9 ms·
I happened to need to do this in NixOS yesterday, and look how easy it is: security.acme = { acceptTerms = true; email = "mail@whatever.net"; };
by spindle 4y ago
I happened to need to do this in NixOS yesterday, and look how easy it is:
security.acme = {
acceptTerms = true;
email = "mail@whatever.net";
};
services.nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
virtualHosts."whatever.net" = { default = true; enableACME = true; addSSL = true; locations."/".proxyPass = "http://127.0.0.1:9955/"; };
};
and then each additional proxy takes just one more line. Not quite zero boilerplate, but almost!
- nyolfen 4y agohere's my caddy config for a reverse proxy with TLS: sub.domain.com { reverse_proxy localhost:8080 }
- kuschku 4y agoYou mean sub.domain.com, sub.domain.com. { reverse_proxy localhost:8080 } ? Because caddy currently doesn’t handle DNS names correctly, so you have to duplicate every single virtual hostname config (it’s a long-standing open bug) [EDIT: Thanks to francislavoie for reminding me about the shorter syntax for this]
- francislavoie 4y agoActually, we mean: sub.domain.com, sub.domain.com. { reverse_proxy localhost:8080 } But seriously. Can you stop posting about this every single time there's even a vague mention of Caddy on HN? It's tired. You've gotten your answer before. Huge majority of people don't care about trailing dot domains. Trailing dots are complicated and really not worth the complexity it would involve to support them. See https://daniel.haxx.se/blog/2022/05/12/a-tale-of-a-trailing-dot/ https://daniel.haxx.se/blog/2022/05/12/a-tale-of-a-trailing-...
- kuschku 4y ago> Can you stop posting about this every single time there's even a vague mention of Caddy on HN? It's tired It’s a genuine issue I’ve got with Caddy, and if someone recommends Caddy, I’m justified to mention the drawbacks of Caddy. In this case, a user recommended switching from nginx to Caddy, and nginx users (who expect trailing dot domains to just work) should keep this drawback in mind. Every time you compare Caddy or Traefik to nginx or apache, you should expect to also see the drawbacks of Caddy and Traefik mentioned.
- gjs278 4y ago
- mholt 4y agoYou're not being a productive member of the community. You only complain about Caddy, instead of giving solid technical arguments for your case. We have presented ample evidence, experience, and technical reasoning to support our argument, but you continue to ignore the logical, technical, and complex arguments and instead complain to rack up fake Internet points here. We want to make a better product, but you need to convince us that your way is better than all the evidence, experience, and technical reasons we have already presented.
- kuschku 4y agoSee that’s exactly the issue. You expect me to do work and spend time just to convince you to be standards-compliant. How can I trust caddy complies with standards in other areas if caddy isn’t willing to follow the standard (which really doesn’t take much work) in this area? It’d be different if the de facto and the de jure standard diverged, as e.g., with IRC, but that’s not the case. nginx, Apache, IIS, Google’s GWS, they all follow the standard exactly, it’s just traefik and caddy that don’t. It’s not an issue of this situation in of itself, it’s an issue of eroding trust. It’s the famous brown m&ms. P.S.: Your arguments explain why implementing this would be a lot of work (keeping the ticket open as known issue is something I’d be fine with), but they can’t justify ignoring the standard and closing it as wontfix.
- nousermane 4y agoHey, at least caddy does case-insensetive hostname match, so you don't need to repeat the domain 2^12 times </s> Seriously though - that's a pretty bizarre bug, absent from both nginx and apache httpd. And that attitude in sibling comment doesn't help either.
- kuschku 4y agoIt’s not just the sibling comment that has this attitude, it’s also mholt himself displaying the same attitude. This hostile opinionated approach is part of what has kept me from using Caddy for the past few years (I went back to nginx at first, and once I started using k8s I also chose nginx as ingress controller there). :/
- nyolfen 4y agoi have to say it is pretty weird to persistently complain about software you haven't used for years lol. i have also never used a trailing dot in a domain in 20+ years.
- kuschku 4y ago1. Just because I’m not running servers using caddy doesn’t mean I’m not affected by this bug, because some of my clients intentionally always postfix addresses they access with a dot to avoid internal DNS resolution. 2. I’d love to use caddy. I’m especially interested in using it for my status page, as that needs to be hosted outside my normal cluster. Ideally it should be an absolutely minimal setup (so nothing except caddy + status page, with status monitors on other servers reporting back to the status page). This would be the perfect use case for caddy, but right now I’m using an overcomplicated nginx setup because I don’t feel like I can trust caddy.
- mholt 4y agoYou don't even need a config file for that! $ caddy reverse-proxy --from sub.domain.com --to localhost:8080 Done :)
- tinco 4y agoThat's super interesting. Automatic ACME is not a feature in nginx right? So the maintainers of the nginx NixOS package have built this integration themselves just to make NixOS more powerful for this use case?
- mholt 4y ago> Automatic ACME is not a feature in nginx right? Correct. You need separate, less reliable tooling to use ACME with nginx.
- jphsnsir 4y agoHow was the Nix experience? Did you try just nix or also NixOS?
- francislavoie 4y agoI think you replied to the wrong comment
- jphsnsir 4y agoNo, I'd like to know why he called it 'less reliable'. He must have used it on nix(linux) or nix(darwin) or NixOS..
- francislavoie 4y agoThe comment wasn't about Nix, it was about ACME clients paired with Nginx being less reliable than having the ACME client built into your server (e.g. how Caddy does it). The comment was by Matt Holt, the author of Caddy.
- kuschku 4y agoDoesn’t the built-in tooling only really provide an advantage if you’re using the http or sni challenges? If you want to use wildcard certs via the dns-01 challenge (in my case via rfc2136), the entire challenge runs out of band anyway, so there’s no difference in reliability. (At least in my tests so far, though support for the RFC 2136 standard in caddy and/or plugins is quite poor afaict)
- evol262 4y agoThis is rapidly becoming a bad joke. "You know how someone does Crossfit/is a vegan?" You know how someone uses NixOS?
- spindle 4y agoRight! I even felt slightly guilty for posting it ... but I posted it anyway because it's useful.