# Caddyfile for auth.74-48-78-17.nip.io (HWLAB Keycloak public HTTPS) # This Caddyfile runs on the master server and reverse-proxies HTTPS to # the G14 keycloak Service via master frps (port 28443). # # Master-side dependency tree: # # client browser # -> 74.48.78.17:443 (Caddy, this file) # -> 127.0.0.1:28443 (master frps remotePort, see frps.dev.toml) # -> G14:/root/hwlab-v02/.worktree/.../deploy/k8s/keycloak/keycloak-frpc.yaml # -> keycloak.keycloak.svc.cluster.local:8080 # # Install: download caddy 2.x from https://github.com/caddyserver/caddy/releases # Put binary at /usr/local/bin/caddy and Caddyfile at /etc/caddy/Caddyfile. # The systemd unit caddy.service goes to /etc/systemd/system/caddy.service. # Run `systemctl daemon-reload && systemctl enable --now caddy`. # Caddy will auto-request a Let's Encrypt production cert for the first # domain in the config (auth.74-48-78-17.nip.io). # To validate the chain end-to-end first, point acme_ca to staging: # # acme_ca https://acme-staging-v02.api.letsencrypt.org/directory # # Then remove the line to switch to production. { email ops@pikas.tech } auth.74-48-78-17.nip.io { encode zstd gzip reverse_proxy 127.0.0.1:28443 { header_up Host {host} header_up X-Real-IP {remote_host} transport http { dial_timeout 5s response_header_timeout 30s } } } hwlab.74-48-78-17.nip.io { encode zstd gzip reverse_proxy 127.0.0.1:19666 { header_up Host {host} header_up X-Real-IP {remote_host} transport http { dial_timeout 5s response_header_timeout 30s } } }