Run the panel as its own compose project behind the host Caddy

The instance's internal Caddy is only for Stoat itself, so the panel no
longer goes through it: the bot ships its own compose project, publishes
3005 on loopback, and the host's external Caddy gives it a domain.

extra_hosts pins the instance domain to host-gateway, so the bot reaches
the API, gateway and LiveKit through the external proxy with a valid
certificate instead of depending on router NAT loopback. The old
in-project layout stays available as a fallback example, together with a
step-by-step guide for when voice fails to connect.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Leonid Pershin
2026-09-08 23:16:04 +03:00
co-authored by Claude Opus 5
parent a9b7ccdd16
commit 62d5291cd9
6 changed files with 84 additions and 72 deletions
+6 -13
View File
@@ -1,15 +1,8 @@
# Добавьте отдельным блоком в /opt/stoat/Caddyfile, рядом с {$HOSTNAME} { ... }.
#
# У вас Caddy слушает только 80 (127.0.0.1:8880 → 80), а TLS терминирует
# внешний прокси на хосте, поэтому используем схему http:// —
# так Caddy не будет пытаться сам выпускать сертификат.
http://music.example.com {
reverse_proxy http://mbot:3005
# Внешний Caddy на хосте: /etc/caddy/Caddyfile
# Добавьте блок рядом с остальными вашими сайтами.
music.example.com {
reverse_proxy 127.0.0.1:3005
}
# Если внешнего прокси нет и Caddy сам держит 80/443 — просто:
# music.example.com {
# reverse_proxy http://mbot:3005
# }
#
# WebSocket (/ws) проксируется автоматически, отдельных директив не нужно.
# Внутренний Caddy инстанса трогать не нужно: панель к нему не относится.
# WebSocket (/ws) Caddy апгрейдит сам, отдельных директив не требуется.