mitbringsl/deploy/Caddyfile.behind-proxy
Tronax 895725b5e5
Backend Phase C: Sync-Kern + Caddy behind-proxy
Sync-Kern:
- internal/sync/hlc.go: Hybrid Logical Clock (wall_ms<<16|counter)
  Tick/Now/After, global mutex, strikt monoton + kausal korrekt
- internal/sync/hlc_test.go: Unit-Tests (monoton, kausal, keine Duplikate)

Store-Schicht:
- internal/store/opstore.go: AppendOps idempotent via UNIQUE(client_id,
  client_seq) ON CONFLICT DO NOTHING; LWW-Projektion (list_create/
  rename/delete, item_add/update/remove) in derselben Transaktion;
  PullOps mit Cursor (seq > since, 500er Pages)
- internal/store/liststore.go: CreateList / GetLists / GetList
- internal/store/itemstore.go: GetItems (nicht-gelöschte Items)
- internal/store/suggeststore.go: Search (pg_trgm + LIKE-fallback, 10)

HTTP-Handler:
- internal/httpapi/lists.go: GET/POST /api/lists, GET /api/lists/{id}
- internal/httpapi/ops.go: POST /api/lists/{id}/ops (Push),
  GET /api/lists/{id}/ops (Pull ?since=)
- internal/httpapi/suggest.go: GET /api/suggestions?q=
- internal/httpapi/api.go: alle Routen verdrahtet (RequireAuth)

Deployment:
- deploy/Caddyfile.behind-proxy: auto_https off, trusted_proxies
- deploy/Caddyfile: X-Forwarded-Proto hinzugefügt, Kommentar aktualisiert
- deploy/docker-compose.yml: CADDY_HTTP_PORT + CADDY_HTTPS_PORT
- deploy/.env.example: Caddy-Port-Variablen dokumentiert

go build ./... && go vet ./... && go test ./... 
HLC-Tests: monoton, kausal, keine Duplikate 
AGENTS.md: Phase C vollständig 
2026-08-05 19:56:05 +02:00

41 lines
1.2 KiB
Text
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Caddyfile for mitbringsl behind external reverse proxy mode.
#
# Use this when your own reverse proxy (nginx, Traefik, etc.) handles TLS
# termination and routes traffic to Caddy over plain HTTP on the internal
# Docker network.
#
# In docker-compose.yml, mount this file instead of the default Caddyfile:
# volumes:
# - ./Caddyfile.behind-proxy:/etc/caddy/Caddyfile:ro
#
# Your external proxy should set:
# X-Forwarded-For <client-ip>
# X-Forwarded-Proto https
# Host <your-domain>
{
# Disable auto-HTTPS TLS is handled by the outer proxy.
auto_https off
}
:80 {
# Trust the private-network upstream so X-Forwarded-* headers are accepted.
# Change to a specific IP/CIDR if your proxy has a fixed address.
trusted_proxies private_ranges
reverse_proxy backend:8080 {
# Forward the real client IP to the backend.
header_up X-Real-IP {http.request.header.X-Forwarded-For}
header_up X-Forwarded-For {http.request.header.X-Forwarded-For}
header_up X-Forwarded-Proto {http.request.header.X-Forwarded-Proto}
}
# Enforce a sensible request body size limit.
request_body {
max_size 2MB
}
log {
output stdout
format console
}
}