Staging DNS + public TLS (vps1)
Staging currently serves staging.dash.kinoforms.com and staging.kinoforms.com with Caddy tls internal on vps1 (141.95.52.123). Public DNS for those names is not configured yet (NXDOMAIN from the public resolver).
Wrangler OAuth on this workstation is expired; there is no usable CLOUDFLARE_API_TOKEN in the environment. Add records in the Cloudflare dashboard (zone kinoforms.com) or after wrangler login.
Cloudflare DNS records (exact)
| Type | Name | Content | Proxy status | TTL |
|---|---|---|---|---|
| A | staging.dash | 141.95.52.123 | DNS only (grey cloud) first | Auto |
| A | staging | 141.95.52.123 | DNS only (grey cloud) first | Auto |
Notes:
- Full hostnames:
staging.dash.kinoforms.com,staging.kinoforms.com. - Start DNS-only so Caddy can complete HTTP-01 / TLS-ALPN against the origin. After certificates issue, you may turn Proxied (orange cloud) on if desired (then origin certs still work; Cloudflare Full/Strict needs a valid origin cert).
- Do not point these at vps2 (
51.91.76.237).
Verify:
dig +short staging.dash.kinoforms.com A # expect 141.95.52.123 (DNS-only)
dig +short staging.kinoforms.com A
curl -sS https://staging.dash.kinoforms.com/healthSwitch Caddy from tls internal → public certs
SSH: ssh vps1
- Backup:
sudo cp -a /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak.before-public-tls-$(date +%Y%m%d%H%M%S)- Edit
/etc/caddy/Caddyfile: in bothstaging.dash.kinoforms.comandstaging.kinoforms.comblocks, delete the line:
tls internalLeave the rest of the staging blocks unchanged (do not touch status.kinoforms.com or other sites).
- Validate + reload:
sudo caddy validate --config /etc/caddy/Caddyfile
sudo systemctl reload caddy
sudo systemctl is-active caddy
journalctl -u caddy -n 40 --no-pager- Confirm public HTTPS (after DNS propagates):
curl -sS https://staging.dash.kinoforms.com/health
curl -sS https://staging.kinoforms.com/healthIf ACME fails, put tls internal back, reload, and fix DNS/proxy mode before retrying. A copy of the staging snippet lives at:
/home/ubuntu/kinoforms-saas-staging/ops/caddy/staging.Caddyfile.snippet
Dedicated WebMCP host (mcp.staging.kinoforms.com)
DNS A mcp.staging → 141.95.52.123 (DNS-only). Caddy site on vps1 reverse-proxies 127.0.0.1:8743 with the same HTTP Basic auth as staging.dash…/webmcp/.
Smoke (expect 401 without credentials):
curl -sS -o /dev/null -w '%{http_code}\n' https://mcp.staging.kinoforms.com/health
curl -sS -u "$WEBMCP_BASIC_USER:$WEBMCP_BASIC_PASSWORD" https://mcp.staging.kinoforms.com/healthWebMCP remains available at https://staging.dash.kinoforms.com/webmcp/ as well.
