#!/bin/sh # Entrypoint for the caddy service. Runs the exposure rail, decides which auth # snippet the Caddyfile imports, then execs caddy. # # The Caddyfile cannot decide this for itself: there is no "apply this directive # only if an env var is non-empty" in Caddyfile syntax. What there IS is env # substitution over the raw file before it is parsed, and that substitution can # expand to more than one token — so {$ARCHILYZER_AUTH_IMPORT} becomes either # `import basicauth`, `import forwardauth`, or nothing at all. # # POSIX sh: caddy:alpine ships busybox. set -eu /etc/archilyzer/guard-exposure.sh case "${ARCHILYZER_AUTH_MODE:-basic}" in none) ARCHILYZER_AUTH_IMPORT="" echo "[caddy] auth: none (ARCHILYZER_AUTH_MODE=none)" ;; forward) if [ -z "${ARCHILYZER_FORWARD_AUTH_UPSTREAM:-}" ]; then echo "[caddy] ARCHILYZER_AUTH_MODE=forward needs ARCHILYZER_FORWARD_AUTH_UPSTREAM" >&2 exit 1 fi ARCHILYZER_AUTH_IMPORT="import forwardauth" echo "[caddy] auth: forward_auth -> ${ARCHILYZER_FORWARD_AUTH_UPSTREAM}" ;; basic) if [ -n "${ARCHILYZER_AUTH_HASH:-}" ]; then ARCHILYZER_AUTH_IMPORT="import basicauth" echo "[caddy] auth: basic_auth as '${ARCHILYZER_AUTH_USER:-archilyzer}'" else # Allowed only because the rail above already proved every private app # is on loopback. ARCHILYZER_AUTH_IMPORT="" echo "[caddy] auth: none — no ARCHILYZER_AUTH_HASH set, admin apps are loopback-only" fi ;; *) echo "[caddy] unknown ARCHILYZER_AUTH_MODE='${ARCHILYZER_AUTH_MODE}' (basic|forward|none)" >&2 exit 1 ;; esac export ARCHILYZER_AUTH_IMPORT exec caddy run --config /etc/caddy/Caddyfile --adapter caddyfile