# CareKiosk — one IP, many hospital domains, automatic HTTPS per domain.
# Caddy asks /_tls/allow before issuing a certificate, so only mapped domains get one.
{
    email ssl@caresoft.co.in
    on_demand_tls {
        ask http://127.0.0.1:8088/_tls/allow
    }
}

# Internal listener used only by the TLS "ask" hook
http://127.0.0.1:8088 {
    root * /var/www/carekiosk/public
    php_fastcgi unix//run/php/php8.3-fpm.sock
}

# Every hospital domain + the Caresoft console
https:// {
    tls {
        on_demand
    }
    root * /var/www/carekiosk/public
    encode zstd gzip
    @static path /assets/*
    header @static Cache-Control "public, max-age=604800"
    php_fastcgi unix//run/php/php8.3-fpm.sock
    file_server
    request_body {
        max_size 4MB
    }
}

http:// {
    redir https://{host}{uri} permanent
}
