# Beta's loopback LB bridge config — the beta counterpart of ./Caddyfile. # # Two differences from prod's, both load-bearing: # # 1. It proxies to beta-web / beta-frontend, not web / frontend. Beta's Swarm # services carry that prefix so their short DNS names cannot collide with # prod's on the shared overlay (see thermograph-beta-stack.yml). # 2. deploy-stack.sh publishes this container on 127.0.0.1:8237 and :8180, # not 8137/8180 — prod's LB already owns 8137/8080 on this host. The # LISTEN ports below stay 8137/8080: those are inside the container, and # the host mapping is what differs. Keeping the container ports identical # to prod's means the two configs differ only in the upstream names. # # The host Caddy on vps2 terminates TLS for beta.thermograph.org and proxies to # 127.0.0.1:8237 / :8180 — see deploy/Caddyfile. { auto_https off admin off # Same reason as ./Caddyfile — see the long note there. Without it this second # Caddy hop overwrites the host Caddy's X-Forwarded-Proto: https with http, # and every OAuth redirect URI the backend builds comes out non-HTTPS, which # Google rejects outright for a web client. # # Beta needs it as much as prod does, and arguably first: beta is where an # OAuth provider change gets tested before it reaches thermograph.org. servers { trusted_proxies static private_ranges } } :8137 { reverse_proxy beta-web:8137 { # Fail fast to the client if the VIP has no healthy task; Swarm's own # task healthchecks handle ejecting dead replicas from the VIP. lb_try_duration 5s } } :8080 { reverse_proxy beta-frontend:8080 { lb_try_duration 5s } }