# The loopback LB bridge's own config — NOT the host Caddy (that one still
# terminates TLS for thermograph.org and proxies to 127.0.0.1:8137 exactly as
# before; it needs no change for the stack cutover).
#
# This Caddy runs as a PLAIN container (deploy-stack.sh manages it) because
# only plain containers can bind a specific host IP: Swarm port configs
# publish on 0.0.0.0 (routing mesh or host mode alike), which would expose
# the plaintext app un-fronted — hazard #6. It joins the stack's attachable
# overlay and proxies to the service VIPs; Swarm's VIP round-robins across
# however many web replicas the autoscaler is running, so this bridge never
# needs to know the replica count.

{
	auto_https off
	admin off
}

:8137 {
	reverse_proxy web:8137 {
		# Fail fast to the client if the VIP has no healthy task; Swarm's own
		# task healthchecks handle ejecting dead replicas from the VIP.
		lb_try_duration 5s
	}
}

:8080 {
	reverse_proxy frontend:8080 {
		lb_try_duration 5s
	}
}
