134 lines
2.9 KiB
Caddyfile
134 lines
2.9 KiB
Caddyfile
{
|
|
admin unix//run/caddy-admin.sock
|
|
auto_https disable_redirects
|
|
skip_install_trust
|
|
}
|
|
|
|
(admin_security) {
|
|
header {
|
|
Cache-Control "no-store"
|
|
Pragma "no-cache"
|
|
Referrer-Policy "same-origin"
|
|
Content-Security-Policy "default-src 'none'; style-src 'self'; form-action 'self'; base-uri 'none'; frame-ancestors 'none'"
|
|
X-Content-Type-Options "nosniff"
|
|
}
|
|
}
|
|
|
|
(admin_gate) {
|
|
import {$TRUF_ADMIN_DENYLIST_FILE:/etc/caddy/denylist/admin-denylist.caddy}
|
|
basic_auth bcrypt "truf-admin" {
|
|
{$TRUF_ADMIN_USER} {$TRUF_ADMIN_PASSWORD_HASH}
|
|
}
|
|
}
|
|
|
|
{$TRUF_EDGE_HOST} {
|
|
import {$TRUF_EDGE_TLS_INCLUDE:/etc/caddy/tls/automatic.caddy}
|
|
import admin_security
|
|
header Strict-Transport-Security "max-age=63072000; includeSubDomains"
|
|
|
|
log routine_access {
|
|
output discard
|
|
}
|
|
|
|
log admin_auth_failures {
|
|
no_hostname
|
|
output file {$TRUF_ADMIN_AUTH_LOG_FILE:/var/log/caddy/admin-auth-failures.json} {
|
|
roll_size 8MiB
|
|
roll_keep 10
|
|
roll_keep_for 240h
|
|
}
|
|
format filter {
|
|
request delete
|
|
bytes_read delete
|
|
user_id delete
|
|
duration delete
|
|
size delete
|
|
resp_headers delete
|
|
wrap json
|
|
}
|
|
}
|
|
|
|
@worker path /api/v1/worker/*
|
|
handle @worker {
|
|
reverse_proxy 127.0.0.1:8766 {
|
|
header_up -X-Truf-Admin-Edge
|
|
header_up -X-Truf-Admin-Operator
|
|
header_up -Forwarded
|
|
header_up -X-Real-IP
|
|
}
|
|
}
|
|
|
|
@admin_root path /{$TRUF_ADMIN_PREFIX}
|
|
handle @admin_root {
|
|
route {
|
|
import admin_security
|
|
import admin_gate
|
|
redir * /{$TRUF_ADMIN_PREFIX}/ 308
|
|
}
|
|
}
|
|
|
|
@admin path /{$TRUF_ADMIN_PREFIX}/*
|
|
handle @admin {
|
|
route {
|
|
import admin_security
|
|
request_header -X-Truf-Admin-Edge
|
|
request_header -X-Truf-Admin-Operator
|
|
import admin_gate
|
|
uri strip_prefix /{$TRUF_ADMIN_PREFIX}
|
|
uri path_regexp ^ /admin-internal
|
|
reverse_proxy 127.0.0.1:8766 {
|
|
header_up -Authorization
|
|
header_up X-Truf-Admin-Edge {$TRUF_ADMIN_EDGE_MARKER}
|
|
header_up X-Truf-Admin-Operator {http.auth.user.id}
|
|
header_up -Forwarded
|
|
header_up -X-Real-IP
|
|
header_down -Strict-Transport-Security
|
|
}
|
|
}
|
|
}
|
|
|
|
handle {
|
|
respond "" 404
|
|
}
|
|
|
|
handle_errors {
|
|
@bad_admin_credentials {
|
|
path /{$TRUF_ADMIN_PREFIX} /{$TRUF_ADMIN_PREFIX}/*
|
|
header Authorization *
|
|
expression {err.status_code} == 401
|
|
}
|
|
handle @bad_admin_credentials {
|
|
route {
|
|
import admin_security
|
|
log_name admin_auth_failures
|
|
log_append event admin_auth_failure
|
|
log_append remote_ip {http.request.remote.host}
|
|
header WWW-Authenticate "Basic realm=\"truf-admin\""
|
|
respond "" 401
|
|
}
|
|
}
|
|
|
|
@admin_unauthorized {
|
|
path /{$TRUF_ADMIN_PREFIX} /{$TRUF_ADMIN_PREFIX}/*
|
|
expression {err.status_code} == 401
|
|
}
|
|
handle @admin_unauthorized {
|
|
route {
|
|
import admin_security
|
|
header WWW-Authenticate "Basic realm=\"truf-admin\""
|
|
respond "" 401
|
|
}
|
|
}
|
|
|
|
@admin_error path /{$TRUF_ADMIN_PREFIX} /{$TRUF_ADMIN_PREFIX}/*
|
|
handle @admin_error {
|
|
import admin_security
|
|
respond "" {err.status_code}
|
|
}
|
|
|
|
handle {
|
|
respond "" {err.status_code}
|
|
}
|
|
}
|
|
}
|