Files
accounted/docker-compose.caddy.yml
Jakob Wennberg ec27228a8e style: remove em/en dashes repo-wide, add CLAUDE.md rule against them (#890)
Em dashes (—) and en dashes (–) had spread across comments, docs, tests,
and a few UI strings, reading as AI-generated boilerplate rather than
house style. Replaced each with punctuation matching its context: colon
for explanatory clauses, comma for asides, plain hyphen for numeric/legal
ranges (e.g. "21-23§"), "to"/"till" for date ranges, parentheses for
paired-dash asides. messages/en.json and messages/sv.json were fixed by
hand together to keep sv/en in sync.

Left untouched where the dash is the functional subject rather than
decorative punctuation: date-range-parser.ts's separator regex,
charset-repair.ts's CP1252 byte-mapping table (and its test), the SIE
encoding mojibake docs, generic-csv.ts's minus-sign normalizer, the
agent system-prompt files that already instruct against em dashes, and
a golden iXBRL test fixture compared byte-for-byte.

Also fixes two bugs surfaced along the way: an off-by-one in
ApiKeysPanel's scope-label split (a leftover from an earlier partial
pass), and a charset-repair test that had lost the literal en-dash it
exists to verify.

Regenerated the agent atom seed migration (skills:generate) since 27
SKILL.md files changed. Added a CLAUDE.md rule against em/en dashes,
with an explicit carve-out for the functional-dash cases above.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-04 15:58:06 +02:00

52 lines
1.4 KiB
YAML

# Optional TLS overlay. Adds a Caddy reverse proxy that auto-provisions
# Let's Encrypt certificates for ${DOMAIN}.
#
# Usage:
# 1. Set DOMAIN=app.example.com in .env (must resolve to this host's public IP)
# 2. Open ports 80 and 443 to the public internet (LE HTTP-01 challenge needs 80)
# 3. docker compose -f docker-compose.yml -f docker-compose.caddy.yml up -d
#
# Caddy reaches the app over the internal Docker network; the app no longer
# binds a host port at all.
services:
app:
# Remove the loopback binding from the base file: traffic comes via Caddy.
ports: !reset null
caddy:
image: caddy:2-alpine@sha256:86deaf5e3d3408a6ccec08fbb79989783dd26e206ae10bcf78a801dc8c9ab794
depends_on:
app:
condition: service_healthy
ports:
- "80:80"
- "443:443"
volumes:
- ./docker/Caddyfile:/etc/caddy/Caddyfile:ro
- caddy_data:/data
- caddy_config:/config
environment:
- DOMAIN=${DOMAIN:?set DOMAIN in .env to enable TLS}
restart: unless-stopped
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
# Caddy needs NET_BIND_SERVICE to bind privileged ports 80/443.
cap_add:
- NET_BIND_SERVICE
read_only: true
tmpfs:
- /tmp
mem_limit: 256m
pids_limit: 50
logging:
driver: json-file
options:
max-size: "10m"
max-file: "5"
volumes:
caddy_data:
caddy_config: