[002] Add Syncthing stack behind Caddy at sync.waldson.com.br

Run an always-on Syncthing peer on the droplet as an off-site copy for the
owner's folders. New syncthing/ compose stack on proxy_net: the sync protocol
is published on host 22000 (tcp+udp) for direct device connections, while the
GUI (8384) is unpublished and reached only through the central Caddy, which
gains a sync.waldson.com.br reverse-proxy block. Config and folder data live on
a host bind mount for SSH inspection and are git-ignored. README documents the
deploy, upgrade, and interactive pairing runbook.

Binding the GUI to a non-loopback address (STGUIADDRESS) also disables
Syncthing's DNS-rebinding host check, so the proxy needs no Host rewrite.
This commit is contained in:
Waldson Patrício 2026-07-23 13:34:10 -03:00
parent 657288bd86
commit 217efdace1
3 changed files with 108 additions and 2 deletions

View file

@ -18,6 +18,8 @@ compose.yaml the Caddy service: publishes 80/443, joins proxy_net,
bind-mounts the Caddyfile, persists certs in caddy_data
Caddyfile one site block per app; each reverse_proxies to a container
reachable by name on proxy_net
syncthing/ the Syncthing stack (own compose file); GUI behind Caddy,
sync protocol published on 22000
```
## Prerequisites
@ -71,6 +73,66 @@ Bring the proxy up (or recreate it after a compose change) from that directory:
docker compose up -d
```
## Syncthing stack
An always-on Syncthing peer for the owner's folders, giving devices somewhere
to sync when no two of them are online together and keeping an off-site copy on
the droplet. It lives in `syncthing/` and deploys to
`/home/waldson/central-proxy/syncthing` on the droplet.
Only the sync protocol is published on the host (`22000/tcp` and `22000/udp`),
so devices connect directly instead of through community relays. The web GUI
(`8384`) is **not** published; it is reached only through Caddy at
`sync.waldson.com.br`, guarded by Syncthing's own username/password. The
central `Caddyfile` already carries the `sync.waldson.com.br` block. Binding the
GUI to a non-loopback address (`STGUIADDRESS=0.0.0.0:8384`, required so Caddy in
its own container can reach it) also turns off Syncthing's DNS-rebinding host
check, so a plain `reverse_proxy` needs no `Host`-header rewrite.
### Where data lives
Config (device keys, the folder list) and every synced folder live under the
host bind mount `syncthing/data` (mounted at `/var/syncthing` in the container),
so state survives container recreation and is inspectable over plain SSH. The
directory is git-ignored. `PUID`/`PGID` default to `1000`; if the droplet's
deploy user has a different id, adjust them in `compose.yaml` so the synced
files stay owned by that user.
### Deploy
From `syncthing/` on the droplet:
```sh
docker compose up -d
```
The container comes up as `syncthing-syncthing-1` on `proxy_net`, which is the
name Caddy reverse-proxies to. A restart preserves config and pairings:
```sh
docker compose restart
```
### Upgrade
The image is `syncthing/syncthing:latest` (Syncthing publishes no rolling major
tag; pin a specific version here if you want reproducible upgrades). To update:
```sh
docker compose pull && docker compose up -d
```
### First-run setup (interactive, in the GUI)
These steps are done once by the owner at `https://sync.waldson.com.br`:
1. Set the GUI username and password (Actions -> Settings -> GUI).
2. Add the droplet as a device on each personal device (and vice versa), using
the device IDs shown under Actions -> Show ID.
3. Share all five folders (Sync, phone-photos, comprovantes, notes,
torque-data) with the droplet and accept them on the droplet, pointing each
folder path under `/var/syncthing` so the data lands in the bind mount.
## Droplet groundwork
Baseline host configuration for the droplet (`wloud`, 174.138.36.232,