commit 17fef5e882720a48de26bbc5ce2d42799d47df97 Author: Aneurin Barker Snook Date: Wed Oct 7 17:13:53 2026 +0100 Build Caddy with the caddy-dns/desec module Stock caddy:2-alpine plus caddy-dns/desec, for ACME DNS-01 against zones hosted at deSEC (*.llm.aneur.in in cloud/cloud's llm stack). CI builds and checks the module on pull requests, and pushes :latest (keeping :previous) on main, weekly and by hand. Co-Authored-By: Claude Opus 5.5 diff --git a/.gitea/workflows/build.yml b/.gitea/workflows/build.yml new file mode 100644 index 0000000..9d3953e --- /dev/null +++ b/.gitea/workflows/build.yml @@ -0,0 +1,44 @@ +name: Build + +on: + push: + branches: [main] + schedule: + # Weekly, so new Caddy and caddy-dns/desec releases land without a commit. + - cron: "17 4 * * 1" + workflow_dispatch: + +jobs: + build-and-push: + runs-on: ubuntu-latest + container: + image: docker:cli + env: + IMAGE: code.aneur.in/${{ gitea.repository }} + steps: + - name: Install Node (for checkout) + run: apk add --no-cache nodejs + + - uses: actions/checkout@v4 + + - name: Build + run: docker build --pull --tag "$IMAGE:latest" . + + - name: Check the deSEC module is built in + run: docker run --rm "$IMAGE:latest" caddy list-modules | grep -x dns.providers.desec + + - name: Log in to the container registry + env: + BUILD_API_TOKEN: ${{ secrets.BUILD_API_TOKEN }} + run: echo "$BUILD_API_TOKEN" | docker login code.aneur.in -u "${{ gitea.actor }}" --password-stdin + + - name: Promote current "latest" to "previous" + run: | + if docker buildx imagetools inspect "$IMAGE:latest" >/dev/null 2>&1; then + docker buildx imagetools create -t "$IMAGE:previous" "$IMAGE:latest" + else + echo "No existing :latest to promote; skipping." + fi + + - name: Push "latest" + run: docker push "$IMAGE:latest" diff --git a/.gitea/workflows/pr-checks.yml b/.gitea/workflows/pr-checks.yml new file mode 100644 index 0000000..7705288 --- /dev/null +++ b/.gitea/workflows/pr-checks.yml @@ -0,0 +1,23 @@ +name: PR Checks + +on: + pull_request: + branches: [main] + workflow_dispatch: + +jobs: + checks: + runs-on: ubuntu-latest + container: + image: docker:cli + steps: + - name: Install Node (for checkout) + run: apk add --no-cache nodejs + + - uses: actions/checkout@v4 + + - name: Build + run: docker build --pull --tag caddy-desec-docker:check . + + - name: Check the deSEC module is built in + run: docker run --rm caddy-desec-docker:check caddy list-modules | grep -x dns.providers.desec diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..e3b608f --- /dev/null +++ b/Dockerfile @@ -0,0 +1,8 @@ +# Caddy with the caddy-dns/desec module, for ACME DNS-01 challenges against +# zones hosted at deSEC. Otherwise the stock caddy:2-alpine image. + +FROM caddy:2-builder AS builder +RUN xcaddy build --with github.com/caddy-dns/desec + +FROM caddy:2-alpine +COPY --from=builder /usr/bin/caddy /usr/bin/caddy diff --git a/README.md b/README.md new file mode 100644 index 0000000..789e559 --- /dev/null +++ b/README.md @@ -0,0 +1,30 @@ +# caddy-desec-docker + +Stock [Caddy](https://caddyserver.com) plus the +[caddy-dns/desec](https://github.com/caddy-dns/desec) module, so Caddy can +get certificates by ACME DNS-01 against a zone hosted at +[deSEC](https://desec.io). Published as +`code.aneur.in/cloud/caddy-desec-docker:latest` (linux/amd64). + +Used by the `llm` stack in [cloud/cloud](https://code.aneur.in/cloud/cloud) +for `*.llm.aneur.in`: + +``` +{ + acme_dns desec { + token {env.DESEC_TOKEN} + } +} +``` + +## Builds + +- **Push to `main`, weekly, or by hand** (`build.yml`): builds the image, + checks the deSEC module is present, then pushes `:latest`, keeping the + previous one as `:previous`. The weekly run picks up new Caddy and module + releases without a commit. +- **Pull requests** (`pr-checks.yml`): the same build and module check, + without pushing. + +The push uses the `BUILD_API_TOKEN` Actions secret, a Gitea token with +package write access.