Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary.
$ npx skills add greenpau/caddy-security --skill configuration-logging -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security configuration-logging --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-logging .claude/skills/configuration-logging && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuration-logging" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-logging into .claude/skills/configuration-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-logging", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-loggingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill configuration-logging -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security configuration-logging --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/configuration-logging .agents/skills/configuration-logging && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuration-logging" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-logging into .agents/skills/configuration-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-logging", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-logging -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security configuration-logging --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/configuration-logging .cursor/skills/configuration-logging && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuration-logging" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-logging into .cursor/skills/configuration-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-logging", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/configuration-logging--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill configuration-logging -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security configuration-logging --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/configuration-logging .gemini/skills/configuration-logging && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuration-logging" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-logging into .gemini/skills/configuration-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-logging", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security configuration-loggingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill configuration-logging -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/configuration-logging .github/skills/configuration-logging && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuration-logging" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-logging into .github/skills/configuration-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-logging", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-logging -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security configuration-logging --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/configuration-logging .opencode/skills/configuration-logging && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuration-logging" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-logging into .opencode/skills/configuration-logging/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-logging", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuration-loggingConfigure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary.
Configuration Logging is an agent skill from greenpau/caddy-security. Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary. Use for component/message filtering; access logs and authorization outcomes are separate concerns.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makegoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Configuration Logging loads about 2.1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 958 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 958 words, ~2,132 tokens.
.claude/skills/configuration-logging/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.The root security logging block configures AuthCrunch component diagnostics.
Caddy v2.11.7's independent http.handlers.authentication logger remains
unfiltered. Issue #280 is not fixed by this adapter. Read the host boundary
below before recommending the issue's message/error patterns to an operator.
Current authorize Caddyfiles use http.handlers.authorization; the legacy
JSON authentication-provider chain is still supported and emits the host error.
Do not change that chain's behavior to silence it.
Published AuthCrunch v1.3.4 supplies Config.Logging, pkg/logging, the shared
parser, and root logger wrapping. No local replacement or library release is
needed for these interfaces. Recheck go list -m -json when dependencies change;
the dependency workflow
owns selection changes. Sibling source and skills remain read-only references.
Inside the global options block:
{
security {
logging {
skip exact text "token validation error"
}
}
}This suppresses the AuthCrunch gatekeeper's diagnostic message; it leaves its returned errors, HTTP denial, redirects and authorization decisions unchanged. Other security declarations and site routes are configured normally.
The complete body grammar is one statement per line:
skip <exact|partial|prefix|suffix|regex> text <value>Every statement has four tokens. Quote multiword values. Repeated rules,
including identical rules and imported rule bodies, append in order and match
with OR. Duplicate logging blocks, header arguments, nested blocks, empty
tokens, malformed keywords/arity, invalid regular expressions, whitespace-only
text and raw newlines are rejected with location-aware errors. Omission or an
empty multiline block suppresses nothing; there are no implicit rules.
The enclosing global security option also occurs once; repeating it fails
instead of silently replacing the earlier app and discarding its rules.
Matching is case-sensitive. Exact compares the whole value, partial finds a
substring, prefix/suffix match an edge, and regex uses Go regexp semantics
(unanchored unless the pattern supplies anchors). Spaces, quotes, Unicode and
regex escapes survive Caddy tokenization, argument encoding and JSON. Patterns
are literal during provisioning: {env.*} and secrets:* are not expanded.
Caddy's normal {$ENV} preprocessing still occurs before tokenization.
The library compares the message and individual string, byte-string, error and
Stringer values, including fields bound after wrapping by With/WithLazy. Keys,
logger names, numeric values, arrays and object contents are outside this
selector. In the host error, reason: no token found occurs in the error
field, not in the message. The component's error field contains no token found
without that host prefix; a partial rule for that value selectively suppresses
its missing-token diagnostics while retaining malformed-token diagnostics.
Native Caddy JSON stores the library type directly:
{"apps":{"security":{"config":{"logging":{"skip":[
{"match":"exact","text":"token validation error"}
]}}}}}caddyfile_logging.go collects the complete block with Caddy's tokenized
values, rejects empty arguments/unsupported structure, encodes each statement
with cfgutil.EncodeArgs, then calls
logging/parser.NewLoggingConfigFromDirectives. Do not split or concatenate
tokens manually, implement another matcher, or publish a partial config.
App.Provision copies the declarative graph through JSON and invokes the
library's Config.Validate before constructing/serving. NewServer creates an
immutable filter and wraps its supplied logger before creating components.
The app's original base logger and unrelated host/access logs remain unchanged;
Caddy retains flushing and lifetime ownership.
Reload creates a new app/runtime/filter from the base logger. Replacing/removing rules cannot mutate the old instance or accumulate wrappers. Logging is excluded from AuthCrunch's persistent-session binding: logging-only stop/start changes retain refresh sessions. Existing runtime restrictions still apply: overlapping persistent roots or local identity files are rejected. Do not relax those restrictions for logging changes.
Trace the pinned host before attempting integration:
modules/caddyhttp/caddyauth/caddyauth.go: Authentication.Provision saves
ctx.Logger() into its private logger before loading providers.
Authentication.ServeHTTP calls that logger's Check and Write on returned
provider errors, attaching provider and zap.Error(err).context.go: Context.Logger calls Logging.Logger. There is no supported
instance logger setter/wrapper. Slog factories do not intercept these Zap calls.logging.go: Logging.Logger assembles configured cores and names the result.
BaseLog.provisionCommon installs CoreRaw using
zapcore.NewTee(cl.core, core); the extension does not receive the existing
core, so dropping its own copy cannot suppress the original output. Logging
setup runs before app provisioning. Encoder/writer modules are too late to
preserve the requested pre-sampling, typed-field, full-entry semantics.The required upstream change is an instance-owned wrapping hook reached by the
actual authentication logger. A concrete option is an opt-in provider interface
that accepts the middleware's original *zap.Logger and returns a wrapped clone
or error during provisioning. Caddy would retain a clone per provider and use
it for that provider's actual error call. The authorizer could then supply
logging.NewFilter(config.Logging).WrapLogger(base). Install it before any
With/WithLazy fields; retain the base logger and existing Sync owner. This is a
proposed upstream contract, not an API available in v2.11.7.
A supported scoped core-wrapper hook is another option, provided it wraps the existing core rather than tees beside it and is isolated to the correct configuration/module. Use the library wrapper to preserve samplers, tees, hooks, error output and terminal actions. Do not add global mutable filters, unsafe private-field access, a Caddy fork, dead-code wrappers, or an alternate authentication implementation. Never swallow a returned error or permit a protected handler to avoid a diagnostic.
caddyfile_logging_test.go covers the issue's exact example, all matchers,
encoding, imports/repetition, malformed grammar/structure, omission/empty blocks,
native JSON validation, public config-file round trips and provisioning.
Adaptation fixtures are testcase_security_logging,
testcase_security_logging_matchers and testcase_security_logging_empty.
TestAppLoggingInstanceIsolation checks multiple simultaneous runtime filters,
detached snapshots, the unchanged base logger and rule removal.
TestCaddyLoggingE2E builds the actual race-enabled Caddy command and captures
JSON output. It uses verified local TLS, temporary identity databases, both
current and legacy routes, real password login and a counted protected upstream.
It proves baseline noise; error-only/message-only/combined host rules remaining
ineffective; selective component filtering; all matchers, case sensitivity and
OR; unchanged denials/success; unrelated access/app output; two live processes;
replacements, removal and invalid-JSON rollback. Its persistent journey rotates
the same refresh session across logging-only stop/start replacements.
These passing tests certify the consumer/component integration and the known host limitation. They do not satisfy the issue's host-suppression acceptance criteria. Once the host hook exists, require error-text-only suppression of missing-token errors while malformed-token errors from the same logger remain, and message-only suppression of the middleware message, through this real process.
make test TEST='TestParseCaddyfileLogging|TestLogging|TestAppLogging|TestCaddyLoggingE2E|TestCaddyfileAdaptAuthenticationToJSON|TestResolveRuntimeAppConfig' TEST_DIR=. COVERAGE_DIR=.coverage/logging© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/configuration-logging of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Configuration Logging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuration Logging this skillgreenpau/caddy-security | 2.3k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| K8s Security PoliciesCybereason-Public/owLSM | 280 | 12 repos | ~2k | Automated safety check: Pass | GPL-2.0 | |
| Payloadpayloadcms/payload | 45k | 5 repos | ~6.2k | Automated safety check: Pass | MIT | |
| Convex Setup Authspokvulcan/poker-planning | 114 | 8 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Abp Authorizationabpframework/abp | 14k | — | ~1.3k | Automated safety check: Pass | LGPL-3.0 |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Cybereason-Public/owLSM
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
payloadcms/payload
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
spokvulcan/poker-planning
Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.
abpframework/abp
ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.
bagofwords1/bagofwords
Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…
greenpau/caddy-security
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
Categories
Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary. Configuration Logging is an agent skill from greenpau/caddy-security. Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary.
Configuration Logging fits situations like: component/message filtering; access logs and authorization outcomes are separate concerns.
Run `npx skills add greenpau/caddy-security --skill configuration-logging -a claude-code`. Or copy the skill folder (.codex/skills/configuration-logging in greenpau/caddy-security) into .claude/skills/configuration-logging in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill configuration-logging -a codex`. Or copy the skill folder (.codex/skills/configuration-logging in greenpau/caddy-security) into .agents/skills/configuration-logging in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-logging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-logging, .gemini/skills/configuration-logging, .github/skills/configuration-logging and .opencode/skills/configuration-logging in your project.
Going by SKILL.md and its folder, Configuration Logging needs the command-line tools its instructions call (make and go).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Configuration Logging is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Configuration Logging: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.