mirror of
https://github.com/psviderski/uncloud.git
synced 2026-10-06 13:18:58 +00:00
feat(caddy): add healthcheck to default Caddy spec and Compose deployment in docs
This commit is contained in:
1 parent
af277639dd
commit
70de7b1b8f
2 files changed
+42
-10
No files matched your search
+19
-2
@@ -4,6 +4,7 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
"regexp"
|
"regexp"
|
||||||
|
"time"
|
||||||
|
|
||||||
"github.com/Masterminds/semver"
|
"github.com/Masterminds/semver"
|
||||||
"github.com/distribution/reference"
|
"github.com/distribution/reference"
|
||||||
@@ -66,6 +67,7 @@ func (c *CaddyClient) Config(ctx context.Context, opts CaddyConfigOptions) (api.
|
|||||||
// CaddyDeploymentOptions configures a Caddy reverse proxy deployment.
|
// CaddyDeploymentOptions configures a Caddy reverse proxy deployment.
|
||||||
type CaddyDeploymentOptions struct {
|
type CaddyDeploymentOptions struct {
|
||||||
// Image defaults to the latest stable 2.x.x official Caddy image.
|
// Image defaults to the latest stable 2.x.x official Caddy image.
|
||||||
|
// Custom images must include curl and start Caddy with /etc/caddy/Caddyfile.
|
||||||
Image string
|
Image string
|
||||||
// Config contains an optional global Caddyfile.
|
// Config contains an optional global Caddyfile.
|
||||||
Config string
|
Config string
|
||||||
@@ -91,17 +93,32 @@ func (c *CaddyClient) NewDeployment(ctx context.Context, opts CaddyDeploymentOpt
|
|||||||
|
|
||||||
spec := api.ServiceSpec{
|
spec := api.ServiceSpec{
|
||||||
Container: api.ContainerSpec{
|
Container: api.ContainerSpec{
|
||||||
Command: []string{"caddy", "run", "-c", "/config/Caddyfile"},
|
|
||||||
Env: map[string]string{
|
Env: map[string]string{
|
||||||
"CADDY_ADMIN": "unix//run/caddy/admin.sock",
|
"CADDY_ADMIN": "unix//run/caddy/admin.sock",
|
||||||
},
|
},
|
||||||
|
Healthcheck: &api.HealthcheckSpec{
|
||||||
|
Test: []string{
|
||||||
|
"CMD",
|
||||||
|
"curl", "-fsS",
|
||||||
|
"-o", "/dev/null",
|
||||||
|
"--unix-socket", "/run/caddy/admin.sock",
|
||||||
|
"http://localhost/config/",
|
||||||
|
},
|
||||||
|
Interval: 30 * time.Second,
|
||||||
|
Timeout: 5 * time.Second,
|
||||||
|
Retries: 3,
|
||||||
|
StartPeriod: 10 * time.Second,
|
||||||
|
StartInterval: 1 * time.Second,
|
||||||
|
},
|
||||||
Image: image,
|
Image: image,
|
||||||
VolumeMounts: []api.VolumeMount{
|
VolumeMounts: []api.VolumeMount{
|
||||||
{
|
{
|
||||||
VolumeName: "data",
|
VolumeName: "data",
|
||||||
ContainerPath: "/config",
|
ContainerPath: "/etc/caddy",
|
||||||
|
ReadOnly: true,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
// Keep local TLS assets persistent while Caddy uses the default file system storage.
|
||||||
VolumeName: "data",
|
VolumeName: "data",
|
||||||
ContainerPath: "/data",
|
ContainerPath: "/data",
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -34,7 +34,7 @@ uc caddy deploy
|
|||||||
Deploy a specific version or custom image:
|
Deploy a specific version or custom image:
|
||||||
|
|
||||||
```shell
|
```shell
|
||||||
uc caddy deploy --image caddybuilds/caddy-cloudflare:2.10.2
|
uc caddy deploy --image caddybuilds/caddy-cloudflare:2.11.4
|
||||||
```
|
```
|
||||||
|
|
||||||
Deploy only to a specific machine or a subset of machines (comma-separated list):
|
Deploy only to a specific machine or a subset of machines (comma-separated list):
|
||||||
@@ -80,19 +80,27 @@ config that uses the DNS challenge with Cloudflare to obtain a wildcard TLS cert
|
|||||||
```yaml
|
```yaml
|
||||||
services:
|
services:
|
||||||
caddy:
|
caddy:
|
||||||
image: caddybuilds/caddy-cloudflare:2.10.2
|
image: caddybuilds/caddy-cloudflare:2.11.4
|
||||||
command: caddy run -c /config/Caddyfile
|
|
||||||
environment:
|
environment:
|
||||||
# unix// is not a typo. Caddy uses network/address format, not a unix:// URL.
|
# unix// is not a typo. Caddy uses network/address format, not a unix:// URL.
|
||||||
CADDY_ADMIN: unix//run/caddy/admin.sock
|
CADDY_ADMIN: unix//run/caddy/admin.sock
|
||||||
env_file:
|
env_file:
|
||||||
# Contains CLOUDFLARE_API_TOKEN=xxxxx
|
# Contains CLOUDFLARE_API_TOKEN=xxxxx
|
||||||
- .env.secrets
|
- .env.secrets
|
||||||
|
healthcheck:
|
||||||
|
test: curl -fsS -o /dev/null --unix-socket /run/caddy/admin.sock http://localhost/config/
|
||||||
|
interval: 30s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 3
|
||||||
|
start_period: 10s
|
||||||
|
start_interval: 1s
|
||||||
volumes:
|
volumes:
|
||||||
|
- /var/lib/uncloud/caddy:/etc/caddy:ro
|
||||||
|
# Persists TLS certificates and other assets when using Caddy's default local storage.
|
||||||
- /var/lib/uncloud/caddy:/data
|
- /var/lib/uncloud/caddy:/data
|
||||||
- /var/lib/uncloud/caddy:/config
|
|
||||||
- /run/uncloud/caddy:/run/caddy
|
- /run/uncloud/caddy:/run/caddy
|
||||||
# Required by caddy.storage.uncloud module. Remove this mount if Uncloud cluster storage is not used for Caddy.
|
# Required by the Uncloud cluster storage module (https://github.com/unlabs-dev/caddy-uncloud).
|
||||||
|
# Remove this mount if cluster storage is not used for Caddy.
|
||||||
# Mount the directory, not the socket file, so Caddy sees a replacement socket after the daemon restarts.
|
# Mount the directory, not the socket file, so Caddy sees a replacement socket after the daemon restarts.
|
||||||
- /run/uncloud/api:/run/uncloud/api:ro
|
- /run/uncloud/api:/run/uncloud/api:ro
|
||||||
x-ports:
|
x-ports:
|
||||||
@@ -142,9 +150,16 @@ internal.example.com {
|
|||||||
|
|
||||||
:::info note
|
:::info note
|
||||||
|
|
||||||
The specified `command`, `environment`, `volumes`, and `x-ports` properties are essential for Caddy to function
|
The specified `environment`, `volumes`, and `x-ports` properties are essential for Caddy to function correctly in the
|
||||||
correctly in the Uncloud cluster. Do not change the source paths of the volume mounts as the Uncloud daemon relies on
|
Uncloud cluster. Do not change the source paths of the volume mounts as the Uncloud daemon relies on them to communicate
|
||||||
them to communicate with Caddy and update its configuration.
|
with Caddy and update its configuration.
|
||||||
|
|
||||||
|
The image must include `curl` for the healthcheck and start Caddy with `/etc/caddy/Caddyfile`. Images based on the
|
||||||
|
official [Caddy image](https://hub.docker.com/_/caddy) do both by default.
|
||||||
|
|
||||||
|
Keep the `/data` mount while using Caddy's default local storage so TLS certificates survive container updates. You can
|
||||||
|
remove this mount when using the [Uncloud storage module](https://github.com/unlabs-dev/caddy-uncloud) with
|
||||||
|
`storage uncloud` in your global Caddy config.
|
||||||
|
|
||||||
:::
|
:::
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user