chore: Fix caddy container

This commit is contained in:
Víctor Falcón 2026-01-17 20:02:14 +01:00
parent 02b8317b17
commit ab21a33e6f
2 changed files with 52 additions and 11 deletions

View File

@ -1,16 +1,16 @@
whisper.money.local {
# Use mkcert certificates (generated by setup script)
# These certificates are automatically trusted by browsers
tls /etc/caddy/certs/whisper.money.local.pem /etc/caddy/certs/whisper.money.local-key.pem
# Use mkcert certificates (generated by setup script)
# These certificates are automatically trusted by browsers
tls /etc/caddy/certs/whisper.money.local.pem /etc/caddy/certs/whisper.money.local-key.pem
reverse_proxy php:8000
reverse_proxy php:8000
header {
-Server
X-Content-Type-Options "nosniff"
X-Frame-Options "DENY"
X-XSS-Protection "1; mode=block"
}
header {
-Server
X-Content-Type-Options "nosniff"
X-Frame-Options "DENY"
X-XSS-Protection "1; mode=block"
}
encode zstd gzip
encode zstd gzip
}

41
docker/caddy/generate-certs.sh Executable file
View File

@ -0,0 +1,41 @@
#!/bin/bash
set -e
certs_dir="$(dirname "$0")/certs"
domain="whisper.money.local"
cert_file="${certs_dir}/${domain}.pem"
key_file="${certs_dir}/${domain}-key.pem"
mkdir -p "$certs_dir"
if command -v mkcert &> /dev/null; then
if [ ! -f "$(mkcert -CAROOT)/rootCA.pem" ]; then
echo "Installing local CA..."
mkcert -install
fi
echo "Generating certificates for ${domain}..."
mkcert -cert-file "$cert_file" -key-file "$key_file" "$domain" "*.${domain}"
echo "Certificates generated successfully!"
echo "Files created:"
echo " - ${cert_file}"
echo " - ${key_file}"
elif command -v openssl &> /dev/null; then
echo "Creating self-signed certificates (browser will show a warning)..."
openssl req -x509 -nodes -days 365 -newkey rsa:2048 \
-keyout "$key_file" \
-out "$cert_file" \
-subj "/CN=${domain}/O=Development/C=US" \
-addext "subjectAltName=DNS:${domain},DNS:*.${domain},IP:127.0.0.1" \
2>/dev/null
chmod 644 "$cert_file"
chmod 600 "$key_file"
echo "Self-signed certificates created"
echo "Note: Your browser will show a security warning."
else
echo "Error: Neither mkcert nor openssl is available"
echo "Please install mkcert (recommended) or openssl"
exit 1
fi