-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCaddyfile
More file actions
93 lines (77 loc) · 1.71 KB
/
Copy pathCaddyfile
File metadata and controls
93 lines (77 loc) · 1.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
# The Caddyfile is an easy way to configure your Caddy web server.
#
# Unless the file starts with a global options block, the first
# uncommented line is always the address of your site.
#
# To use your own domain name (with automatic HTTPS), first make
# sure your domain's A/AAAA DNS records are properly pointed to
# this machine's public IP
# Refer to the Caddy docs for more information:
# https://caddyserver.com/docs/caddyfile
{$CADDY_GLOBAL_EXTRA_CONFIG}
(tls-ovh) {
tls {
dns ovh {
endpoint {$OVH_ENDPOINT:ovh-eu}
application_key {$OVH_APPLICATION_KEY}
application_secret {$OVH_APPLICATION_SECRET}
consumer_key {$OVH_CONSUMER_KEY}
}
}
}
(tls-azure) {
tls {
dns azure {
tenant_id {$AZURE_TENANT_ID}
client_id {$AZURE_CLIENT_ID}
client_secret {$AZURE_CLIENT_SECRET}
subscription_id {$AZURE_SUBSCRIPTION_ID}
resource_group_name {$AZURE_RESOURCE_GROUP_NAME}
}
}
}
(tls-cloudflare) {
tls {
dns cloudflare {$CLOUDFLARE_API_TOKEN}
resolvers 1.1.1.1
}
}
(tls-duck) {
tls {
dns duckdns {$DUCK_DNS_TOKEN}
}
}
(tls-njalla) {
tls {
dns njalla {$NJALLA_API_TOKEN}
resolvers 1.1.1.1
}
}
(reverse-proxy) {
reverse_proxy {$BACKEND_ENDPOINT:nginx:80} {
trusted_proxies {$TRUSTED_PROXIES:172.19.0.0/16}
}
}
(php-fpm) {
root * {$WEBROOT:/var/www/html}
php_fastcgi {$PHP_FASTCGI:php:9000}
file_server
encode zstd gzip
}
(html) {
root * {$WEBROOT:/var/www/html}
file_server
}
(whitelist-ip) {
@client_ip not remote_ip {args.0}
respond @client_ip 403
}
(false) {
}
{$DOMAIN:localhost}:{$DOMAIN_PORT:443} {
import whitelist-ip {$WHITELIST_IPS:0.0.0.0/0}
import {$CADDY_MODE:reverse-proxy}
import {$TLS_PROVIDER:tls-ovh}
{$CADDY_DOMAIN_EXTRA_CONFIG}
}
{$CADDY_DOMAIN_EXTRA_DOMAINS}