Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
488777367f
|
+3
-7
@@ -159,10 +159,6 @@ WRITE_TIMEOUT=0s
|
|||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.smtp.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.smtp.yml"
|
||||||
#SMTP_ENABLED=1
|
#SMTP_ENABLED=1
|
||||||
|
|
||||||
## PGSQL recipe open port 5432
|
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.pgsql.yml"
|
|
||||||
#PGSQL_ENABLED=1
|
|
||||||
|
|
||||||
## Compy
|
## Compy
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.compy.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.compy.yml"
|
||||||
#COMPY_ENABLED=1
|
#COMPY_ENABLED=1
|
||||||
@@ -227,8 +223,8 @@ WRITE_TIMEOUT=0s
|
|||||||
#ANUBIS_SERVE_ROBOTS_TXT=true
|
#ANUBIS_SERVE_ROBOTS_TXT=true
|
||||||
#ANUBIS_SLOG_LEVEL=INFO
|
#ANUBIS_SLOG_LEVEL=INFO
|
||||||
|
|
||||||
## Anubis metrics
|
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.anubis-metrics.yml"
|
|
||||||
|
|
||||||
## Enable onion service support
|
## Enable onion service support
|
||||||
#ONION_ENABLED=1
|
#ONION_ENABLED=1
|
||||||
|
|
||||||
|
# YAML array of trusted subnets
|
||||||
|
TRUSTED_IPS=
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
> https://docs.traefik.io
|
> https://docs.traefik.io
|
||||||
|
|
||||||
<!-- metadata -->
|
<!-- metadata -->
|
||||||
* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@javielico](https://git.coopcloud.tech/javielico), Local-IT: [@moritz](https://git.coopcloud.tech/moritz), [@msimon](https://git.coopcloud.tech/simon), [@carla](https://git.coopcloud.tech/carla)
|
* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@decentral1se](https://git.coopcloud.tech/decentral1se), [@javielico](https://git.coopcloud.tech/javielico), Local-IT: [@moritz](https://git.coopcloud.tech/moritz), [@msimon](https://git.coopcloud.tech/simon), [@carla](https://git.coopcloud.tech/carla)
|
||||||
* **Status**: `stable`
|
* **Status**: `stable`
|
||||||
* **Category**: Utilities
|
* **Category**: Utilities
|
||||||
* **Features**: ?
|
* **Features**: ?
|
||||||
@@ -72,9 +72,6 @@ After deploying these changes, go to each recipe that supports Anubis
|
|||||||
and follow the process there. **Enabling Anubis here is not enough for
|
and follow the process there. **Enabling Anubis here is not enough for
|
||||||
protection your apps.**
|
protection your apps.**
|
||||||
|
|
||||||
If you want to collect Prometheus metrics for Anubis, for instance with
|
|
||||||
[monitoring-ng](/monitoring-ng), uncomment the "Anubis metrics" section.
|
|
||||||
|
|
||||||
## Enabling onion service
|
## Enabling onion service
|
||||||
|
|
||||||
Uncomment the line in the config setting `ONION_ENABLED=1`. This will create a new entrypoint on port 9052 which can be used to bypass forced SSL. For more details, see the [onion recipe](https://recipes.coopcloud.tech/onion).
|
Uncomment the line in the config setting `ONION_ENABLED=1`. This will create a new entrypoint on port 9052 which can be used to bypass forced SSL. For more details, see the [onion recipe](https://recipes.coopcloud.tech/onion).
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
export TRAEFIK_YML_VERSION=v32
|
export TRAEFIK_YML_VERSION=v32a
|
||||||
export FILE_PROVIDER_YML_VERSION=v12
|
export FILE_PROVIDER_YML_VERSION=v12
|
||||||
export ENTRYPOINT_VERSION=v5
|
export ENTRYPOINT_VERSION=v5
|
||||||
export ANUBIS_YML_VERSION=v1
|
|
||||||
|
|||||||
@@ -1,7 +0,0 @@
|
|||||||
bots:
|
|
||||||
- import: (data)/meta/default-config.yaml
|
|
||||||
{{ if eq (env "ANUBIS_METRICS_ENABLED") "true" }}
|
|
||||||
metrics:
|
|
||||||
bind: ":9090"
|
|
||||||
network: "tcp"
|
|
||||||
{{ end }}
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
---
|
|
||||||
version: "3.8"
|
|
||||||
services:
|
|
||||||
anubis:
|
|
||||||
environment:
|
|
||||||
ANUBIS_METRICS_ENABLED: "true"
|
|
||||||
deploy:
|
|
||||||
labels:
|
|
||||||
- "prometheus.io/scrape=true"
|
|
||||||
- "prometheus.io/port=9090"
|
|
||||||
- "prometheus.io/path=/metrics"
|
|
||||||
+1
-10
@@ -7,7 +7,7 @@ services:
|
|||||||
- "traefik.http.middlewares.anubis.forwardauth.address=http://anubis:8080/.within.website/x/cmd/anubis/api/check"
|
- "traefik.http.middlewares.anubis.forwardauth.address=http://anubis:8080/.within.website/x/cmd/anubis/api/check"
|
||||||
- "traefik.http.middlewares.anubis.forwardauth.trustForwardHeader=true"
|
- "traefik.http.middlewares.anubis.forwardauth.trustForwardHeader=true"
|
||||||
anubis:
|
anubis:
|
||||||
image: "ghcr.io/techarohq/anubis:v1.27.0"
|
image: "ghcr.io/techarohq/anubis:v1.26.2"
|
||||||
environment:
|
environment:
|
||||||
BIND: ":8080"
|
BIND: ":8080"
|
||||||
TARGET: " "
|
TARGET: " "
|
||||||
@@ -19,10 +19,6 @@ services:
|
|||||||
OG_CACHE_CONSIDER_HOST: "${ANUBIS_OG_CACHE_CONSIDER_HOST}"
|
OG_CACHE_CONSIDER_HOST: "${ANUBIS_OG_CACHE_CONSIDER_HOST}"
|
||||||
SERVE_ROBOTS_TXT: "${ANUBIS_SERVE_ROBOTS_TXT}"
|
SERVE_ROBOTS_TXT: "${ANUBIS_SERVE_ROBOTS_TXT}"
|
||||||
SLOG_LEVEL: "${ANUBIS_SLOG_LEVEL:-INFO}"
|
SLOG_LEVEL: "${ANUBIS_SLOG_LEVEL:-INFO}"
|
||||||
POLICY_FNAME: "/data/cfg/botPolicy.yaml"
|
|
||||||
configs:
|
|
||||||
- source: anubis_yml
|
|
||||||
target: /data/cfg/botPolicy.yaml
|
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
deploy:
|
deploy:
|
||||||
@@ -33,8 +29,3 @@ services:
|
|||||||
- "traefik.http.routers.anubis.entrypoints=web-secure"
|
- "traefik.http.routers.anubis.entrypoints=web-secure"
|
||||||
- "traefik.http.services.anubis.loadbalancer.server.port=8080"
|
- "traefik.http.services.anubis.loadbalancer.server.port=8080"
|
||||||
- "traefik.http.routers.anubis.service=anubis"
|
- "traefik.http.routers.anubis.service=anubis"
|
||||||
configs:
|
|
||||||
anubis_yml:
|
|
||||||
name: ${STACK_NAME}_anubis_yml_${ANUBIS_YML_VERSION}
|
|
||||||
file: anubis.yml.tmpl
|
|
||||||
template_driver: golang
|
|
||||||
|
|||||||
@@ -1,12 +0,0 @@
|
|||||||
---
|
|
||||||
version: "3.8"
|
|
||||||
|
|
||||||
services:
|
|
||||||
app:
|
|
||||||
environment:
|
|
||||||
- PGSQL_ENABLED
|
|
||||||
ports:
|
|
||||||
- target: 5432
|
|
||||||
published: 5432
|
|
||||||
protocol: tcp
|
|
||||||
mode: host
|
|
||||||
+2
-2
@@ -3,7 +3,7 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
image: "traefik:v3.7.10"
|
image: "traefik:v3.7.9"
|
||||||
# Note(decentral1se): *please do not* add any additional ports here.
|
# Note(decentral1se): *please do not* add any additional ports here.
|
||||||
# Doing so could break new installs with port conflicts. Please use
|
# Doing so could break new installs with port conflicts. Please use
|
||||||
# the usual `compose.$app.yml` approach for any additional ports
|
# the usual `compose.$app.yml` approach for any additional ports
|
||||||
@@ -62,7 +62,7 @@ services:
|
|||||||
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
||||||
|
|
||||||
socket-proxy:
|
socket-proxy:
|
||||||
image: lscr.io/linuxserver/socket-proxy:3.4.3
|
image: lscr.io/linuxserver/socket-proxy:3.4.2
|
||||||
deploy:
|
deploy:
|
||||||
endpoint_mode: dnsrr
|
endpoint_mode: dnsrr
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
@@ -33,6 +33,10 @@ entrypoints:
|
|||||||
to: web-secure
|
to: web-secure
|
||||||
web-secure:
|
web-secure:
|
||||||
address: ":443"
|
address: ":443"
|
||||||
|
{{ if ne (env "TRUSTED_IPS") "" }}
|
||||||
|
forwardedHeaders:
|
||||||
|
trustedIPs: {{ env "TRUSTED_IPS" }}
|
||||||
|
{{ end }}
|
||||||
transport:
|
transport:
|
||||||
respondingTimeouts:
|
respondingTimeouts:
|
||||||
readTimeout: {{ env "READ_TIMEOUT" }}
|
readTimeout: {{ env "READ_TIMEOUT" }}
|
||||||
|
|||||||
Reference in New Issue
Block a user