forked from coop-cloud/traefik
Compare commits
15 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e34a0e909d | |||
| 4f1b71c8d6 | |||
| 37a73bb791 | |||
| 25c219f844 | |||
| ef0d154bb1 | |||
| adeaf5afa3 | |||
| ad8a7f1bd9 | |||
|
81869a049e
|
|||
| f47a200c0b | |||
| 693fa79449 | |||
| 928bc2104a | |||
| 92b7093e45 | |||
| b2b311fef4 | |||
| b39bb5adaf | |||
| 97a68f28ac |
+30
-14
@@ -15,6 +15,13 @@ LOG_MAX_AGE=1
|
|||||||
# This is here so later lines can extend it; you likely don't wanna edit
|
# This is here so later lines can extend it; you likely don't wanna edit
|
||||||
COMPOSE_FILE="compose.yml"
|
COMPOSE_FILE="compose.yml"
|
||||||
|
|
||||||
|
# Increase read timeout (or change it to 0s) to ensure large file
|
||||||
|
# uploads work.
|
||||||
|
#
|
||||||
|
# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-transport-respondingTimeouts-readTimeout
|
||||||
|
READ_TIMEOUT=60s
|
||||||
|
WRITE_TIMEOUT=0s
|
||||||
|
|
||||||
#####################################################################
|
#####################################################################
|
||||||
# General settings #
|
# General settings #
|
||||||
#####################################################################
|
#####################################################################
|
||||||
@@ -38,7 +45,7 @@ COMPOSE_FILE="compose.yml"
|
|||||||
## Enable dns challenge (for wildcard domains)
|
## Enable dns challenge (for wildcard domains)
|
||||||
## https://go-acme.github.io/lego/dns/#dns-providers
|
## https://go-acme.github.io/lego/dns/#dns-providers
|
||||||
#LETS_ENCRYPT_DNS_CHALLENGE_ENABLED=1
|
#LETS_ENCRYPT_DNS_CHALLENGE_ENABLED=1
|
||||||
## *Currently* one of ovh, gandi, gandiv5, digitalocean, azure, porkbun.
|
## *Currently* one of ovh, gandi, gandiv5, digitalocean, azure, porkbun, and cloudflare.
|
||||||
## Uncomment the corresponding provider below to insert your secret token/key.
|
## Uncomment the corresponding provider below to insert your secret token/key.
|
||||||
#LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER=ovh
|
#LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER=ovh
|
||||||
|
|
||||||
@@ -47,25 +54,25 @@ COMPOSE_FILE="compose.yml"
|
|||||||
#OVH_ENABLED=1
|
#OVH_ENABLED=1
|
||||||
#OVH_APPLICATION_KEY=
|
#OVH_APPLICATION_KEY=
|
||||||
#OVH_ENDPOINT=
|
#OVH_ENDPOINT=
|
||||||
#SECRET_OVH_APP_SECRET_VERSION=v1
|
#SECRET_OVH_APP_SECRET_VERSION=v1 # generate=false
|
||||||
#SECRET_OVH_CONSUMER_KEY=v1
|
#SECRET_OVH_CONSUMER_KEY=v1 # generate=false
|
||||||
|
|
||||||
## Gandi, https://gandi.net
|
## Gandi, https://gandi.net
|
||||||
## note(3wc): only "V5" (new) API is supported, so far
|
## note(3wc): only "V5" (new) API is supported, so far
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-api-key.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-api-key.yml"
|
||||||
#GANDI_API_KEY_ENABLED=1
|
#GANDI_API_KEY_ENABLED=1
|
||||||
#SECRET_GANDIV5_API_KEY_VERSION=v1
|
#SECRET_GANDIV5_API_KEY_VERSION=v1 # generate=false
|
||||||
|
|
||||||
## Gandi, https://gandi.net
|
## Gandi, https://gandi.net
|
||||||
## note: uses GandiV5 Personal Access Token
|
## note: uses GandiV5 Personal Access Token
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-personal-access-token.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-personal-access-token.yml"
|
||||||
#GANDI_PERSONAL_ACCESS_TOKEN_ENABLED=1
|
#GANDI_PERSONAL_ACCESS_TOKEN_ENABLED=1
|
||||||
#SECRET_GANDIV5_PERSONAL_ACCESS_TOKEN_VERSION=v1
|
#SECRET_GANDIV5_PERSONAL_ACCESS_TOKEN_VERSION=v1 # generate=false
|
||||||
|
|
||||||
## DigitalOcean, https://digitalocean.com
|
## DigitalOcean, https://digitalocean.com
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.digitalocean.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.digitalocean.yml"
|
||||||
#DIGITALOCEAN_ENABLED=1
|
#DIGITALOCEAN_ENABLED=1
|
||||||
#SECRET_DIGITALOCEAN_AUTH_TOKEN_VERSION=v1
|
#SECRET_DIGITALOCEAN_AUTH_TOKEN_VERSION=v1 # generate=false
|
||||||
|
|
||||||
## Azure, https://azure.com
|
## Azure, https://azure.com
|
||||||
## To insert your Azure client secret:
|
## To insert your Azure client secret:
|
||||||
@@ -76,24 +83,26 @@ COMPOSE_FILE="compose.yml"
|
|||||||
#AZURE_CLIENT_ID=
|
#AZURE_CLIENT_ID=
|
||||||
#AZURE_SUBSCRIPTION_ID=
|
#AZURE_SUBSCRIPTION_ID=
|
||||||
#AZURE_RESOURCE_GROUP=
|
#AZURE_RESOURCE_GROUP=
|
||||||
#SECRET_AZURE_SECRET_VERSION=v1
|
#SECRET_AZURE_SECRET_VERSION=v1 # generate=false
|
||||||
|
|
||||||
## Porkbun, https://porkbun.com
|
## Porkbun, https://porkbun.com
|
||||||
## To insert your secrets:
|
## To insert your secrets:
|
||||||
## abra app secret insert 1312.net pb_api_key v1 pk1_413
|
## abra app secret insert 1312.net pb_api_key v1 pk1_413
|
||||||
## abra app secret insert 1312.net pb_s_api_key v1 sk1_612
|
## abra app secret insert 1312.net pb_s_api_key v1 sk1_612
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.porkbun.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.porkbun.yml"
|
||||||
#SECRET_PORKBUN_API_KEY_VERSION=v1
|
#SECRET_PORKBUN_API_KEY_VERSION=v1 # generate=false
|
||||||
#SECRET_PORKBUN_SECRET_API_KEY_VERSION=v1
|
#SECRET_PORKBUN_SECRET_API_KEY_VERSION=v1 # generate=false
|
||||||
|
|
||||||
## Cloudflare, htps://cloudflare.com
|
## Cloudflare, htps://cloudflare.com
|
||||||
## To insert your secrets:
|
## To insert your secrets:
|
||||||
## abra app secret insert {myapp.example.coop} cf_email v1 "<CLOUDFLARE_EMAIL>"
|
## abra app secret insert {myapp.example.coop} cf_dns_token v1 "<CLOUDFLARE_DNS_API_TOKEN>"
|
||||||
## abra app secret insert {myapp.example.coop} cf_api_key v1 "<CLOUDFLARE_API_KEY>"
|
## abra app secret insert {myapp.example.coop} cf_zone_token v1 "<CLOUDFLARE_ZONE_API_TOKEN>"
|
||||||
## cf_api_key is an account API key from Cloudflare that has DNS read + edit permission
|
## These can be the same token or different tokens
|
||||||
|
## cf_dns_token needs DNS edit access, cf_zone_token needs zone edit access
|
||||||
|
## See LEGO docs for more info: https://go-acme.github.io/lego/dns/cloudflare/index.html
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.cloudflare.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.cloudflare.yml"
|
||||||
#SECRET_CLOUDFLARE_EMAIL_VERSION=v1 # generate=false
|
#SECRET_CLOUDFLARE_DNS_API_TOKEN_VERSION=v1 # generate=false
|
||||||
#SECRET_CLOUDFLARE_API_KEY_VERSION=v1 # generate=false
|
#SECRET_CLOUDFLARE_ZONE_API_TOKEN_VERSION=v1 # generate=false
|
||||||
|
|
||||||
#####################################################################
|
#####################################################################
|
||||||
# Manual wildcard certificate insertion #
|
# Manual wildcard certificate insertion #
|
||||||
@@ -212,6 +221,13 @@ COMPOSE_FILE="compose.yml"
|
|||||||
#ANUBIS_OG_EXPIRY_TIME=1h
|
#ANUBIS_OG_EXPIRY_TIME=1h
|
||||||
#ANUBIS_OG_CACHE_CONSIDER_HOST=true
|
#ANUBIS_OG_CACHE_CONSIDER_HOST=true
|
||||||
#ANUBIS_SERVE_ROBOTS_TXT=true
|
#ANUBIS_SERVE_ROBOTS_TXT=true
|
||||||
|
#ANUBIS_SLOG_LEVEL=INFO
|
||||||
|
|
||||||
|
## Crowdsec
|
||||||
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.crowdsec.yml"
|
||||||
|
#CROWDSEC_ENABLED=1
|
||||||
|
#CROWDSEC_BOUNCER_ENABLED=1
|
||||||
|
#CROWDSEC_TRAEFIK_BOUNCER_API_KEY="some-api-key"
|
||||||
|
|
||||||
## Enable onion service support
|
## Enable onion service support
|
||||||
#ONION_ENABLED=1
|
#ONION_ENABLED=1
|
||||||
|
|||||||
@@ -32,15 +32,16 @@
|
|||||||
3. Insert the secret: `abra app secret insert <domain> usersfile v1 -f usersfile
|
3. Insert the secret: `abra app secret insert <domain> usersfile v1 -f usersfile
|
||||||
4. Redploy your app: `abra app deploy -f <domain>`
|
4. Redploy your app: `abra app deploy -f <domain>`
|
||||||
|
|
||||||
## Configuring wildcard SSL using DNS
|
## Configuring SSL using DNS
|
||||||
|
|
||||||
Automatic certificate generation will Just Work™ for most recipes which use a fixed
|
Automatic certificate generation will Just Work™ for most recipes which use a
|
||||||
number of subdomains. For some recipes which need to work across arbitrary
|
fixed number of subdomains. If your server can't be reached from the Internet,
|
||||||
|
or if you're deploying a recipe that needs to work across arbitrary
|
||||||
subdomains, like
|
subdomains, like
|
||||||
[`federatedwiki`](https://git.coopcloud.tech/coop-cloud/federatedwiki/) and
|
[`federatedwiki`](https://git.coopcloud.tech/coop-cloud/federatedwiki/) and
|
||||||
[`go-ssb-room`](https://git.coopcloud.tech/coop-cloud/federatedwiki/), you'll
|
[`go-ssb-room`](https://git.coopcloud.tech/coop-cloud/federatedwiki/) (requiring
|
||||||
need to give Traefik access to your DNS provider so that it can carry out
|
the use of wildcard certificates,) you can give Traefik access to your DNS provider
|
||||||
Letsencrypt DNS challenges.
|
so that it can carry out Letsencrypt DNS challenges.
|
||||||
|
|
||||||
1. Use Gandi, OVH, DO, Azure, or PorkBun for DNS 🤡 (support for other providers
|
1. Use Gandi, OVH, DO, Azure, or PorkBun for DNS 🤡 (support for other providers
|
||||||
can be easily added, see
|
can be easily added, see
|
||||||
@@ -71,6 +72,52 @@ After deploying these changes, go to each recipe that supports Anubis
|
|||||||
and follow the process there. **Enabling Anubis here is not enough for
|
and follow the process there. **Enabling Anubis here is not enough for
|
||||||
protection your apps.**
|
protection your apps.**
|
||||||
|
|
||||||
|
## Crowdsec
|
||||||
|
|
||||||
|
IMPORTANT even though Crowdsec is Open Source, the software sends information of the attacker IP and what decision(ban or captcha) to a centralized server for communit managed block lists.
|
||||||
|
|
||||||
|
On first deployment you need to generate an empty secret, because the lapi key is created at runtime.
|
||||||
|
```
|
||||||
|
abra app secret insert <domain> crowdsec_lapi_key v1
|
||||||
|
```
|
||||||
|
|
||||||
|
Then deploy your traefik recipe with the crowdsec compose and variables enabled and set `CROWDSEC_BOUNCER_ENABLED=0` to prevent initializing the bouncer that has no key yet.
|
||||||
|
|
||||||
|
When traefik is running, generate the LAPI key with the following command:
|
||||||
|
```
|
||||||
|
abra app run <domain> crowdsec cscli bouncers add crowdsecBouncer
|
||||||
|
```
|
||||||
|
|
||||||
|
After that insert the LAPI key(command below) and redeploy traefik with `CROWDSEC_BOUNCER_ENABLED=1` and `CROWDSEC_TRAEFIK_CONFIG_VERSION=v2`.
|
||||||
|
```
|
||||||
|
abra app secret insert <domain> crowdsec_lapi_key v2 -f -t <path-to/lapi-key-file>
|
||||||
|
```
|
||||||
|
|
||||||
|
When it is up and running go to the recipe you want to protect and add the following snippet and redeploy.
|
||||||
|
```
|
||||||
|
---
|
||||||
|
version: "3.8"
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
deploy:
|
||||||
|
labels:
|
||||||
|
- "traefik.http.routers.${STACK_NAME}.middlewares=crowdsec@file"
|
||||||
|
```
|
||||||
|
|
||||||
|
You can see if it is working by checking the ban list.
|
||||||
|
```
|
||||||
|
abra app run <domain> crowdsec cscli decisions list
|
||||||
|
```
|
||||||
|
|
||||||
|
When there are not bans yet you can try by banning your own IP.
|
||||||
|
```
|
||||||
|
abra app run <domain> crowdsec cscli decisions add --ip <your-ip> -d 10m # this will be effective 10min
|
||||||
|
```
|
||||||
|
Remove it with:
|
||||||
|
```
|
||||||
|
abra app run <domain> crowdsec cscli decisions remove --ip <your-ip> # this can still take a few minutes because of cache
|
||||||
|
```
|
||||||
|
|
||||||
## Enabling onion service
|
## Enabling onion service
|
||||||
|
|
||||||
Uncomment the line in the config setting `ONION_ENABLED=1`. This will create a new entrypoint on port 9052 which can be used to bypass forced SSL. For more details, see the [onion recipe](https://recipes.coopcloud.tech/onion).
|
Uncomment the line in the config setting `ONION_ENABLED=1`. This will create a new entrypoint on port 9052 which can be used to bypass forced SSL. For more details, see the [onion recipe](https://recipes.coopcloud.tech/onion).
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
export TRAEFIK_YML_VERSION=v30
|
export TRAEFIK_YML_VERSION=v33
|
||||||
export FILE_PROVIDER_YML_VERSION=v12
|
export FILE_PROVIDER_YML_VERSION=v15
|
||||||
export ENTRYPOINT_VERSION=v5
|
export ENTRYPOINT_VERSION=v5
|
||||||
|
export CROWDSEC_TRAEFIK_CONFIG_VERSION=v1
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ services:
|
|||||||
deploy:
|
deploy:
|
||||||
labels:
|
labels:
|
||||||
- "traefik.http.middlewares.anubis.forwardauth.address=http://anubis:8080/.within.website/x/cmd/anubis/api/check"
|
- "traefik.http.middlewares.anubis.forwardauth.address=http://anubis:8080/.within.website/x/cmd/anubis/api/check"
|
||||||
|
- "traefik.http.middlewares.anubis.forwardauth.trustForwardHeader=true"
|
||||||
anubis:
|
anubis:
|
||||||
image: "ghcr.io/techarohq/anubis:v1.25.0"
|
image: "ghcr.io/techarohq/anubis:v1.25.0"
|
||||||
environment:
|
environment:
|
||||||
@@ -17,6 +18,7 @@ services:
|
|||||||
OG_EXPIRY_TIME: "${ANUBIS_OG_EXPIRY_TIME}"
|
OG_EXPIRY_TIME: "${ANUBIS_OG_EXPIRY_TIME}"
|
||||||
OG_CACHE_CONSIDER_HOST: "${ANUBIS_OG_CACHE_CONSIDER_HOST}"
|
OG_CACHE_CONSIDER_HOST: "${ANUBIS_OG_CACHE_CONSIDER_HOST}"
|
||||||
SERVE_ROBOTS_TXT: "${ANUBIS_SERVE_ROBOTS_TXT}"
|
SERVE_ROBOTS_TXT: "${ANUBIS_SERVE_ROBOTS_TXT}"
|
||||||
|
SLOG_LEVEL: "${ANUBIS_SLOG_LEVEL:-INFO}"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
deploy:
|
deploy:
|
||||||
|
|||||||
@@ -3,16 +3,16 @@ version: "3.8"
|
|||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
environment:
|
environment:
|
||||||
- CLOUDFLARE_EMAIL_FILE=/run/secrets/cf_email
|
- CLOUDFLARE_DNS_API_TOKEN_FILE=/run/secrets/cf_dns_token
|
||||||
- CLOUDFLARE_API_KEY_FILE=/run/secrets/cf_api_key
|
- CLOUDFLARE_ZONE_API_TOKEN_FILE=/run/secrets/cf_zone_token
|
||||||
secrets:
|
secrets:
|
||||||
- cf_email
|
- cf_dns_token
|
||||||
- cf_api_key
|
- cf_zone_token
|
||||||
|
|
||||||
secrets:
|
secrets:
|
||||||
cf_email:
|
cf_dns_token:
|
||||||
name: ${STACK_NAME}_cf_email_${SECRET_CLOUDFLARE_EMAIL_VERSION}
|
name: ${STACK_NAME}_cf_dns_token_${SECRET_CLOUDFLARE_DNS_API_TOKEN_VERSION}
|
||||||
external: true
|
external: true
|
||||||
cf_api_key:
|
cf_zone_token:
|
||||||
name: ${STACK_NAME}_cf_api_key_${SECRET_CLOUDFLARE_API_KEY_VERSION}
|
name: ${STACK_NAME}_cf_zone_token_${SECRET_CLOUDFLARE_ZONE_API_TOKEN_VERSION}
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -0,0 +1,42 @@
|
|||||||
|
version: "3.8"
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
deploy:
|
||||||
|
labels:
|
||||||
|
- "traefik.http.routers.${STACK_NAME}.middlewares=crowdsec@file"
|
||||||
|
secrets:
|
||||||
|
- crowdsec_lapi_key
|
||||||
|
crowdsec:
|
||||||
|
image: crowdsecurity/crowdsec:v1.7.8
|
||||||
|
environment:
|
||||||
|
GID: "${GID-1000}"
|
||||||
|
COLLECTIONS: "crowdsecurity/linux crowdsecurity/traefik"
|
||||||
|
volumes:
|
||||||
|
- crowdsec-db:/var/lib/crowdsec/data/
|
||||||
|
- crowdsec-config:/etc/crowdsec/
|
||||||
|
- traefik-logs:/var/log/traefik/:ro
|
||||||
|
configs:
|
||||||
|
- source: crowdsec_traefik_config
|
||||||
|
target: /etc/crowdsec/acquis.d/traefik_config.yaml
|
||||||
|
mode: 0555
|
||||||
|
networks:
|
||||||
|
- internal
|
||||||
|
deploy:
|
||||||
|
update_config:
|
||||||
|
failure_action: rollback
|
||||||
|
order: stop-first
|
||||||
|
|
||||||
|
configs:
|
||||||
|
crowdsec_traefik_config:
|
||||||
|
name: ${STACK_NAME}_crowdsec_traefik_${CROWDSEC_TRAEFIK_CONFIG_VERSION}
|
||||||
|
file: crowdsec_traefik_config.yaml.tmpl
|
||||||
|
template_driver: golang
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
crowdsec_lapi_key:
|
||||||
|
external: true
|
||||||
|
name: ${STACK_NAME}_crowdsec_lapi_key_${SECRET_CROWDSEC_LAPI_KEY_VERSION}
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
crowdsec-db:
|
||||||
|
crowdsec-config:
|
||||||
+8
-3
@@ -3,7 +3,7 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
image: "traefik:v3.6.15"
|
image: "traefik:v3.7.8"
|
||||||
# Note(decentral1se): *please do not* add any additional ports here.
|
# Note(decentral1se): *please do not* add any additional ports here.
|
||||||
# Doing so could break new installs with port conflicts. Please use
|
# Doing so could break new installs with port conflicts. Please use
|
||||||
# the usual `compose.$app.yml` approach for any additional ports
|
# the usual `compose.$app.yml` approach for any additional ports
|
||||||
@@ -19,6 +19,7 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
- "letsencrypt:/etc/letsencrypt"
|
- "letsencrypt:/etc/letsencrypt"
|
||||||
- "file-providers:/etc/traefik/file-providers"
|
- "file-providers:/etc/traefik/file-providers"
|
||||||
|
- "traefik-logs:/var/log/traefik"
|
||||||
configs:
|
configs:
|
||||||
- source: traefik_yml
|
- source: traefik_yml
|
||||||
target: /etc/traefik/traefik.yml
|
target: /etc/traefik/traefik.yml
|
||||||
@@ -34,6 +35,8 @@ services:
|
|||||||
- DASHBOARD_ENABLED
|
- DASHBOARD_ENABLED
|
||||||
- LOG_LEVEL
|
- LOG_LEVEL
|
||||||
- ${LOG_MAX_AGE:-0}
|
- ${LOG_MAX_AGE:-0}
|
||||||
|
- READ_TIMEOUT=${READ_TIMEOUT:-60s}
|
||||||
|
- WRITE_TIMEOUT=${WRITE_TIMEOUT:-0s}
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "traefik", "healthcheck"]
|
test: ["CMD", "traefik", "healthcheck"]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
@@ -55,12 +58,12 @@ services:
|
|||||||
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||||
- "traefik.http.routers.${STACK_NAME}.service=api@internal"
|
- "traefik.http.routers.${STACK_NAME}.service=api@internal"
|
||||||
- "traefik.http.routers.${STACK_NAME}.middlewares=security@file"
|
- "traefik.http.routers.${STACK_NAME}.middlewares=security@file"
|
||||||
- "coop-cloud.${STACK_NAME}.version=5.1.1+v3.6.15"
|
- "coop-cloud.${STACK_NAME}.version=6.0.0+v3.7.7"
|
||||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
||||||
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
||||||
|
|
||||||
socket-proxy:
|
socket-proxy:
|
||||||
image: lscr.io/linuxserver/socket-proxy:3.2.19
|
image: lscr.io/linuxserver/socket-proxy:3.4.2
|
||||||
deploy:
|
deploy:
|
||||||
endpoint_mode: dnsrr
|
endpoint_mode: dnsrr
|
||||||
environment:
|
environment:
|
||||||
@@ -91,6 +94,7 @@ services:
|
|||||||
- TASKS=1 # Needs access
|
- TASKS=1 # Needs access
|
||||||
- VERSION=1 # Needs access
|
- VERSION=1 # Needs access
|
||||||
- VOLUMES=0
|
- VOLUMES=0
|
||||||
|
- LOG_LEVEL=warning
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
networks:
|
networks:
|
||||||
@@ -118,3 +122,4 @@ configs:
|
|||||||
volumes:
|
volumes:
|
||||||
letsencrypt:
|
letsencrypt:
|
||||||
file-providers:
|
file-providers:
|
||||||
|
traefik-logs:
|
||||||
|
|||||||
@@ -0,0 +1,5 @@
|
|||||||
|
filenames:
|
||||||
|
- /var/log/traefik/*
|
||||||
|
labels:
|
||||||
|
type: traefik
|
||||||
|
|
||||||
@@ -22,6 +22,16 @@ http:
|
|||||||
basicAuth:
|
basicAuth:
|
||||||
usersFile: "/run/secrets/usersfile"
|
usersFile: "/run/secrets/usersfile"
|
||||||
{{ end }}
|
{{ end }}
|
||||||
|
{{ if eq (env "CROWDSEC_ENABLED") "1" }}
|
||||||
|
crowdsec:
|
||||||
|
plugin:
|
||||||
|
bouncer:
|
||||||
|
enabled: {{ if eq (env "CROWDSEC_BOUNCER_ENABLED") "1" }}true{{ else }}false{{ end }}
|
||||||
|
logLevel: DEBUG
|
||||||
|
crowdsecMode: live
|
||||||
|
crowdsecLapiKey: "{{ if eq (env "CROWDSEC_BOUNCER_ENABLED") "1" }}{{ secret "crowdsec_lapi_key" }}{{ else }}please_set_CROWDSEC_BOUNCER_ENABLED_to_1{{ end }}"
|
||||||
|
crowdsecLapiHost: crowdsec:8080
|
||||||
|
{{ end }}
|
||||||
security:
|
security:
|
||||||
headers:
|
headers:
|
||||||
frameDeny: true
|
frameDeny: true
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
!Breaking: Starting with v3.6.16, the Docker provider requires Docker API version v1.40 or above (Docker Engine v19.03). Users running older (end of life) versions of Docker Engine should update their Docker Engine or use the DOCKER_API_VERSION environment variable to override the API version used by Traefik.
|
||||||
|
|
||||||
|
letsencrypt: Avoid HTTP-01 challenge if `LETS_ENCRYPT_DNS_CHALLENGE_ENABLED` is set, in order to rely on DNS-01 challenges for servers not exposed to the internet.
|
||||||
|
|
||||||
|
matrix-federation: Entrypoint was changed to :8448 to match published port
|
||||||
|
|
||||||
|
fix: ensure large uploads work. You can now set the following env vars:
|
||||||
|
- READ_TIMEOUT
|
||||||
|
- WRITE_TIMEOUT
|
||||||
|
|
||||||
|
cloudflare: Add Cloudflare as DNS provider
|
||||||
|
|
||||||
|
For more information take a look at the migration guide: https://doc.traefik.io/traefik/v3.7/migrate/v3/#v377
|
||||||
+22
-1
@@ -5,6 +5,11 @@ core:
|
|||||||
log:
|
log:
|
||||||
level: {{ env "LOG_LEVEL" }}
|
level: {{ env "LOG_LEVEL" }}
|
||||||
maxAge: {{ env "LOG_MAX_AGE" }}
|
maxAge: {{ env "LOG_MAX_AGE" }}
|
||||||
|
{{- if eq (env "CROWDSEC_ENABLED") "1" }}
|
||||||
|
filePath: "/var/log/traefik/traefik.log"
|
||||||
|
accessLog:
|
||||||
|
filePath: "/var/log/traefik/access.log"
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
providers:
|
providers:
|
||||||
swarm:
|
swarm:
|
||||||
@@ -33,6 +38,10 @@ entrypoints:
|
|||||||
to: web-secure
|
to: web-secure
|
||||||
web-secure:
|
web-secure:
|
||||||
address: ":443"
|
address: ":443"
|
||||||
|
transport:
|
||||||
|
respondingTimeouts:
|
||||||
|
readTimeout: {{ env "READ_TIMEOUT" }}
|
||||||
|
writeTimeout: {{ env "WRITE_TIMEOUT" }}
|
||||||
http:
|
http:
|
||||||
encodedCharacters:
|
encodedCharacters:
|
||||||
allowEncodedSlash: true
|
allowEncodedSlash: true
|
||||||
@@ -96,7 +105,7 @@ entrypoints:
|
|||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if eq (env "MATRIX_FEDERATION_ENABLED") "1" }}
|
{{- if eq (env "MATRIX_FEDERATION_ENABLED") "1" }}
|
||||||
matrix-federation:
|
matrix-federation:
|
||||||
address: ":9001"
|
address: ":8448"
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if eq (env "NEXTCLOUD_TALK_HPB_ENABLED") "1" }}
|
{{- if eq (env "NEXTCLOUD_TALK_HPB_ENABLED") "1" }}
|
||||||
nextcloud-talk-hpb:
|
nextcloud-talk-hpb:
|
||||||
@@ -127,8 +136,10 @@ certificatesResolvers:
|
|||||||
email: {{ env "LETS_ENCRYPT_EMAIL" }}
|
email: {{ env "LETS_ENCRYPT_EMAIL" }}
|
||||||
storage: /etc/letsencrypt/staging-acme.json
|
storage: /etc/letsencrypt/staging-acme.json
|
||||||
caServer: "https://acme-staging-v02.api.letsencrypt.org/directory"
|
caServer: "https://acme-staging-v02.api.letsencrypt.org/directory"
|
||||||
|
{{- if ne (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
||||||
httpChallenge:
|
httpChallenge:
|
||||||
entryPoint: web
|
entryPoint: web
|
||||||
|
{{- end }}
|
||||||
{{- if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
{{- if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
||||||
dnsChallenge:
|
dnsChallenge:
|
||||||
provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }}
|
provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }}
|
||||||
@@ -140,8 +151,10 @@ certificatesResolvers:
|
|||||||
acme:
|
acme:
|
||||||
email: {{ env "LETS_ENCRYPT_EMAIL" }}
|
email: {{ env "LETS_ENCRYPT_EMAIL" }}
|
||||||
storage: /etc/letsencrypt/production-acme.json
|
storage: /etc/letsencrypt/production-acme.json
|
||||||
|
{{- if ne (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
||||||
httpChallenge:
|
httpChallenge:
|
||||||
entryPoint: web
|
entryPoint: web
|
||||||
|
{{- end }}
|
||||||
{{- if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
{{- if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
||||||
dnsChallenge:
|
dnsChallenge:
|
||||||
provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }}
|
provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }}
|
||||||
@@ -149,3 +162,11 @@ certificatesResolvers:
|
|||||||
- "1.1.1.1:53"
|
- "1.1.1.1:53"
|
||||||
- "9.9.9.9:53"
|
- "9.9.9.9:53"
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|
||||||
|
{{ if eq (env "CROWDSEC_ENABLED") "1" }}
|
||||||
|
experimental:
|
||||||
|
plugins:
|
||||||
|
bouncer:
|
||||||
|
moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
|
||||||
|
version: v1.6.0
|
||||||
|
{{- end }}
|
||||||
|
|||||||
Reference in New Issue
Block a user