====== Caddy ======
Caddy can manage https certificate automatically.
===== Install =====
services:
caddy:
image: caddy:latest
container_name: caddy
restart: unless-stopped
networks:
- web
ports:
- "80:80"
- "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile
- ./data:/data
- ./config:/config
networks:
web:
external: true
Then run in docker
cd ~/services/caddy
docker compose up -d
===== Config =====
Write ''Caddyfile'' to map your site.
For any change in ''Caddyfile'' during its run, reload it using
cd ~/services/caddy
docker compose exec caddy caddy validate --config /etc/caddy/Caddyfile && \
docker compose exec caddy caddy reload --config /etc/caddy/Caddyfile
==== Host a static site ====
xiaobenmao.win {
encode zstd gzip
root * /srv/www
file_server
}
Need to ensure the root path in docker container, here ''/srv/www'', mapped to a real directory using the ''compose.yml''.
==== Map to a site (reverse_proxy) ====
auth.xiaobenmao.win {
reverse_proxy authentik-server-1:9000
}
bits.xiaobenmao.win {
reverse_proxy bits-wordpress:80
}
wiki.xiaobenmao.win {
reverse_proxy pkb:8080
}
==== Redirect ====
www.xiaobenmao.win {
redir https://xiaobenmao.win{uri}
}
''{uri}'' will copy all path and parameters as-is to the redirected one.
==== Authentication required page (with Authentik) ====
url.to.website {
encode zstd gzip
# Authentik outpost
handle /outpost.goauthentik.io/* {
reverse_proxy authentik-server-1:9000
}
# sample: no need auth for index page
handle index.html {
reverse_proxy xxx:80
}
# rest pages need auth
handle {
forward_auth authentik-server-1:9000 {
uri /outpost.goauthentik.io/auth/caddy
copy_headers X-Authentik-Username X-Authentik-Groups X-Authentik-Email X-Authentik-Name
}
reverse_proxy xxx:80
}
}
Take note the ''caddy'' in ''uri /outpost.goauthentik.io/auth/caddy'' specify the host program, alternatives like ''/outpost.goauthentik.io/auth/nginx'' for Nginx and ''/outpost.goauthentik.io/auth/traefik'' for Traefik. Do not change it.
Then create a new forward auth provider in Authentik. Go to Applications - Providers - New Provider, select Proxy Provider, and fill in details. Select authorization flow as default-provider-authorization-implicit-consent (Authorize Application), and type forward auth (single application).
{{pasted:20260627-080759.png?500}}{{pasted:20260627-080818.png?500}}
After that, create a new application with this provider. Bind users or access groups to this application.
Add the application into default outpost (authentik Embedded Outpost) via Applications - Outposts.
Testing should have 302 response for auth required page, while the remaining pages are normal.
curl -I https://url.to.website/index.html
curl -I https://url.to.website/test.html