{ on_demand_tls { ask http://app:9000/tls-check } } # production lichen.page sites: wildcard cert via DNS-01 *.lichen.page { tls { dns gandi {env.GANDI_API_TOKEN} } @app path /cms/* /ws/* /login/* /logout/* /static/* /api/* /tls-check /git/* /publish/* /oauth/* /oidc/* /shell/* /assets/yjs-bundle.iife.js handle @app { reverse_proxy app:9000 } handle { root * /sites/{host}/dist @static file {path} {path}/index.html {path}index.html handle @static { file_server } handle { reverse_proxy app:9000 } } } # custom domains: on-demand TLS (validated via tls-check) :443 { tls { on_demand } @app path /cms/* /ws/* /login/* /logout/* /static/* /api/* /tls-check /git/* /publish/* /oauth/* /oidc/* /shell/* /assets/yjs-bundle.iife.js handle @app { reverse_proxy app:9000 } handle { root * /sites/{host}/dist @static file {path} {path}/index.html {path}index.html handle @static { file_server } handle { reverse_proxy app:9000 } } } :80 { redir https://{host}{uri} permanent }