Compare commits

..

6 Commits

Author SHA1 Message Date
fauno d0494ea4cc fix: don't generate the basic auth password 2026-07-28 19:34:44 -03:00
fauno f05ad93459 doc: anubis metrics 2026-07-28 19:34:37 -03:00
fauno b2b94baf78 feat: anubis metrics 2026-07-28 15:35:38 -03:00
renovate-bot 0ff4ef759b chore(deps): update ghcr.io/techarohq/anubis docker tag to v1.26.2 (#125)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/techarohq/anubis](https://images.chainguard.dev/directory/image/static/overview) ([source](https://github.com/chainguard-images/images/tree/HEAD/images/static)) | patch | `v1.26.0` -> `v1.26.2` |

>  **Important**
>
> Release Notes retrieval for this PR were skipped because no github.com credentials were available.
> If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes).

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: coop-cloud/traefik#125
Reviewed-by: d1 <2+decentral1se@noreply.git.coopcloud.tech>
Co-authored-by: Renovate Bot <renovate@coopcloud.tech>
Co-committed-by: Renovate Bot <renovate@coopcloud.tech>
2026-07-27 19:20:28 +00:00
renovate-bot e5229b9ad2 chore(deps): update traefik docker tag to v3.7.9 (#124)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [traefik](https://github.com/containous/traefik) | patch | `v3.7.8` -> `v3.7.9` |

>  **Important**
>
> Release Notes retrieval for this PR were skipped because no github.com credentials were available.
> If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes).

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: coop-cloud/traefik#124
Reviewed-by: p4u1 <133+p4u1@noreply.git.coopcloud.tech>
Reviewed-by: d1 <2+decentral1se@noreply.git.coopcloud.tech>
Co-authored-by: Renovate Bot <renovate@coopcloud.tech>
Co-committed-by: Renovate Bot <renovate@coopcloud.tech>
2026-07-25 09:27:16 +00:00
renovate-bot 8a73e4e21a chore(deps): update ghcr.io/techarohq/anubis docker tag to v1.26.0 (#123)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/techarohq/anubis](https://images.chainguard.dev/directory/image/static/overview) ([source](https://github.com/chainguard-images/images/tree/HEAD/images/static)) | minor | `v1.25.0` -> `v1.26.0` |

>  **Important**
>
> Release Notes retrieval for this PR were skipped because no github.com credentials were available.
> If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes).

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xNzMuMSIsInVwZGF0ZWRJblZlciI6IjQxLjE3My4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: coop-cloud/traefik#123
Reviewed-by: d1 <2+decentral1se@noreply.git.coopcloud.tech>
Co-authored-by: Renovate Bot <renovate@coopcloud.tech>
Co-committed-by: Renovate Bot <renovate@coopcloud.tech>
2026-07-25 07:29:58 +00:00
11 changed files with 50 additions and 128 deletions
+3 -5
View File
@@ -223,11 +223,9 @@ WRITE_TIMEOUT=0s
#ANUBIS_SERVE_ROBOTS_TXT=true
#ANUBIS_SLOG_LEVEL=INFO
## Crowdsec
#COMPOSE_FILE="$COMPOSE_FILE:compose.crowdsec.yml"
#CROWDSEC_ENABLED=1
#CROWDSEC_BOUNCER_ENABLED=1
#CROWDSEC_TRAEFIK_BOUNCER_API_KEY="some-api-key"
## Anubis metrics
#COMPOSE_FILE="$COMPOSE_FILE:compose.anubis-metrics.yml"
#SECRET_BASIC_AUTH_VERSION=v1 # generate=false
## Enable onion service support
#ONION_ENABLED=1
+4 -45
View File
@@ -72,51 +72,10 @@ After deploying these changes, go to each recipe that supports Anubis
and follow the process there. **Enabling Anubis here is not enough for
protection your apps.**
## Crowdsec
IMPORTANT even though Crowdsec is Open Source, the software sends information of the attacker IP and what decision(ban or captcha) to a centralized server for communit managed block lists.
On first deployment you need to generate an empty secret, because the lapi key is created at runtime.
```
abra app secret insert <domain> crowdsec_lapi_key v1
```
Then deploy your traefik recipe with the crowdsec compose and variables enabled and set `CROWDSEC_BOUNCER_ENABLED=0` to prevent initializing the bouncer that has no key yet.
When traefik is running, generate the LAPI key with the following command:
```
abra app run <domain> crowdsec cscli bouncers add crowdsecBouncer
```
After that insert the LAPI key(command below) and redeploy traefik with `CROWDSEC_BOUNCER_ENABLED=1` and `CROWDSEC_TRAEFIK_CONFIG_VERSION=v2`.
```
abra app secret insert <domain> crowdsec_lapi_key v2 -f -t <path-to/lapi-key-file>
```
When it is up and running go to the recipe you want to protect and add the following snippet and redeploy.
```
---
version: "3.8"
services:
app:
deploy:
labels:
- "traefik.http.routers.${STACK_NAME}.middlewares=crowdsec@file"
```
You can see if it is working by checking the ban list.
```
abra app run <domain> crowdsec cscli decisions list
```
When there are not bans yet you can try by banning your own IP.
```
abra app run <domain> crowdsec cscli decisions add --ip <your-ip> -d 10m # this will be effective 10min
```
Remove it with:
```
abra app run <domain> crowdsec cscli decisions remove --ip <your-ip> # this can still take a few minutes because of cache
```
If you want to collect Prometheus metrics for Anubis, for instance with
[monitoring-ng](/monitoring-ng), uncomment the "Anubis metrics" section
and insert the basic auth password as a secret. The username will be
"admin".
## Enabling onion service
+3 -3
View File
@@ -1,4 +1,4 @@
export TRAEFIK_YML_VERSION=v33
export FILE_PROVIDER_YML_VERSION=v15
export TRAEFIK_YML_VERSION=v32
export FILE_PROVIDER_YML_VERSION=v12
export ENTRYPOINT_VERSION=v5
export CROWDSEC_TRAEFIK_CONFIG_VERSION=v1
export ANUBIS_YML_VERSION=v1
+10
View File
@@ -0,0 +1,10 @@
bots:
- import: (data)/meta/default-config.yaml
{{ if eq (env "ANUBIS_METRICS_ENABLED") "true" }}
metrics:
bind: ":9090"
network: "tcp"
basicAuth:
username: "admin"
password: "{{ secret "basic_auth" }}"
{{ end }}
+18
View File
@@ -0,0 +1,18 @@
---
version: "3.8"
services:
anubis:
environment:
ANUBIS_METRICS_ENABLED: "true"
secrets:
- "basic_auth"
deploy:
labels:
- "prometheus.io/scrape=true"
- "prometheus.io/port=9090"
- "prometheus.io/path=/metrics"
- "prometheus.io/auth=basic"
secrets:
basic_auth:
external: true
name: "${STACK_NAME}_basic_auth_${SECRET_BASIC_AUTH_VERSION}"
+10 -1
View File
@@ -7,7 +7,7 @@ services:
- "traefik.http.middlewares.anubis.forwardauth.address=http://anubis:8080/.within.website/x/cmd/anubis/api/check"
- "traefik.http.middlewares.anubis.forwardauth.trustForwardHeader=true"
anubis:
image: "ghcr.io/techarohq/anubis:v1.25.0"
image: "ghcr.io/techarohq/anubis:v1.26.2"
environment:
BIND: ":8080"
TARGET: " "
@@ -19,6 +19,10 @@ services:
OG_CACHE_CONSIDER_HOST: "${ANUBIS_OG_CACHE_CONSIDER_HOST}"
SERVE_ROBOTS_TXT: "${ANUBIS_SERVE_ROBOTS_TXT}"
SLOG_LEVEL: "${ANUBIS_SLOG_LEVEL:-INFO}"
POLICY_FNAME: "/data/cfg/botPolicy.yaml"
configs:
- source: anubis_yml
target: /data/cfg/botPolicy.yaml
networks:
- proxy
deploy:
@@ -29,3 +33,8 @@ services:
- "traefik.http.routers.anubis.entrypoints=web-secure"
- "traefik.http.services.anubis.loadbalancer.server.port=8080"
- "traefik.http.routers.anubis.service=anubis"
configs:
anubis_yml:
name: ${STACK_NAME}_anubis_yml_${ANUBIS_YML_VERSION}
file: anubis.yml.tmpl
template_driver: golang
-42
View File
@@ -1,42 +0,0 @@
version: "3.8"
services:
app:
deploy:
labels:
- "traefik.http.routers.${STACK_NAME}.middlewares=crowdsec@file"
secrets:
- crowdsec_lapi_key
crowdsec:
image: crowdsecurity/crowdsec:v1.7.8
environment:
GID: "${GID-1000}"
COLLECTIONS: "crowdsecurity/linux crowdsecurity/traefik"
volumes:
- crowdsec-db:/var/lib/crowdsec/data/
- crowdsec-config:/etc/crowdsec/
- traefik-logs:/var/log/traefik/:ro
configs:
- source: crowdsec_traefik_config
target: /etc/crowdsec/acquis.d/traefik_config.yaml
mode: 0555
networks:
- internal
deploy:
update_config:
failure_action: rollback
order: stop-first
configs:
crowdsec_traefik_config:
name: ${STACK_NAME}_crowdsec_traefik_${CROWDSEC_TRAEFIK_CONFIG_VERSION}
file: crowdsec_traefik_config.yaml.tmpl
template_driver: golang
secrets:
crowdsec_lapi_key:
external: true
name: ${STACK_NAME}_crowdsec_lapi_key_${SECRET_CROWDSEC_LAPI_KEY_VERSION}
volumes:
crowdsec-db:
crowdsec-config:
+1 -3
View File
@@ -3,7 +3,7 @@ version: "3.8"
services:
app:
image: "traefik:v3.7.8"
image: "traefik:v3.7.9"
# Note(decentral1se): *please do not* add any additional ports here.
# Doing so could break new installs with port conflicts. Please use
# the usual `compose.$app.yml` approach for any additional ports
@@ -19,7 +19,6 @@ services:
volumes:
- "letsencrypt:/etc/letsencrypt"
- "file-providers:/etc/traefik/file-providers"
- "traefik-logs:/var/log/traefik"
configs:
- source: traefik_yml
target: /etc/traefik/traefik.yml
@@ -122,4 +121,3 @@ configs:
volumes:
letsencrypt:
file-providers:
traefik-logs:
-5
View File
@@ -1,5 +0,0 @@
filenames:
- /var/log/traefik/*
labels:
type: traefik
+1 -11
View File
@@ -22,16 +22,6 @@ http:
basicAuth:
usersFile: "/run/secrets/usersfile"
{{ end }}
{{ if eq (env "CROWDSEC_ENABLED") "1" }}
crowdsec:
plugin:
bouncer:
enabled: {{ if eq (env "CROWDSEC_BOUNCER_ENABLED") "1" }}true{{ else }}false{{ end }}
logLevel: DEBUG
crowdsecMode: live
crowdsecLapiKey: "{{ if eq (env "CROWDSEC_BOUNCER_ENABLED") "1" }}{{ secret "crowdsec_lapi_key" }}{{ else }}please_set_CROWDSEC_BOUNCER_ENABLED_to_1{{ end }}"
crowdsecLapiHost: crowdsec:8080
{{ end }}
security:
headers:
frameDeny: true
@@ -71,4 +61,4 @@ tls:
certificates:
- certFile: /run/secrets/ssl_cert
keyFile: /run/secrets/ssl_key
{{ end }}
{{ end }}
-13
View File
@@ -5,11 +5,6 @@ core:
log:
level: {{ env "LOG_LEVEL" }}
maxAge: {{ env "LOG_MAX_AGE" }}
{{- if eq (env "CROWDSEC_ENABLED") "1" }}
filePath: "/var/log/traefik/traefik.log"
accessLog:
filePath: "/var/log/traefik/access.log"
{{- end }}
providers:
swarm:
@@ -162,11 +157,3 @@ certificatesResolvers:
- "1.1.1.1:53"
- "9.9.9.9:53"
{{- end }}
{{ if eq (env "CROWDSEC_ENABLED") "1" }}
experimental:
plugins:
bouncer:
moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
version: v1.6.0
{{- end }}