feat(caddy-local): nspawn with declarative config; split the fleet by network #8

Merged
Faris merged 1 commit from caddy-local-nspawn into main 2026-10-02 20:33:09 +01:00
Owner

What

caddy-local becomes a NixOS nspawn with a fully declarative config, mirroring the vlan50 caddy:

  • containers.caddy-local in new hosts/server/containers/local/caddy-local.nix — host netns, still 192.168.0.30:80/443, so forwards don't move
  • all 31 vhosts are services.caddy.virtualHosts (rendered + caddy fmt at build time — the tracked Caddyfile and the syncCaddyfile hook are deleted; bad directives now fail the build instead of the deploy)
  • the 13 Authelia-gated vhosts share one autheliaGate string (identical by construction; ACL invariant unchanged)
  • DNS-01: nixpkgs caddy 2.11.4 + cloudflare DNS plugin via caddy.withPlugins (github.com/caddy-dns/cloudflare@v0.2.4 + hash), globalConfig = acme_dns cloudflare {env.CLOUDFLARE_API_TOKEN} — token at /pool/services/secrets/caddy-local-acme (0600, copied out of the old conf/acme.conf on the server)
  • cert continuity: the rootless caddy's /pool/services/podman/caddy-local/data binds to /data (XDG_DATA_HOME + Z /data caddy caddy - -; conf/, site/, config/ kept as rollback artifacts)

Fleet split by network: hosts/server/containers/ now has vlan50/ (caddy, forgejo, matrix, privatebin) and local/ (caddy-local, librechat, otbr); common.nix stays at the root, imports go ../common.nix.

Gate: systemHealthCheck gains the rename pair podman-caddy-local/container@caddy-local (gate script comes from the previous generation).

Deploy notes

The switch stops rootless podman-caddy-local and starts the nspawn — brief proxy downtime for the local vhosts, one time. kuma monitors unchanged (same vhost names). Verified: toplevel builds (43 small drvs + prebuilt caddy plugin), rendered Caddyfile has 13 forward_auth blocks + env-token acme_dns.

## What **caddy-local becomes a NixOS nspawn with a fully declarative config**, mirroring the vlan50 caddy: - `containers.caddy-local` in new `hosts/server/containers/local/caddy-local.nix` — host netns, still 192.168.0.30:80/443, so forwards don't move - all 31 vhosts are `services.caddy.virtualHosts` (rendered + `caddy fmt` at build time — the tracked Caddyfile and the `syncCaddyfile` hook are deleted; bad directives now fail the build instead of the deploy) - the 13 Authelia-gated vhosts share one `autheliaGate` string (identical by construction; ACL invariant unchanged) - DNS-01: nixpkgs caddy 2.11.4 + cloudflare DNS plugin via `caddy.withPlugins` (`github.com/caddy-dns/cloudflare@v0.2.4` + hash), `globalConfig = acme_dns cloudflare {env.CLOUDFLARE_API_TOKEN}` — token at `/pool/services/secrets/caddy-local-acme` (0600, copied out of the old `conf/acme.conf` on the server) - cert continuity: the rootless caddy's `/pool/services/podman/caddy-local/data` binds to `/data` (XDG_DATA_HOME + `Z /data caddy caddy - -`; `conf/`, `site/`, `config/` kept as rollback artifacts) **Fleet split by network**: `hosts/server/containers/` now has `vlan50/` (caddy, forgejo, matrix, privatebin) and `local/` (caddy-local, librechat, otbr); `common.nix` stays at the root, imports go `../common.nix`. **Gate**: `systemHealthCheck` gains the rename pair `podman-caddy-local`/`container@caddy-local` (gate script comes from the previous generation). ## Deploy notes The switch stops rootless `podman-caddy-local` and starts the nspawn — brief proxy downtime for the local vhosts, one time. kuma monitors unchanged (same vhost names). Verified: toplevel builds (43 small drvs + prebuilt caddy plugin), rendered Caddyfile has 13 forward_auth blocks + env-token acme_dns.
feat(caddy-local): nspawn with declarative config; split the fleet by network
All checks were successful
eval / eval (pull_request) Successful in 22s
6240b7ba66
caddy-local moves out of the rootless podman fleet: containers.caddy-local
(host netns, still 192.168.0.30:80/443) runs native services.caddy with all
31 vhosts declared as virtualHosts — rendered at build time, so the tracked
Caddyfile and the syncCaddyfile hook are gone. The 13 gated vhosts share one
autheliaGate string; DNS-01 via nixpkgs caddy + the cloudflare plugin
(caddy.withPlugins @v0.2.4 + hash), token in /pool/services/secrets/
caddy-local-acme. Cert storage stays the rootless caddy's /data bind.
containers/ now splits into vlan50/ (macvlan) and local/ (host netns).
Gate keeps both unit names for the rename.
Faris merged commit 35c3234c3a into main 2026-10-02 20:33:09 +01:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Faris/nixos!8
No description provided.