Caddy routes the duel server's paths with handle blocks, from one template
try_files ran before reverse_proxy and rewrote /api to the shell; handle blocks are exclusive. Both setup scripts render deploy/Caddyfile.tmpl. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
29e908efeb
commit
605f8c511b
@@ -0,0 +1,42 @@
|
|||||||
|
__HOST__
|
||||||
|
|
||||||
|
root * /opt/waving-hands/build
|
||||||
|
encode gzip zstd
|
||||||
|
|
||||||
|
header {
|
||||||
|
Strict-Transport-Security "max-age=31536000"
|
||||||
|
X-Content-Type-Options "nosniff"
|
||||||
|
X-Frame-Options "DENY"
|
||||||
|
Referrer-Policy "no-referrer"
|
||||||
|
}
|
||||||
|
|
||||||
|
log {
|
||||||
|
output file /var/lib/caddy/access.log {
|
||||||
|
roll_size 10MiB
|
||||||
|
roll_keep 30
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# The duel server answers the API and the websocket; a deploy restarts it for
|
||||||
|
# a few seconds, and the proxy holds requests that land in that gap.
|
||||||
|
@duel path /api/* /ws
|
||||||
|
handle @duel {
|
||||||
|
reverse_proxy localhost:8788 {
|
||||||
|
lb_try_duration 30s
|
||||||
|
lb_try_interval 250ms
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# Everything else is the static site. SvelteKit writes each route as
|
||||||
|
# <route>.html, so /rules is tried as /rules.html before falling back to the
|
||||||
|
# app shell, which serves the rooms. Hashed assets under _app/immutable are
|
||||||
|
# cached for a year; every other response is revalidated so a deploy shows
|
||||||
|
# up on the next load. The two header matchers are disjoint.
|
||||||
|
handle {
|
||||||
|
@immutable path /_app/immutable/*
|
||||||
|
header @immutable Cache-Control "public, max-age=31536000, immutable"
|
||||||
|
@mutable not path /_app/immutable/*
|
||||||
|
header @mutable Cache-Control "no-cache"
|
||||||
|
try_files {path} {path}.html /index.html
|
||||||
|
file_server
|
||||||
|
}
|
||||||
+2
-2
@@ -33,10 +33,10 @@ uptime and upgrades independent of anything else.
|
|||||||
1. `doctl compute droplet create waving-hands --region nyc3 \
|
1. `doctl compute droplet create waving-hands --region nyc3 \
|
||||||
--size s-1vcpu-512mb-10gb --image ubuntu-24-04-x64 \
|
--size s-1vcpu-512mb-10gb --image ubuntu-24-04-x64 \
|
||||||
--ssh-keys <your-key-ids> --tag-name waving-hands --wait`
|
--ssh-keys <your-key-ids> --tag-name waving-hands --wait`
|
||||||
2. `scp deploy/setup-droplet.sh root@<ip>:/root/ && ssh root@<ip> \
|
2. `scp deploy/setup-droplet.sh deploy/Caddyfile.tmpl root@<ip>:/root/ && ssh root@<ip> \
|
||||||
"bash /root/setup-droplet.sh 'hands.kestrelsnest.social, waving-hands.<ip>.sslip.io'"`
|
"bash /root/setup-droplet.sh 'hands.kestrelsnest.social, waving-hands.<ip>.sslip.io'"`
|
||||||
(point the A record at the new IP first, or leave the real name out until it is).
|
(point the A record at the new IP first, or leave the real name out until it is).
|
||||||
3. `scp deploy/setup-server.sh root@<ip>:/root/ && ssh root@<ip> "bash /root/setup-server.sh"`
|
3. `scp deploy/setup-server.sh deploy/Caddyfile.tmpl root@<ip>:/root/ && ssh root@<ip> "bash /root/setup-server.sh"`
|
||||||
4. `deploy/deploy.sh <ip>`
|
4. `deploy/deploy.sh <ip>`
|
||||||
|
|
||||||
The sslip.io hostname works with no DNS at all. To add a real name, point an
|
The sslip.io hostname works with no DNS at all. To add a real name, point an
|
||||||
|
|||||||
+5
-34
@@ -1,5 +1,6 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
# One-time droplet setup. Run ON the droplet as root:
|
# One-time droplet setup. Copy this script and Caddyfile.tmpl to the droplet
|
||||||
|
# and run ON the droplet as root:
|
||||||
# bash setup-droplet.sh 'hands.kestrelsnest.social, waving-hands.<droplet-ip>.sslip.io'
|
# bash setup-droplet.sh 'hands.kestrelsnest.social, waving-hands.<droplet-ip>.sslip.io'
|
||||||
# The argument is the Caddy site address line: one name, or several
|
# The argument is the Caddy site address line: one name, or several
|
||||||
# separated by commas. Every name must already resolve to this droplet.
|
# separated by commas. Every name must already resolve to this droplet.
|
||||||
@@ -24,39 +25,9 @@ mkdir -p /opt/waving-hands/build
|
|||||||
chown -R root:caddy /opt/waving-hands
|
chown -R root:caddy /opt/waving-hands
|
||||||
chmod -R g+rX /opt/waving-hands
|
chmod -R g+rX /opt/waving-hands
|
||||||
|
|
||||||
# Caddy vhost: auto-TLS, security headers, static files. SvelteKit writes
|
# Caddy: the site and the duel server's paths, from the template beside this script.
|
||||||
# each route as <route>.html, so /rules is tried as /rules.html before
|
sed "s|__HOST__|$HOST|" "$(dirname "$0")/Caddyfile.tmpl" > /etc/caddy/Caddyfile
|
||||||
# falling back to the app shell. Hashed assets under _app/immutable are
|
caddy validate --config /etc/caddy/Caddyfile
|
||||||
# cached for a year; every other response is revalidated so a deploy shows
|
|
||||||
# up on the next load. The two header matchers are disjoint, so their order
|
|
||||||
# does not matter.
|
|
||||||
cat > /etc/caddy/Caddyfile <<CADDY
|
|
||||||
$HOST
|
|
||||||
|
|
||||||
root * /opt/waving-hands/build
|
|
||||||
encode gzip zstd
|
|
||||||
|
|
||||||
header {
|
|
||||||
Strict-Transport-Security "max-age=31536000"
|
|
||||||
X-Content-Type-Options "nosniff"
|
|
||||||
X-Frame-Options "DENY"
|
|
||||||
Referrer-Policy "no-referrer"
|
|
||||||
}
|
|
||||||
@immutable path /_app/immutable/*
|
|
||||||
header @immutable Cache-Control "public, max-age=31536000, immutable"
|
|
||||||
@mutable not path /_app/immutable/*
|
|
||||||
header @mutable Cache-Control "no-cache"
|
|
||||||
|
|
||||||
log {
|
|
||||||
output file /var/lib/caddy/access.log {
|
|
||||||
roll_size 10MiB
|
|
||||||
roll_keep 30
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
try_files {path} {path}.html /index.html
|
|
||||||
file_server
|
|
||||||
CADDY
|
|
||||||
systemctl reload caddy
|
systemctl reload caddy
|
||||||
|
|
||||||
# Firewall: ssh + web only.
|
# Firewall: ssh + web only.
|
||||||
|
|||||||
+8
-20
@@ -1,8 +1,9 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
# Adds the duel server to a droplet that setup-droplet.sh already prepared.
|
# Adds the duel server to a droplet that setup-droplet.sh already prepared.
|
||||||
# Run ON the droplet as root; safe to run again. Installs Node 22, creates
|
# Copy this script and Caddyfile.tmpl to the droplet and run ON the droplet
|
||||||
# the service user and data directory, and teaches Caddy to hand /api and
|
# as root; safe to run again. Installs Node 22, creates the service user and
|
||||||
# /ws to the server while it keeps serving the static site itself.
|
# data directory, and teaches Caddy to hand /api and /ws to the server while
|
||||||
|
# it keeps serving the static site itself.
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
if ! command -v node >/dev/null || [[ "$(node -v)" != v22* ]]; then
|
if ! command -v node >/dev/null || [[ "$(node -v)" != v22* ]]; then
|
||||||
@@ -14,24 +15,11 @@ id -u waving-hands &>/dev/null || useradd -r -m -d /opt/waving-hands-home waving
|
|||||||
mkdir -p /opt/waving-hands/app /var/lib/waving-hands/rooms
|
mkdir -p /opt/waving-hands/app /var/lib/waving-hands/rooms
|
||||||
chown -R waving-hands:waving-hands /var/lib/waving-hands
|
chown -R waving-hands:waving-hands /var/lib/waving-hands
|
||||||
|
|
||||||
# Caddy: the two proxied paths go in before the static file handling.
|
# Caddy: rewrite the site's configuration from the template, keeping its
|
||||||
if ! grep -q 'reverse_proxy' /etc/caddy/Caddyfile; then
|
# address line, so the duel server's paths are routed before the files.
|
||||||
python3 - <<'PY'
|
HOST_LINE=$(head -1 /etc/caddy/Caddyfile)
|
||||||
import pathlib
|
sed "s|__HOST__|$HOST_LINE|" "$(dirname "$0")/Caddyfile.tmpl" > /etc/caddy/Caddyfile
|
||||||
p = pathlib.Path('/etc/caddy/Caddyfile'); s = p.read_text()
|
|
||||||
marker = 'try_files {path} {path}.html /index.html'
|
|
||||||
proxy = '''@duel path /api/* /ws
|
|
||||||
reverse_proxy @duel localhost:8788 {
|
|
||||||
lb_try_duration 30s
|
|
||||||
lb_try_interval 250ms
|
|
||||||
}
|
|
||||||
|
|
||||||
'''
|
|
||||||
assert marker in s
|
|
||||||
p.write_text(s.replace(marker, proxy + marker))
|
|
||||||
PY
|
|
||||||
caddy validate --config /etc/caddy/Caddyfile
|
caddy validate --config /etc/caddy/Caddyfile
|
||||||
systemctl reload caddy
|
systemctl reload caddy
|
||||||
fi
|
|
||||||
|
|
||||||
echo "server prerequisites ready: now run deploy/deploy.sh <ip> from your machine"
|
echo "server prerequisites ready: now run deploy/deploy.sh <ip> from your machine"
|
||||||
|
|||||||
Reference in New Issue
Block a user