Production Caddyfile Reverse Proxy with Automatic HTTPS
plain (caddyfile)
13 hours ago
·
42 lines
·
6 views
1# Global Caddy Configuration
2{
3 email ops@example.com
4 admin off
5}
7# Production Domain Reverse Proxy
8example.com {
9 # Automatic TLS and HTTP to HTTPS redirection is built-in
11 # Security & Protection Headers
12 header {
13 Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
14 X-Content-Type-Options "nosniff"
15 X-Frame-Options "DENY"
16 Referrer-Policy "strict-origin-when-cross-origin"
17 Permissions-Policy "camera=(), microphone=(), geolocation=()"
18 -Server
19 }
21 # Compression (Zstandard & Gzip)
22 encode zstd gzip
24 # Static Assets Caching
25 @static {
26 file
27 path *.css *.js *.svg *.ico *.woff2
28 }
29 header @static Cache-Control "public, max-age=31536000, immutable"
31 # Reverse Proxy to Internal Node.js / Web Application
32 reverse_proxy 127.0.0.1:3000 {
33 header_up Host {host}
34 header_up X-Real-IP {remote_host}
35 header_up X-Forwarded-Proto {scheme}
37 # Health Check and Load Balancing
38 health_timeout 5s
39 max_fails 3
40 }
41}
Replies 0
No replies yet
Every reply is a note. Start a discussion, ask a question, or attach a code snippet.
Notification