-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathCaddyfile
More file actions
107 lines (93 loc) · 2.55 KB
/
Copy pathCaddyfile
File metadata and controls
107 lines (93 loc) · 2.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
{
admin localhost:2019
email {$ACME_EMAIL}
# Enable request logging
log default {
level info
format json
output stdout
}
}
{$DOMAIN} {
encode zstd gzip
# Request logging for this domain
log {
level info
format json
output stdout
}
# Large file uploads need extended proxy timeouts (default API routes stay at 60s).
@upload_paths {
path /api/videos/upload*
path /api/voices/clone
path /api/upload/avatar
}
handle @upload_paths {
reverse_proxy backend:8000 {
health_uri /api/health
health_interval 30s
health_timeout 5s
fail_duration 30s
max_fails 2
lb_try_duration 5s
transport http {
dial_timeout 10s
response_header_timeout 30s
read_timeout 30m
write_timeout 30m
}
}
}
# API routes always go to backend
handle /api/* {
reverse_proxy backend:8000 {
# Active health check against backend health endpoint
health_uri /api/health
health_interval 30s
health_timeout 5s
# Passive health behavior to avoid hanging on unhealthy upstreams
fail_duration 30s
max_fails 2
lb_try_duration 5s
# Upstream transport timeouts
transport http {
dial_timeout 10s
response_header_timeout 30s
read_timeout 60s
write_timeout 60s
}
}
}
# All other routes are served by the SPA with index fallback
handle {
root * /srv
try_files {path} /index.html
file_server
}
# Basic hardening headers
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
X-Content-Type-Options "nosniff"
X-Frame-Options "DENY"
Referrer-Policy "strict-origin-when-cross-origin"
-Server
}
}
minio.{$DOMAIN} {
reverse_proxy minio:9001
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains"
X-Content-Type-Options "nosniff"
Referrer-Policy "strict-origin-when-cross-origin"
-Server
}
}
flower.{$DOMAIN} {
reverse_proxy flower:5555
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains"
X-Content-Type-Options "nosniff"
Referrer-Policy "strict-origin-when-cross-origin"
-Server
}
}