One-step production HTTPS with a bundled Caddy reverse proxy
A standalone Caddy reverse proxy now ships under deploy/caddy/, putting automatic Let’s Encrypt TLS and your own domain in front of the Kubernetes web LoadBalancer. Set the domain in .env and run docker compose up -d; certificates provision and renew automatically, with no Caddyfile editing.
The proxy is optional and production-only — local development and the standard deploy path do not require it.
No action required unless you want managed TLS in front of a self-hosted deployment.