TestingOpsDocumentation

HTTPS configuration (Docker)

Serve TestingOps over TLS with the bundled Caddy front end

The kit ships Caddy as the front end, listening on port 80. Three ways to get HTTPS:

A. Public DNS name — automatic certificate

If the server's name resolves from the internet and ports 80/443 are reachable, Caddy obtains and renews a Let's Encrypt certificate itself. Edit caddy/Caddyfile:

testingops.company.com {
	reverse_proxy app:3100 {
		lb_try_duration 45s
		lb_try_interval 1s
	}
}

B. Your own certificate

Copy the certificate chain and key to caddy/certs/ssl.crt and caddy/certs/ssl.key, then:

testingops.company.local {
	tls /certs/ssl.crt /certs/ssl.key
	reverse_proxy app:3100 {
		lb_try_duration 45s
		lb_try_interval 1s
	}
}

C. TLS terminated in front (load balancer, corporate proxy)

Leave the Caddyfile as shipped (HTTP on port 80) and point the load balancer at it.

Apply

In every case set the public address to https://… and reload:

sed -i 's#^TESTINGOPS_PUBLIC_URL=.*#TESTINGOPS_PUBLIC_URL=https://testingops.company.com#' env.list
docker compose up -d app
docker compose exec caddy caddy reload --config /etc/caddy/Caddyfile

TESTINGOPS_PUBLIC_URL must match the address in the browser: session cookies, OAuth callbacks (<public url>/api/knowledge/oauth/callback) and invitation links are built from it.

Corporate root CA

If outbound traffic goes through an SSL-inspecting proxy, put the root certificate at caddy/certs/corporate-ca.crt, uncomment the matching volume line under app in docker-compose.yml, set HTTPS_PROXY in env.list and docker compose up -d app.