# Routing rules

> Configure redirects, response headers, HTTP basic auth, IP allow and deny lists, request body limits and compression for a Falak site at the Caddy edge.

Source: https://falak.sh/docs/guides/routing-rules/

Routing rules run in Caddy on your servers (or the load balancer), before requests reach your app. Manage them under the site's **Settings → Networking** (the **Routing** section). On a [Compose site](/docs/guides/compose-apps/#edge-for-every-public-service), pick a public service in the service picker: redirects, basic auth and headers apply to the whole site or to that service, and a service's allow list replaces the site's while its deny list adds to it. Every change recompiles the full Caddy configuration of each server and applies it atomically; bursts of changes within 2 seconds are applied once (`FALAK_EDGE_APPLY_DELAY`).

![The Routing page of a site: redirects, basic auth, custom headers and security settings (IP allow and deny lists, request body limit, compression).](./_images/sites-site-routing.png)

## Redirects

| Field | Rule |
|---|---|
| From | A path starting with `/` (unique per site) |
| To | An absolute `http(s)://` URL or a path starting with `/` |
| Status | `301`, `302`, `307` or `308` |

```text title="Examples"
/blog      →  https://blog.example.com   301
/old-docs  →  /docs                       308
```

## Headers

Add response headers by name and value, for example `Strict-Transport-Security: max-age=31536000` or `X-Robots-Tag: noindex`. Names use letters, digits and dashes; values are a single line up to 2000 characters.

## Basic auth

Protect the whole site or one path with HTTP basic auth:

| Field | Rule |
|---|---|
| Name | Optional label |
| Path | Optional, starts with `/` (empty = whole site) |
| Username | Letters, digits, `.`, `_`, `@`, `-` |
| Password | 8–200 characters |

Useful for staging environments and admin areas.

## Security

| Setting | Meaning |
|---|---|
| Allow IPs | If set, only these IPs/CIDRs may connect (up to 200 entries) |
| Deny IPs | These IPs/CIDRs are refused (up to 200 entries) |
| Max body size | Maximum request body in bytes (up to 10 GiB); empty = no limit |
| Compression | Enable response compression (`encode`) |

Behind a load balancer, set IP rules on the site and they apply where the site's traffic is terminated. The client IP is the one Caddy sees.

## Edge status

The Networking settings show, per server, whether the latest configuration was applied, and a **Re-apply** button. If an apply fails, the error is shown there.

## Next steps
