Staging runs on a private-network VM, not reachable from outside, so the HTTP basic-auth layer was unnecessary defense-in-depth. Removing it also lets the Caddyfile drop the render-around-Compose workaround entirely (that workaround existed specifically because Compose's interpolation mangles a bcrypt hash) — the noindex header and blog_public=0 stay, since those guard against search-engine indexing, a separate concern from network-level access. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
39 lines
831 B
YAML
39 lines
831 B
YAML
x-env-type: &env-type
|
|
WP_ENVIRONMENT_TYPE: staging
|
|
|
|
services:
|
|
wordpress:
|
|
environment: *env-type
|
|
|
|
cron:
|
|
environment: *env-type
|
|
|
|
caddy:
|
|
image: caddy:2-alpine
|
|
restart: unless-stopped
|
|
depends_on:
|
|
- wordpress
|
|
ports:
|
|
- "80:80"
|
|
- "443:443"
|
|
env_file:
|
|
- .env.staging
|
|
volumes:
|
|
- ./docker/caddy/Caddyfile.staging:/etc/caddy/Caddyfile:ro
|
|
- wp_core:/var/www/html:ro
|
|
- wp_uploads:/var/www/html/wp-content/uploads:ro
|
|
- wp_themes:/var/www/html/wp-content/themes:ro
|
|
- ./wp-content/plugins/bookstore-core:/var/www/html/wp-content/plugins/bookstore-core:ro
|
|
- caddy_data:/data
|
|
- caddy_config:/config
|
|
|
|
mailhog:
|
|
image: mailhog/mailhog:v1.0.1
|
|
restart: unless-stopped
|
|
ports:
|
|
- "8025:8025"
|
|
|
|
volumes:
|
|
caddy_data:
|
|
caddy_config:
|