- caddy -> profiles: [edge]: on kasse the host Caddy already owns 80/443 and reverse-proxies vel.klingenbergbygg.no -> 127.0.0.1:3050, so the bundled Caddy is off by default (use `--profile edge` only on a standalone host) - portal publishes 127.0.0.1:3050 so the host Caddy reaches it; the existing conf.d/vel.klingenbergbygg.no target is unchanged Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+17
-5
@@ -1,8 +1,10 @@
|
|||||||
# Tomter Vel's own platform: one host, four containers, everything
|
# Tomter Vel's own platform: portal + its own Kanidm and NATS as podman
|
||||||
# behind Caddy. The content (pages, forms, desks) is not here: portal
|
# containers. The content (pages, forms, desks) is not here: portal fetches
|
||||||
# fetches it from tomtervel/questions on prosjekt.klingenbergbygg.no
|
# it from tomtervel/questions on prosjekt.klingenbergbygg.no and hot-reloads
|
||||||
# and hot-reloads it over NATS. This repo owns the host: identity,
|
# it over NATS. This repo owns identity, the bus, and which portal version
|
||||||
# the bus, TLS, and which portal version runs.
|
# runs. TLS depends on where it runs: on a standalone host the bundled Caddy
|
||||||
|
# (`--profile edge`) terminates it; on kasse the host Caddy already owns
|
||||||
|
# 80/443 and reverse-proxies vel.klingenbergbygg.no -> portal (127.0.0.1:3050).
|
||||||
#
|
#
|
||||||
# bootstrap.sh first time on a fresh host: renders configs from
|
# bootstrap.sh first time on a fresh host: renders configs from
|
||||||
# .env, makes Kanidm's internal cert, starts it all,
|
# .env, makes Kanidm's internal cert, starts it all,
|
||||||
@@ -14,6 +16,11 @@ name: tomtervel
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
caddy:
|
caddy:
|
||||||
|
# Bundled TLS for a standalone host only: `podman compose --profile edge up`.
|
||||||
|
# On kasse the host Caddy already owns 80/443 (it reverse-proxies
|
||||||
|
# vel.klingenbergbygg.no -> 127.0.0.1:3050, the portal port below), so this
|
||||||
|
# is profiled off there to avoid the port clash. Default `up` skips it.
|
||||||
|
profiles: ["edge"]
|
||||||
image: caddy:2
|
image: caddy:2
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
ports:
|
ports:
|
||||||
@@ -73,6 +80,11 @@ services:
|
|||||||
LEPTOS_SITE_ADDR: 0.0.0.0:3000
|
LEPTOS_SITE_ADDR: 0.0.0.0:3000
|
||||||
LEPTOS_SITE_ROOT: site
|
LEPTOS_SITE_ROOT: site
|
||||||
LEPTOS_HASH_FILES: "true"
|
LEPTOS_HASH_FILES: "true"
|
||||||
|
ports:
|
||||||
|
# Host-published for kasse's host Caddy (vel.klingenbergbygg.no -> here).
|
||||||
|
# With --profile edge the bundled Caddy proxies portal:3000 internally
|
||||||
|
# instead, but publishing loopback-only is harmless there.
|
||||||
|
- "127.0.0.1:3050:3000"
|
||||||
depends_on:
|
depends_on:
|
||||||
nats:
|
nats:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
|||||||
Reference in New Issue
Block a user