infra, ansible, and required container changes
This commit is contained in:
@@ -23,8 +23,11 @@ ReadOnly=true
|
||||
DropCapability=ALL
|
||||
Tmpfs=/tmp:rw,size=64m,mode=1777
|
||||
|
||||
# Not exposed publicly – Caddy reverse-proxies in over the internal network.
|
||||
# PublishPort=4321:4321
|
||||
# Caddy now runs on the host network namespace, so it cannot reach the app
|
||||
# via podman DNS (`app:4321`). Publish the app port on the host's *loopback*
|
||||
# only -- it is reachable to Caddy on the host but not from outside.
|
||||
PublishPort=127.0.0.1:4321:4321
|
||||
PublishPort=[::1]:4321:4321
|
||||
|
||||
[Service]
|
||||
Restart=on-failure
|
||||
|
||||
@@ -9,12 +9,11 @@ ContainerName=dev-blog-caddy
|
||||
# Build with: podman build -t localhost/dev-blog-caddy:latest ./caddy
|
||||
Image=localhost/dev-blog-caddy:latest
|
||||
|
||||
Network=dev-blog.network
|
||||
NetworkAlias=caddy
|
||||
|
||||
PublishPort=80:80
|
||||
PublishPort=443:443
|
||||
PublishPort=443:443/udp
|
||||
# Caddy uses the *host* network namespace so it sees real client IP addresses
|
||||
# (both v4 and v6). Required for fail2ban / Coraza to act on actual sources
|
||||
# instead of the bridge gateway. With Network=host, PublishPort= is a no-op
|
||||
# and is intentionally omitted -- Caddy binds 80/443 directly on the host.
|
||||
Network=host
|
||||
|
||||
# --- Configuration ---
|
||||
Environment=SITE_ADDRESS=https://example.com
|
||||
@@ -33,6 +32,10 @@ Secret=gcp-dns-sa,type=mount,target=gcp-dns.json,mode=0400
|
||||
Volume=caddy-data.volume:/data
|
||||
Volume=caddy-config.volume:/config
|
||||
|
||||
# Bind-mount the host log directory so fail2ban can tail Caddy access logs
|
||||
# and Coraza audit logs. The :Z suffix asks Podman to relabel for SELinux.
|
||||
Volume=/var/log/caddy:/var/log/caddy:Z
|
||||
|
||||
# Hardening
|
||||
NoNewPrivileges=true
|
||||
DropCapability=ALL
|
||||
|
||||
@@ -5,6 +5,9 @@ Description=Internal network for the dev-blog stack
|
||||
NetworkName=dev-blog
|
||||
Driver=bridge
|
||||
DisableDNS=false
|
||||
IPv6=true
|
||||
Subnet=10.89.0.0/24
|
||||
Subnet=fd00:dead:beef::/64
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target default.target
|
||||
|
||||
Reference in New Issue
Block a user