# Email used for the Let's Encrypt account (certificate expiry notices).
{
	email {$ACME_EMAIL}
}

# {$DOMAIN} is injected from the environment. Because it is a real hostname,
# Caddy automatically provisions and renews a Let's Encrypt certificate and
# redirects HTTP -> HTTPS. For local testing set DOMAIN=localhost to get a
# self-signed cert instead.
{$DOMAIN} {
	root * /var/www/html/public

	encode zstd gzip

	# Hand PHP requests to the php-fpm container; serve everything else as files.
	php_fastcgi app:9000
	file_server

	# Cap upload size (matches the dev nginx config).
	request_body {
		max_size 64MB
	}

	header {
		X-Content-Type-Options "nosniff"
		X-Frame-Options "SAMEORIGIN"
		-Server
	}

	# Block dotfiles except ACME's /.well-known challenge path.
	@hidden {
		path /.*
		not path /.well-known/*
	}
	respond @hidden 403
}
