# Caddy reverse-proxy snippet for Oikos — Phase 6 cutover, updated for the # client/server split (plans/2026-07-12-wails-desktop-app.md, Phase 0). # Lives in dtoro/caddy-conf repo; auto-deploys to caddy (LXC 121). THIS COPY # IS A REFERENCE, NOT DEPLOYED FROM HERE — keep it in sync manually. # # The SPA is no longer embedded in the oikos binary; it's served here as # static files (`make deploy-ui`). Every API/MCP/agent route now requires a # bearer token in all cases (api's dev-open bypass was removed) — non-browser # clients (Wails, curl, a future mobile client) can't complete Authentik's # browser-session login, so those routes bypass `import authentik` the same # way the enrollment endpoint always has and rely on api's own combinedAuth # instead. See the Wails plan's "Plan review" section, gap 1. oikos.hubris.network { tls { dns ionos {env.IONOS_AUTH_API_TOKEN} } @enroll path /api/v1/clients/enroll handle @enroll { reverse_proxy :8090 } # Bearer-token clients — api's combinedAuth (internal/httpapi/server.go) # is the real gate for all three; Authentik would just reject non-browser # callers before they ever get there. /agent/* now goes through api's own # (auth'd) proxy mount rather than straight to nomos:8092, so it's # covered by the same check as /api/v1/* and /mcp. @api path /api/v1/* /mcp /agent/* handle @api { reverse_proxy :8090 } # Everything else: the static SPA shell. No sensitive data lives here — # real enforcement is the bearer-token check above — Authentik is just a # first line of defense against anonymous crawlers finding the bundle. handle { import authentik root * /var/www/oikos-ui file_server try_files {path} /index.html } } # Oikos MCP endpoint (agents) — bearer token required (api's combinedAuth), # no separate gate here. mcp.hubris.network { reverse_proxy :8090 } # Nomos's own gateway (workstation access) — still has NO auth of its own # (C1, plans/2026-07-11-nomos-agent-code-review.md, still open). Anyone who # can reach this host can talk to nomos directly, bypassing api entirely. # Not fixed by the client/server split — tracked separately. nomos.hubris.network { reverse_proxy :8092 }