# SPDX-License-Identifier: AGPL-3.0-or-later
{
 https_port 8443
 auto_https disable_redirects
}
http://:80 {
 redir {$PUBLIC_ORIGIN}{uri} 308
}
{$SITE_ADDRESS} {
 {$TLS_DIRECTIVE}
 header {
  -Server
  X-Content-Type-Options nosniff
  Referrer-Policy no-referrer
 }
 @private path /internal /internal/* /run /plugins
 handle @private {
  respond 404
 }
 @admin path /admin /admin/*
 @release_api path /admin/api/releases/*
 handle @release_api {
  request_body {
   max_size 5MB
  }
  reverse_proxy admin:8780 {
   header_up X-Real-IP {remote_host}
   header_up -X-Admin-Internal
   transport http {
    response_header_timeout 90s
   }
  }
 }
 @feed path /downloads/latest-phone.json /downloads/latest-watch.json /downloads/latest-desktop.json /downloads/latest-ios.json
 handle @feed {
  reverse_proxy admin:8780
 }
 @artifact path_regexp artifact ^/downloads/[A-Za-z0-9][A-Za-z0-9_.-]*\.(apk|ipa|exe|msi|dmg|deb|rpm|appimage|AppImage|zip)$
 @source path /downloads/backend-source.zip
 handle @source {
  root * /srv/public
  header Cache-Control no-store
  file_server
 }
 handle @artifact {
  uri strip_prefix /downloads
  root * /srv/releases
  header X-Content-Type-Options nosniff
  file_server
 }
 handle @admin {
  request_body {
   max_size 1500KB
  }
  reverse_proxy admin:8780 {
   header_up X-Real-IP {remote_host}
   header_up -X-Admin-Internal
   transport http {
    dial_timeout 3s
    response_header_timeout 15s
   }
  }
 }
 @api path /api/*
 handle @api {
  request_body {
   max_size 4KB
  }
  reverse_proxy gateway:8766 {
   header_up X-Real-IP {remote_host}
   header_up -X-Admin-Internal
   transport http {
    dial_timeout 5s
    response_header_timeout 55s
   }
  }
 }
 handle {
  root * /srv/public
  header Cache-Control no-store
  file_server
 }
}
