From 74c120dc3044d86800291b096e03b3d4c95eaf28 Mon Sep 17 00:00:00 2001 From: Bendik Aagaard Lynghaug Date: Mon, 28 Sep 2026 12:15:30 +0200 Subject: [PATCH] podman/caddy: fit kasse's single-front-Caddy model - caddy -> profiles: [edge]: on kasse the host Caddy already owns 80/443 and reverse-proxies vel.klingenbergbygg.no -> 127.0.0.1:3050, so the bundled Caddy is off by default (use `--profile edge` only on a standalone host) - portal publishes 127.0.0.1:3050 so the host Caddy reaches it; the existing conf.d/vel.klingenbergbygg.no target is unchanged Co-Authored-By: Claude Opus 4.8 --- compose.yml | 22 +++++++++++++++++----- 1 file changed, 17 insertions(+), 5 deletions(-) diff --git a/compose.yml b/compose.yml index 8a19626..8752cc7 100644 --- a/compose.yml +++ b/compose.yml @@ -1,8 +1,10 @@ -# Tomter Vel's own platform: one host, four containers, everything -# behind Caddy. The content (pages, forms, desks) is not here: portal -# fetches it from tomtervel/questions on prosjekt.klingenbergbygg.no -# and hot-reloads it over NATS. This repo owns the host: identity, -# the bus, TLS, and which portal version runs. +# Tomter Vel's own platform: portal + its own Kanidm and NATS as podman +# containers. The content (pages, forms, desks) is not here: portal fetches +# it from tomtervel/questions on prosjekt.klingenbergbygg.no and hot-reloads +# it over NATS. This repo owns identity, the bus, and which portal version +# runs. TLS depends on where it runs: on a standalone host the bundled Caddy +# (`--profile edge`) terminates it; on kasse the host Caddy already owns +# 80/443 and reverse-proxies vel.klingenbergbygg.no -> portal (127.0.0.1:3050). # # bootstrap.sh first time on a fresh host: renders configs from # .env, makes Kanidm's internal cert, starts it all, @@ -14,6 +16,11 @@ name: tomtervel services: caddy: + # Bundled TLS for a standalone host only: `podman compose --profile edge up`. + # On kasse the host Caddy already owns 80/443 (it reverse-proxies + # vel.klingenbergbygg.no -> 127.0.0.1:3050, the portal port below), so this + # is profiled off there to avoid the port clash. Default `up` skips it. + profiles: ["edge"] image: caddy:2 restart: unless-stopped ports: @@ -73,6 +80,11 @@ services: LEPTOS_SITE_ADDR: 0.0.0.0:3000 LEPTOS_SITE_ROOT: site LEPTOS_HASH_FILES: "true" + ports: + # Host-published for kasse's host Caddy (vel.klingenbergbygg.no -> here). + # With --profile edge the bundled Caddy proxies portal:3000 internally + # instead, but publishing loopback-only is harmless there. + - "127.0.0.1:3050:3000" depends_on: nats: condition: service_healthy