# The single front door for the whole stack. # # NO application container publishes a port. The editor has no authentication of # any kind, shells out to yt-dlp, and deletes files — so it sits on an internal # docker network and is reachable only through here. That removes the entire # class of "I published 3001 once to try something and forgot". # # Caddy publishes one port per app, and docker-compose.yml binds every one of # them to 127.0.0.1 by default — the public sites included. Nothing is reachable # off the box until you change a bind in .env. # # 8080 export site -> site:3000 public by design, no auth # 8081 editor -> editor:3001 PRIVATE: admin, no auth of its own # 8082 homepage -> homepage:3031 public by design, no auth # 8083 umtool -> umtool:3050 PRIVATE # # A port whose service isn't running (site/homepage/umtool are behind compose # profiles) answers 502. That is expected, not a misconfiguration. # # Auth is pluggable and applies to the two PRIVATE apps. docker/caddy-start.sh # picks the mode and expands {$ARCHILYZER_AUTH_IMPORT} to one of the snippets # below — or to nothing at all. See RUNNING_IN_DOCKER.md. { # No admin API: it is an unauthenticated control plane by default, and # nothing here needs it. admin off # These are plain HTTP ports behind whatever you put in front of them (or # behind nothing, on loopback). Certificate management is not this file's job. auto_https off log { output stdout format console } } # --- auth modes ------------------------------------------------------------ # Built into Caddy: nothing to install, nothing to keep running, and it cannot # break on somebody's first evening. Generate the hash with: # docker run --rm caddy:2.11-alpine caddy hash-password --plaintext 'secret' (basicauth) { basic_auth { {$ARCHILYZER_AUTH_USER:archilyzer} {$ARCHILYZER_AUTH_HASH} } } # Hand the decision to an external identity provider (Tinyauth, Authelia, …). # See docker-compose.tinyauth.yml and docker-compose.authelia.yml. (forwardauth) { forward_auth {$ARCHILYZER_FORWARD_AUTH_UPSTREAM} { uri {$ARCHILYZER_FORWARD_AUTH_URI:/api/auth/caddy} copy_headers Remote-User Remote-Groups Remote-Name Remote-Email } } # --- the four apps --------------------------------------------------------- # The export site: a static archive. Public is the whole point of it. :8080 { reverse_proxy site:3000 } # The editor. PRIVATE — this is the admin app. :8081 { {$ARCHILYZER_AUTH_IMPORT} # Server actions and log streams; the editor streams job output for as long # as a job runs, which is longer than any sensible proxy default. reverse_proxy editor:3001 { flush_interval -1 } } # The project's own site (marketing + docs). Public. :8082 { reverse_proxy homepage:3031 } # umtool. PRIVATE. :8083 { {$ARCHILYZER_AUTH_IMPORT} reverse_proxy umtool:3050 { flush_interval -1 } }