差别
这里会显示出您选择的修订版和当前版本之间的差别。
| 两侧同时换到之前的修订记录 前一修订版 | |||
| caddy [2026/06/26 06:05] – xiaobenmao | caddy [2026/06/27 08:41] (当前版本) – xiaobenmao | ||
|---|---|---|---|
| 行 49: | 行 49: | ||
| ==== Host a static site ==== | ==== Host a static site ==== | ||
| - | < | + | < |
| xiaobenmao.win { | xiaobenmao.win { | ||
| encode zstd gzip | encode zstd gzip | ||
| 行 61: | 行 61: | ||
| ==== Map to a site (reverse_proxy) ==== | ==== Map to a site (reverse_proxy) ==== | ||
| - | < | + | < |
| auth.xiaobenmao.win { | auth.xiaobenmao.win { | ||
| reverse_proxy authentik-server-1: | reverse_proxy authentik-server-1: | ||
| 行 78: | 行 78: | ||
| ==== Redirect ==== | ==== Redirect ==== | ||
| - | < | + | < |
| www.xiaobenmao.win { | www.xiaobenmao.win { | ||
| redir https:// | redir https:// | ||
| 行 84: | 行 84: | ||
| </ | </ | ||
| + | '' | ||
| + | |||
| + | ==== Authentication required page (with Authentik) ==== | ||
| + | |||
| + | <code text [enable_line_numbers=" | ||
| + | url.to.website { | ||
| + | encode zstd gzip | ||
| + | |||
| + | # Authentik outpost | ||
| + | handle / | ||
| + | reverse_proxy authentik-server-1: | ||
| + | } | ||
| + | |||
| + | # sample: no need auth for index page | ||
| + | handle index.html { | ||
| + | reverse_proxy xxx:80 | ||
| + | } | ||
| + | |||
| + | # rest pages need auth | ||
| + | handle { | ||
| + | forward_auth authentik-server-1: | ||
| + | uri / | ||
| + | copy_headers X-Authentik-Username X-Authentik-Groups X-Authentik-Email X-Authentik-Name | ||
| + | } | ||
| + | |||
| + | reverse_proxy xxx:80 | ||
| + | } | ||
| + | } | ||
| + | |||
| + | </ | ||
| + | |||
| + | Take note the '' | ||
| + | |||
| + | Then create a new forward auth provider in Authentik. Go to Applications - Providers - New Provider, select Proxy Provider, and fill in details. Select authorization flow as default-provider-authorization-implicit-consent (Authorize Application), | ||
| + | |||
| + | {{pasted: | ||
| + | |||
| + | After that, create a new application with this provider. Bind users or access groups to this application. | ||
| + | |||
| + | Add the application into default outpost (authentik Embedded Outpost) via Applications - Outposts. | ||
| + | |||
| + | Testing should have 302 response for auth required page, while the remaining pages are normal. | ||
| + | |||
| + | <code bash> | ||
| + | curl -I https:// | ||
| + | curl -I https:// | ||
| + | </ | ||