- Caddyfile: disable auto_https and admin, listen on :80 only
- docker-compose: bind port only on 127.0.0.1 to avoid public exposure
- bootstrap/app.php: trust all proxies so Laravel generates correct URLs
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Caddy still listens on :80 inside the container, but only port 5000 is
exposed to the host. Removes 443/HTTPS ports and Caddy cert volumes —
TLS is handled by the upstream reverse proxy.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>