mincemeat.id · client infrastructure
Singapore · OVH

Scola Internal Platform — Saravejo

You have reached scola-internal-saravejo.mincemeat.app. This is a dedicated server hosting Scola's internal applications. It is not a public website — application hostnames live on their own subdomains.

Publishing an app? Read “For application owners” below. You need a DNS record pointing at this server, and nothing else — routing and TLS are handled automatically on the host.

Points of entry

Both entry points are access-controlled. Credentials are issued by the operators separately — they are deliberately not published on this page.

For application owners

1. Point DNS at this server

Add a record for your application hostname in the Cloudflare zone for its domain, with the orange cloud switched off (DNS-only):

Type   Name                        Content            Proxy
A      your-app                   15.235.215.101     DNS only  (grey)

DNS-only matters: TLS is terminated on this server using Let's Encrypt validation over port 80. A proxied record breaks that validation.

2. Tell us the hostname and the port your app listens on

Your service becomes reachable at https://your-app.example.com. Routing is declared in the workload spec, not configured by hand: the service carries tags, and the edge picks them up.

service {
  name     = "your-app"
  port     = "http"
  provider = "nomad"        # required — there is no Consul here
  tags = [
    "traefik.enable=true",
    "traefik.http.routers.your-app.rule=Host(`your-app.example.com`)",
    "traefik.http.routers.your-app.entrypoints=websecure",
    "traefik.http.routers.your-app.tls=true",
  ]
}
3. That's it

A certificate is issued automatically on the first request and renewed without downtime. HTTP is redirected to HTTPS. Traffic is filtered by CrowdSec before it reaches your application.

Things that will save you a support ticket:

For Scola operators