homelab-blueprint/caddy/Caddyfile
2026-02-21 19:53:31 +02:00

231 lines
5.5 KiB
Caddyfile

{
admin :2019
}
#### Reusable Snippets
(common) {
tls brian.method@gmail.com {
dns cloudflare {env.CLOUDFLARE_DNS_TOKEN}
}
header {
# Enable HSTS
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
X-XSS-Protection 0
# Prevent browsers from incorrectly detecting non-scripts as scripts and MIME type sniffing
X-Content-Type-Options nosniff
Referrer-Policy same-origin
-Server
X-Frame-Options "SAMEORIGIN"
Permissions-Policy "geolocation=(self), microphone=(), camera=(), interest-cohort=()"
import content-security-general
}
}
#### Content Security Snippets
(content-security-general) { # Default setup
# Disable unsafe inline/eval and plugins, only load scripts and stylesheets from same origin, fonts from google,
# and images from same origin and imgur. Sites should aim for policies like this.
Content-Security-Policy "frame-ancestors 'self' https://*.home.brianpooe.com"
#"default-src 'self'; style-src 'self'; script-src 'self'; font-src 'self'; img-src 'self'; form-action 'self'; connect-src 'self'; frame-ancestors 'none';"
#default-src 'none'; font-src https://fonts.gstatic.com; img-src 'self' https://i.imgur.com; object-src 'none'; script-src 'self'; style-src 'self'
}
(content-security-basic) { # Most basic setup
# Disable unsafe inline/eval, only load resources from same origin except also allow images from imgur
# Also disables the execution of plugins
Content-Security-Policy default-src 'self'; img-src 'self' https://i.imgur.com; object-src 'none'
}
(content-security-api) { # API
# Disable the loading of any resources and disable framing, recommended for APIs to use
Content-Security-Policy default-src 'none'; frame-ancestors 'none'
}
switchlite8poe.home.brianpooe.com {
import common
reverse_proxy 192.168.1.5
}
tplink16de.home.brianpooe.com {
import common
reverse_proxy 192.168.1.8
}
# Proxmox
proxmox.home.brianpooe.com {
import common
reverse_proxy 192.168.10.10:8006 {
transport http {
tls_insecure_skip_verify
}
header_up Host {upstream_hostport}
}
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
X-Content-Type-Options "nosniff"
X-Frame-Options "SAMEORIGIN"
Referrer-Policy "no-referrer"
}
encode gzip
}
# Proxmox Backup Server
pbs.home.brianpooe.com {
import common
reverse_proxy 192.168.10.8:8007 {
transport http {
tls_insecure_skip_verify
}
header_up Host {upstream_hostport}
}
header {
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
X-Content-Type-Options "nosniff"
X-Frame-Options "SAMEORIGIN"
Referrer-Policy "no-referrer"
}
encode gzip
}
# pihole running on a raspberry pi different vlan
pihole.home.brianpooe.com {
import common
encode zstd gzip
rewrite * /admin{uri}
reverse_proxy 192.168.60.5:80 {
header_up Host {host}
header_up X-Real-IP {remote_host}
header_up Referer {http.request.header.Referer}
header_up Origin {http.request.header.Origin}
}
}
# The rest of the apps are running in docker inside synology nas
nas.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:5000
}
dav.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:5006 {
transport http {
tls_insecure_skip_verify
}
}
}
emby.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:8096
}
qbittorrent.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:8080
}
radarr.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:7878
}
sonarr.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:8989
}
prowlarr.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:9696
}
bazarr.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:6767
}
sabnzbd.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:8282
}
seerr.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:5055
}
# Legacy hostname redirect for old bookmarks
jellyseerr.home.brianpooe.com {
import common
redir https://seerr.home.brianpooe.com{uri} permanent
}
flaresolverr.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:8191
}
gluetun.home.brianpooe.com {
import common
reverse_proxy 192.168.10.24:8000
}
# Proxmox apps
paperless-ngx.home.brianpooe.com {
import common
reverse_proxy 192.168.10.11:8000 {
header_up Host {host}
}
encode gzip
}
paperless-ai.home.brianpooe.com {
import common
reverse_proxy 192.168.10.12:3000
}
ollama.home.brianpooe.com {
import common
reverse_proxy 192.168.10.9:11434
}
it-tools.home.brianpooe.com {
import common
reverse_proxy 192.168.10.7:80
}
bento-pdf.home.brianpooe.com {
import common
reverse_proxy 192.168.10.6:8080
}
beszel.home.brianpooe.com {
import common
reverse_proxy 192.168.10.13:8090
}
ytd.home.brianpooe.com {
import common
uri strip_prefix metube
reverse_proxy 192.168.10.14:3033
}
immich.home.brianpooe.com {
import common
reverse_proxy 192.168.10.15:2283
}
speedtest.home.brianpooe.com {
import common
reverse_proxy 192.168.10.16:80
}
gramps.home.brianpooe.com {
import common
reverse_proxy 192.168.10.18:80
}