mirror of
https://github.com/HeyPuter/puter.git
synced 2026-08-24 06:58:21 +00:00
Replaced Nginx with Caddy (#3378)
* Replace nginx with Caddy * updated caddy location * seprate logic for local and with domain caddy setup * updated install * updated install scripts new ps1 script with caddy, and removed instances of nginx * fix Caddy Host routing, restore TLS/SELinux/healthcheck, update docs --------- Co-authored-by: Daniel Salazar <daniel.salazar@puter.com>
This commit is contained in:
co-authored by
Daniel Salazar
parent
0a61b4e78b
commit
7cf3e03433
+36
-18
@@ -7,7 +7,8 @@
|
||||
# What this does, in order:
|
||||
# 1. Checks that docker (with the compose plugin), curl, and openssl exist.
|
||||
# 2. Creates ./puter-selfhosted/ (override with PUTER_DIR=...).
|
||||
# 3. Downloads docker-compose.yml from the OSS repo (raw.githubusercontent.com).
|
||||
# 3. Downloads docker-compose.yml + caddy/Caddyfile from the OSS repo
|
||||
# (raw.githubusercontent.com).
|
||||
# 4. Generates fresh secrets and writes .env + puter/config/config.json.
|
||||
# 5. Runs `docker compose up -d` and prints the first-boot admin password.
|
||||
#
|
||||
@@ -19,15 +20,17 @@
|
||||
# PUTER_DIR install directory (default: ./puter-selfhosted)
|
||||
# PUTER_URL base URL to fetch docker-compose.yml (default: GitHub raw, main branch)
|
||||
# PUTER_DOMAIN domain Puter will serve on (default: puter.localhost)
|
||||
# PUTER_PORT HTTP port for nginx (default: 80)
|
||||
# PUTER_PORT HTTP port for Caddy (default: 80)
|
||||
# PUTER_PROTOCOL public scheme: http | https (default: http)
|
||||
# Set https when a TLS-terminating reverse proxy (Caddy,
|
||||
# Traefik, nginx, a cloud LB) sits in front — Puter then
|
||||
# builds https:// origins, S3 URLs, and redirects. See
|
||||
# "Running behind your own reverse proxy" in doc/self-hosting.md.
|
||||
# Set https once TLS is terminating in front of Puter —
|
||||
# either the bundled Caddy with your certs (see "Step 3 —
|
||||
# TLS" in doc/self-hosting.md) or your own proxy (Traefik,
|
||||
# a cloud LB). Puter then builds https:// origins, S3
|
||||
# URLs, and redirects. Leave it http and the installer
|
||||
# serves plain HTTP on PUTER_PORT.
|
||||
# PUTER_TRUST_PROXY number of reverse-proxy hops in front (default: 1)
|
||||
# 1 = the bundled nginx (or a single external proxy);
|
||||
# 2 = two hops (e.g. Cloudflare → your proxy → Puter).
|
||||
# 1 = the bundled Caddy (or a single external proxy);
|
||||
# 2 = two hops (e.g. Cloudflare → Caddy → Puter).
|
||||
# PUTER_ENV prod | dev (default: prod)
|
||||
# PUTER_FORCE set to 1 to overwrite existing .env / config.json
|
||||
|
||||
@@ -72,25 +75,27 @@ mkdir -p puter/config puter/data puter/tls
|
||||
# bind-mount roots sidesteps the mismatch without guessing each image's
|
||||
# internal UID. (Docker Desktop on macOS/Windows papers over this with
|
||||
# its VM layer; native Linux docker on Debian/Alpine doesn't.)
|
||||
mkdir -p puter/data/valkey puter/data/mariadb puter/data/dynamo puter/data/s3 puter/data/puter
|
||||
chmod 0777 puter/data/valkey puter/data/mariadb puter/data/dynamo puter/data/s3 puter/data/puter
|
||||
mkdir -p puter/data/valkey puter/data/mariadb puter/data/dynamo puter/data/s3 puter/data/puter puter/data/caddy
|
||||
chmod 0777 puter/data/valkey puter/data/mariadb puter/data/dynamo puter/data/s3 puter/data/puter puter/data/caddy
|
||||
log "install dir: $(pwd)"
|
||||
|
||||
# ── Step 3: docker-compose.yml + nginx config ──────────────────────
|
||||
# ── Step 3: docker-compose.yml + Caddy config ──────────────────────
|
||||
log "downloading docker-compose.yml from $PUTER_URL"
|
||||
curl -fsSL "$PUTER_URL/docker-compose.yml" -o docker-compose.yml \
|
||||
|| die "could not fetch $PUTER_URL/docker-compose.yml"
|
||||
|
||||
# nginx is mounted as `./nginx/nginx.conf:/etc/nginx/nginx.conf:ro` — if
|
||||
# Caddy is mounted as `./caddy/Caddyfile:/etc/caddy/Caddyfile:ro,z` — if
|
||||
# the host file is missing, docker silently creates a directory at that
|
||||
# path and the mount fails with "not a directory" at container start.
|
||||
log "downloading nginx/nginx.conf from $PUTER_URL"
|
||||
mkdir -p nginx
|
||||
# The Caddyfile is domain-agnostic — it answers on every Host and leaves
|
||||
# the subdomain routing to Puter — so there's nothing to template in.
|
||||
log "downloading caddy/Caddyfile from $PUTER_URL"
|
||||
mkdir -p caddy
|
||||
# If the path was previously auto-created as a dir by a failed `compose up`,
|
||||
# remove it so curl can write the file.
|
||||
[ -d nginx/nginx.conf ] && rmdir nginx/nginx.conf 2>/dev/null || true
|
||||
curl -fsSL "$PUTER_URL/nginx/nginx.conf" -o nginx/nginx.conf \
|
||||
|| die "could not fetch $PUTER_URL/nginx/nginx.conf"
|
||||
[ -d caddy/Caddyfile ] && rmdir caddy/Caddyfile 2>/dev/null || true
|
||||
curl -fsSL "$PUTER_URL/caddy/Caddyfile" -o caddy/Caddyfile \
|
||||
|| die "could not fetch $PUTER_URL/caddy/Caddyfile"
|
||||
|
||||
# ── Step 4: secrets, .env, config.json ──────────────────────────────
|
||||
write_config=1
|
||||
@@ -113,7 +118,8 @@ if [ "$write_config" = "1" ]; then
|
||||
|
||||
cat > .env <<EOF
|
||||
HTTP_PORT=$PUTER_PORT
|
||||
# HTTPS_PORT=443 # uncomment after enabling TLS (see doc/selfhosting/full-stack.md)
|
||||
# HTTPS_PORT=443 # uncomment after enabling TLS in caddy/Caddyfile
|
||||
# # (see "Step 3 — TLS" in doc/self-hosting.md)
|
||||
|
||||
MARIADB_ROOT_PASSWORD=$MARIADB_ROOT_PASSWORD
|
||||
MARIADB_DATABASE=puter
|
||||
@@ -190,6 +196,18 @@ EOF
|
||||
EOF
|
||||
fi
|
||||
|
||||
# `https` only works if something in front is actually terminating it. The
|
||||
# bundled Caddy does that from ./puter/tls once you enable its `:443` block
|
||||
# (see "Step 3 — TLS" in doc/self-hosting.md); your own edge proxy is fine
|
||||
# too. Neither in place means Puter hands out https:// URLs for an endpoint
|
||||
# that only speaks HTTP — broken logins and mixed content.
|
||||
if [ "$PUTER_PROTOCOL" = "https" ] && [ ! -f puter/tls/fullchain.pem ]; then
|
||||
warn "PUTER_PROTOCOL=https but ./puter/tls/fullchain.pem is missing."
|
||||
warn "The bundled Caddy is still serving plain HTTP on port $PUTER_PORT."
|
||||
warn "Either drop a wildcard cert into ./puter/tls and uncomment the :443"
|
||||
warn "block in caddy/Caddyfile, or terminate TLS in your own proxy."
|
||||
fi
|
||||
|
||||
# ── Step 5: bring it up ─────────────────────────────────────────────
|
||||
log "docker compose up -d"
|
||||
docker compose up -d
|
||||
|
||||
Reference in New Issue
Block a user