{
	servers {
		listener_wrappers {
			proxy_protocol
			tls
		}
		trusted_proxies static 127.0.0.1/32 ::1/128
	}
	http_port 8080
	https_port 8443
}

# Replace example.com with your domain. Requires web service on the same compose network.
example.com {
	reverse_proxy web:80 {
		header_up X-Real-IP {remote_host}
	}

	header {
		X-Content-Type-Options "nosniff"
		X-Frame-Options "DENY"
		Referrer-Policy "strict-origin-when-cross-origin"
		Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
	}
}

# API on same host (optional second site block)
api.example.com {
	reverse_proxy main:8300 {
		header_up X-Real-IP {remote_host}
	}
}
