infra, ansible, and required container changes

This commit is contained in:
Jason Ross
2026-04-29 16:39:00 -05:00
parent 5219e3131d
commit 45f2a9a073
35 changed files with 1379 additions and 12 deletions
+5 -2
View File
@@ -23,8 +23,11 @@ ReadOnly=true
DropCapability=ALL
Tmpfs=/tmp:rw,size=64m,mode=1777
# Not exposed publicly – Caddy reverse-proxies in over the internal network.
# PublishPort=4321:4321
# Caddy now runs on the host network namespace, so it cannot reach the app
# via podman DNS (`app:4321`). Publish the app port on the host's *loopback*
# only -- it is reachable to Caddy on the host but not from outside.
PublishPort=127.0.0.1:4321:4321
PublishPort=[::1]:4321:4321
[Service]
Restart=on-failure
+9 -6
View File
@@ -9,12 +9,11 @@ ContainerName=dev-blog-caddy
# Build with: podman build -t localhost/dev-blog-caddy:latest ./caddy
Image=localhost/dev-blog-caddy:latest
Network=dev-blog.network
NetworkAlias=caddy
PublishPort=80:80
PublishPort=443:443
PublishPort=443:443/udp
# Caddy uses the *host* network namespace so it sees real client IP addresses
# (both v4 and v6). Required for fail2ban / Coraza to act on actual sources
# instead of the bridge gateway. With Network=host, PublishPort= is a no-op
# and is intentionally omitted -- Caddy binds 80/443 directly on the host.
Network=host
# --- Configuration ---
Environment=SITE_ADDRESS=https://example.com
@@ -33,6 +32,10 @@ Secret=gcp-dns-sa,type=mount,target=gcp-dns.json,mode=0400
Volume=caddy-data.volume:/data
Volume=caddy-config.volume:/config
# Bind-mount the host log directory so fail2ban can tail Caddy access logs
# and Coraza audit logs. The :Z suffix asks Podman to relabel for SELinux.
Volume=/var/log/caddy:/var/log/caddy:Z
# Hardening
NoNewPrivileges=true
DropCapability=ALL
+3
View File
@@ -5,6 +5,9 @@ Description=Internal network for the dev-blog stack
NetworkName=dev-blog
Driver=bridge
DisableDNS=false
IPv6=true
Subnet=10.89.0.0/24
Subnet=fd00:dead:beef::/64
[Install]
WantedBy=multi-user.target default.target