显示页面过去修订反向链接全部折叠/展开回到顶部 本页面只读。您可以查看源文件,但不能更改它。如果您觉得这是系统错误,请联系管理员。 ====== Caddy ====== Caddy can manage https certificate automatically. ===== Install ===== <code yaml [enable_line_numbers="true"] compose.yml> services: caddy: image: caddy:latest container_name: caddy restart: unless-stopped networks: - web ports: - "80:80" - "443:443" volumes: - ./Caddyfile:/etc/caddy/Caddyfile - ./data:/data - ./config:/config networks: web: external: true </code> Then run in docker <code bash> cd ~/services/caddy docker compose up -d </code> ===== Config ===== Write ''Caddyfile'' to map your site. For any change in ''Caddyfile'' during its run, reload it using <code bash> cd ~/services/caddy docker compose exec caddy caddy validate --config /etc/caddy/Caddyfile && \ docker compose exec caddy caddy reload --config /etc/caddy/Caddyfile </code> ==== Host a static site ==== <code text [enable_line_numbers="true"]> xiaobenmao.win { encode zstd gzip root * /srv/www file_server } </code> Need to ensure the root path in docker container, here ''/srv/www'', mapped to a real directory using the ''compose.yml''. ==== Map to a site (reverse_proxy) ==== <code text [enable_line_numbers="true"]> auth.xiaobenmao.win { reverse_proxy authentik-server-1:9000 } bits.xiaobenmao.win { reverse_proxy bits-wordpress:80 } wiki.xiaobenmao.win { reverse_proxy pkb:8080 } </code> ==== Redirect ==== <code text [enable_line_numbers="true"]> www.xiaobenmao.win { redir https://xiaobenmao.win{uri} } </code> ''{uri}'' will copy all path and parameters as-is to the redirected one. ==== Authentication required page (with Authentik) ==== <code text [enable_line_numbers="true"]> url.to.website { encode zstd gzip # Authentik outpost handle /outpost.goauthentik.io/* { reverse_proxy authentik-server-1:9000 } # sample: no need auth for index page handle index.html { reverse_proxy xxx:80 } # rest pages need auth handle { forward_auth authentik-server-1:9000 { uri /outpost.goauthentik.io/auth/caddy copy_headers X-Authentik-Username X-Authentik-Groups X-Authentik-Email X-Authentik-Name } reverse_proxy xxx:80 } } </code> Take note the ''caddy'' in ''uri /outpost.goauthentik.io/auth/caddy'' specify the host program, alternatives like ''/outpost.goauthentik.io/auth/nginx'' for Nginx and ''/outpost.goauthentik.io/auth/traefik'' for Traefik. Do not change it. Then create a new forward auth provider in Authentik. Go to Applications - Providers - New Provider, select Proxy Provider, and fill in details. Select authorization flow as default-provider-authorization-implicit-consent (Authorize Application), and type forward auth (single application). {{pasted:20260627-080759.png?500}}{{pasted:20260627-080818.png?500}} After that, create a new application with this provider. Bind users or access groups to this application. Add the application into default outpost (authentik Embedded Outpost) via Applications - Outposts. Testing should have 302 response for auth required page, while the remaining pages are normal. <code bash> curl -I https://url.to.website/index.html curl -I https://url.to.website/test.html </code> caddy.txt 最后更改: 2026/06/27 08:41由 xiaobenmao