{
	email {$ACME_EMAIL}
	# Explicit ACME issuer in each TLS site: Let's Encrypt only.
	http_port 8080
	https_port 8443
	# Admin API stays on container loopback; never publish port 2019.
	admin localhost:2019
	servers {
		protocols h1 h2
		max_header_size 16KB
		timeouts {
			read_header 10s
			read_body 30s
			idle 60s
		}
	}
}

(letsencrypt) {
    tls {
        issuer acme {
            dir https://acme-v02.api.letsencrypt.org/directory
            email {$ACME_EMAIL}
        }
    }
}

(common) {
	encode gzip
	header {
		-X-Powered-By
		-Server
		X-Content-Type-Options nosniff
		Referrer-Policy strict-origin-when-cross-origin
		X-Frame-Options DENY
		Strict-Transport-Security "max-age=86400"
	}
	# One-day HSTS, no includeSubDomains/preload; no untested blanket CSP.
	# No access logging by default; runtime/error logs have Docker rotation.
}

tradingdevacademy.com {
	import letsencrypt
	import common
	route {
		# Research ingestion and provider-backed operations are not public learning endpoints.
		@privateAPI path /api /api/*
		header @privateAPI Cache-Control "no-store"
		respond @privateAPI "Forbidden" 403
		reverse_proxy axiom:8000 {
			# One value, overwritten rather than appended. With no trusted CDN,
			# client_ip is the actual peer, never visitor-supplied XFF.
			header_up X-Forwarded-For {client_ip}
			header_up -Forwarded
			transport http {
				dial_timeout 2s
				response_header_timeout 30s
				max_conns_per_host 32
			}
		}
	}
	# Node serves the public curriculum and server-rendered lesson pages.
}

www.tradingdevacademy.com {
    import letsencrypt
    import common
    redir https://tradingdevacademy.com{uri} permanent
}

# Container-local readiness. Port 8081 is NOT published.
http://:8081 {
    respond /healthz "ok" 200
    respond 404
}
