Files

4.1 KiB

Global Caddy Proxy

Use scripts/register-global-caddy-proxy.sh to register one cloud's public domains into a shared Caddy proxy.

For an end-to-end multi-instance host setup, use:

./scripts/setup-shared-host-global-caddy.sh

If a cloud previously used a nonstandard bundled-SSL HTTPS port such as 444, make sure its no-SSL env is normalized to the shared proxy's real public HTTPS port via PUBLIC_HTTPS_PORT before syncing overwrite URLs. The helper script does this automatically, defaulting to 443 unless you pass --public-https-port.

This is intended for clouds running the no-SSL stack:

  • docker-compose.devprod.nossl.yml
  • or any equivalent setup where Nextcloud/Broker/optional Office/Talk are published on host ports

Why

  • One proxy can terminate TLS for multiple cloud instances.
  • Cloud app containers can be recreated independently from the proxy.
  • You avoid running one dedicated TLS proxy container per cloud.

Modes

Register into an existing Caddy config directory

If you already have a global Caddy container or host install and its config directory is mounted on disk:

./scripts/register-global-caddy-proxy.sh \
  --env-file .env.devprod \
  --target-dir /srv/global-caddy \
  --reload \
  --container-name global_caddy

Expected layout:

  • /srv/global-caddy/Caddyfile
  • /srv/global-caddy/sites/

The root Caddyfile should import:

import /etc/caddy/sites/*.caddy

If that shared Caddy is running in Docker, its upstream host must be host.docker.internal instead of 127.0.0.1, because the no-SSL clouds publish on the Docker host's loopback ports, not inside the Caddy container. The registration script now auto-detects the bootstrapped container layout and picks host.docker.internal; for any other manually managed containerized global Caddy, pass:

--upstream-host host.docker.internal

Containerized shared Caddy also requires the no-SSL cloud upstreams to bind on a non-loopback host interface. In each cloud env, set at least:

DEVPROD_HTTP_BIND_HOST=0.0.0.0
DEVPROD_BROKER_BIND_HOST=0.0.0.0

And if those profiles are enabled:

COLLABORA_BIND_HOST=0.0.0.0
TALK_RECORDING_BIND_HOST=0.0.0.0

Then recreate the no-SSL cloud stack so those new bind hosts take effect.

If a cloud env defines one of these:

QORTAL_PUBLIC_GATEWAY_URL=
QORTAL_GATEWAY_PUBLIC_URL=
QORTAL_GATEWAY_URL=

the registration script will also publish a Qortal gateway site block for that host, proxied to QORTAL_NODE_GATEWAY_HOST_PORT. For a containerized shared Caddy, set:

QORTAL_NODE_GATEWAY_BIND_HOST=0.0.0.0

Bootstrap a standalone shared Caddy container

./scripts/register-global-caddy-proxy.sh \
  --env-file .env.devprod \
  --target-dir ./deploy/global-caddy \
  --bootstrap \
  --start \
  --reload \
  --container-name global_caddy

This creates:

  • deploy/global-caddy/Caddyfile
  • deploy/global-caddy/docker-compose.yml
  • deploy/global-caddy/sites/
  • deploy/global-caddy/data/
  • deploy/global-caddy/config/

The bootstrapped container proxies to host.docker.internal, so it can reach the host-published cloud ports.

Defaults

  • Existing/non-bootstrap target: upstream host defaults to 127.0.0.1
  • Bootstrapped container target: upstream host defaults to host.docker.internal
  • Site file id defaults from NEXTCLOUD_DOMAIN

Notes

  • Optional office and talk site blocks are only generated when those profiles are enabled in COMPOSE_PROFILES.
  • For office, run scripts/ensure-nextcloud-office-config.sh after proxy/domain changes to enable richdocuments and align wopi_url / public_wopi_url.
  • Talk signaling proxies to the host-published TALK_SIGNALING_PORT. The talk_hpb container target remains TALK_SIGNALING_CONTAINER_PORT=8081, which lets multi-instance hosts use unique public signaling ports.
  • TURN traffic is still direct on TALK_TURN_PORT; it is not proxied through Caddy.
  • After moving a cloud behind an external/global proxy, run:
./scripts/ensure-nextcloud-url-config.sh \
  --compose-file docker-compose.devprod.nossl.yml \
  --env-file .env.devprod