
|
reverse_proxy authelia:9091
|
|
}
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Proxied services — copy a block per service. The local IP:port comes from
|
|
# the {$APPx_UPSTREAM} variable in .env.
|
|
# ---------------------------------------------------------------------------
|
|
app1.example.com {
|
|
tls internal
|
|
# basic_auth { admin {$PORTAL_AUTH_HASH} } # or the Authelia forward_auth block
|
|
reverse_proxy {$APP1_UPSTREAM}
|
|
}
|
|
|
|
app2.example.com {
|
|
tls internal
|
|
# basic_auth { admin {$PORTAL_AUTH_HASH} }
|
|
reverse_proxy {$APP2_UPSTREAM}
|
|
}
|