# Caddyfile used only by the E2E test stack. Listens on the in-container :3101 # (mapped to host :3101) and proxies API + media to the backend, everything else # to the SvelteKit frontend container — same layout as production but stripped # of HTTPS/Let's Encrypt. :3101 { # Mirror prod: exclude the SSE stream from compression so buffering doesn't # delay real-time events (and so the test stack exercises the real behavior). @compressible not path /api/v1/stream encode @compressible zstd gzip # Mirror prod's security headers (minus HSTS, which is HTTPS-only). header { X-Content-Type-Options "nosniff" Referrer-Policy "strict-origin-when-cross-origin" } # Mirror prod's export carve-out: the keepsake download targets a hidden # same-origin iframe, and WebKit enforces XFO before Content-Disposition. # Two disjoint matchers, not an override — see the comment in ../Caddyfile. @framable path /api/v1/export/zip /api/v1/export/html @not_framable not path /api/v1/export/zip /api/v1/export/html header @framable X-Frame-Options "SAMEORIGIN" header @not_framable X-Frame-Options "DENY" reverse_proxy /api/* app:3000 reverse_proxy /media/* app:3000 reverse_proxy /health app:3000 reverse_proxy frontend:3001 }