Caddy

Guestcaddy — LXC 100 @ 10.0.1.20
RoleSole reverse proxy + TLS ingress for all HTTP services
Tailnetyes — «CADDY_TAILNET_IP» (all service DNS points here)
Config/etc/caddy/Caddyfile — snapshot in caddyfile
Updatemanual binary install, systemd service

Purpose

The single HTTP ingress for «PROJECT». Every *.«MYDOMAIN» service hostname resolves (via Technitium, tailnet-side) to «CADDY_TAILNET_IP»; Caddy routes by SNI/hostname to the internal 10.0.1.x backends.

TLS

Per-site Let’s Encrypt certs via Cloudflare DNS-01 — no public DNS records needed:

  • CLOUDFLARE_API_TOKEN comes from the service environment.
  • resolvers 1.1.1.1 + propagation_timeout 10m per site block.
  • tailscale set --accept-dns=false on this container so ACME public DNS resolution works despite tailnet DNS settings.

Adding a site

See add-service — the Caddyfile block template lives there and in caddyfile.

Notes

  • SSH is not proxied — non-HTTP protocols need their own tailnet path (why gitea is tailnet-joined).