Compare commits

...
Author SHA1 Message Date
fauno 28778ca411 feat: implement basic rate limiting by ip address
continuous-integration/drone/pr Build is failing
2026-09-09 06:24:39 -03:00
renovate-bot 5af432db59 chore(deps): update traefik docker tag to v3.7.13 (#141)
continuous-integration/drone/push Build is failing
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [traefik](https://github.com/containous/traefik) | patch | `v3.7.12` -> `v3.7.13` |

>  **Important**
>
> Release Notes retrieval for this PR were skipped because no github.com credentials were available.
> If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes).

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: #141
Co-authored-by: Renovate Bot <renovate@coopcloud.tech>
2026-09-07 18:51:17 +00:00
ammaratef45 a5daf26196 add garage admin entry point (#139)
continuous-integration/drone/push Build is failing
<!--
Thank you for doing recipe maintenance work!
Please mark all checklist items which are relevant for your changes.
Please remove the checklist items which are not relevant for your changes.
Feel free to remove this comment.
-->

* [x] I have deployed and tested my changes
* [x] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash)
* [x] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes)
* [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes)
  - no release note needed

Reviewed-on: #139
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
Co-authored-by: ammar <ammaratef45@proton.me>
2026-09-07 18:49:02 +00:00
p4u1 e6ba592774 chore: publish 6.2.0+v3.7.12 release
continuous-integration/drone/push Build is failing
continuous-integration/drone/tag Build is passing
2026-09-02 12:41:19 +02:00
p4u1 39e52668d2 feat: Add labels for label-based metric scraping (#140)
continuous-integration/drone/push Build is failing
Co-authored-by: p4u1 <p4u1_f4u1@riseup.net>
2026-09-02 10:28:13 +00:00
fauno ca4f4113d9 feat: trusted ips (#128)
continuous-integration/drone/push Build is failing
when traefik is behind a reverse proxy, we need to tell it which
networks to trust with x-real-ip headers

<!--
Thank you for doing recipe maintenance work!
Please mark all checklist items which are relevant for your changes.
Please remove the checklist items which are not relevant for your changes.
Feel free to remove this comment.
-->

* [x] I have deployed and tested my changes
* [x] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash)
* [x] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes)
* [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes)

Reviewed-on: #128
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
Co-authored-by: f <f@sutty.nl>
2026-09-01 13:10:59 +00:00
renovate-bot 0059b9011f chore(deps): update traefik docker tag to v3.7.12 (#135)
continuous-integration/drone/push Build is failing
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [traefik](https://github.com/containous/traefik) | patch | `v3.7.10` -> `v3.7.12` |

>  **Important**
>
> Release Notes retrieval for this PR were skipped because no github.com credentials were available.
> If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes).

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: #135
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
Co-authored-by: Renovate Bot <renovate@coopcloud.tech>
2026-09-01 13:09:51 +00:00
renovate-bot 7c1c36e23a chore(deps): update lscr.io/linuxserver/socket-proxy docker tag to v3.4.4 (#137)
continuous-integration/drone/push Build is failing
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [lscr.io/linuxserver/socket-proxy](https://github.com/linuxserver/docker-socket-proxy/packages) ([source](https://github.com/linuxserver/docker-socket-proxy)) | patch | `3.4.3` -> `3.4.4` |

>  **Important**
>
> Release Notes retrieval for this PR were skipped because no github.com credentials were available.
> If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes).

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: #137
Co-authored-by: Renovate Bot <renovate@coopcloud.tech>
2026-09-01 13:08:33 +00:00
fauno c4f9421f72 feat: access logs (#126)
continuous-integration/drone/push Build is failing
<!--
Thank you for doing recipe maintenance work!
Please mark all checklist items which are relevant for your changes.
Please remove the checklist items which are not relevant for your changes.
Feel free to remove this comment.
-->

* [x] I have deployed and tested my changes
* [ ] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash)
* [x] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes)
* [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes)

Reviewed-on: #126
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
Co-authored-by: f <f@sutty.nl>
2026-08-25 17:19:08 +00:00
javielico 76ab12c797 Added mention to matrix room (#134)
continuous-integration/drone/push Build is failing
Modifying the maintainers.md to mention new #cc-|-traefik-maintenance:matrix.org chat room.

Reviewed-on: #134
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
Co-authored-by: Javielico <103+javielico@noreply.git.coopcloud.tech>
2026-08-25 17:17:02 +00:00
javielico 14f0d953a4 chore: publish 6.1.0+v3.7.10 release
continuous-integration/drone/push Build is failing
continuous-integration/drone/tag Build is passing
2026-08-13 16:21:30 +01:00
javielico 7c8a44bd26 Open ports 5432 for PGSQL new recipe (#133)
continuous-integration/drone/push Build is failing
Reviewed-on: #133
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
Co-authored-by: Javielico <103+javielico@noreply.git.coopcloud.tech>
2026-08-13 14:10:09 +00:00
13 changed files with 140 additions and 8 deletions
+32 -2
View File
@@ -139,10 +139,14 @@ WRITE_TIMEOUT=0s
##################################################################### #####################################################################
## Enable prometheus metrics collection ## Enable prometheus metrics collection
## used used by the coop-cloud monitoring stack ## Metrics are served unauthenticated on :8082, reachable only from
## BASIC_AUTH should also be enabled ## other services on the proxy network (e.g. monitoring-ng's Alloy,
## which auto-discovers it via the prometheus.io/scrape label)
#COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
#METRICS_ENABLED=1 #METRICS_ENABLED=1
## Setting METRICS_FQDN also adds a public metrics endpoint (behind
## basic auth). BASIC_AUTH should be enabled for this.
#METRICS_FQDN=metrics.traefik.example.com #METRICS_FQDN=metrics.traefik.example.com
##################################################################### #####################################################################
@@ -159,6 +163,10 @@ WRITE_TIMEOUT=0s
#COMPOSE_FILE="$COMPOSE_FILE:compose.smtp.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.smtp.yml"
#SMTP_ENABLED=1 #SMTP_ENABLED=1
## PGSQL recipe open port 5432
#COMPOSE_FILE="$COMPOSE_FILE:compose.pgsql.yml"
#PGSQL_ENABLED=1
## Compy ## Compy
#COMPOSE_FILE="$COMPOSE_FILE:compose.compy.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.compy.yml"
#COMPY_ENABLED=1 #COMPY_ENABLED=1
@@ -207,6 +215,8 @@ WRITE_TIMEOUT=0s
## Garage ## Garage
#COMPOSE_FILE="$COMPOSE_FILE:compose.garage.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.garage.yml"
#GARAGE_RPC_ENABLED=1 #GARAGE_RPC_ENABLED=1
#COMPOSE_FILE="$COMPOSE_FILE:compose.garage-admin.yml"
#GARAGE_ADMIN_ENABLED=1
## Nextcloud Talk HPB ## Nextcloud Talk HPB
#COMPOSE_FILE="$COMPOSE_FILE:compose.nextcloud-talk-hpb.yml" #COMPOSE_FILE="$COMPOSE_FILE:compose.nextcloud-talk-hpb.yml"
@@ -228,3 +238,23 @@ WRITE_TIMEOUT=0s
## Enable onion service support ## Enable onion service support
#ONION_ENABLED=1 #ONION_ENABLED=1
## Access logs
#COMPOSE_FILE="$COMPOSE_FILE:compose.access-log.yml"
## Behind a reverse proxy
#
# YAML array of subnets from which Traefik's trusts the x-real-ip
# header when behind a reverse proxy.
#
# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-forwardedHeaders-trustedIPs
#TRUSTED_IPS="['10.13.12.1']" # 10.13.12.1 is an example
## Rate limits
# You can enable universal rate limits by setting RATE_LIMIT_EVERYTHING
# to true, otherwise each app needs to export their own middleware labels.
#
# https://doc.traefik.io/traefik/reference/routing-configuration/http/middlewares/ratelimit/
#RATE_LIMIT_EVERYTHING=false
#RATE_LIMIT_AVERAGE=100
#RATE_LIMIT_BURST=200
+1
View File
@@ -29,3 +29,4 @@ Everyone can apply to be a recipe maintainer:
1. Watch the repository to always get updates 1. Watch the repository to always get updates
2. Simply add your self to the list in the [README.md](./README.md) and open a new pull request with the change. 2. Simply add your self to the list in the [README.md](./README.md) and open a new pull request with the change.
3. Once the pull request gets merged you will be added to the [traefik maintainers team](https://git.coopcloud.tech/org/coop-cloud/teams/traefik-maintainers). 3. Once the pull request gets merged you will be added to the [traefik maintainers team](https://git.coopcloud.tech/org/coop-cloud/teams/traefik-maintainers).
4. Join the room [#cc-|-traefik-maintenance:matrix.org](#cc-|-traefik-maintenance:matrix.org) and chat to other maintainers.
+16
View File
@@ -80,3 +80,19 @@ If you want to collect Prometheus metrics for Anubis, for instance with
Uncomment the line in the config setting `ONION_ENABLED=1`. This will create a new entrypoint on port 9052 which can be used to bypass forced SSL. For more details, see the [onion recipe](https://recipes.coopcloud.tech/onion). Uncomment the line in the config setting `ONION_ENABLED=1`. This will create a new entrypoint on port 9052 which can be used to bypass forced SSL. For more details, see the [onion recipe](https://recipes.coopcloud.tech/onion).
[`abra`]: https://git.autonomic.zone/autonomic-cooperative/abra [`abra`]: https://git.autonomic.zone/autonomic-cooperative/abra
## Access logs
To keep access logs on a volume, uncomment the "Access logs" section.
You'll need to setup rotation yourself and send the USR1 signal to
Traefik for reloading. For instance, with `logrotate:
```
# /etc/logrotate.d/traefik.conf
/var/lib/docker/volumes/traefik_SERVICE_NAME_access-logs/_data/access_log.jsonl {
postrotate
pkill -USR1 traefik
endscript
}
```
+2 -2
View File
@@ -1,4 +1,4 @@
export TRAEFIK_YML_VERSION=v32 export TRAEFIK_YML_VERSION=v37
export FILE_PROVIDER_YML_VERSION=v12 export FILE_PROVIDER_YML_VERSION=v14
export ENTRYPOINT_VERSION=v5 export ENTRYPOINT_VERSION=v5
export ANUBIS_YML_VERSION=v1 export ANUBIS_YML_VERSION=v1
+10
View File
@@ -0,0 +1,10 @@
---
version: "3.8"
services:
app:
environment:
ACCESS_LOG_ENABLED: "true"
volumes:
- "access-logs:/var/log/"
volumes:
access-logs:
+10
View File
@@ -0,0 +1,10 @@
version: "3.8"
services:
app:
environment:
- GARAGE_ADMIN_ENABLED
ports:
- target: 3903
published: 3903
protocol: tcp
mode: host
+6
View File
@@ -3,3 +3,9 @@ services:
app: app:
environment: environment:
- METRICS_ENABLED - METRICS_ENABLED
deploy:
labels:
# lets monitoring-ng's Alloy auto-discover and scrape metrics-internal
# via the proxy network.
- "prometheus.io/scrape=true"
- "prometheus.io/port=8082"
+12
View File
@@ -0,0 +1,12 @@
---
version: "3.8"
services:
app:
environment:
- PGSQL_ENABLED
ports:
- target: 5432
published: 5432
protocol: tcp
mode: host
+3 -3
View File
@@ -3,7 +3,7 @@ version: "3.8"
services: services:
app: app:
image: "traefik:v3.7.10" image: "traefik:v3.7.13"
# Note(decentral1se): *please do not* add any additional ports here. # Note(decentral1se): *please do not* add any additional ports here.
# Doing so could break new installs with port conflicts. Please use # Doing so could break new installs with port conflicts. Please use
# the usual `compose.$app.yml` approach for any additional ports # the usual `compose.$app.yml` approach for any additional ports
@@ -57,12 +57,12 @@ services:
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}" - "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.http.routers.${STACK_NAME}.service=api@internal" - "traefik.http.routers.${STACK_NAME}.service=api@internal"
- "traefik.http.routers.${STACK_NAME}.middlewares=security@file" - "traefik.http.routers.${STACK_NAME}.middlewares=security@file"
- "coop-cloud.${STACK_NAME}.version=6.0.0+v3.7.7" - "coop-cloud.${STACK_NAME}.version=6.2.0+v3.7.12"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
- "backupbot.backup=${ENABLE_BACKUPS:-true}" - "backupbot.backup=${ENABLE_BACKUPS:-true}"
socket-proxy: socket-proxy:
image: lscr.io/linuxserver/socket-proxy:3.4.3 image: lscr.io/linuxserver/socket-proxy:3.4.4
deploy: deploy:
endpoint_mode: dnsrr endpoint_mode: dnsrr
environment: environment:
+14
View File
@@ -22,6 +22,11 @@ http:
basicAuth: basicAuth:
usersFile: "/run/secrets/usersfile" usersFile: "/run/secrets/usersfile"
{{ end }} {{ end }}
ip-rate-limit:
rateLimit:
average: {{ or (env "RATE_LIMIT_AVERAGE") "100" }}
burst: {{ or (env "RATE_LIMIT_BURST") "200" }}
period: "1s"
security: security:
headers: headers:
frameDeny: true frameDeny: true
@@ -32,6 +37,7 @@ http:
stsSeconds: "31536000" stsSeconds: "31536000"
{{ if eq (env "METRICS_ENABLED") "1" }} {{ if eq (env "METRICS_ENABLED") "1" }}
routers: routers:
{{ if ne (env "METRICS_FQDN") "" }}
traefik-metrics: traefik-metrics:
rule: "Host(`{{ env "METRICS_FQDN" }}`)" rule: "Host(`{{ env "METRICS_FQDN" }}`)"
entrypoints: entrypoints:
@@ -41,6 +47,14 @@ http:
middlewares: middlewares:
- basicauth@file - basicauth@file
service: prometheus@internal service: prometheus@internal
{{ end }}
# reachable from other services on the proxy network only (this port
# isn't published to the host), without auth
traefik-metrics-internal:
rule: "PathPrefix(`/`)"
entrypoints:
- metrics-internal
service: prometheus@internal
{{ end }} {{ end }}
tls: tls:
+1
View File
@@ -0,0 +1 @@
Adds option ability to open ports for PGSQL recipe, new version of anubis, and ability to add anubis metrics on this release.
+1
View File
@@ -0,0 +1 @@
1. compose.metrics.yml now adds prometheus.io/scrape labels so services like monitoring-ng can automatically discover and scrape Traefik's metrics.
+31
View File
@@ -6,6 +6,21 @@ log:
level: {{ env "LOG_LEVEL" }} level: {{ env "LOG_LEVEL" }}
maxAge: {{ env "LOG_MAX_AGE" }} maxAge: {{ env "LOG_MAX_AGE" }}
{{ if eq (env "ACCESS_LOG_ENABLED") "true" }}
accessLog:
format: "json"
filePath: "/var/log/access_log.jsonl"
fields:
defaultMode: "keep"
headers:
defaultMode: "keep"
names:
Authorization: "drop"
Cookie: "drop"
queryParameters:
defaultMode: "keep"
{{ end }}
providers: providers:
swarm: swarm:
endpoint: "tcp://socket-proxy:2375" endpoint: "tcp://socket-proxy:2375"
@@ -33,6 +48,14 @@ entrypoints:
to: web-secure to: web-secure
web-secure: web-secure:
address: ":443" address: ":443"
{{ if ne (env "TRUSTED_IPS") "" }}
forwardedHeaders:
trustedIPs: {{ env "TRUSTED_IPS" }}
{{ end }}
{{ if eq (env "RATE_LIMIT_EVERYTHING") "true" }}
middlewares:
- "ip-rate-limit@file"
{{ end }}
transport: transport:
respondingTimeouts: respondingTimeouts:
readTimeout: {{ env "READ_TIMEOUT" }} readTimeout: {{ env "READ_TIMEOUT" }}
@@ -60,6 +83,10 @@ entrypoints:
garage-rpc: garage-rpc:
address: ":3901" address: ":3901"
{{- end }} {{- end }}
{{- if eq (env "GARAGE_ADMIN_ENABLED") "1" }}
garage-admin:
address: ":3903"
{{- end }}
{{- if eq (env "FOODSOFT_SMTP_ENABLED") "1" }} {{- if eq (env "FOODSOFT_SMTP_ENABLED") "1" }}
foodsoft-smtp: foodsoft-smtp:
address: ":2525" address: ":2525"
@@ -112,6 +139,10 @@ entrypoints:
onion: onion:
address: ":9052" address: ":9052"
{{- end }} {{- end }}
{{- if eq (env "METRICS_ENABLED") "1" }}
metrics-internal:
address: ":8082"
{{- end }}
ping: ping:
entryPoint: web entryPoint: web