infra, ansible, and required container changes

This commit is contained in:
Jason Ross
2026-04-29 16:39:00 -05:00
parent 5219e3131d
commit 45f2a9a073
35 changed files with 1379 additions and 12 deletions
+10 -4
View File
@@ -47,9 +47,11 @@
}
# ------------------------------------------------------------------
# Reverse-proxy to the Astro container on the internal network
# Reverse-proxy to the Astro container. Caddy is on the host network
# namespace, so we connect over loopback to the port the app container
# publishes on 127.0.0.1 / [::1]:4321.
# ------------------------------------------------------------------
reverse_proxy app:4321 {
reverse_proxy 127.0.0.1:4321 {
header_up X-Real-IP {remote_host}
header_up X-Forwarded-Proto {scheme}
}
@@ -64,7 +66,11 @@
}
log {
output stdout
format console
output file /var/log/caddy/access.log {
roll_size 10MiB
roll_keep 5
roll_keep_for 168h
}
format json
}
}
+10
View File
@@ -21,3 +21,13 @@ SecRule REQUEST_URI "@beginsWith /_astro/" \
"id:1000,phase:1,pass,nolog,ctl:ruleEngine=Off"
SecRule REQUEST_URI "@beginsWith /fonts/" \
"id:1001,phase:1,pass,nolog,ctl:ruleEngine=Off"
# ---------------------------------------------------------------------------
# Audit log — every blocked request gets an entry in serial format that
# fail2ban tails on the host (mounted at /var/log/caddy/coraza-audit.log).
# ---------------------------------------------------------------------------
SecAuditEngine RelevantOnly
SecAuditLogRelevantStatus "^(?:5|4(?!04))"
SecAuditLogParts ABIJDEFHZ
SecAuditLogType Serial
SecAuditLog /var/log/caddy/coraza-audit.log