40 lines
1.2 KiB
Caddyfile
40 lines
1.2 KiB
Caddyfile
# Caddyfile for pocket-id stack.
|
|
#
|
|
# Auto-issues a Let's Encrypt cert for $POCKETID_DOMAIN and reverse-proxies
|
|
# to anubis-pid (which forwards to pocket-id after the PoW challenge).
|
|
#
|
|
# To skip anubis, change the reverse_proxy target to `pocket-id:1411`.
|
|
{
|
|
email {$ACME_EMAIL}
|
|
# Uncomment for staging certs while testing (avoids LE rate limits):
|
|
# acme_ca https://acme-staging-v02.api.letsencrypt.org/directory
|
|
}
|
|
|
|
{$POCKETID_DOMAIN} {
|
|
encode zstd gzip
|
|
|
|
# Forward through anubis (PoW anti-bot) -> pocket-id.
|
|
reverse_proxy anubis-pid:8923 {
|
|
header_up X-Real-IP {remote_host}
|
|
header_up X-Forwarded-For {remote_host}
|
|
header_up X-Forwarded-Proto {scheme}
|
|
header_up X-Forwarded-Host {host}
|
|
}
|
|
|
|
# Sensible security headers. Adjust CSP if you embed pocket-id elsewhere.
|
|
header {
|
|
Strict-Transport-Security "max-age=31536000; includeSubDomains"
|
|
X-Content-Type-Options "nosniff"
|
|
X-Frame-Options "DENY"
|
|
Referrer-Policy "strict-origin-when-cross-origin"
|
|
Permissions-Policy "interest-cohort=()"
|
|
-Server
|
|
}
|
|
|
|
log {
|
|
output stdout
|
|
format console
|
|
}
|
|
}
|