-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCaddyfile
More file actions
152 lines (127 loc) · 4.08 KB
/
Copy pathCaddyfile
File metadata and controls
152 lines (127 loc) · 4.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
# Shared reverse proxy definition for Unsloth Studio
(proxy_studio) {
reverse_proxy {$STUDIO_HOST}:{$STUDIO_PORT} {
header_up Host {host}
header_up X-Real-IP {remote_host}
}
}
# Trusted local network ranges (used by both the HTTPS and HTTP sites).
# Edit these ranges if your LAN uses different addressing.
(lan_ranges) {
remote_ip 192.168.0.0/16 10.0.0.0/8 172.16.0.0/12 127.0.0.0/8 ::1 fc00::/7
}
{
admin off
order authenticate first
order trace before reverse_proxy
order authorize before reverse_proxy
# Disable the automatic HTTP->HTTPS redirect: it would be prepended to the
# :80 server and shadow the LAN bypass below. Internet clients are still
# redirected to HTTPS by the explicit @wan_clients route in the :80 site.
auto_https disable_redirects
# Security configuration with MFA
security {
# Local user store backing file
local identity store localdb {
realm local
path /var/lib/caddy/users.json
}
# Email configuration for password reset
messaging email provider localhost-smtp-server {
address 127.0.0.1:1025
protocol smtp
passwordless
sender root@localhost "Unsloth Studio MFA Portal"
bcc admin@localhost
}
# Authentication portal with MFA
authentication portal unsloth-portal {
# JWT configuration for tokens
crypto default token lifetime 3600
crypto key sign-verify {env.JWT_SECRET}
# Enable local identity store
enable identity store localdb
# Cookie settings
cookie domain {$DOMAIN}
# UI configuration
ui {
# Logo fetched from Unsloth instance at container startup
static_asset "assets/images/logo.svg" "image/svg+xml" /var/lib/caddy/assets/logo.svg
static_asset "assets/images/logo.png" "image/png" /var/lib/caddy/assets/logo.png
logo url "/auth/assets/images/logo.svg"
logo description "Unsloth Studio"
links {
"Unsloth Studio" https://{$DOMAIN} target_blank icon "las la-flask"
}
}
# User transformation
transform user {
match origin local
action add role authp/user
require mfa
ui link "My Identity" /auth/whoami icon "las la-user"
}
}
# Authorization policy
authorization policy unsloth-policy {
set auth url /auth
crypto key verify {env.JWT_SECRET}
allow roles authp/admin authp/user
}
}
}
# Main reverse proxy with same-domain authentication
{$DOMAIN} {
@public_api {
path /api /api/* /v1 /v1/* /openai /openai/* /chat/completions
}
# Clients from trusted local networks skip the login/MFA portal entirely.
@trusted_lan {
import lan_ranges
}
@untrusted {
not {
import lan_ranges
}
}
route /auth* {
authenticate with unsloth-portal
}
route @public_api {
import proxy_studio
}
# Local LAN traffic: direct access, no authentication required
route @trusted_lan {
import proxy_studio
}
# Internet traffic: full password + MFA flow
route @untrusted {
authorize with unsloth-policy
import proxy_studio
}
encode gzip zstd
header {
X-Content-Type-Options "nosniff"
X-Frame-Options "DENY"
Referrer-Policy "strict-origin-when-cross-origin"
}
}
:80 {
@trusted_lan {
import lan_ranges
}
@wan_clients {
not {
import lan_ranges
}
}
# Trusted LAN clients: plain HTTP, no TLS, no authentication
route @trusted_lan {
import proxy_studio
}
# Everyone else: force HTTPS (must be inside a route so it does not
# run before the LAN check — Caddy orders redir before route)
route @wan_clients {
redir https://{$DOMAIN}{uri}
}
}