# Public TLS for both hosts, real certificates from Let's Encrypt over
# HTTP-01: the DNS A records for ${PORTAL_HOST} and ${ID_HOST} must
# point at this host before the first start.

{$ID_HOST} {
	# Kanidm serves its own (internal, self-signed) TLS; verification is
	# skipped on the inside hop only.
	reverse_proxy kanidm:8443 {
		transport http {
			tls_insecure_skip_verify
		}
	}
	log {
		output file /data/id.log
	}
}

{$PORTAL_HOST} {
	reverse_proxy portal:3000
	log {
		output file /data/portal.log
	}
}
