# if using caddy v2.9.x+ you can use this snippet
# snippet to put the preauth system in front any service easily
(preauth) {
	# make sure caddy and preauth are on the same network
	reverse_proxy {args[0]} preauth {
		# leave body content for protected service
		method GET
		# if auth is successful, send request to protected service
		@preauth_ok status 2xx
		handle_response @preauth_ok {
			{block}
		}
	}
}

# example of securing full subdomain
# TODO replace domain and service name
service.example.com {
	import preauth * {
		reverse_proxy service_container
	}
}

# you can only lock down only select paths
# or any other match criteria, if desired
# https://protected.example.com/secure/
protected.example.com {
	import preauth /secure/* {
		reverse_proxy protected-service:9000
	}
	reverse_proxy exposed-service:9000
}

