From 7f9e73a8497a00f7922cb867d75cf59441473032 Mon Sep 17 00:00:00 2001 From: Jeroen Schweitzer Date: Thu, 25 Dec 2025 11:51:13 +0100 Subject: [PATCH] feat(npm): add internal domain aliases for all external hosts MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add *.schweitz.internal domains as HTTP-only alternatives to *.schweitz.net domains for programmatic access without SSL or Authentik authentication. - Configure 11 internal domain proxy hosts in NPM - Document internal domain setup process in setup-new-host.md - Add internal domains reference table to CONTAINERS.md - Update external domains list with library and tatlock mappings 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 --- CONTAINERS.md | 27 ++++++++++- setup-new-host.md | 121 +++++++++++++++++++++++++++++++++++++++++++++- 2 files changed, 144 insertions(+), 4 deletions(-) diff --git a/CONTAINERS.md b/CONTAINERS.md index e554850..cd17783 100644 --- a/CONTAINERS.md +++ b/CONTAINERS.md @@ -48,7 +48,30 @@ - **amp.schweitz.net** → AMP Game Server - **housekeeping.schweitz.net** → Home Assistant - **documents.schweitz.net** → Paperless-ngx -- **tatlock.schweitz.net** → (Reserved) +- **library.schweitz.net** → Wiki.js +- **tatlock.schweitz.net** → Open WebUI + +### Internal Domains (HTTP, No Auth) + +Internal domains provide LAN-accessible URLs without SSL or Authentik, ideal for programmatic access, scripts, and healthchecks. Each mirrors its external counterpart. + +| Internal Domain | Backend | Port | +|-----------------|---------|------| +| home.schweitz.internal | localhost | 9999 | +| media.schweitz.internal | localhost | 8096 | +| cloud.schweitz.internal | localhost | 8082 | +| api.schweitz.internal | localhost | 8083 | +| code.schweitz.internal | localhost | 8084 | +| amp.schweitz.internal | localhost | 8080 | +| housekeeping.schweitz.internal | localhost | 8123 | +| documents.schweitz.internal | 192.168.86.149 | 8091 | +| git.schweitz.internal | localhost | 3002 | +| library.schweitz.internal | localhost | 8088 | +| tatlock.schweitz.internal | localhost | 82 | + +**DNS Resolution:** Via `/etc/hosts` on tower-of-joy (192.168.86.149) + +**Usage:** `curl http://api.schweitz.internal/health` or `docker pull git.schweitz.internal/jpmschweitzer/core-api:latest` ### External Repositories @@ -690,4 +713,4 @@ redis-cli -h redis-shared # Redis connection --- -*Last Updated: 2025-12-14* +*Last Updated: 2025-12-25* diff --git a/setup-new-host.md b/setup-new-host.md index 8e80b1a..9182b3c 100644 --- a/setup-new-host.md +++ b/setup-new-host.md @@ -259,6 +259,123 @@ If already logged into another `.schweitz.net` service: --- +## Setting Up an Internal Domain (*.schweitz.internal) + +Internal domains provide LAN-accessible URLs without SSL or Authentik authentication, ideal for: +- Programmatic API access (scripts, automation, healthchecks) +- Local development and testing +- Container-to-container communication via DNS +- Avoiding port number confusion on LAN + +### Pattern + +Every external `.schweitz.net` domain has a corresponding `.schweitz.internal` domain that: +- Uses HTTP only (no SSL certificates) +- Has NO Authentik forward auth +- Points to the same backend service +- Resolves via `/etc/hosts` on the server + +### Current Internal Domains + +| Internal Domain | Backend | External Equivalent | +|-----------------|---------|---------------------| +| home.schweitz.internal | localhost:9999 | home.schweitz.net | +| media.schweitz.internal | localhost:8096 | media.schweitz.net | +| cloud.schweitz.internal | localhost:8082 | cloud.schweitz.net | +| api.schweitz.internal | localhost:8083 | api.schweitz.net | +| code.schweitz.internal | localhost:8084 | code.schweitz.net | +| amp.schweitz.internal | localhost:8080 | amp.schweitz.net | +| housekeeping.schweitz.internal | localhost:8123 | housekeeping.schweitz.net | +| documents.schweitz.internal | 192.168.86.149:8091 | documents.schweitz.net | +| git.schweitz.internal | localhost:3002 | git.schweitz.net | +| library.schweitz.internal | localhost:8088 | library.schweitz.net | +| tatlock.schweitz.internal | localhost:82 | tatlock.schweitz.net | + +### Step 1: Add DNS Entry + +Add the internal domain to `/etc/hosts` on the tower-of-joy server: + +```bash +# Add to /etc/hosts +192.168.86.149 .schweitz.internal +``` + +### Step 2: Create NPM Proxy Host + +**Via NPM UI (port 8000):** + +**Details Tab:** + +| Setting | Value | +|---------|-------| +| Domain Names | `.schweitz.internal` | +| Scheme | `http` | +| Forward Hostname/IP | Same as external domain (e.g., `localhost`) | +| Forward Port | Same as external domain | +| Cache Assets | On (optional) | +| Block Common Exploits | On | +| Websockets Support | On (if needed) | + +**SSL Tab:** Leave empty (no SSL for internal domains) + +**Advanced Tab:** Leave empty (no Authentik forward auth) + +**Via NPM API:** + +```bash +# Get token +TOKEN=$(curl -s -X POST http://localhost:81/api/tokens \ + -H "Content-Type: application/json" \ + -d '{"identity": "", "secret": ""}' | python3 -c "import sys,json; print(json.load(sys.stdin)['token'])") + +# Create internal proxy host +curl -s -X POST http://localhost:81/api/nginx/proxy-hosts \ + -H "Authorization: Bearer $TOKEN" \ + -H "Content-Type: application/json" \ + -d '{ + "domain_names": [".schweitz.internal"], + "forward_scheme": "http", + "forward_host": "localhost", + "forward_port": , + "access_list_id": 0, + "certificate_id": 0, + "ssl_forced": false, + "caching_enabled": true, + "block_exploits": true, + "advanced_config": "", + "allow_websocket_upgrade": true, + "http2_support": false, + "hsts_enabled": false, + "hsts_subdomains": false, + "enabled": true, + "locations": [] + }' +``` + +### Step 3: Test + +```bash +curl -s -o /dev/null -w "%{http_code}" http://.schweitz.internal/ +``` + +Expected: `200`, `302` (redirect), or service-specific response. + +### Usage Examples + +```bash +# API calls without auth +curl http://api.schweitz.internal/health + +# Git operations (Docker image pulls) +docker pull git.schweitz.internal/jpmschweitzer/core-api:latest + +# Healthchecks in Docker Compose +healthcheck: + test: ["CMD-SHELL", "curl -fSs http://git.schweitz.internal/api/healthz"] +``` + +--- + ## Appendix: Portainer API for Remote Stack Deployment When you cannot access the Portainer web UI (e.g., outside home network), you can deploy stacks via the API. @@ -453,5 +570,5 @@ curl -s -X PUT http://192.168.86.149:81/api/nginx/proxy-hosts/ \ --- -**Last Updated**: 2025-12-24 -**Based on**: library.schweitz.net setup session, Paperless-ngx API deployment +**Last Updated**: 2025-12-25 +**Based on**: library.schweitz.net setup session, Paperless-ngx API deployment, Internal domain consolidation