Clean initial state: removed all wrapper scripts and debug code. deploy_script.sh and the dev server are the only files that should drive the next deploy.
This commit is contained in:
commit
8c8ee6b4be
9 files changed
+128
No files matched your search
+32
@@ -0,0 +1,32 @@
|
||||
# Environment files (contain secrets)
|
||||
**/.env
|
||||
|
||||
# AGE private key (never commit)
|
||||
**/age-key.txt
|
||||
|
||||
# OS files
|
||||
.DS_Store
|
||||
Thumbs.db
|
||||
|
||||
# Editor files
|
||||
*.swp
|
||||
*.swo
|
||||
*~
|
||||
.vscode/
|
||||
.idea/
|
||||
|
||||
# Temporary scratch folder
|
||||
scratch/
|
||||
|
||||
# Generated additions
|
||||
temp.txt
|
||||
*.tmp
|
||||
*.log
|
||||
.venv/
|
||||
|
||||
# Caddy fragments directory (assembled by deploy_script.sh from each service's *.caddy)
|
||||
services/caddy/fragments/
|
||||
|
||||
# Local docker save backups (don't accidentally commit these — too big)
|
||||
paperclip-image.tar
|
||||
paperclip-image.tar.gz
|
||||
@@ -0,0 +1 @@
|
||||
age1sa3q5qxl5dylld7v839m9lkv5h7l457wq4h40pt7kfmcfhcqkfjqspdjpn
|
||||
@@ -0,0 +1,9 @@
|
||||
{
|
||||
# Caddy global options
|
||||
# admin off disables the admin API endpoint (security)
|
||||
admin off
|
||||
}
|
||||
|
||||
# Import all service-specific reverse-proxy fragments.
|
||||
# The deploy_script.sh assembles these from services/*/*.caddy at every run.
|
||||
import /etc/caddy/fragments/*.caddy
|
||||
@@ -0,0 +1,24 @@
|
||||
# Caddy Reverse Proxy
|
||||
|
||||
Caddy container that terminates HTTPS (Let's Encrypt) and routes traffic to PaperClip.
|
||||
|
||||
## How it works
|
||||
|
||||
- `docker-compose.yml` mounts `/mnt/Jannik-Cloud-Volume-01/caddy/` into the container:
|
||||
- `Caddyfile` — main config, imports all `*.caddy` fragments from `fragments/`
|
||||
- `fragments/` — per-service reverse-proxy definitions, assembled by `deploy_script.sh`
|
||||
- `data/`, `config/` — Caddy cert + state storage
|
||||
- Only ports 80 and 443 are exposed to the host
|
||||
- PaperClip itself binds only on the internal `paperclip-net` Docker network
|
||||
|
||||
## Adding new subdomains
|
||||
|
||||
Drop a `<name>.caddy` file into `services/<name>/` with:
|
||||
|
||||
```caddyfile
|
||||
subdomain.orfel.de {
|
||||
reverse_proxy <container-name>:<port>
|
||||
}
|
||||
```
|
||||
|
||||
The deploy script picks it up automatically.
|
||||
@@ -0,0 +1,30 @@
|
||||
services:
|
||||
caddy:
|
||||
image: caddy:2-alpine
|
||||
container_name: caddy
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- "80:80"
|
||||
- "443:443"
|
||||
# Mount a custom resolv.conf that has BOTH Docker's embedded DNS
|
||||
# (127.0.0.11, for service discovery of 'postgres' and 'paperclip')
|
||||
# AND public IPv6-capable resolvers (for ACME's letsencrypt.org).
|
||||
# Don't use docker-compose's `dns:` option — it REPLACES the default
|
||||
# 127.0.0.11 entry, breaking service discovery.
|
||||
volumes:
|
||||
- ./Caddyfile:/etc/caddy/Caddyfile:ro
|
||||
- ./fragments:/etc/caddy/fragments:ro
|
||||
- ./resolv.conf:/etc/resolv.conf:ro
|
||||
- caddy_data:/data
|
||||
- caddy_config:/config
|
||||
networks:
|
||||
- paperclip-net
|
||||
|
||||
|
||||
networks:
|
||||
paperclip-net:
|
||||
external: true
|
||||
|
||||
volumes:
|
||||
caddy_data:
|
||||
caddy_config:
|
||||
@@ -0,0 +1,9 @@
|
||||
# Used by both Caddy and Paperclip containers on the IPv6-only host.
|
||||
# - 127.0.0.11 = Docker's embedded DNS for service discovery (postgres, paperclip)
|
||||
# - 1.1.1.1, 8.8.8.8, and 2606:4700:4700::1111 = public DNS for external hosts
|
||||
# (acme-v02.api.letsencrypt.org, registry.npmjs.org, etc.)
|
||||
nameserver 127.0.0.11
|
||||
nameserver 1.1.1.1
|
||||
nameserver 8.8.8.8
|
||||
nameserver 2606:4700:4700::1111
|
||||
options edns0 trust-ad ndots:0
|
||||
@@ -0,0 +1 @@
|
||||
This file enables the service for deployment.
|
||||
Executable
+21
@@ -0,0 +1,21 @@
|
||||
#!/usr/bin/env bash
|
||||
###############################################################################
|
||||
# caddy service.init — runs before Caddy container starts
|
||||
# Ensures the Caddyfile and fragments/ directory exist where the container
|
||||
# expects them (relative to this service directory).
|
||||
###############################################################################
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
||||
FRAGMENTS_DIR="${SCRIPT_DIR}/fragments"
|
||||
|
||||
log() { echo -e "\e[32m[CADDY-INIT]\e[0m $*"; }
|
||||
|
||||
mkdir -p "${FRAGMENTS_DIR}"
|
||||
log "Fragments directory ready: ${FRAGMENTS_DIR}"
|
||||
|
||||
if [[ ! -f "${SCRIPT_DIR}/Caddyfile" ]]; then
|
||||
echo -e "\e[31m[CADDY-INIT][ERROR]\e[0m Caddyfile missing at ${SCRIPT_DIR}/Caddyfile"
|
||||
exit 1
|
||||
fi
|
||||
log "Caddyfile present at ${SCRIPT_DIR}/Caddyfile"
|
||||
@@ -0,0 +1 @@
|
||||
This file enables the service for deployment.
|
||||
Reference in new issue
Block a user