diff --git a/.env.sample b/.env.sample index 2a21319..f8b511e 100644 --- a/.env.sample +++ b/.env.sample @@ -52,6 +52,8 @@ COMPOSE_FILE="compose.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.keycloak.yml" #KEYCLOAK_MIDDLEWARE_ENABLED=1 #KEYCLOAK_TFA_SERVICE=traefik-forward-auth_app +#KEYCLOAK_MIDDLEWARE_2_ENABLED=1 +#KEYCLOAK_TFA_SERVICE_2=traefik-forward-auth_app ##################################################################### # Prometheus metrics # diff --git a/abra.sh b/abra.sh index 088f253..70b2693 100644 --- a/abra.sh +++ b/abra.sh @@ -1,3 +1,3 @@ export TRAEFIK_YML_VERSION=v12 -export FILE_PROVIDER_YML_VERSION=v3 +export FILE_PROVIDER_YML_VERSION=v6 export ENTRYPOINT_VERSION=v2 diff --git a/compose.keycloak.yml b/compose.keycloak.yml index 7c5c853..e8678e1 100644 --- a/compose.keycloak.yml +++ b/compose.keycloak.yml @@ -5,7 +5,9 @@ services: app: deploy: labels: - - "traefik.http.routers.traefik.middlewares=keycloak@file" + - "traefik.http.routers.${STACK_NAME}.middlewares=keycloak@file" environment: - KEYCLOAK_MIDDLEWARE_ENABLED - KEYCLOAK_TFA_SERVICE + - KEYCLOAK_MIDDLEWARE_2_ENABLED + - KEYCLOAK_TFA_SERVICE_2 diff --git a/file-provider.yml.tmpl b/file-provider.yml.tmpl index 51b97d1..d12761e 100644 --- a/file-provider.yml.tmpl +++ b/file-provider.yml.tmpl @@ -9,6 +9,14 @@ http: authResponseHeaders: - X-Forwarded-User {{ end }} + {{ if eq (env "KEYCLOAK_MIDDLEWARE_2_ENABLED") "1" }} + keycloak2: + forwardAuth: + address: "http://{{ env "KEYCLOAK_TFA_SERVICE_2" }}:4181" + trustForwardHeader: true + authResponseHeaders: + - X-Forwarded-User + {{ end }} security: headers: frameDeny: true