Clean initial state: removed all wrapper scripts and debug code. deploy_script.sh and the dev server are the only files that should drive the next deploy.

This commit is contained in:
Jannik committed 2026-10-01 17:11:10 +02:00
commit 8c8ee6b4be
9 files changed
+128

No files matched your search

+32
View File
@@ -0,0 +1,32 @@
# Environment files (contain secrets)
**/.env
# AGE private key (never commit)
**/age-key.txt
# OS files
.DS_Store
Thumbs.db
# Editor files
*.swp
*.swo
*~
.vscode/
.idea/
# Temporary scratch folder
scratch/
# Generated additions
temp.txt
*.tmp
*.log
.venv/
# Caddy fragments directory (assembled by deploy_script.sh from each service's *.caddy)
services/caddy/fragments/
# Local docker save backups (don't accidentally commit these — too big)
paperclip-image.tar
paperclip-image.tar.gz
+1
View File
@@ -0,0 +1 @@
age1sa3q5qxl5dylld7v839m9lkv5h7l457wq4h40pt7kfmcfhcqkfjqspdjpn
+9
View File
@@ -0,0 +1,9 @@
{
# Caddy global options
# admin off disables the admin API endpoint (security)
admin off
}
# Import all service-specific reverse-proxy fragments.
# The deploy_script.sh assembles these from services/*/*.caddy at every run.
import /etc/caddy/fragments/*.caddy
+24
View File
@@ -0,0 +1,24 @@
# Caddy Reverse Proxy
Caddy container that terminates HTTPS (Let's Encrypt) and routes traffic to PaperClip.
## How it works
- `docker-compose.yml` mounts `/mnt/Jannik-Cloud-Volume-01/caddy/` into the container:
- `Caddyfile` — main config, imports all `*.caddy` fragments from `fragments/`
- `fragments/` — per-service reverse-proxy definitions, assembled by `deploy_script.sh`
- `data/`, `config/` — Caddy cert + state storage
- Only ports 80 and 443 are exposed to the host
- PaperClip itself binds only on the internal `paperclip-net` Docker network
## Adding new subdomains
Drop a `<name>.caddy` file into `services/<name>/` with:
```caddyfile
subdomain.orfel.de {
reverse_proxy <container-name>:<port>
}
```
The deploy script picks it up automatically.
+30
View File
@@ -0,0 +1,30 @@
services:
caddy:
image: caddy:2-alpine
container_name: caddy
restart: unless-stopped
ports:
- "80:80"
- "443:443"
# Mount a custom resolv.conf that has BOTH Docker's embedded DNS
# (127.0.0.11, for service discovery of 'postgres' and 'paperclip')
# AND public IPv6-capable resolvers (for ACME's letsencrypt.org).
# Don't use docker-compose's `dns:` option — it REPLACES the default
# 127.0.0.11 entry, breaking service discovery.
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile:ro
- ./fragments:/etc/caddy/fragments:ro
- ./resolv.conf:/etc/resolv.conf:ro
- caddy_data:/data
- caddy_config:/config
networks:
- paperclip-net
networks:
paperclip-net:
external: true
volumes:
caddy_data:
caddy_config:
+9
View File
@@ -0,0 +1,9 @@
# Used by both Caddy and Paperclip containers on the IPv6-only host.
# - 127.0.0.11 = Docker's embedded DNS for service discovery (postgres, paperclip)
# - 1.1.1.1, 8.8.8.8, and 2606:4700:4700::1111 = public DNS for external hosts
# (acme-v02.api.letsencrypt.org, registry.npmjs.org, etc.)
nameserver 127.0.0.11
nameserver 1.1.1.1
nameserver 8.8.8.8
nameserver 2606:4700:4700::1111
options edns0 trust-ad ndots:0
+1
View File
@@ -0,0 +1 @@
This file enables the service for deployment.
+21
View File
@@ -0,0 +1,21 @@
#!/usr/bin/env bash
###############################################################################
# caddy service.init — runs before Caddy container starts
# Ensures the Caddyfile and fragments/ directory exist where the container
# expects them (relative to this service directory).
###############################################################################
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
FRAGMENTS_DIR="${SCRIPT_DIR}/fragments"
log() { echo -e "\e[32m[CADDY-INIT]\e[0m $*"; }
mkdir -p "${FRAGMENTS_DIR}"
log "Fragments directory ready: ${FRAGMENTS_DIR}"
if [[ ! -f "${SCRIPT_DIR}/Caddyfile" ]]; then
echo -e "\e[31m[CADDY-INIT][ERROR]\e[0m Caddyfile missing at ${SCRIPT_DIR}/Caddyfile"
exit 1
fi
log "Caddyfile present at ${SCRIPT_DIR}/Caddyfile"
+1
View File
@@ -0,0 +1 @@
This file enables the service for deployment.