Finalise this app setup
This commit is contained in:
parent
ee1e186146
commit
3947537018
|
@ -1,5 +1,3 @@
|
||||||
# traefik-forward-auth
|
# traefik-forward-auth
|
||||||
|
|
||||||
> https://github.com/thomseddon/traefik-forward-auth
|
[![Build Status](https://drone.autonomic.zone/api/badges/coop-cloud/traefik-forward-auth/status.svg)](https://drone.autonomic.zone/coop-cloud/traefik-forward-auth)
|
||||||
|
|
||||||
**Work In Progress.**
|
|
||||||
|
|
|
@ -0,0 +1,46 @@
|
||||||
|
---
|
||||||
|
version: "3.8"
|
||||||
|
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
image: "thomseddon/traefik-forward-auth:2"
|
||||||
|
configs:
|
||||||
|
- source: forward_ini
|
||||||
|
target: /etc/forward.ini
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
environment:
|
||||||
|
- CONFIG=/etc/forward.ini
|
||||||
|
- OIDC_CLIENT_ID
|
||||||
|
- OIDC_ISSUER_URL
|
||||||
|
- COOKIE_DOMAIN
|
||||||
|
- AUTH_HOST
|
||||||
|
secrets:
|
||||||
|
- oidc_client_secret
|
||||||
|
- secret_nonce
|
||||||
|
deploy:
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.services.tfa.loadBalancer.server.port=4181"
|
||||||
|
- "traefik.http.routers.tfa.rule=Host(`${DOMAIN}`)"
|
||||||
|
- "traefik.http.routers.tfa.entrypoints=web-secure"
|
||||||
|
- "traefik.http.routers.tfa.tls.certresolver=production"
|
||||||
|
- "traefik.http.routers.tfa.middlewares=keycloak@file"
|
||||||
|
|
||||||
|
networks:
|
||||||
|
proxy:
|
||||||
|
external: true
|
||||||
|
|
||||||
|
configs:
|
||||||
|
forward_ini:
|
||||||
|
name: ${STACK_NAME}_forward_ini_${FORWARD_INI_VERSION}
|
||||||
|
file: forward.ini.tmpl
|
||||||
|
template_driver: golang
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
secret_nonce:
|
||||||
|
name: ${STACK_NAME}_secret_nonce_${SERCRET_NONCE_VERSION}
|
||||||
|
external: true
|
||||||
|
oidc_client_secret:
|
||||||
|
name: ${STACK_NAME}_oidc_client_secret_${OIDC_CLIENT_SECRET_VERSION}
|
||||||
|
external: true
|
|
@ -1,45 +0,0 @@
|
||||||
---
|
|
||||||
version: "3.8"
|
|
||||||
|
|
||||||
services:
|
|
||||||
traefik-forward-auth:
|
|
||||||
image: thomseddon/traefik-forward-auth:2
|
|
||||||
configs:
|
|
||||||
- source: forward-ini-prod-v1
|
|
||||||
target: /etc/forward.ini
|
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
environment:
|
|
||||||
- CONFIG=/etc/forward.ini
|
|
||||||
secrets:
|
|
||||||
- oidc-client-id-v1
|
|
||||||
- oidc-client-secret-v1
|
|
||||||
- oidc-issuer-url-v1
|
|
||||||
- secret-nonce-v1
|
|
||||||
deploy:
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.http.services.tfa.loadBalancer.server.port=4181"
|
|
||||||
- "traefik.http.routers.tfa.rule=Host(`auth.swarm.autonomic.zone`)"
|
|
||||||
- "traefik.http.routers.tfa.entrypoints=web-secure"
|
|
||||||
- "traefik.http.routers.tfa.tls.certresolver=staging"
|
|
||||||
- "traefik.http.routers.tfa.middlewares=keycloak@file"
|
|
||||||
|
|
||||||
networks:
|
|
||||||
proxy:
|
|
||||||
external: true
|
|
||||||
|
|
||||||
configs:
|
|
||||||
forward-ini-prod-v1:
|
|
||||||
file: forward.ini.tmpl
|
|
||||||
template_driver: golang
|
|
||||||
|
|
||||||
secrets:
|
|
||||||
secret-nonce-v1:
|
|
||||||
external: true
|
|
||||||
oidc-issuer-url-v1:
|
|
||||||
external: true
|
|
||||||
oidc-client-id-v1:
|
|
||||||
external: true
|
|
||||||
oidc-client-secret-v1:
|
|
||||||
external: true
|
|
|
@ -1,9 +1,9 @@
|
||||||
secret = {{ secret "secret-nonce-v1" }}
|
secret = {{ secret "secret_nonce" }}
|
||||||
log-level = info
|
log-level = info
|
||||||
cookie-domain = swarm.autonomic.zone
|
cookie-domain = {{ env "COOKIE_DOMAIN" }}
|
||||||
auth-host = auth.swarm.autonomic.zone
|
auth-host = {{ env "AUTH_HOST" }}
|
||||||
|
|
||||||
default-provider = oidc
|
default-provider = oidc
|
||||||
providers.oidc.issuer-url = {{ secret "oidc-issuer-url-v1" }}
|
providers.oidc.issuer-url = {{ env "OIDC_ISSUER_URL" }}
|
||||||
providers.oidc.client-id = {{ secret "oidc-client-id-v1" }}
|
providers.oidc.client-id = {{ env "OIDC_CLIENT_ID" }}
|
||||||
providers.oidc.client-secret = {{ secret "oidc-client-secret-v1" }}
|
providers.oidc.client-secret = {{ secret "oidc_client_secret" }}
|
||||||
|
|
Loading…
Reference in New Issue