Compare commits

..
Author SHA1 Message Date
fauno 99936080ae doc: trusted ips context
continuous-integration/drone/pr Build is failing
2026-08-25 18:08:28 -03:00
fauno 7610c9f4db feat: trusted ips
continuous-integration/drone/pr Build is failing
when traefik is behind a reverse proxy, we need to tell it which
networks to trust with x-real-ip headers
2026-08-25 16:46:35 -03:00
4 changed files with 14 additions and 2 deletions
+8
View File
@@ -235,3 +235,11 @@ WRITE_TIMEOUT=0s
## Access logs
#COMPOSE_FILE="$COMPOSE_FILE:compose.access-log.yml"
## Behind a reverse proxy
#
# YAML array of subnets from which Traefik's trusts the x-real-ip
# header when behind a reverse proxy.
#
# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-forwardedHeaders-trustedIPs
#TRUSTED_IPS="['10.13.12.1']" # 10.13.12.1 is an example
+1 -1
View File
@@ -1,4 +1,4 @@
export TRAEFIK_YML_VERSION=v33
export TRAEFIK_YML_VERSION=v34
export FILE_PROVIDER_YML_VERSION=v12
export ENTRYPOINT_VERSION=v5
export ANUBIS_YML_VERSION=v1
+1 -1
View File
@@ -62,7 +62,7 @@ services:
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
socket-proxy:
image: lscr.io/linuxserver/socket-proxy:3.4.4
image: lscr.io/linuxserver/socket-proxy:3.4.3
deploy:
endpoint_mode: dnsrr
environment:
+4
View File
@@ -48,6 +48,10 @@ entrypoints:
to: web-secure
web-secure:
address: ":443"
{{ if ne (env "TRUSTED_IPS") "" }}
forwardedHeaders:
trustedIPs: {{ env "TRUSTED_IPS" }}
{{ end }}
transport:
respondingTimeouts:
readTimeout: {{ env "READ_TIMEOUT" }}