{
	email {$ACME_EMAIL}
	http_port 8080
	https_port 8443
	admin localhost:2019
	servers {
		protocols h1 h2
		max_header_size 16KB
		timeouts {
			read_header 10s
			read_body 30s
			idle 60s
		}
	}
}

{$SITE_DOMAIN} {
	encode zstd gzip
	tls {
		issuer acme {
			dir https://acme-v02.api.letsencrypt.org/directory
		}
	}
	header {
		-Server
		-X-Powered-By
		X-Content-Type-Options nosniff
		Referrer-Policy strict-origin-when-cross-origin
		X-Frame-Options DENY
		Strict-Transport-Security "max-age=86400"
	}
	route {
		# All operator APIs stay off the public site, including future APIs.
		@private path /api /api/*
		header @private Cache-Control no-store
		respond @private "Forbidden" 403
		reverse_proxy app:8000 {
			header_up X-Forwarded-For {client_ip}
			header_up -Forwarded
			transport http {
				dial_timeout 2s
				response_header_timeout 30s
				max_conns_per_host 32
			}
		}
	}
	# Preserve the origin's revalidation policy: filenames are not fingerprinted.
}

# Container-local proxy readiness; never published by Compose.
http://:8081 {
	respond /healthz "ok" 200
	respond 404
}
