Caddy
| Guest | caddy — LXC 100 @ 10.0.1.20 |
| Role | Sole reverse proxy + TLS ingress for all HTTP services |
| Tailnet | yes — «CADDY_TAILNET_IP» (all service DNS points here) |
| Config | /etc/caddy/Caddyfile — snapshot in caddyfile |
| Update | manual binary install, systemd service |
Purpose
The single HTTP ingress for «PROJECT». Every *.«MYDOMAIN» service
hostname resolves (via Technitium, tailnet-side) to «CADDY_TAILNET_IP»;
Caddy routes by SNI/hostname to the internal 10.0.1.x backends.
TLS
Per-site Let’s Encrypt certs via Cloudflare DNS-01 — no public DNS records needed:
CLOUDFLARE_API_TOKENcomes from the service environment.resolvers 1.1.1.1+propagation_timeout 10mper site block.tailscale set --accept-dns=falseon this container so ACME public DNS resolution works despite tailnet DNS settings.
Adding a site
See add-service — the Caddyfile block template lives there and in caddyfile.
Notes
- SSH is not proxied — non-HTTP protocols need their own tailnet path (why gitea is tailnet-joined).