Write the deployment guide and an example Caddy config (closes #89)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
README.md gains a "Deployment" section: what the reverse proxy in front of pixa must do (terminate TLS, pass Host, Origin and Referer on unchanged, set X-Forwarded-For with trusted_proxies to match, wait at least downstream_timeout, optionally refuse /metrics) and what pixa does itself; that the state directory needs a persistent volume, what cache_max_bytes counts and why to set it; the health check for a load balancer; what SIGTERM does and the exit codes; and what running outside Docker needs. configs/Caddyfile is the example, as Caddy needs no settings beyond the host name and pixa's address. Model: opus-5-5
This commit was merged in pull request #182.
This commit is contained in:
@@ -0,0 +1,17 @@
|
||||
# Example Caddy config for running pixa behind Caddy; see "Deployment" in
|
||||
# README.md. Replace images.example.com with pixa's public host name, and
|
||||
# 127.0.0.1:8080 with the address Caddy reaches pixa on.
|
||||
#
|
||||
# Caddy gets and renews the TLS certificate for the host name, passes the
|
||||
# Host, Origin and Referer headers on unchanged, sets X-Forwarded-For to the
|
||||
# client's address, and waits for pixa's answer with no time limit of its
|
||||
# own, so pixa's downstream_timeout is what ends a slow request.
|
||||
|
||||
images.example.com
|
||||
|
||||
# pixa asks for metrics.username and metrics.password on /metrics. This
|
||||
# line also keeps it off the public address, for a scraper that reaches
|
||||
# pixa directly; remove it to read /metrics through Caddy.
|
||||
respond /metrics 404
|
||||
|
||||
reverse_proxy 127.0.0.1:8080
|
||||
Reference in New Issue
Block a user