deploy: Docker Compose stack with Caddy + Cloudflare TLS
Full production stack via docker compose:
- Caddy reverse proxy with Cloudflare DNS-01 TLS certs
- warzone-server (featherChat API + web UI)
- wzp-relay (QUIC audio SFU)
- wzp-web (browser WS ↔ QUIC bridge)
Architecture:
Internet → Caddy (443/TLS) → voip.manko.yoga
/* → warzone-server:7700
/audio/* → wzp-web:8080
Files:
- docker-compose.yml: main stack (4 services)
- docker-compose.ipv6.yml: IPv6 overlay
- Caddyfile: Cloudflare DNS challenge + reverse proxy
- Dockerfile.server: featherChat multi-stage build
- Dockerfile.wzp: wzp-relay + wzp-web multi-stage build
- .env.example: DNS records for dev/staging/prod
- test-stack.sh: smoke test (8 checks)
- .dockerignore: excludes target/, .git/, etc.
Deployment targets:
dev: 172.16.81.135
ipv6: 2a0d:3344:692c:2500:14f2:5885:d73c:b0a1
prod: 63.250.54.239 / 2602:ff16:9:0:1:3d9:0:1
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
21
warzone/deploy/docker/Caddyfile
Normal file
21
warzone/deploy/docker/Caddyfile
Normal file
@@ -0,0 +1,21 @@
|
||||
{
|
||||
# Global ACME settings
|
||||
email admin@manko.yoga
|
||||
}
|
||||
|
||||
voip.manko.yoga {
|
||||
# TLS via Cloudflare DNS-01 challenge
|
||||
tls {
|
||||
dns cloudflare {$CF_API_TOKEN}
|
||||
}
|
||||
|
||||
# Audio bridge WebSocket (wzp-web)
|
||||
# /audio/ws/* → wzp-web:8080/ws/*
|
||||
handle_path /audio/* {
|
||||
reverse_proxy wzp-web:8080
|
||||
}
|
||||
|
||||
# Everything else → featherChat server
|
||||
# Web UI (/), API (/v1/*), WebSocket (/v1/ws/*)
|
||||
reverse_proxy warzone-server:7700
|
||||
}
|
||||
Reference in New Issue
Block a user