{$CADDY_DOMAINS} {
    # HTTP validation works both directly and behind a DNS proxy such as Cloudflare.
    tls {
        issuer acme {
            disable_tlsalpn_challenge
        }
    }
    encode zstd gzip
    handle /source/* {
        root * /srv
        file_server
    }
    @matrix path /_matrix/*
    handle @matrix {
        reverse_proxy tuwunel:6167
    }
    handle {
        reverse_proxy core:8080
    }
    header {
        Strict-Transport-Security "max-age=31536000; includeSubDomains"
        -Server
    }
}
