# Several instances of the WAF can be deployed onto the same host if their # names are different and they bind to different ports/interfaces. These # instances may use different versions of Go, xcaddy, Caddy, and Coraza. caddy_my_name: "mywaf" caddy_http_port: 80 caddy_https_port: 443 caddy_default_bind: null # If true, will not install software, just deploy Caddy and OWASP CRS # configuration files. caddy_config_only: false # Debug will go to /var/log//debug.log. caddy_debug: false # Required for Let's Encrypt auto certificates. caddy_email: null # If a custom CA root have to be used. caddy_ca_root: null # For using a Consul cluster. caddy_consul: false caddy_consul_server: "{{ ansible_fqdn }}:8501" caddy_consul_delegate_to: null # Required, Consul host for running Consul commands caddy_consul_admin_token: null # Required caddy_consul_aes_key: null # Required, 32 characters caddy_consul_client_cert: null # Required caddy_consul_client_key: null # Required # Accound id and license key are required if a site use Geoip filtering. # See: https://dev.maxmind.com/geoip/updating-databases/ caddy_geoip_account_id: null caddy_geoip_license_key: null caddy_geoip_edition_ids: "GeoLite2-ASN,GeoLite2-Country,GeoLite2-City" caddy_geoip_update_frequency: 86400 # In seconds # Sotware versions caddy_version: "2.10.2" caddy_go_version: "1.25.6" caddy_xcaddy_version: "0.4.5" caddy_coraza_caddy_version: "v2@v2.1.0" # Coraza v3.3.3 # Different sites can use different versions of OWASP CRS caddy_owasp_crs_versions: ["4.23.0"] # Paths caddy_binary: "/usr/local/bin/{{ caddy_my_name }}" caddy_system_user: "{{ caddy_my_name }}" caddy_system_group: "{{ caddy_my_name }}" caddy_home_dir: "/opt/{{ caddy_my_name }}" caddy_config_dir: "/etc/{{ caddy_my_name }}" caddy_crs_plugins_dir: "{{ caddy_config_dir }}/crs-plugins" caddy_sites_dir: "{{ caddy_config_dir }}/sites" caddy_log_dir: "/var/log/{{ caddy_my_name }}" # OWASP CRS plugins that will can be actived per site. # Cf.: https://github.com/coreruleset/plugin-registry caddy_crs_plugins: - name: "drupal-rule-exclusions" version: "1.0.0" - name: "wordpress-rule-exclusions" version: "1.2.0" - name: "nextcloud-rule-exclusions" version: "1.5.0" - name: "dokuwiki-rule-exclusions" version: "1.0.0" - name: "phpmyadmin-rule-exclusions" version: "1.0.0" has_after_config: true - name: "roundcube-rule-exclusions" version: "1.0.4" provider: "EsadCetiner" - name: "sogo-rule-exclusions" version: "1.0.4" provider: "EsadCetiner" # Sites caddy_sites: [] # - id: "" # Mandatory: short id for the site (for site specific directories and files) # name: "" # Mandatory: canonical domain name # paths: # Mandatory: targets for the reverse proxy # - path: "" # Optionnal: path of the request, default "*" # addrs: # Mandatory: upstreams # - "" # Mandatory: URL of the upstream, minimum 1 required # For overriding default global parameters. Will be merged with # caddy_global_sites_defaults (in vars/main.yml). caddy_my_sites_defaults: {}