Compare commits

..
Author SHA1 Message Date
fauno 21ea1dd698 feat: implement basic rate limiting by ip address
continuous-integration/drone/pr Build is failing
2026-10-03 01:31:30 -03:00
renovate-bot 3272a9a7c8 chore(deps): update lscr.io/linuxserver/socket-proxy docker tag to v3.4.5 (#144)
continuous-integration/drone/push Build is failing
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [lscr.io/linuxserver/socket-proxy](https://github.com/linuxserver/docker-socket-proxy/packages) ([source](https://github.com/linuxserver/docker-socket-proxy)) | patch | `3.4.4` -> `3.4.5` |

> ❗ **Important**
>
> Release Notes retrieval for this PR were skipped because no github.com credentials were available.
> If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes).

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: #144
Co-authored-by: Renovate Bot <renovate@coopcloud.tech>
2026-09-28 08:48:50 +00:00
fauno b06cc6df3e fix: certs are only inserted (#143)
continuous-integration/drone/push Build is failing
<!--
Thank you for doing recipe maintenance work!
Please mark all checklist items which are relevant for your changes.
Please remove the checklist items which are not relevant for your changes.
Feel free to remove this comment.
-->

* [ ] I have deployed and tested my changes
* [ ] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash)
* [ ] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes)
* [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes)

Reviewed-on: #143
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
Co-authored-by: f <f@sutty.nl>
2026-09-28 08:47:58 +00:00
5 changed files with 26 additions and 8 deletions
+13 -4
View File
@@ -110,11 +110,11 @@ WRITE_TIMEOUT=0s
# Set wildcards = 1, and uncomment compose_file to enable.
# Create your certs elsewhere and add them like:
# abra app secret insert {myapp.example.coop} ssl_cert v1 "$(cat /path/to/fullchain.pem)"
# abra app secret insert {myapp.example.coop} ssl_key v1 "$(cat /path/to/privkey.pem)"
# abra app secret insert traefik.example.coop ssl_cert v1 -f /path/to/fullchain.pem
# abra app secret insert traefik.example.coop ssl_key v1 -f /path/to/privkey.pem
#WILDCARDS_ENABLED=1
#SECRET_WILDCARD_CERT_VERSION=v1
#SECRET_WILDCARD_KEY_VERSION=v1
#SECRET_WILDCARD_CERT_VERSION=v1 # generate=false
#SECRET_WILDCARD_KEY_VERSION=v1 # generate=false
#COMPOSE_FILE="$COMPOSE_FILE:compose.wildcard.yml"
#####################################################################
@@ -249,3 +249,12 @@ WRITE_TIMEOUT=0s
#
# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-forwardedHeaders-trustedIPs
#TRUSTED_IPS="['10.13.12.1']" # 10.13.12.1 is an example
## Rate limits
# You can enable universal rate limits by setting RATE_LIMIT_EVERYTHING
# to true, otherwise each app needs to export their own middleware labels.
#
# https://doc.traefik.io/traefik/reference/routing-configuration/http/middlewares/ratelimit/
#RATE_LIMIT_EVERYTHING=false
#RATE_LIMIT_AVERAGE=100
#RATE_LIMIT_BURST=200
+2 -2
View File
@@ -1,4 +1,4 @@
export TRAEFIK_YML_VERSION=v36
export FILE_PROVIDER_YML_VERSION=v13
export TRAEFIK_YML_VERSION=v37
export FILE_PROVIDER_YML_VERSION=v14
export ENTRYPOINT_VERSION=v5
export ANUBIS_YML_VERSION=v1
+1 -1
View File
@@ -62,7 +62,7 @@ services:
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
socket-proxy:
image: lscr.io/linuxserver/socket-proxy:3.4.4
image: lscr.io/linuxserver/socket-proxy:3.4.5
deploy:
endpoint_mode: dnsrr
environment:
+6 -1
View File
@@ -22,6 +22,11 @@ http:
basicAuth:
usersFile: "/run/secrets/usersfile"
{{ end }}
ip-rate-limit:
rateLimit:
average: {{ or (env "RATE_LIMIT_AVERAGE") "100" }}
burst: {{ or (env "RATE_LIMIT_BURST") "200" }}
period: "1s"
security:
headers:
frameDeny: true
@@ -70,4 +75,4 @@ tls:
certificates:
- certFile: /run/secrets/ssl_cert
keyFile: /run/secrets/ssl_key
{{ end }}
{{ end }}
+4
View File
@@ -65,6 +65,10 @@ entrypoints:
allowEncodedPercent: true
allowEncodedQuestionMark: true
allowEncodedHash: true
{{ if eq (env "RATE_LIMIT_EVERYTHING") "true" }}
middlewares:
- "ip-rate-limit@file"
{{ end }}
{{- if eq (env "GITEA_SSH_ENABLED") "1" }}
gitea-ssh:
address: ":2222"