# Caddyfile for mitbringsl.
# Caddy automatically obtains and renews a Let's Encrypt certificate when the
# site address is a real domain. For local development it falls back to an
# internal CA / self-signed cert automatically.
{
	# email you@example.com   # optional, for ACME account
}

{$SITE_ADDRESS:localhost} {
	reverse_proxy backend:8080 {
		header_up X-Real-IP {remote_host}
		header_up X-Forwarded-For {remote_host}
	}

	# Useful default headers
	header {
		Strict-Transport-Security "max-age=31536000"
		X-Content-Type-Options "nosniff"
		Referrer-Policy "no-referrer"
	}

	# Health endpoint passthrough already handled by backend; keep it simple.
	request_body {
		max_size 2MB
	}

	log {
		output stdout
		format console
	}
}
