{ admin unix//run/caddy-admin.sock auto_https off skip_install_trust servers { trusted_proxies static 127.0.0.1/32 ::1/128 trusted_proxies_strict client_ip_headers X-Forwarded-For } } (admin_security) { header { Cache-Control "no-store" Pragma "no-cache" Referrer-Policy "same-origin" Content-Security-Policy "default-src 'none'; style-src 'self'; form-action 'self'; base-uri 'none'; frame-ancestors 'none'" X-Content-Type-Options "nosniff" } } (admin_gate) { import {$TRUF_ADMIN_DENYLIST_FILE:/etc/caddy/denylist/admin-denylist.caddy} basic_auth bcrypt "truf-admin" { {$TRUF_ADMIN_USER} {$TRUF_ADMIN_PASSWORD_HASH} } } http://:18766 { bind 127.0.0.1 log routine_access { output discard } log admin_auth_failures { no_hostname output file {$TRUF_ADMIN_AUTH_LOG_FILE:/var/log/caddy/admin-auth-failures.json} { roll_size 8MiB roll_keep 10 roll_keep_for 240h } format filter { request delete bytes_read delete user_id delete duration delete size delete resp_headers delete wrap json } } route { @invalid_ingress not header X-Truf-Shared-Ingress {$TRUF_SHARED_INGRESS_MARKER} respond @invalid_ingress "" 403 request_header -X-Truf-Shared-Ingress import admin_security header Strict-Transport-Security "max-age=63072000; includeSubDomains" @worker path /api/v1/worker/* handle @worker { reverse_proxy 127.0.0.1:8766 { header_up -X-Truf-Admin-Edge header_up -X-Truf-Admin-Operator header_up -X-Truf-Shared-Ingress header_up -Forwarded header_up -X-Real-IP } } @admin_root path /{$TRUF_ADMIN_PREFIX} handle @admin_root { route { import admin_security import admin_gate redir * /{$TRUF_ADMIN_PREFIX}/ 308 } } @admin path /{$TRUF_ADMIN_PREFIX}/* handle @admin { route { import admin_security request_header -X-Truf-Admin-Edge request_header -X-Truf-Admin-Operator import admin_gate uri strip_prefix /{$TRUF_ADMIN_PREFIX} uri path_regexp ^ /admin-internal reverse_proxy 127.0.0.1:8766 { header_up -Authorization header_up X-Truf-Admin-Edge {$TRUF_ADMIN_EDGE_MARKER} header_up X-Truf-Admin-Operator {http.auth.user.id} header_up -X-Truf-Shared-Ingress header_up -Forwarded header_up -X-Real-IP header_down -Strict-Transport-Security } } } handle { respond "" 404 } } handle_errors { @bad_admin_credentials { path /{$TRUF_ADMIN_PREFIX} /{$TRUF_ADMIN_PREFIX}/* header Authorization * expression {err.status_code} == 401 } handle @bad_admin_credentials { route { import admin_security log_name admin_auth_failures log_append event admin_auth_failure log_append remote_ip {http.request.client_ip} header WWW-Authenticate "Basic realm=\"truf-admin\"" respond "" 401 } } @admin_unauthorized { path /{$TRUF_ADMIN_PREFIX} /{$TRUF_ADMIN_PREFIX}/* expression {err.status_code} == 401 } handle @admin_unauthorized { route { import admin_security header WWW-Authenticate "Basic realm=\"truf-admin\"" respond "" 401 } } @admin_error path /{$TRUF_ADMIN_PREFIX} /{$TRUF_ADMIN_PREFIX}/* handle @admin_error { import admin_security respond "" {err.status_code} } handle { respond "" {err.status_code} } } }