mirror of
https://github.com/psviderski/uncloud.git
synced 2026-10-06 13:18:58 +00:00
docs(caddy): new page Cluster storage for Caddy
This commit is contained in:
1 parent
f78a8ca8b5
commit
87e99ae369
3 files changed
+71
-2
No files matched your search
@@ -24,3 +24,11 @@ When you [publish a service port](2-publishing-services.md), Uncloud automatical
|
|||||||
|
|
||||||
For advanced use cases, Uncloud allows to customise the Caddy config using the `x-caddy` extension in Compose files.
|
For advanced use cases, Uncloud allows to customise the Caddy config using the `x-caddy` extension in Compose files.
|
||||||
See [Custom Caddy configuration](2-publishing-services.md#custom-caddy-configuration) for details.
|
See [Custom Caddy configuration](2-publishing-services.md#custom-caddy-configuration) for details.
|
||||||
|
|
||||||
|
:::tip Shared TLS certificates
|
||||||
|
|
||||||
|
Uncloud also provides native cluster storage for Caddy. It shares TLS certificates and ACME challenge tokens across
|
||||||
|
machines and coordinates certificate issuance. See [Cluster storage for Caddy](4-cluster-storage-for-caddy.md)
|
||||||
|
to enable it.
|
||||||
|
|
||||||
|
:::
|
||||||
@@ -3,6 +3,10 @@
|
|||||||
Caddy is automatically deployed as a global service `caddy` when you initialise a cluster with `uc machine init`. By
|
Caddy is automatically deployed as a global service `caddy` when you initialise a cluster with `uc machine init`. By
|
||||||
default, it runs on every machine to handle incoming HTTP/HTTPS traffic and route it to your services.
|
default, it runs on every machine to handle incoming HTTP/HTTPS traffic and route it to your services.
|
||||||
|
|
||||||
|
Since [v0.21.0](https://github.com/psviderski/uncloud/releases/tag/v0.21.0), Uncloud provides native
|
||||||
|
[cluster storage for Caddy](4-cluster-storage-for-caddy.md) (opt-in) to share TLS certificates and coordinate
|
||||||
|
certificate issuance across machines.
|
||||||
|
|
||||||
## Checking status
|
## Checking status
|
||||||
|
|
||||||
View the `caddy` service status and which machines it's running on:
|
View the `caddy` service status and which machines it's running on:
|
||||||
@@ -158,8 +162,7 @@ The image must include `curl` for the healthcheck and start Caddy with `/etc/cad
|
|||||||
official [Caddy image](https://hub.docker.com/_/caddy) do both by default.
|
official [Caddy image](https://hub.docker.com/_/caddy) do both by default.
|
||||||
|
|
||||||
Keep the `/data` mount while using Caddy's default local storage so TLS certificates survive container updates. You can
|
Keep the `/data` mount while using Caddy's default local storage so TLS certificates survive container updates. You can
|
||||||
remove this mount when using the [Uncloud storage module](https://github.com/unlabs-dev/caddy-uncloud) with
|
remove this mount when using [cluster storage for Caddy](4-cluster-storage-for-caddy.md).
|
||||||
`storage uncloud` in your global Caddy config.
|
|
||||||
|
|
||||||
:::
|
:::
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,58 @@
|
|||||||
|
# Cluster storage for Caddy
|
||||||
|
|
||||||
|
The [Uncloud storage module](https://github.com/unlabs-dev/caddy-uncloud) lets Caddy instances share TLS certificates,
|
||||||
|
private keys, and ACME challenge tokens through Uncloud's cluster store. It uses distributed locks to coordinate
|
||||||
|
certificate issuance. Once one instance obtains a certificate, the others can use it too.
|
||||||
|
|
||||||
|
## Why use cluster storage?
|
||||||
|
|
||||||
|
By default, each Caddy instance stores its certificates locally. When DNS points to multiple machines or a load balancer
|
||||||
|
distributes traffic between them, an ACME challenge can reach a different instance from the one requesting the
|
||||||
|
certificate. That instance may not have the challenge token, which can delay or prevent certificate issuance.
|
||||||
|
|
||||||
|
Cluster storage is optional. The default Caddy image does not include the module, so you need to deploy an image that
|
||||||
|
includes it and configure Caddy to use it.
|
||||||
|
|
||||||
|
## Enabling cluster storage
|
||||||
|
|
||||||
|
:::info Requirements
|
||||||
|
|
||||||
|
Cluster storage requires Uncloud **v0.21.0 or newer** for both the `uc` CLI and the daemon on every cluster machine.
|
||||||
|
Check your CLI version with `uc version` and daemon versions with `uc machine ls`. Upgrade older versions before
|
||||||
|
enabling cluster storage.
|
||||||
|
|
||||||
|
:::
|
||||||
|
|
||||||
|
Create a global Caddyfile, or add `storage uncloud` to the global options in your existing one:
|
||||||
|
|
||||||
|
```caddyfile title="global.Caddyfile"
|
||||||
|
{
|
||||||
|
storage uncloud
|
||||||
|
|
||||||
|
# Uncomment to enable debug logs useful for troubleshooting storage operations:
|
||||||
|
# debug
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
Deploy Caddy with the pre-built module image and your global config:
|
||||||
|
|
||||||
|
```shell
|
||||||
|
uc caddy deploy --image ghcr.io/unlabs-dev/caddy-uncloud:0.1.1 --caddyfile global.Caddyfile
|
||||||
|
```
|
||||||
|
|
||||||
|
See the [module README](https://github.com/unlabs-dev/caddy-uncloud#usage) for custom image builds, Compose deployment,
|
||||||
|
and additional storage options.
|
||||||
|
|
||||||
|
## Verifying storage
|
||||||
|
|
||||||
|
Check that `storage uncloud` appears in the Caddy config:
|
||||||
|
|
||||||
|
```shell
|
||||||
|
uc caddy config
|
||||||
|
```
|
||||||
|
|
||||||
|
List issued certificates in cluster storage with [`uc caddy cert ls`](../../9-cli-reference/uc_caddy_cert_ls.md):
|
||||||
|
|
||||||
|
```shell
|
||||||
|
uc caddy cert ls
|
||||||
|
```
|
||||||
Reference in new issue
Block a user