# Edge & TLS (Caddy) The "front door" that gives every site its HTTPS. ## Primary edge — pi4 (`.2`) - Native Caddy at `/etc/caddy/Caddyfile`, listens `:80` + `:443`. - Terminates TLS for every `*.tomasetti.online` / `*.tomasetti.shop` / leebens host. - **Self-healing** since 2026-08-19: `Restart=on-failure` + a 2-minute health-check cron restarts it if it dies. ## Standby edge — mini1 (`.4`) - Second Caddy, `:443` only (`http_port 81` so nginx keeps `:80`). - TLS certs are rsync'd nightly from pi4. - LAN clients reach it via **dual-A DNS** when pi4 is down. ## Deploying changes `scripts/sync-edge.ps1` pushes the canonical `infra/edge/Caddyfile` to **both** pi4 and mini1, validates, and reloads. Edit the Caddyfile in the vault, then run the script. ## Certificates Caddy auto-issues/refreshes Let's Encrypt / ZeroSSL certs per hostname over ACME. As long as a name resolves publicly to the edge, the cert "just works." ## Retired services (410) `stats.tomasetti.online`, `omnitools.tomasetti.online`, `pdftools.tomasetti.online`, `habitica.tomasetti.online`, `moodist.tomasetti.online`, `plants.tomasetti.online` — retired 2026-08-19. These names now return **410 Gone** instead of a site — kept as clean "gone" responses rather than errors.