# The one Caddy snippet. # # Three server designs each brought their own, on three different ports, and all # three wrote to this filename. This is the one that replaced them: one service, # one port, one prefix. CONTRACT.md §5. # # Install it beside your Caddyfile and import it into whichever site serves the # Tera browser build: # # import /etc/caddy/snippets/tera-api.snippet # # tera.lumbridgecorp.com { # import tera_api # root * /srv/tera/dist # file_server # } # # The API and the static build are deliberately the same origin. Nothing here # needs CORS, which is why TERA_CORS_ORIGIN defaults to empty — set it only for # a Vite dev server on another port. (tera_api) { handle /api/v1/* { reverse_proxy 127.0.0.1:8431 { # Fail fast rather than holding a browser connection open while the # API is restarting. systemd brings it back in under two seconds. transport http { dial_timeout 2s } } } # The API stamps its own Cache-Control — `private, no-store` by default, and # `public, max-age=…` only where a route opted in. Do not add a cache # directive here: this file cannot tell which route answered, and the # fail-closed policy is only fail-closed if nothing downstream overrides it. header { X-Content-Type-Options nosniff Referrer-Policy strict-origin-when-cross-origin } }