From 26fcaaea69c403da1c58c4533575fef7b740f1fb Mon Sep 17 00:00:00 2001 From: 3wc <3wc@doesthisthing.work> Date: Tue, 16 Nov 2021 16:08:04 +0200 Subject: [PATCH] Add a slot for a second traefik-forward-auth instance --- .env.sample | 1 + compose.keycloak.yml | 4 +++- file-provider.yml.tmpl | 8 ++++++++ 3 files changed, 12 insertions(+), 1 deletion(-) diff --git a/.env.sample b/.env.sample index 2a21319..d176cdd 100644 --- a/.env.sample +++ b/.env.sample @@ -52,6 +52,7 @@ COMPOSE_FILE="compose.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.keycloak.yml" #KEYCLOAK_MIDDLEWARE_ENABLED=1 #KEYCLOAK_TFA_SERVICE=traefik-forward-auth_app +#KEYCLOAK_MIDDLEWARE_2_ENABLED=1 ##################################################################### # Prometheus metrics # diff --git a/compose.keycloak.yml b/compose.keycloak.yml index 7c5c853..666baec 100644 --- a/compose.keycloak.yml +++ b/compose.keycloak.yml @@ -5,7 +5,9 @@ services: app: deploy: labels: - - "traefik.http.routers.traefik.middlewares=keycloak@file" + - "traefik.http.routers.${STACK_NAME}.middlewares=keycloak@file" environment: - KEYCLOAK_MIDDLEWARE_ENABLED - KEYCLOAK_TFA_SERVICE + - KEYCLOAK_MIDDLEWARE_2_ENABLED + - KEYCLOAK_MIDDLEWARE_2_SERVICE diff --git a/file-provider.yml.tmpl b/file-provider.yml.tmpl index 51b97d1..f7a22f4 100644 --- a/file-provider.yml.tmpl +++ b/file-provider.yml.tmpl @@ -9,6 +9,14 @@ http: authResponseHeaders: - X-Forwarded-User {{ end }} + {{ if eq (env "KEYCLOAK_MIDDLEWARE_2_ENABLED") "1" }} + keycloak2: + forwardAuth: + address: "http://${KEYCLOAK_MIDDLEWARE_2_SERVICE}:4181" + trustForwardHeader: true + authResponseHeaders: + - X-Forwarded-User + {{ end }} security: headers: frameDeny: true