Wiz-War's host follows the hall's shared layout: its own Caddy site file, its own access log, a memory cap for a shared box

The host's Caddyfile gathers each game's site from /etc/caddy/sites/;
Wiz-War's is rendered from deploy/Caddyfile.tmpl and logs to
wizwar-access.log, which the rollup and the pulse read. The server's memory
cap drops from 700M to 350M (it runs in about 125M), so a runaway cannot
starve other games sharing the box. Applied on the live droplet with its
logs renamed in place.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jm2auWk6RP71CjaAb4FMoG
This commit is contained in:
Eric Wagoner
2026-09-29 12:37:06 -04:00
co-authored by Claude Opus 5.5
parent d5b92d9a63
commit 811d5f84cb
6 changed files with 62 additions and 17 deletions
+26 -10
View File
@@ -1,8 +1,12 @@
#!/usr/bin/env bash
# One-time droplet setup. Run ON the droplet as root:
# bash setup-droplet.sh wizwar.<droplet-ip>.sslip.io
# One-time host setup. The host may be shared with the other games of
# Kestrel's Hall; this touches nothing of theirs. Copy it and Caddyfile.tmpl
# to the host and run ON it as root:
# bash setup-droplet.sh 'wizwar.kestrelsnest.social, wizwar.<host-ip>.sslip.io'
# The argument is Wiz-War's Caddy site address line: one name, or several
# separated by commas. Every name must already resolve to this host.
set -euo pipefail
HOST="${1:?usage: setup-droplet.sh <hostname>}"
HOST="${1:?usage: setup-droplet.sh <site address line>}"
apt-get update -q
apt-get install -qy curl git rsync
@@ -24,13 +28,25 @@ id -u wizwar &>/dev/null || useradd -r -m -d /opt/wizwar-home wizwar
mkdir -p /opt/wizwar /var/lib/wizwar/rooms
chown -R wizwar:wizwar /opt/wizwar /var/lib/wizwar
# Caddy vhost: auto-TLS, security headers, proxy to the game.
# Access log kept to 30 rolls of 10MiB: the nightly rollup keeps the
# counts; the raw lines back it for a while. A deploy restarts the game
# for a few seconds; the proxy holds requests that land in that gap and
# keeps dialing, so a visitor waits instead of meeting a 502.
printf '%s\n\nheader {\n\tStrict-Transport-Security "max-age=31536000"\n\tX-Content-Type-Options "nosniff"\n\tX-Frame-Options "DENY"\n\tReferrer-Policy "no-referrer"\n}\nlog {\n\toutput file /var/lib/caddy/access.log {\n\t\troll_size 10MiB\n\t\troll_keep 30\n\t}\n}\nreverse_proxy localhost:8787 {\n\tlb_try_duration 30s\n\tlb_try_interval 250ms\n}\n' "$HOST" > /etc/caddy/Caddyfile
systemctl reload caddy
# Caddy: the host's Caddyfile only gathers each game's site file, so this
# host can be shared with the other games of Kestrel's Hall. A Caddyfile
# that is neither Caddy's stock one nor that is a single-site host from
# before the shared layout: stop rather than overwrite it.
ROOT_CADDY='# Kestrel'"'"'s Hall: every game on this host brings its own site file.
import sites/*.caddy'
mkdir -p /etc/caddy/sites
if ! grep -q '^import sites/\*.caddy' /etc/caddy/Caddyfile 2>/dev/null; then
if [ -s /etc/caddy/Caddyfile ] && ! grep -q 'root \* /usr/share/caddy' /etc/caddy/Caddyfile; then
echo "/etc/caddy/Caddyfile holds another site; move it into /etc/caddy/sites/ first" >&2
exit 1
fi
printf '%s\n' "$ROOT_CADDY" > /etc/caddy/Caddyfile
fi
sed "s|__HOST__|$HOST|" "$(dirname "$0")/Caddyfile.tmpl" > /etc/caddy/sites/wizwar.caddy
caddy validate --config /etc/caddy/Caddyfile
# Validation as root touches the access logs; Caddy runs as caddy and must own them.
chown -R caddy:caddy /var/lib/caddy
systemctl reload-or-restart caddy
# Firewall: ssh + web only. The game server binds loopback and is reached
# through Caddy; nothing else should answer the internet.