-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathCaddyfile
More file actions
44 lines (37 loc) · 1.2 KB
/
Copy pathCaddyfile
File metadata and controls
44 lines (37 loc) · 1.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
# Solarch — single-origin reverse proxy (Caddy). Copy to /etc/caddy/Caddyfile.
# Replace DOMAIN with your hostname. Caddy handles HTTPS (Let's Encrypt) automatically.
#
# Single origin: frontend and /api share one host so cookies and API keys stay on one origin.
# www → apex redirect (avoid split-host issues).
www.DOMAIN {
redir https://DOMAIN{uri} permanent
}
DOMAIN {
encode zstd gzip
# /api/* → backend (listens on loopback only). Caddy adds X-Forwarded-*;
# backend trust proxy=1 for correct client IP (rate limits).
handle /api/* {
reverse_proxy 127.0.0.1:4000
}
# Remaining paths → Vite static build (SPA). try_files falls back to index.html.
handle {
root * /var/www/solarch/dist
try_files {path} /index.html
file_server
# Hashed assets are immutable; index.html no-cache (new deploy must not serve stale HTML
# referencing old asset hashes).
@assets path /assets/*
header @assets Cache-Control "public, max-age=31536000, immutable"
@html path /index.html /
header @html Cache-Control "no-cache"
}
header {
-Server
Referrer-Policy strict-origin-when-cross-origin
X-Content-Type-Options nosniff
X-Frame-Options DENY
}
log {
output file /var/log/caddy/solarch.log
}
}