Merge pull request #182 from outis1one/claude/asterisk-digital-ocean-w22kk8
Claude/asterisk digital ocean w22kk8
This commit is contained in:
@@ -330,3 +330,19 @@ networks:
|
|||||||
```
|
```
|
||||||
|
|
||||||
And read the network name from `.env` using `CADDY_NET=$SITE_CADDY_NET`.
|
And read the network name from `.env` using `CADDY_NET=$SITE_CADDY_NET`.
|
||||||
|
|
||||||
|
`external: true` means *this* service expects the network to already exist —
|
||||||
|
it doesn't create it. `require_docker` creates it for you (via
|
||||||
|
`ensure_caddy_network` in `lib/common.sh`) the first time any service calls
|
||||||
|
it, so as long as your `install_<name>()` calls `require_docker` before
|
||||||
|
`docker compose up` (it always should), the network is guaranteed to exist
|
||||||
|
regardless of whether Caddy itself has been installed yet.
|
||||||
|
|
||||||
|
**`network_mode: host` services (e.g. `asterisk`/`asterisk-do`) don't join
|
||||||
|
`caddy_net` at all** — Caddy reaching them (or anything else on the host
|
||||||
|
network) needs `host.docker.internal:PORT` in the Caddyfile, not
|
||||||
|
`localhost:PORT` or a container name. Caddy's own compose file
|
||||||
|
(`services/caddy.sh`) sets `extra_hosts: host.docker.internal:host-gateway`
|
||||||
|
so that hostname resolves; `configure_caddy_for_service`'s bare-port upstream
|
||||||
|
case already does this for you — don't hand-roll `localhost:PORT` in a
|
||||||
|
Caddy site block.
|
||||||
|
|||||||
+29
-4
@@ -164,6 +164,7 @@ require_root() {
|
|||||||
|
|
||||||
require_docker() {
|
require_docker() {
|
||||||
if command -v docker &>/dev/null; then
|
if command -v docker &>/dev/null; then
|
||||||
|
ensure_caddy_network
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -222,6 +223,25 @@ require_docker() {
|
|||||||
local _docker_bin
|
local _docker_bin
|
||||||
_docker_bin="$(command -v docker 2>/dev/null || echo /usr/bin/docker)"
|
_docker_bin="$(command -v docker 2>/dev/null || echo /usr/bin/docker)"
|
||||||
log_success "Docker installed ($("$_docker_bin" --version 2>/dev/null))"
|
log_success "Docker installed ($("$_docker_bin" --version 2>/dev/null))"
|
||||||
|
|
||||||
|
ensure_caddy_network
|
||||||
|
}
|
||||||
|
|
||||||
|
# Create the shared caddy_net bridge network if it doesn't exist yet.
|
||||||
|
# Most services declare it "external: true" in their docker-compose.yml (see
|
||||||
|
# CLAUDE.md → Caddy network wiring) — meaning THEY require it to already
|
||||||
|
# exist, and only Caddy's own compose file (services/caddy.sh) actually
|
||||||
|
# creates it. Installing any caddy_net-dependent service before Caddy would
|
||||||
|
# otherwise fail outright with "network caddy_net declared as external, but
|
||||||
|
# could not be found." Called from require_docker so every service gets this
|
||||||
|
# for free regardless of install order. No-op in DRY_RUN; safe/idempotent
|
||||||
|
# otherwise — docker network create is a no-op if the network already exists.
|
||||||
|
ensure_caddy_network() {
|
||||||
|
[ "$DRY_RUN" = true ] && return 0
|
||||||
|
local _net="${SITE_CADDY_NET:-caddy_net}"
|
||||||
|
docker network inspect "$_net" &>/dev/null && return 0
|
||||||
|
docker network create "$_net" &>/dev/null \
|
||||||
|
&& log_info "Created Docker network ${_net} (needed by Caddy-fronted services)"
|
||||||
}
|
}
|
||||||
|
|
||||||
# ── SSH client config (~/.ssh/config) Host aliases ────────────────────────────
|
# ── SSH client config (~/.ssh/config) Host aliases ────────────────────────────
|
||||||
@@ -416,12 +436,17 @@ configure_caddy_for_service() {
|
|||||||
local SERVICE_NAME="$1" SERVICE_UPSTREAM="$2" DEFAULT_SUBDOMAIN="$3" EXTRA_CONFIG="${4:-}"
|
local SERVICE_NAME="$1" SERVICE_UPSTREAM="$2" DEFAULT_SUBDOMAIN="$3" EXTRA_CONFIG="${4:-}"
|
||||||
|
|
||||||
# Derive the proxy upstream and a port number for display messages.
|
# Derive the proxy upstream and a port number for display messages.
|
||||||
# Plain number → localhost:PORT (host-network or legacy services)
|
# Plain number → host.docker.internal:PORT (host-network or legacy
|
||||||
# name:port → used as-is (preferred: service on shared caddy_net)
|
# services — Caddy itself runs in its own container on
|
||||||
|
# caddy_net, a bridge network, so "localhost" here would
|
||||||
|
# resolve to Caddy's own container, not the host. Requires
|
||||||
|
# the extra_hosts entry set in services/caddy.sh's compose
|
||||||
|
# file — see the comment there.)
|
||||||
|
# name:port → used as-is (preferred: service on shared caddy_net)
|
||||||
local _UPSTREAM _DISPLAY_PORT
|
local _UPSTREAM _DISPLAY_PORT
|
||||||
case "$SERVICE_UPSTREAM" in
|
case "$SERVICE_UPSTREAM" in
|
||||||
*:*) _UPSTREAM="$SERVICE_UPSTREAM"; _DISPLAY_PORT="${SERVICE_UPSTREAM##*:}" ;;
|
*:*) _UPSTREAM="$SERVICE_UPSTREAM"; _DISPLAY_PORT="${SERVICE_UPSTREAM##*:}" ;;
|
||||||
*) _UPSTREAM="localhost:$SERVICE_UPSTREAM"; _DISPLAY_PORT="$SERVICE_UPSTREAM" ;;
|
*) _UPSTREAM="host.docker.internal:$SERVICE_UPSTREAM"; _DISPLAY_PORT="$SERVICE_UPSTREAM" ;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
# ── Determine Caddy mode ──────────────────────────────────────────────────
|
# ── Determine Caddy mode ──────────────────────────────────────────────────
|
||||||
|
|||||||
+10
-1
@@ -769,12 +769,21 @@ ENV
|
|||||||
local _CADDY_MODE="local"
|
local _CADDY_MODE="local"
|
||||||
[[ ! -d "$DOCKER_DIR/caddy" ]] && [[ -n "${CADDY_REMOTE_HOST:-}" ]] && _CADDY_MODE="remote"
|
[[ ! -d "$DOCKER_DIR/caddy" ]] && [[ -n "${CADDY_REMOTE_HOST:-}" ]] && _CADDY_MODE="remote"
|
||||||
|
|
||||||
|
# Asterisk runs with network_mode: host, so whatever proxies to it
|
||||||
|
# needs a way to reach the host, not "localhost" (which resolves
|
||||||
|
# to the proxying container's own netns). A local Caddy container
|
||||||
|
# reaches the host via host.docker.internal (wired up in
|
||||||
|
# services/caddy.sh's compose file); a remote Caddy machine needs
|
||||||
|
# this droplet's actual public IP instead.
|
||||||
|
local _PROXY_TARGET="host.docker.internal:${WEB_ADMIN_PORT_VAL}"
|
||||||
|
[[ "$_CADDY_MODE" == "remote" ]] && _PROXY_TARGET="${PUBLIC_IP}:${WEB_ADMIN_PORT_VAL}"
|
||||||
|
|
||||||
local _SITE_BLOCK
|
local _SITE_BLOCK
|
||||||
_SITE_BLOCK="$(cat << CADDY_BLOCK
|
_SITE_BLOCK="$(cat << CADDY_BLOCK
|
||||||
|
|
||||||
# Asterisk Web Admin
|
# Asterisk Web Admin
|
||||||
${DOMAIN_NAME} {
|
${DOMAIN_NAME} {
|
||||||
reverse_proxy localhost:${WEB_ADMIN_PORT_VAL}
|
reverse_proxy ${_PROXY_TARGET}
|
||||||
|
|
||||||
header {
|
header {
|
||||||
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
||||||
|
|||||||
@@ -387,13 +387,8 @@ AUTHELIA_USERS
|
|||||||
chown -R 1000:1000 "$AUTHELIA_DIR/config" "$AUTHELIA_DIR/data"
|
chown -R 1000:1000 "$AUTHELIA_DIR/config" "$AUTHELIA_DIR/data"
|
||||||
log_success "Authelia configured at $AUTHELIA_DIR"
|
log_success "Authelia configured at $AUTHELIA_DIR"
|
||||||
|
|
||||||
# ── Docker network ────────────────────────────────────────────────────────
|
# $CADDY_NET already exists at this point — require_docker (called at the
|
||||||
if ! docker network ls --format '{{.Name}}' | grep -q "^${CADDY_NET}$"; then
|
# top of this function) creates it via ensure_caddy_network in lib/common.sh.
|
||||||
docker network create "$CADDY_NET" >/dev/null 2>&1 && echo " ✓ Created docker network ${CADDY_NET}" \
|
|
||||||
|| echo " ⚠ Failed to create ${CADDY_NET}"
|
|
||||||
else
|
|
||||||
echo " ✓ Docker network ${CADDY_NET} already exists"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# ── Caddyfile forward-auth snippet + portal block ────────────────────────
|
# ── Caddyfile forward-auth snippet + portal block ────────────────────────
|
||||||
local CADDY_FILE="$DOCKER_DIR/caddy/Caddyfile"
|
local CADDY_FILE="$DOCKER_DIR/caddy/Caddyfile"
|
||||||
|
|||||||
@@ -267,6 +267,12 @@ services:
|
|||||||
- ACME_AGREE=true
|
- ACME_AGREE=true
|
||||||
labels:
|
labels:
|
||||||
- "io.podman.annotations.label/crowdsec.enable=true"
|
- "io.podman.annotations.label/crowdsec.enable=true"
|
||||||
|
# Lets Caddyfile blocks reach services that use network_mode: host
|
||||||
|
# (e.g. asterisk/asterisk-do) via "host.docker.internal:PORT" — Caddy
|
||||||
|
# itself is on the caddy_net bridge network below, so plain "localhost"
|
||||||
|
# in a site block resolves to Caddy's own container, not the host.
|
||||||
|
extra_hosts:
|
||||||
|
- "host.docker.internal:host-gateway"
|
||||||
networks:
|
networks:
|
||||||
- caddy_net
|
- caddy_net
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user