diff --git a/compose.yml b/compose.yml index 8a19626..8752cc7 100644 --- a/compose.yml +++ b/compose.yml @@ -1,8 +1,10 @@ -# Tomter Vel's own platform: one host, four containers, everything -# behind Caddy. The content (pages, forms, desks) is not here: portal -# fetches it from tomtervel/questions on prosjekt.klingenbergbygg.no -# and hot-reloads it over NATS. This repo owns the host: identity, -# the bus, TLS, and which portal version runs. +# Tomter Vel's own platform: portal + its own Kanidm and NATS as podman +# containers. The content (pages, forms, desks) is not here: portal fetches +# it from tomtervel/questions on prosjekt.klingenbergbygg.no and hot-reloads +# it over NATS. This repo owns identity, the bus, and which portal version +# runs. TLS depends on where it runs: on a standalone host the bundled Caddy +# (`--profile edge`) terminates it; on kasse the host Caddy already owns +# 80/443 and reverse-proxies vel.klingenbergbygg.no -> portal (127.0.0.1:3050). # # bootstrap.sh first time on a fresh host: renders configs from # .env, makes Kanidm's internal cert, starts it all, @@ -14,6 +16,11 @@ name: tomtervel services: caddy: + # Bundled TLS for a standalone host only: `podman compose --profile edge up`. + # On kasse the host Caddy already owns 80/443 (it reverse-proxies + # vel.klingenbergbygg.no -> 127.0.0.1:3050, the portal port below), so this + # is profiled off there to avoid the port clash. Default `up` skips it. + profiles: ["edge"] image: caddy:2 restart: unless-stopped ports: @@ -73,6 +80,11 @@ services: LEPTOS_SITE_ADDR: 0.0.0.0:3000 LEPTOS_SITE_ROOT: site LEPTOS_HASH_FILES: "true" + ports: + # Host-published for kasse's host Caddy (vel.klingenbergbygg.no -> here). + # With --profile edge the bundled Caddy proxies portal:3000 internally + # instead, but publishing loopback-only is harmless there. + - "127.0.0.1:3050:3000" depends_on: nats: condition: service_healthy