====== Caddy ====== Caddy can manage https certificate automatically. ===== Install ===== services: caddy: image: caddy:latest container_name: caddy restart: unless-stopped networks: - web ports: - "80:80" - "443:443" volumes: - ./Caddyfile:/etc/caddy/Caddyfile - ./data:/data - ./config:/config networks: web: external: true Then run in docker cd ~/services/caddy docker compose up -d ===== Config ===== Write ''Caddyfile'' to map your site. For any change in ''Caddyfile'' during its run, reload it using cd ~/services/caddy docker compose exec caddy caddy validate --config /etc/caddy/Caddyfile && \ docker compose exec caddy caddy reload --config /etc/caddy/Caddyfile ==== Host a static site ==== xiaobenmao.win { encode zstd gzip root * /srv/www file_server } Need to ensure the root path in docker container, here ''/srv/www'', mapped to a real directory using the ''compose.yml''. ==== Map to a site (reverse_proxy) ==== auth.xiaobenmao.win { reverse_proxy authentik-server-1:9000 } bits.xiaobenmao.win { reverse_proxy bits-wordpress:80 } wiki.xiaobenmao.win { reverse_proxy pkb:8080 } ==== Redirect ==== www.xiaobenmao.win { redir https://xiaobenmao.win{uri} } ''{uri}'' will copy all path and parameters as-is to the redirected one. ==== Authentication required page (with Authentik) ==== url.to.website { encode zstd gzip # Authentik outpost handle /outpost.goauthentik.io/* { reverse_proxy authentik-server-1:9000 } # sample: no need auth for index page handle index.html { reverse_proxy xxx:80 } # rest pages need auth handle { forward_auth authentik-server-1:9000 { uri /outpost.goauthentik.io/auth/caddy copy_headers X-Authentik-Username X-Authentik-Groups X-Authentik-Email X-Authentik-Name } reverse_proxy xxx:80 } } Take note the ''caddy'' in ''uri /outpost.goauthentik.io/auth/caddy'' specify the host program, alternatives like ''/outpost.goauthentik.io/auth/nginx'' for Nginx and ''/outpost.goauthentik.io/auth/traefik'' for Traefik. Do not change it. Then create a new forward auth provider in Authentik. Go to Applications - Providers - New Provider, select Proxy Provider, and fill in details. Select authorization flow as default-provider-authorization-implicit-consent (Authorize Application), and type forward auth (single application). {{pasted:20260627-080759.png?500}}{{pasted:20260627-080818.png?500}} After that, create a new application with this provider. Bind users or access groups to this application. Add the application into default outpost (authentik Embedded Outpost) via Applications - Outposts. Testing should have 302 response for auth required page, while the remaining pages are normal. curl -I https://url.to.website/index.html curl -I https://url.to.website/test.html