# Only the block below (from "git.thermograph.org, dev.jinemi.com {") goes into # the live Caddyfile — append just that part, not this instructional header, or # it ends up as a confusing orphaned comment in production config with no # surrounding context (docker-stack.yml isn't visible from there). # # Target: /etc/caddy/Caddyfile on vps1 (the box `forgejo` is pinned to — see # docker-stack.yml; this is the box also called "vps1", 75.119.132.91). # Reuses vps1's existing Caddy instead of a second reverse proxy/ACME flow: # Forgejo publishes its web UI to 127.0.0.1:3080 only (host-local), and this # block is the only thing that ever talks to it. # # TWO hostnames, ONE block, and that is load-bearing — see "Registry exposure" # below. Both names must share a site block so the /v2/* restriction covers # both. Splitting dev.jinemi.com into its own block serves the same Forgejo # with the registry API open to the public internet. # # dev.jinemi.com is CANONICAL — it is Forgejo's ROOT_URL (docker-stack.yml, # FORGEJO_DOMAIN), so it is the name Forgejo puts in clone URLs, the OAuth # callback, webhook payload URLs and mail links. # # git.thermograph.org is kept as a served alias, NOT as dead weight: the # registry host baked into image names, the mesh /etc/hosts pins and the # runners' registered instance URL all still say git.thermograph.org. Removing # this name from the block breaks CI, not just old bookmarks. Both names get # their own Let's Encrypt cert automatically (HTTP-01); both A records point # at vps1. See README.md, "Migrating the domain". # # Registry exposure (hazard #15, see docker-stack.yml's header comment): # /v2/* is the built-in OCI registry API. It's blocked from anywhere except # the WireGuard mesh (10.10.0.0/24) — reachable to CI runners and Swarm nodes # over wg0, not from the public internet. Everything else (web UI, # git-over-HTTP, PR pages) stays public like the rest of the site. # --- copy from here down into /etc/caddy/Caddyfile --- git.thermograph.org, dev.jinemi.com { encode zstd gzip @registry_external { path /v2/* not remote_ip 10.10.0.0/24 } respond @registry_external 403 reverse_proxy 127.0.0.1:3080 log { output file /var/log/caddy/git.log } }