31 lines
913 B
Markdown
31 lines
913 B
Markdown
# caddy-desec-docker
|
|||
|
|
|
||
|
|
Stock [Caddy](https://caddyserver.com) plus the
|
||
|
|
[caddy-dns/desec](https://github.com/caddy-dns/desec) module, so Caddy can
|
||
|
|
get certificates by ACME DNS-01 against a zone hosted at
|
||
|
|
[deSEC](https://desec.io). Published as
|
||
|
|
`code.aneur.in/cloud/caddy-desec-docker:latest` (linux/amd64).
|
||
|
|
|
||
|
|
Used by the `llm` stack in [cloud/cloud](https://code.aneur.in/cloud/cloud)
|
||
|
|
for `*.llm.aneur.in`:
|
||
|
|
|
||
|
|
```
|
||
|
|
{
|
||
|
|
acme_dns desec {
|
||
|
|
token {env.DESEC_TOKEN}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
```
|
||
|
|
|
||
|
|
## Builds
|
||
|
|
|
||
|
|
- **Push to `main`, weekly, or by hand** (`build.yml`): builds the image,
|
||
|
|
checks the deSEC module is present, then pushes `:latest`, keeping the
|
||
|
|
previous one as `:previous`. The weekly run picks up new Caddy and module
|
||
|
|
releases without a commit.
|
||
|
|
- **Pull requests** (`pr-checks.yml`): the same build and module check,
|
||
|
|
without pushing.
|
||
|
|
|
||
|
|
The push uses the `BUILD_API_TOKEN` Actions secret, a Gitea token with
|
||
|
|
package write access.
|