You have reached scola-internal-saravejo.mincemeat.app. This is a
dedicated server hosting Scola's internal applications. It is not a public
website — application hostnames live on their own subdomains.
Both entry points are access-controlled. Credentials are issued by the operators separately — they are deliberately not published on this page.
Add a record for your application hostname in the Cloudflare zone for its domain, with the orange cloud switched off (DNS-only):
Type Name Content Proxy
A your-app 15.235.215.101 DNS only (grey)
DNS-only matters: TLS is terminated on this server using Let's Encrypt validation over port 80. A proxied record breaks that validation.
Your service becomes reachable at https://your-app.example.com.
Routing is declared in the workload spec, not configured by hand:
the service carries tags, and the edge picks them up.
service {
name = "your-app"
port = "http"
provider = "nomad" # required — there is no Consul here
tags = [
"traefik.enable=true",
"traefik.http.routers.your-app.rule=Host(`your-app.example.com`)",
"traefik.http.routers.your-app.entrypoints=websecure",
"traefik.http.routers.your-app.tls=true",
]
}
A certificate is issued automatically on the first request and renewed without downtime. HTTP is redirected to HTTPS. Traffic is filtered by CrowdSec before it reaches your application.
service block needs provider = "nomad";
without it the job is never scheduled.