Caddy reverse proxy: the single public entry point for the lab server. HTTPS certificates are obtained and renewed automatically, so no certbot on the host.
| Address | Goes to |
|---|---|
pth.ddomlab.org |
pth container (PTH sensor API + dashboard) |
eln.ddomlab.org |
eLabFTW (added at cutover) |
elntoolkit.ddomlab.org |
eln-server (ELN Toolkit: scanner page, add-bottle page, labels) |
Apps publish no ports of their own; only this project is exposed.
sudo docker network create lab-net # once per server
git clone https://github.com/ddomlab/lab-edge.git /opt/edge
cd /opt/edge && sudo docker compose up -d
sudo docker compose logs caddy | tail -20 # expect "certificate obtained successfully"Update a route: edit Caddyfile via a PR, then on the server git pull && sudo docker compose restart caddy.
- DNS record for each hostname pointing at this server
- Ports 80 and 443 open (DigitalOcean Cloud Firewall; note Docker bypasses ufw)
- The
caddy_datavolume must persist: it holds the certificates (Let's Encrypt has rate limits)