{
    # email your-email@example.com
}

# Dynamic domain configuration
{$COLLABASE_DOMAIN:localhost} {
    # If Cloudflare is proxied, auto-HTTPS might fail.
    # 'tls internal' ensures a self-signed cert is always available for Cloudflare's "Full" mode.
    # If you have a real certificate, you can replace this.
    tls internal

    # Core Security Headers
    header {
        Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
        X-Content-Type-Options "nosniff"
        X-Frame-Options "SAMEORIGIN"
        X-XSS-Protection "1; mode=block"
        Referrer-Policy "strict-origin-when-cross-origin"
        -Server
    }

    reverse_proxy collabase-app:3000 {
        header_up Host {host}
        header_up X-Real-IP {remote_host}
        header_up X-Forwarded-For {remote_host}
        header_up X-Forwarded-Proto {scheme}
    }

    encode gzip

    log {
        output stderr
    }
}
