fix(caddy): move layer4 into global block; use :6380 listener address
Some checks failed
CI / Backend (push) Successful in 30s
CI / UI (push) Successful in 39s
Release / Test backend (push) Successful in 40s
Release / Check ui (push) Successful in 25s
CI / UI (pull_request) Successful in 25s
Release / Docker / caddy (push) Successful in 1m9s
CI / Backend (pull_request) Successful in 1m14s
Release / Docker / ui (push) Successful in 3m56s
Release / Docker / runner (push) Successful in 4m41s
Release / Docker / backend (push) Successful in 7m51s
Release / Gitea Release (push) Failing after 2s
Some checks failed
CI / Backend (push) Successful in 30s
CI / UI (push) Successful in 39s
Release / Test backend (push) Successful in 40s
Release / Check ui (push) Successful in 25s
CI / UI (pull_request) Successful in 25s
Release / Docker / caddy (push) Successful in 1m9s
CI / Backend (pull_request) Successful in 1m14s
Release / Docker / ui (push) Successful in 3m56s
Release / Docker / runner (push) Successful in 4m41s
Release / Docker / backend (push) Successful in 7m51s
Release / Gitea Release (push) Failing after 2s
The bare { } block at the bottom was a second global options block which
Caddy's caddyfile adapter rejects on reload. Merged layer4 into the single
top-level global block. Changed listener from hostname (redis.libnovel.cc:6380)
to :6380 so Caddy binds to the local interface rather than the Cloudflare IP
that resolves for the hostname.
This commit is contained in:
40
Caddyfile
40
Caddyfile
@@ -56,6 +56,22 @@
|
|||||||
ticker_interval 15s
|
ticker_interval 15s
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ── Redis TCP proxy via layer4 ────────────────────────────────────────────
|
||||||
|
# Exposes homelab Redis over TLS for Asynq job enqueueing from the backend.
|
||||||
|
# Listens on :6380 (all interfaces). TLS is terminated here using the cert
|
||||||
|
# for redis.libnovel.cc; traffic is proxied to the homelab Redis instance.
|
||||||
|
# Requires the caddy-l4 module in the custom Caddy build.
|
||||||
|
layer4 {
|
||||||
|
:6380 {
|
||||||
|
route {
|
||||||
|
tls
|
||||||
|
proxy {
|
||||||
|
upstream {$HOMELAB_REDIS_ADDR:192.168.0.109:6379}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
(security_headers) {
|
(security_headers) {
|
||||||
header {
|
header {
|
||||||
@@ -253,27 +269,3 @@ search.libnovel.cc {
|
|||||||
reverse_proxy meilisearch:7700
|
reverse_proxy meilisearch:7700
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
# ── Redis TCP proxy: exposes homelab Redis over TLS for Asynq ─────────────────
|
|
||||||
# The backend (prod) connects to rediss://redis.libnovel.cc:6380 to enqueue
|
|
||||||
# Asynq jobs. Caddy terminates TLS (Let's Encrypt cert for redis.libnovel.cc)
|
|
||||||
# and proxies the raw TCP stream to the homelab Redis via this reverse proxy.
|
|
||||||
#
|
|
||||||
# NOTE: Redis is NOT running on the prod server — it runs on the homelab
|
|
||||||
# (192.168.0.109:6379) and is exposed to the internet via this Caddy proxy.
|
|
||||||
# The homelab Redis is protected by REDIS_PASSWORD (requirepass).
|
|
||||||
#
|
|
||||||
# Caddy layer4 app handles this; requires the caddy-l4 module in the build.
|
|
||||||
{
|
|
||||||
layer4 {
|
|
||||||
redis.libnovel.cc:6380 {
|
|
||||||
route {
|
|
||||||
tls
|
|
||||||
proxy {
|
|
||||||
# Homelab Redis — replace with actual homelab IP or FQDN
|
|
||||||
upstream {$HOMELAB_REDIS_ADDR:192.168.0.109:6379}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
Reference in New Issue
Block a user