From 8ee44cad92e87348b568a251f7e2be565db65b7f Mon Sep 17 00:00:00 2001 From: John Anderson Date: Wed, 8 Jul 2026 16:59:55 +0100 Subject: [PATCH] Add caddy/Caddyfile --- caddy/Caddyfile | 267 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 267 insertions(+) create mode 100644 caddy/Caddyfile diff --git a/caddy/Caddyfile b/caddy/Caddyfile new file mode 100644 index 0000000..5aeba0d --- /dev/null +++ b/caddy/Caddyfile @@ -0,0 +1,267 @@ +# Caddyfile on production cluster +{ + # Global options, omly one such block at the head of the file + servers { + trusted_proxies static 192.168.1.0/24 10.0.0.0/24 2a00:23c6::/32 + } + # make admin available to all trusted nodes on the network + admin :2019 + metrics +} +# + +# +# For Authelia +# +(trusted_proxy_list) { + trusted_proxies 192.168.1.0/24 10.0.0.0/24 2a00:23c6::/32 +} + +(secure_site) { + forward_auth {args[0]} 192.168.1.21:9091 { + uri /api/verify?rd=https://auth.home.johnsnexus.click + copy_headers Remote-User Remote-Groups Remote-Name Remote-Email + import trusted_proxy_list + header_up Host {upstream_hostport} + } +} +# +# it appears you need this to allow prometheus on a remote node to scrape the metrics +:2019 { + handle { + metrics + } +} +# +# Snippet for basic authorisation +# +(basic-auth) { + basic_auth { + john.anderson $2a$10$4ka55bXqNBpoQcBDrJtd5OQje6Nt/HmvRNAGavqO03xq/Noth5xH. + mary.anderson $2a$10$UOuB5DpDcKRho0rRPDCmCeFlDSx/f6Bkwqpw8CEeQCbAGA0yULcny + frazer.anderson $2a$10$UleGw5O0BB18XtSenFSawudO.qKbNVMFU772XMP4cAAUbWzRo/zr6 + chris.anderson $2a$10$1MeL9m8M7FW/k6/DW3HB1.rkijS3qao8RraNO/tJKN8OuRTCzc3fK + ruth.hoyos $2a$10$9z/3SajAWhxJfu6Xs1lbEeuPpZWUzcuBI/8n5hfv5FUqt11Uxo92S + sarah.anderson-beecham $2a$10$.8J1FMBwGDr8XSXCMWcn2ODxSW6txLEqSBHZmA6zQs8qQCDT2KbR2 + fiona.green $2a$10$Nid0Lg6Wauwi/5BN4N2H5u8T6XumK4EE2MBxZaKXajxUAuUXPEvGO + helen.crichton $2a$10$zOcnxMCr62NtNK3YTaWbRuOclI/lC1Lkn1RidTOxkgBTgruQgfg9K + david.rawsthorne $2a$10$OIALdPjjQT6i5exUg8GtmOGk4BD4WmanmDhF7wCVH/IbpQQSt6PAS + peter.rawsthorne $2a$10$asUwJpdwc4QlGc8b1A1v7ukBCIQTlzm59uRnBH6AnWiK6NAECW03S + marilyn.pope $2a$10$6iD1J3FVmFbY7i02gQaF0eu1fY4ufUsXiXMyc1G9YfXbYKwuamjI2 + alan.potts $2a$10$tzbIZwIuzcdrIzJICIS1oeadwoKyr3JqL2Ec9aB8Dj.MR4Q7lMcV. + kate.griffin $2a$10$9R57yOgGilEPZNwCbjWHeOu/ytTv4SLbW0P/plRnI.GqHe3w3IJjO + craig.johnson $2a$10$LQf3tK0ZHl63LHybpDfSdu1WT9OtcLeNZTfCwniPlmuqHiNF.yOq6 + grant.johnson $2a$10$7XZ3aoQdL/fLex48t6hgi.p9Xt3yNJNIXJKflxChprwT5O9zPy2hG + barbara.wright $2a$10$Mlp0Y2wPzzomL1EnTInS2u18yv7ksMY.ATURzQz4luRRe2JwBMEJS + janet.kennedy $2a$10$/8VCpm68CLSF2zSL5sHtR.hzwJ.h3cX3r8XHogHbz8o7KIYPDHOVW + } +# respond "Welcome, {http.auth.user.id}" 200 +} +# +# Authelia running on Production Cluster +# +auth.home.johnsnexus.click { + reverse_proxy 192.168.1.21:9091 { + import trusted_proxy_list + } +} +# +# Portainer running on PROXMOX cluster +# +port.home.johnsnexus.click { + reverse_proxy https://192.168.1.240:9443 { + transport http { + tls + tls_insecure_skip_verify + } + } +} +# +# Locally hosted site +# +testcaddy.home.johnsnexus.click { + root * /usr/share/caddy # compose file points to this + php_fastcgi 192.168.1.11:80 + file_server +} +# +# Family history web site via container on this cluster +# +sandancer.ddnsfree.com { + root * /var/www/html + file_server + reverse_proxy 192.168.1.243:8081 +# reverse_proxy famhistweb_famhistweb +} +# +# Family History Web Site on virtual machine on PROXMOX cluster +nginx.home.johnsnexus.click { + reverse_proxy 192.168.1.243:80 +} +# +famhist.home.johnsnexus.click { + root * /var/www/html + file_server + reverse_proxy 192.168.1.243:8081 +} +# +# PocketID OIDC security, come here from DYNU, running on PROXMOX cluster +# +https://hold.johnsnexus.click { + reverse_proxy 192.168.1.238:1411 +} +# +# Test GHOST site on BETA +# +#ghost.johnsnexus.click { +# root * /var/www/mymag +# file_server +# reverse_proxy 192.168.1.9:2368 +#} +# +# Fanily History Web site on Production cluster system, come here via BIND9 +# +nextfam.home.johnsnexus.click { +# import secure_site * +# root * /mnt/disk/NextFamilyWeb + file_server + reverse_proxy 192.168.1.243:8082 { + import trusted_proxy_list + } +} +# +# Test web site on Production Cluster, come here via BIND9 +# +northweb.home.johnsnexus.click { + import secure_site * + file_server + reverse_proxy 192.168.1.243:8083 +} +# +# Test version of paperless-ngx on OMEGA come here via BIND9 +# +wastebin.johnsnexus.click { + file_server + reverse_proxy 192.168.1.5:8600 +} +# +# Version of pydio cells on NODE-16 using SAMBA volume - DYNU public address +# +#pydiocells.johnsnexus.click { +# tls tls@johnsnexus.click +# reverse_proxy 192.168.1.4:8888 { +# transport http { +# tls +# tls_insecure_skip_verify +# } +# } +#} +# +# NEXTCLOUDAIO on virtual node 22, via DYNU +# +amudanan.johnsnexus.click { + file_server + reverse_proxy 192.168.1.22:11000 +} +# +#codeamud.johnsnexus.click { +# file_server +# reverse_proxy 192.168.1.26:9980 { +# header_up X-Forwarded-Proto {scheme} +# transport http { +# tls_insecure_skip_verify +# } +# } +#} +# +# OWNCLOUD on vmnode21 +# +mycloud.johnsnexus.click { + header Strict-Transport-Security max-age=15552000 + file_server + reverse_proxy 192.168.1.21:8080 +} +# +code.johnsnexus.click { + file_server + reverse_proxy 192.168.1.21:9980 { + header_up X-Forwarded-Proto {scheme} +# transport http { +# tls_insecure_skip_verify +# } + } +} +# +# Vaultwarden on PROXMOX Cluster +# +warden.johnsnexus.click { + reverse_proxy https://192.168.1.25:8000 { + transport http { + tls + tls_insecure_skip_verify + } + } +} +# +# SongKong on VALHALLA, come here via DYNU +https://chord.johnsnexus.click { + root * /music + file_server + reverse_proxy http://192.168.1.7:4567 +} +## +# n8n running on DELTA, come here via DYNU +# +#donut.johnsnexus.click { +# reverse_proxy http://192.168.1.10:5678 { +# flush_interval -1 +# } +#} +# +# CTiO magazine using NICEPAGE on PROXMOX Cluster +# two ways to access +# +ctio.johnsnexus.click { + file_server + reverse_proxy 192.168.1.243:8084 +} +# +#**************************************** +# +# Needs SSL; +# +hoard.johnsnexus.click { + reverse_proxy 192.168.1.234:3000 +} +# +# runs on virtual LXC +# +https://grafana.home.johnsnexus.click { + file_server + reverse_proxy 192.168.1.236:3000 +} +# +# runs on virtual node 21; not sure about additional line! +# +lldap.home.johnsnexus.click { + reverse_proxy 192.168.1.21:17170 { + header_up Host {http.request.host} + } +} +# +# copy of mygit on the proxmox cluster +gitea.home.johnsnexus.click { + file_server + reverse_proxy 192.168.1.235:3000 +} +# +# now a virtual container on PROXMOX +gotify.home.johnsnexus.click { + reverse_proxy 192.168.1.230:80 +} +# +# New home assistant, running under docker on NODE-16 via wireless +https://have.johnsnexus.click { + file_server + reverse_proxy 192.168.1.16:8123 +} \ No newline at end of file