feat(caddy-local): nspawn with declarative config; split the fleet by network #8
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "caddy-local-nspawn"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
caddy-local becomes a NixOS nspawn with a fully declarative config, mirroring the vlan50 caddy:
containers.caddy-localin newhosts/server/containers/local/caddy-local.nix— host netns, still 192.168.0.30:80/443, so forwards don't moveservices.caddy.virtualHosts(rendered +caddy fmtat build time — the tracked Caddyfile and thesyncCaddyfilehook are deleted; bad directives now fail the build instead of the deploy)autheliaGatestring (identical by construction; ACL invariant unchanged)caddy.withPlugins(github.com/caddy-dns/cloudflare@v0.2.4+ hash),globalConfig = acme_dns cloudflare {env.CLOUDFLARE_API_TOKEN}— token at/pool/services/secrets/caddy-local-acme(0600, copied out of the oldconf/acme.confon the server)/pool/services/podman/caddy-local/databinds to/data(XDG_DATA_HOME +Z /data caddy caddy - -;conf/,site/,config/kept as rollback artifacts)Fleet split by network:
hosts/server/containers/now hasvlan50/(caddy, forgejo, matrix, privatebin) andlocal/(caddy-local, librechat, otbr);common.nixstays at the root, imports go../common.nix.Gate:
systemHealthCheckgains the rename pairpodman-caddy-local/container@caddy-local(gate script comes from the previous generation).Deploy notes
The switch stops rootless
podman-caddy-localand starts the nspawn — brief proxy downtime for the local vhosts, one time. kuma monitors unchanged (same vhost names). Verified: toplevel builds (43 small drvs + prebuilt caddy plugin), rendered Caddyfile has 13 forward_auth blocks + env-token acme_dns.