Skip to content

Serve our deployment behind the shared front door - #194

Merged
n8bar merged 2 commits into
mainfrom
claude/frontdoor
Oct 2, 2026
Merged

n8bar merged 2 commits into
mainfrom
claude/frontdoor

Conversation

@n8bar

@n8bar n8bar commented Oct 2, 2026

Copy link
Copy Markdown
Owner

A shared front door (its own stack at /opt/frontdoor on the server, owned by neither app) takes ports 80/443 and TLS. Neither app's deploy or mistake can take the other offline.

  • cz-nginx drops its public ports and certificates and serves behind the front door over the frontdoor network (templates-frontdoor). It trusts forwarded client addresses only from that network's fixed subnet, and its redirects stay relative.
  • deploy.sh renders our front door blocks (docker/production/frontdoor/) and loads them through the front door's guard. A rejected block warns and the last good one keeps serving.
  • Do It List's block and doitlist-guard.sh leave cz-nginx; the front door loads Do It List's folder itself.

Tested locally end to end: redirects, TLS, stats, unknown names rejected, real client address reaching cz-nginx, a broken block from either app turned away while the other keeps serving, live reload, and restart.

Server cutover is a separate step: install the front door, move the ACME webroot and renewal hook, switch cz-nginx, then update Do It List's apply-proxy.

🤖 Generated with Claude Code

https://claude.ai/code/session_01MchCV6T5B393x87E8xonCX

n8bar and others added 2 commits October 2, 2026 02:02
cz-nginx gives up ports 80/443 and TLS to the front door (its own stack) and
serves the apex and stats names over the frontdoor network, trusting forwarded
client addresses only from that subnet. deploy.sh renders our front door blocks
and loads them through its guard. Do It List's block and the old guard leave
cz-nginx.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MchCV6T5B393x87E8xonCX
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MchCV6T5B393x87E8xonCX
@n8bar
n8bar merged commit e5433da into main Oct 2, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant