# Caddy: automatic HTTPS for the platform domain, wildcard subdomains and every society's custom domain.
# 1) Replace sahakarcloud.in with your platform domain.  2) /etc/caddy/Caddyfile  3) systemctl reload caddy
{
    email you@example.com
    on_demand_tls {
        # Caddy asks the app before issuing a certificate, so only registered society domains get one
        ask http://127.0.0.1:9123/tls-check
    }
}

# Internal endpoint used by "ask" above
:9123 {
    root * /var/www/coopsaas/public
    rewrite /tls-check /tls-check.php
    php_fastcgi unix//run/php/php8.3-fpm.sock
}

https:// {
    tls {
        on_demand
    }
    root * /var/www/coopsaas/public
    encode gzip
    php_fastcgi unix//run/php/php8.3-fpm.sock
    file_server
    @blocked path /install.php /router.php /tls-check.php
    respond @blocked 404
}
