# The single front door for the whole stack.
#
# NO application container publishes a port. The editor has no authentication of
# any kind, shells out to yt-dlp, and deletes files — so it sits on an internal
# docker network and is reachable only through here. That removes the entire
# class of "I published 3001 once to try something and forgot".
#
# Caddy publishes one port per app, and docker-compose.yml binds every one of
# them to 127.0.0.1 by default — the public sites included. Nothing is reachable
# off the box until you change a bind in .env.
#
#   8080  export site   -> site:3000       public by design, no auth
#   8081  editor        -> editor:3001     PRIVATE: admin, no auth of its own
#   8082  homepage      -> homepage:3031   public by design, no auth
#   8083  umtool        -> umtool:3050     PRIVATE
#
# A port whose service isn't running (site/homepage/umtool are behind compose
# profiles) answers 502. That is expected, not a misconfiguration.
#
# Auth is pluggable and applies to the two PRIVATE apps. docker/caddy-start.sh
# picks the mode and expands {$ARCHILYZER_AUTH_IMPORT} to one of the snippets
# below — or to nothing at all. See RUNNING_IN_DOCKER.md.

{
	# No admin API: it is an unauthenticated control plane by default, and
	# nothing here needs it.
	admin off
	# These are plain HTTP ports behind whatever you put in front of them (or
	# behind nothing, on loopback). Certificate management is not this file's job.
	auto_https off
	log {
		output stdout
		format console
	}
}

# --- auth modes ------------------------------------------------------------
# Built into Caddy: nothing to install, nothing to keep running, and it cannot
# break on somebody's first evening. Generate the hash with:
#   docker run --rm caddy:2.11-alpine caddy hash-password --plaintext 'secret'
(basicauth) {
	basic_auth {
		{$ARCHILYZER_AUTH_USER:archilyzer} {$ARCHILYZER_AUTH_HASH}
	}
}

# Hand the decision to an external identity provider (Tinyauth, Authelia, …).
# See docker-compose.tinyauth.yml and docker-compose.authelia.yml.
(forwardauth) {
	forward_auth {$ARCHILYZER_FORWARD_AUTH_UPSTREAM} {
		uri {$ARCHILYZER_FORWARD_AUTH_URI:/api/auth/caddy}
		copy_headers Remote-User Remote-Groups Remote-Name Remote-Email
	}
}

# --- the four apps ---------------------------------------------------------

# The export site: a static archive. Public is the whole point of it.
:8080 {
	reverse_proxy site:3000
}

# The editor. PRIVATE — this is the admin app.
:8081 {
	{$ARCHILYZER_AUTH_IMPORT}
	# Server actions and log streams; the editor streams job output for as long
	# as a job runs, which is longer than any sensible proxy default.
	reverse_proxy editor:3001 {
		flush_interval -1
	}
}

# The project's own site (marketing + docs). Public.
:8082 {
	reverse_proxy homepage:3031
}

# umtool. PRIVATE.
:8083 {
	{$ARCHILYZER_AUTH_IMPORT}
	reverse_proxy umtool:3050 {
		flush_interval -1
	}
}
