Serve the frontend on the bare domain instead of app.<domain>
Only drb.cusano.net and api.drb.cusano.net have public A records, so the app.<domain> vhost had no cert to present and the bare domain — the record that actually exists — matched no site at all, producing ERR_SSL_PROTOCOL_ERROR in the browser. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,4 +1,4 @@
|
|||||||
# Managed by Ansible — do not edit manually on the server.
|
# Managed by Ansible — do not edit manually.
|
||||||
|
|
||||||
api.{{ domain }} {
|
api.{{ domain }} {
|
||||||
reverse_proxy localhost:8888 {
|
reverse_proxy localhost:8888 {
|
||||||
@@ -6,7 +6,12 @@ api.{{ domain }} {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
app.{{ domain }} {
|
# Frontend is served on the bare domain, not app.{{ domain }}: only drb and api
|
||||||
|
# have public DNS records. A vhost for a name with no A record still starts,
|
||||||
|
# but Caddy retries ACME against it forever and logs a failure each time.
|
||||||
|
# To move it to app.{{ domain }}, create the A record first, then change this
|
||||||
|
# line — the reverse_proxy target stays the same either way.
|
||||||
|
{{ domain }} {
|
||||||
reverse_proxy localhost:3000 {
|
reverse_proxy localhost:3000 {
|
||||||
header_up X-Forwarded-For {remote_host}
|
header_up X-Forwarded-For {remote_host}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user