forked from coop-cloud/traefik
Compare commits
63 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e34a0e909d | |||
| 4f1b71c8d6 | |||
| 37a73bb791 | |||
| 25c219f844 | |||
| ef0d154bb1 | |||
| adeaf5afa3 | |||
| ad8a7f1bd9 | |||
|
81869a049e
|
|||
| f47a200c0b | |||
| 693fa79449 | |||
| 928bc2104a | |||
| 92b7093e45 | |||
| b2b311fef4 | |||
| b39bb5adaf | |||
| 97a68f28ac | |||
| 6e67d0c8c0 | |||
| 25cf7862ed | |||
| 7fc2cac6ff | |||
| 005f0235c0 | |||
|
7c6dd3f5a5
|
|||
| 440a7f5228 | |||
|
74193326fb
|
|||
| 57a6aed540 | |||
| ff138864d4 | |||
|
7370ecfa9d
|
|||
|
57e5c49c81
|
|||
| 063d194119 | |||
| 9a46c85735 | |||
| 08669fcd60 | |||
| bac3f30609 | |||
| 1fb6925846 | |||
| d164d2870e | |||
| 795592ea3c | |||
| b67ed0ca88 | |||
| 5f977f1cca | |||
| ee344cce5d | |||
| 27cc7efb72 | |||
|
324933a9cc
|
|||
| dc3e50838f | |||
| d59f6e0302 | |||
| c2cdfd80b6 | |||
| 139202fa9c | |||
| de7989f3ca | |||
| d3bf1bce24 | |||
| 1ce9d9ca72 | |||
| a233438f80 | |||
|
ed257bd0b2
|
|||
| 7dd833dbec | |||
| d5f19d3b11 | |||
|
f16f434877
|
|||
| 5d656ccb72 | |||
| fa55efb0c3 | |||
| 98fe0de193 | |||
| 0238b73f77 | |||
| 5df55f7833 | |||
| 92650aa12a | |||
| 0e38a772e9 | |||
| f469a1a90e | |||
| 0d85f97200 | |||
| ac33efe73a | |||
| a135d170bb | |||
| fa7cf3e17b | |||
| d05c81b4d7 |
+67
-11
@@ -1,5 +1,5 @@
|
|||||||
TYPE=traefik
|
TYPE=traefik
|
||||||
TIMEOUT=300
|
#TIMEOUT=300
|
||||||
ENABLE_AUTO_UPDATE=true
|
ENABLE_AUTO_UPDATE=true
|
||||||
ENABLE_BACKUPS=true
|
ENABLE_BACKUPS=true
|
||||||
|
|
||||||
@@ -15,12 +15,25 @@ LOG_MAX_AGE=1
|
|||||||
# This is here so later lines can extend it; you likely don't wanna edit
|
# This is here so later lines can extend it; you likely don't wanna edit
|
||||||
COMPOSE_FILE="compose.yml"
|
COMPOSE_FILE="compose.yml"
|
||||||
|
|
||||||
|
# Increase read timeout (or change it to 0s) to ensure large file
|
||||||
|
# uploads work.
|
||||||
|
#
|
||||||
|
# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-transport-respondingTimeouts-readTimeout
|
||||||
|
READ_TIMEOUT=60s
|
||||||
|
WRITE_TIMEOUT=0s
|
||||||
|
|
||||||
#####################################################################
|
#####################################################################
|
||||||
# General settings #
|
# General settings #
|
||||||
#####################################################################
|
#####################################################################
|
||||||
|
|
||||||
## Host-mode networking
|
## Ingress-mode port publishing for ports 80 and 443
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.host.yml"
|
##
|
||||||
|
## /!\ Using this prevents the use of any compose override adding
|
||||||
|
## published ports to the traefik_app service (almost all of them)
|
||||||
|
## and it prevents the use of IPv6 for ingress traffic.
|
||||||
|
## Do not uncomment unless you know exactly what you are doing
|
||||||
|
##
|
||||||
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.no-host.yml"
|
||||||
|
|
||||||
## "Headless mode" (no domain configured)
|
## "Headless mode" (no domain configured)
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.headless.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.headless.yml"
|
||||||
@@ -30,8 +43,10 @@ COMPOSE_FILE="compose.yml"
|
|||||||
#####################################################################
|
#####################################################################
|
||||||
|
|
||||||
## Enable dns challenge (for wildcard domains)
|
## Enable dns challenge (for wildcard domains)
|
||||||
## https://doc.traefik.io/traefik/https/acme/#dnschallenge
|
## https://go-acme.github.io/lego/dns/#dns-providers
|
||||||
#LETS_ENCRYPT_DNS_CHALLENGE_ENABLED=1
|
#LETS_ENCRYPT_DNS_CHALLENGE_ENABLED=1
|
||||||
|
## *Currently* one of ovh, gandi, gandiv5, digitalocean, azure, porkbun, and cloudflare.
|
||||||
|
## Uncomment the corresponding provider below to insert your secret token/key.
|
||||||
#LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER=ovh
|
#LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER=ovh
|
||||||
|
|
||||||
## OVH, https://ovh.com
|
## OVH, https://ovh.com
|
||||||
@@ -39,25 +54,25 @@ COMPOSE_FILE="compose.yml"
|
|||||||
#OVH_ENABLED=1
|
#OVH_ENABLED=1
|
||||||
#OVH_APPLICATION_KEY=
|
#OVH_APPLICATION_KEY=
|
||||||
#OVH_ENDPOINT=
|
#OVH_ENDPOINT=
|
||||||
#SECRET_OVH_APP_SECRET_VERSION=v1
|
#SECRET_OVH_APP_SECRET_VERSION=v1 # generate=false
|
||||||
#SECRET_OVH_CONSUMER_KEY=v1
|
#SECRET_OVH_CONSUMER_KEY=v1 # generate=false
|
||||||
|
|
||||||
## Gandi, https://gandi.net
|
## Gandi, https://gandi.net
|
||||||
## note(3wc): only "V5" (new) API is supported, so far
|
## note(3wc): only "V5" (new) API is supported, so far
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-api-key.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-api-key.yml"
|
||||||
#GANDI_API_KEY_ENABLED=1
|
#GANDI_API_KEY_ENABLED=1
|
||||||
#SECRET_GANDIV5_API_KEY_VERSION=v1
|
#SECRET_GANDIV5_API_KEY_VERSION=v1 # generate=false
|
||||||
|
|
||||||
## Gandi, https://gandi.net
|
## Gandi, https://gandi.net
|
||||||
## note: uses GandiV5 Personal Access Token
|
## note: uses GandiV5 Personal Access Token
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-personal-access-token.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-personal-access-token.yml"
|
||||||
#GANDI_PERSONAL_ACCESS_TOKEN_ENABLED=1
|
#GANDI_PERSONAL_ACCESS_TOKEN_ENABLED=1
|
||||||
#SECRET_GANDIV5_PERSONAL_ACCESS_TOKEN_VERSION=v1
|
#SECRET_GANDIV5_PERSONAL_ACCESS_TOKEN_VERSION=v1 # generate=false
|
||||||
|
|
||||||
## DigitalOcean, https://digitalocean.com
|
## DigitalOcean, https://digitalocean.com
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.digitalocean.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.digitalocean.yml"
|
||||||
#DIGITALOCEAN_ENABLED=1
|
#DIGITALOCEAN_ENABLED=1
|
||||||
#SECRET_DIGITALOCEAN_AUTH_TOKEN_VERSION=v1
|
#SECRET_DIGITALOCEAN_AUTH_TOKEN_VERSION=v1 # generate=false
|
||||||
|
|
||||||
## Azure, https://azure.com
|
## Azure, https://azure.com
|
||||||
## To insert your Azure client secret:
|
## To insert your Azure client secret:
|
||||||
@@ -68,7 +83,26 @@ COMPOSE_FILE="compose.yml"
|
|||||||
#AZURE_CLIENT_ID=
|
#AZURE_CLIENT_ID=
|
||||||
#AZURE_SUBSCRIPTION_ID=
|
#AZURE_SUBSCRIPTION_ID=
|
||||||
#AZURE_RESOURCE_GROUP=
|
#AZURE_RESOURCE_GROUP=
|
||||||
#SECRET_AZURE_SECRET_VERSION=v1
|
#SECRET_AZURE_SECRET_VERSION=v1 # generate=false
|
||||||
|
|
||||||
|
## Porkbun, https://porkbun.com
|
||||||
|
## To insert your secrets:
|
||||||
|
## abra app secret insert 1312.net pb_api_key v1 pk1_413
|
||||||
|
## abra app secret insert 1312.net pb_s_api_key v1 sk1_612
|
||||||
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.porkbun.yml"
|
||||||
|
#SECRET_PORKBUN_API_KEY_VERSION=v1 # generate=false
|
||||||
|
#SECRET_PORKBUN_SECRET_API_KEY_VERSION=v1 # generate=false
|
||||||
|
|
||||||
|
## Cloudflare, htps://cloudflare.com
|
||||||
|
## To insert your secrets:
|
||||||
|
## abra app secret insert {myapp.example.coop} cf_dns_token v1 "<CLOUDFLARE_DNS_API_TOKEN>"
|
||||||
|
## abra app secret insert {myapp.example.coop} cf_zone_token v1 "<CLOUDFLARE_ZONE_API_TOKEN>"
|
||||||
|
## These can be the same token or different tokens
|
||||||
|
## cf_dns_token needs DNS edit access, cf_zone_token needs zone edit access
|
||||||
|
## See LEGO docs for more info: https://go-acme.github.io/lego/dns/cloudflare/index.html
|
||||||
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.cloudflare.yml"
|
||||||
|
#SECRET_CLOUDFLARE_DNS_API_TOKEN_VERSION=v1 # generate=false
|
||||||
|
#SECRET_CLOUDFLARE_ZONE_API_TOKEN_VERSION=v1 # generate=false
|
||||||
|
|
||||||
#####################################################################
|
#####################################################################
|
||||||
# Manual wildcard certificate insertion #
|
# Manual wildcard certificate insertion #
|
||||||
@@ -106,8 +140,10 @@ COMPOSE_FILE="compose.yml"
|
|||||||
|
|
||||||
## Enable prometheus metrics collection
|
## Enable prometheus metrics collection
|
||||||
## used used by the coop-cloud monitoring stack
|
## used used by the coop-cloud monitoring stack
|
||||||
|
## BASIC_AUTH should also be enabled
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
|
||||||
#METRICS_ENABLED=1
|
#METRICS_ENABLED=1
|
||||||
|
#METRICS_FQDN=metrics.traefik.example.com
|
||||||
|
|
||||||
#####################################################################
|
#####################################################################
|
||||||
# File provider directory configuration #
|
# File provider directory configuration #
|
||||||
@@ -174,4 +210,24 @@ COMPOSE_FILE="compose.yml"
|
|||||||
|
|
||||||
## Nextcloud Talk HPB
|
## Nextcloud Talk HPB
|
||||||
#COMPOSE_FILE="$COMPOSE_FILE:compose.nextcloud-talk-hpb.yml"
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.nextcloud-talk-hpb.yml"
|
||||||
#NEXTCLOUD_TALK_HPB_ENABLED=1
|
#NEXTCLOUD_TALK_HPB_ENABLED=1
|
||||||
|
|
||||||
|
## Anubis
|
||||||
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.anubis.yml"
|
||||||
|
#ANUBIS_COOKIE_DOMAIN=example.com
|
||||||
|
#ANUBIS_DOMAIN=anubis.example.com
|
||||||
|
#ANUBIS_REDIRECT_DOMAINS=
|
||||||
|
#ANUBIS_OG_PASSTHROUGH=true
|
||||||
|
#ANUBIS_OG_EXPIRY_TIME=1h
|
||||||
|
#ANUBIS_OG_CACHE_CONSIDER_HOST=true
|
||||||
|
#ANUBIS_SERVE_ROBOTS_TXT=true
|
||||||
|
#ANUBIS_SLOG_LEVEL=INFO
|
||||||
|
|
||||||
|
## Crowdsec
|
||||||
|
#COMPOSE_FILE="$COMPOSE_FILE:compose.crowdsec.yml"
|
||||||
|
#CROWDSEC_ENABLED=1
|
||||||
|
#CROWDSEC_BOUNCER_ENABLED=1
|
||||||
|
#CROWDSEC_TRAEFIK_BOUNCER_API_KEY="some-api-key"
|
||||||
|
|
||||||
|
## Enable onion service support
|
||||||
|
#ONION_ENABLED=1
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
name: "Traefik pull request template"
|
||||||
|
about: "Traefik pull request template"
|
||||||
|
---
|
||||||
|
|
||||||
|
<!--
|
||||||
|
Thank you for doing recipe maintenance work!
|
||||||
|
Please mark all checklist items which are relevant for your changes.
|
||||||
|
Please remove the checklist items which are not relevant for your changes.
|
||||||
|
Feel free to remove this comment.
|
||||||
|
-->
|
||||||
|
|
||||||
|
* [ ] I have deployed and tested my changes
|
||||||
|
* [ ] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash)
|
||||||
|
* [ ] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes)
|
||||||
|
* [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes)
|
||||||
+3
-4
@@ -7,10 +7,9 @@ certain quality and consistency, that others can rely on.
|
|||||||
|
|
||||||
A recipe maintainer has the following responsibilities:
|
A recipe maintainer has the following responsibilities:
|
||||||
|
|
||||||
- Respond to pull requests / issues within a week
|
- Respond to pull requests / issues within two weeks
|
||||||
- Make image security updates within a day
|
- Make image security updates within a week
|
||||||
- Make image patch / minor updates within a week
|
- Make image major updates every three months
|
||||||
- Make image major updates within a month
|
|
||||||
|
|
||||||
In order to fullfill these responsibilities a recipe maintainer:
|
In order to fullfill these responsibilities a recipe maintainer:
|
||||||
|
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
> https://docs.traefik.io
|
> https://docs.traefik.io
|
||||||
|
|
||||||
<!-- metadata -->
|
<!-- metadata -->
|
||||||
* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@decentral1se](https://git.coopcloud.tech/decentral1se)
|
* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@decentral1se](https://git.coopcloud.tech/decentral1se), [@javielico](https://git.coopcloud.tech/javielico), Local-IT: [@moritz](https://git.coopcloud.tech/moritz), [@msimon](https://git.coopcloud.tech/simon), [@carla](https://git.coopcloud.tech/carla)
|
||||||
* **Status**: `stable`
|
* **Status**: `stable`
|
||||||
* **Category**: Utilities
|
* **Category**: Utilities
|
||||||
* **Features**: ?
|
* **Features**: ?
|
||||||
@@ -32,27 +32,94 @@
|
|||||||
3. Insert the secret: `abra app secret insert <domain> usersfile v1 -f usersfile
|
3. Insert the secret: `abra app secret insert <domain> usersfile v1 -f usersfile
|
||||||
4. Redploy your app: `abra app deploy -f <domain>`
|
4. Redploy your app: `abra app deploy -f <domain>`
|
||||||
|
|
||||||
## Configuring wildcard SSL using DNS
|
## Configuring SSL using DNS
|
||||||
|
|
||||||
Automatic certificate generation will Just Work™ for most recipes which use a fixed
|
Automatic certificate generation will Just Work™ for most recipes which use a
|
||||||
number of subdomains. For some recipes which need to work across arbitrary
|
fixed number of subdomains. If your server can't be reached from the Internet,
|
||||||
|
or if you're deploying a recipe that needs to work across arbitrary
|
||||||
subdomains, like
|
subdomains, like
|
||||||
[`federatedwiki`](https://git.coopcloud.tech/coop-cloud/federatedwiki/) and
|
[`federatedwiki`](https://git.coopcloud.tech/coop-cloud/federatedwiki/) and
|
||||||
[`go-ssb-room`](https://git.coopcloud.tech/coop-cloud/federatedwiki/), you'll
|
[`go-ssb-room`](https://git.coopcloud.tech/coop-cloud/federatedwiki/) (requiring
|
||||||
need to give Traefik access to your DNS provider so that it can carry out
|
the use of wildcard certificates,) you can give Traefik access to your DNS provider
|
||||||
Letsencrypt DNS challenges.
|
so that it can carry out Letsencrypt DNS challenges.
|
||||||
|
|
||||||
1. Use Gandi or OVH for DNS 🤡 (support for other providers can be easily added,
|
1. Use Gandi, OVH, DO, Azure, or PorkBun for DNS 🤡 (support for other providers
|
||||||
see [the `lego` docs](https://go-acme.github.io/lego/dns/#dns-providers).
|
can be easily added, see
|
||||||
|
[the `lego` docs](https://go-acme.github.io/lego/dns/#dns-providers).
|
||||||
2. Run `abra app config YOURAPPDOMAIN`
|
2. Run `abra app config YOURAPPDOMAIN`
|
||||||
3. Uncomment e.g. `ENABLE_GANDI` and the related `SECRET_.._VERSION` line, e.g.
|
3. Uncomment e.g. `ENABLE_GANDI` and the related `SECRET_.._VERSION` line, e.g.
|
||||||
`SECRET_GANDIV5_API_KEY_VERSION`
|
`SECRET_GANDIV5_API_KEY_VERSION`
|
||||||
4. Generate an API key for your provider
|
4. Set `LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER` to your provider, e.g. `gandi`
|
||||||
|
4. Generate an API key for your provider, probably using their web interface.
|
||||||
5. Run `abra app secret insert YOURAPPDOMAIN SECRETNAME v1 SECRETVALUE`, where
|
5. Run `abra app secret insert YOURAPPDOMAIN SECRETNAME v1 SECRETVALUE`, where
|
||||||
`SECRETNAME` is from the compose file (e.g. `compose.gandi-api-key.yml`) e.g.
|
`SECRETNAME` is from the compose file (e.g. `compose.gandi-api-key.yml`) e.g.
|
||||||
`gandiv5_api_key` and `SECRETVALUE` is the API key.
|
`gandiv5_api_key` and `SECRETVALUE` is the API key.
|
||||||
- For Gandi, you can use either the deprecated API Key or a GandiV5 Personal
|
- For Gandi, you can use either the deprecated API Key or a GandiV5 Personal
|
||||||
Access Token, in which case use compose.gandi-personal-access-token.yml.
|
Access Token, in which case use compose.gandi-personal-access-token.yml.
|
||||||
|
- See comments for each provider in your env file for specific instructions
|
||||||
6. Redeploy Traefik, using e.g. `abra app deploy YOURAPPDOMAIN -f`
|
6. Redeploy Traefik, using e.g. `abra app deploy YOURAPPDOMAIN -f`
|
||||||
|
|
||||||
|
## Blocking scrapers with [Anubis](https://anubis.techaro.lol/)
|
||||||
|
|
||||||
|
Uncomment the lines on the Anubis section of the configuration. Set
|
||||||
|
a domain name for the cookies and a domain that will serve Anubis
|
||||||
|
redirection service. Optionally and for [added
|
||||||
|
security](https://anubis.techaro.lol/docs/admin/configuration/redirect-domains),
|
||||||
|
set a list of the domain names for the apps that are going to be
|
||||||
|
protected.
|
||||||
|
|
||||||
|
After deploying these changes, go to each recipe that supports Anubis
|
||||||
|
and follow the process there. **Enabling Anubis here is not enough for
|
||||||
|
protection your apps.**
|
||||||
|
|
||||||
|
## Crowdsec
|
||||||
|
|
||||||
|
IMPORTANT even though Crowdsec is Open Source, the software sends information of the attacker IP and what decision(ban or captcha) to a centralized server for communit managed block lists.
|
||||||
|
|
||||||
|
On first deployment you need to generate an empty secret, because the lapi key is created at runtime.
|
||||||
|
```
|
||||||
|
abra app secret insert <domain> crowdsec_lapi_key v1
|
||||||
|
```
|
||||||
|
|
||||||
|
Then deploy your traefik recipe with the crowdsec compose and variables enabled and set `CROWDSEC_BOUNCER_ENABLED=0` to prevent initializing the bouncer that has no key yet.
|
||||||
|
|
||||||
|
When traefik is running, generate the LAPI key with the following command:
|
||||||
|
```
|
||||||
|
abra app run <domain> crowdsec cscli bouncers add crowdsecBouncer
|
||||||
|
```
|
||||||
|
|
||||||
|
After that insert the LAPI key(command below) and redeploy traefik with `CROWDSEC_BOUNCER_ENABLED=1` and `CROWDSEC_TRAEFIK_CONFIG_VERSION=v2`.
|
||||||
|
```
|
||||||
|
abra app secret insert <domain> crowdsec_lapi_key v2 -f -t <path-to/lapi-key-file>
|
||||||
|
```
|
||||||
|
|
||||||
|
When it is up and running go to the recipe you want to protect and add the following snippet and redeploy.
|
||||||
|
```
|
||||||
|
---
|
||||||
|
version: "3.8"
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
deploy:
|
||||||
|
labels:
|
||||||
|
- "traefik.http.routers.${STACK_NAME}.middlewares=crowdsec@file"
|
||||||
|
```
|
||||||
|
|
||||||
|
You can see if it is working by checking the ban list.
|
||||||
|
```
|
||||||
|
abra app run <domain> crowdsec cscli decisions list
|
||||||
|
```
|
||||||
|
|
||||||
|
When there are not bans yet you can try by banning your own IP.
|
||||||
|
```
|
||||||
|
abra app run <domain> crowdsec cscli decisions add --ip <your-ip> -d 10m # this will be effective 10min
|
||||||
|
```
|
||||||
|
Remove it with:
|
||||||
|
```
|
||||||
|
abra app run <domain> crowdsec cscli decisions remove --ip <your-ip> # this can still take a few minutes because of cache
|
||||||
|
```
|
||||||
|
|
||||||
|
## Enabling onion service
|
||||||
|
|
||||||
|
Uncomment the line in the config setting `ONION_ENABLED=1`. This will create a new entrypoint on port 9052 which can be used to bypass forced SSL. For more details, see the [onion recipe](https://recipes.coopcloud.tech/onion).
|
||||||
|
|
||||||
[`abra`]: https://git.autonomic.zone/autonomic-cooperative/abra
|
[`abra`]: https://git.autonomic.zone/autonomic-cooperative/abra
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
export TRAEFIK_YML_VERSION=v28
|
export TRAEFIK_YML_VERSION=v33
|
||||||
export FILE_PROVIDER_YML_VERSION=v11
|
export FILE_PROVIDER_YML_VERSION=v15
|
||||||
export ENTRYPOINT_VERSION=v5
|
export ENTRYPOINT_VERSION=v5
|
||||||
|
export CROWDSEC_TRAEFIK_CONFIG_VERSION=v1
|
||||||
|
|||||||
@@ -0,0 +1,31 @@
|
|||||||
|
---
|
||||||
|
version: "3.8"
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
deploy:
|
||||||
|
labels:
|
||||||
|
- "traefik.http.middlewares.anubis.forwardauth.address=http://anubis:8080/.within.website/x/cmd/anubis/api/check"
|
||||||
|
- "traefik.http.middlewares.anubis.forwardauth.trustForwardHeader=true"
|
||||||
|
anubis:
|
||||||
|
image: "ghcr.io/techarohq/anubis:v1.25.0"
|
||||||
|
environment:
|
||||||
|
BIND: ":8080"
|
||||||
|
TARGET: " "
|
||||||
|
REDIRECT_DOMAINS: "${ANUBIS_REDIRECT_DOMAINS}"
|
||||||
|
COOKIE_DOMAIN: "${ANUBIS_COOKIE_DOMAIN}"
|
||||||
|
PUBLIC_URL: "https://${ANUBIS_DOMAIN}"
|
||||||
|
OG_PASSTHROUGH: "${ANUBIS_OG_PASSTHROUGH}"
|
||||||
|
OG_EXPIRY_TIME: "${ANUBIS_OG_EXPIRY_TIME}"
|
||||||
|
OG_CACHE_CONSIDER_HOST: "${ANUBIS_OG_CACHE_CONSIDER_HOST}"
|
||||||
|
SERVE_ROBOTS_TXT: "${ANUBIS_SERVE_ROBOTS_TXT}"
|
||||||
|
SLOG_LEVEL: "${ANUBIS_SLOG_LEVEL:-INFO}"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
deploy:
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.http.routers.anubis.rule=Host(`${ANUBIS_DOMAIN}`)"
|
||||||
|
- "traefik.http.routers.anubis.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||||
|
- "traefik.http.routers.anubis.entrypoints=web-secure"
|
||||||
|
- "traefik.http.services.anubis.loadbalancer.server.port=8080"
|
||||||
|
- "traefik.http.routers.anubis.service=anubis"
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
version: "3.8"
|
||||||
|
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
environment:
|
||||||
|
- CLOUDFLARE_DNS_API_TOKEN_FILE=/run/secrets/cf_dns_token
|
||||||
|
- CLOUDFLARE_ZONE_API_TOKEN_FILE=/run/secrets/cf_zone_token
|
||||||
|
secrets:
|
||||||
|
- cf_dns_token
|
||||||
|
- cf_zone_token
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
cf_dns_token:
|
||||||
|
name: ${STACK_NAME}_cf_dns_token_${SECRET_CLOUDFLARE_DNS_API_TOKEN_VERSION}
|
||||||
|
external: true
|
||||||
|
cf_zone_token:
|
||||||
|
name: ${STACK_NAME}_cf_zone_token_${SECRET_CLOUDFLARE_ZONE_API_TOKEN_VERSION}
|
||||||
|
external: true
|
||||||
+4
-1
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- COMPY_ENABLED
|
- COMPY_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "9999:9999"
|
- target: 9999
|
||||||
|
published: 9999
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
@@ -0,0 +1,42 @@
|
|||||||
|
version: "3.8"
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
deploy:
|
||||||
|
labels:
|
||||||
|
- "traefik.http.routers.${STACK_NAME}.middlewares=crowdsec@file"
|
||||||
|
secrets:
|
||||||
|
- crowdsec_lapi_key
|
||||||
|
crowdsec:
|
||||||
|
image: crowdsecurity/crowdsec:v1.7.8
|
||||||
|
environment:
|
||||||
|
GID: "${GID-1000}"
|
||||||
|
COLLECTIONS: "crowdsecurity/linux crowdsecurity/traefik"
|
||||||
|
volumes:
|
||||||
|
- crowdsec-db:/var/lib/crowdsec/data/
|
||||||
|
- crowdsec-config:/etc/crowdsec/
|
||||||
|
- traefik-logs:/var/log/traefik/:ro
|
||||||
|
configs:
|
||||||
|
- source: crowdsec_traefik_config
|
||||||
|
target: /etc/crowdsec/acquis.d/traefik_config.yaml
|
||||||
|
mode: 0555
|
||||||
|
networks:
|
||||||
|
- internal
|
||||||
|
deploy:
|
||||||
|
update_config:
|
||||||
|
failure_action: rollback
|
||||||
|
order: stop-first
|
||||||
|
|
||||||
|
configs:
|
||||||
|
crowdsec_traefik_config:
|
||||||
|
name: ${STACK_NAME}_crowdsec_traefik_${CROWDSEC_TRAEFIK_CONFIG_VERSION}
|
||||||
|
file: crowdsec_traefik_config.yaml.tmpl
|
||||||
|
template_driver: golang
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
crowdsec_lapi_key:
|
||||||
|
external: true
|
||||||
|
name: ${STACK_NAME}_crowdsec_lapi_key_${SECRET_CROWDSEC_LAPI_KEY_VERSION}
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
crowdsec-db:
|
||||||
|
crowdsec-config:
|
||||||
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- FOODSOFT_SMTP_ENABLED
|
- FOODSOFT_SMTP_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "2525:2525"
|
- target: 2525
|
||||||
|
published: 2525
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
+4
-1
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- GARAGE_RPC_ENABLED
|
- GARAGE_RPC_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "3901:3901"
|
- target: 3901
|
||||||
|
published: 3901
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
+4
-1
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- GITEA_SSH_ENABLED
|
- GITEA_SSH_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "2222:2222"
|
- target: 2222
|
||||||
|
published: 2222
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
@@ -1,15 +1,2 @@
|
|||||||
---
|
---
|
||||||
version: "3.8"
|
version: "3.8"
|
||||||
|
|
||||||
services:
|
|
||||||
app:
|
|
||||||
deploy:
|
|
||||||
update_config:
|
|
||||||
order: stop-first
|
|
||||||
ports:
|
|
||||||
- target: 80
|
|
||||||
published: 80
|
|
||||||
mode: host
|
|
||||||
- target: 443
|
|
||||||
published: 443
|
|
||||||
mode: host
|
|
||||||
|
|||||||
+4
-1
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- IRC_ENABLED
|
- IRC_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "6697:6697"
|
- target: 6697
|
||||||
|
published: 6697
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
+4
-1
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- MATRIX_FEDERATION_ENABLED
|
- MATRIX_FEDERATION_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "8448:8448"
|
- target: 8448
|
||||||
|
published: 8448
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
@@ -3,7 +3,3 @@ services:
|
|||||||
app:
|
app:
|
||||||
environment:
|
environment:
|
||||||
- METRICS_ENABLED
|
- METRICS_ENABLED
|
||||||
ports:
|
|
||||||
- target: 8082
|
|
||||||
published: 8082
|
|
||||||
mode: host
|
|
||||||
|
|||||||
+4
-1
@@ -6,4 +6,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- MINIO_CONSOLE_ENABLED
|
- MINIO_CONSOLE_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "9001:9001"
|
- target: 9001
|
||||||
|
published: 9001
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
+8
-3
@@ -4,6 +4,11 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- MUMBLE_ENABLED
|
- MUMBLE_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "64738:64738/udp"
|
- target: 64738
|
||||||
# note (3wc): see https://github.com/docker/compose/issues/7627
|
published: 64738
|
||||||
- "64737-64739:64737-64739/tcp"
|
protocol: udp
|
||||||
|
mode: host
|
||||||
|
- target: 64738
|
||||||
|
published: 64738
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
@@ -4,5 +4,11 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- NEXTCLOUD_TALK_HPB_ENABLED
|
- NEXTCLOUD_TALK_HPB_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "3478:3478/udp"
|
- target: 3478
|
||||||
- "3478:3478/tcp"
|
published: 3478
|
||||||
|
protocol: udp
|
||||||
|
mode: host
|
||||||
|
- target: 3478
|
||||||
|
published: 3478
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
version: "3.8"
|
||||||
|
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
ports:
|
||||||
|
- target: 80
|
||||||
|
published: 80
|
||||||
|
protocol: tcp
|
||||||
|
mode: ingress
|
||||||
|
- target: 443
|
||||||
|
published: 443
|
||||||
|
protocol: tcp
|
||||||
|
mode: ingress
|
||||||
|
deploy:
|
||||||
|
endpoint_mode: vip
|
||||||
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- PEERTUBE_RTMP_ENABLED
|
- PEERTUBE_RTMP_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "1935:1935"
|
- target: 1935
|
||||||
|
published: 1935
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
version: "3.8"
|
||||||
|
|
||||||
|
services:
|
||||||
|
app:
|
||||||
|
environment:
|
||||||
|
- PORKBUN_API_KEY_FILE=/run/secrets/pb_api_key
|
||||||
|
- PORKBUN_SECRET_API_KEY_FILE=/run/secrets/pb_s_api_key
|
||||||
|
secrets:
|
||||||
|
- pb_api_key
|
||||||
|
- pb_s_api_key
|
||||||
|
|
||||||
|
secrets:
|
||||||
|
pb_api_key:
|
||||||
|
name: ${STACK_NAME}_pb_api_key_${SECRET_PORKBUN_API_KEY_VERSION}
|
||||||
|
external: true
|
||||||
|
pb_s_api_key:
|
||||||
|
name: ${STACK_NAME}_pb_s_api_key_${SECRET_PORKBUN_SECRET_API_KEY_VERSION}
|
||||||
|
external: true
|
||||||
+4
-1
@@ -6,4 +6,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- SMTP_ENABLED
|
- SMTP_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "587:587"
|
- target: 587
|
||||||
|
published: 587
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
+4
-1
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- SSB_MUXRPC_ENABLED
|
- SSB_MUXRPC_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "8008:8008"
|
- target: 8008
|
||||||
|
published: 8008
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
+4
-1
@@ -4,4 +4,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
- WEB_ALT_ENABLED
|
- WEB_ALT_ENABLED
|
||||||
ports:
|
ports:
|
||||||
- "8000:8000"
|
- target: 8000
|
||||||
|
published: 8000
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
|||||||
+19
-7
@@ -3,16 +3,23 @@ version: "3.8"
|
|||||||
|
|
||||||
services:
|
services:
|
||||||
app:
|
app:
|
||||||
image: "traefik:v3.6.5"
|
image: "traefik:v3.7.8"
|
||||||
# Note(decentral1se): *please do not* add any additional ports here.
|
# Note(decentral1se): *please do not* add any additional ports here.
|
||||||
# Doing so could break new installs with port conflicts. Please use
|
# Doing so could break new installs with port conflicts. Please use
|
||||||
# the usual `compose.$app.yml` approach for any additional ports
|
# the usual `compose.$app.yml` approach for any additional ports
|
||||||
ports:
|
ports:
|
||||||
- "80:80"
|
- target: 80
|
||||||
- "443:443"
|
published: 80
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
|
- target: 443
|
||||||
|
published: 443
|
||||||
|
protocol: tcp
|
||||||
|
mode: host
|
||||||
volumes:
|
volumes:
|
||||||
- "letsencrypt:/etc/letsencrypt"
|
- "letsencrypt:/etc/letsencrypt"
|
||||||
- "file-providers:/etc/traefik/file-providers"
|
- "file-providers:/etc/traefik/file-providers"
|
||||||
|
- "traefik-logs:/var/log/traefik"
|
||||||
configs:
|
configs:
|
||||||
- source: traefik_yml
|
- source: traefik_yml
|
||||||
target: /etc/traefik/traefik.yml
|
target: /etc/traefik/traefik.yml
|
||||||
@@ -28,6 +35,8 @@ services:
|
|||||||
- DASHBOARD_ENABLED
|
- DASHBOARD_ENABLED
|
||||||
- LOG_LEVEL
|
- LOG_LEVEL
|
||||||
- ${LOG_MAX_AGE:-0}
|
- ${LOG_MAX_AGE:-0}
|
||||||
|
- READ_TIMEOUT=${READ_TIMEOUT:-60s}
|
||||||
|
- WRITE_TIMEOUT=${WRITE_TIMEOUT:-0s}
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "traefik", "healthcheck"]
|
test: ["CMD", "traefik", "healthcheck"]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
@@ -37,9 +46,10 @@ services:
|
|||||||
command: traefik
|
command: traefik
|
||||||
entrypoint: /custom-entrypoint.sh
|
entrypoint: /custom-entrypoint.sh
|
||||||
deploy:
|
deploy:
|
||||||
|
endpoint_mode: dnsrr
|
||||||
update_config:
|
update_config:
|
||||||
failure_action: rollback
|
failure_action: rollback
|
||||||
order: start-first
|
order: stop-first
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=web"
|
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=web"
|
||||||
@@ -48,12 +58,12 @@ services:
|
|||||||
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
|
||||||
- "traefik.http.routers.${STACK_NAME}.service=api@internal"
|
- "traefik.http.routers.${STACK_NAME}.service=api@internal"
|
||||||
- "traefik.http.routers.${STACK_NAME}.middlewares=security@file"
|
- "traefik.http.routers.${STACK_NAME}.middlewares=security@file"
|
||||||
- "coop-cloud.${STACK_NAME}.version=3.9.0+v3.6.5"
|
- "coop-cloud.${STACK_NAME}.version=6.0.0+v3.7.7"
|
||||||
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT:-120}"
|
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
|
||||||
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
- "backupbot.backup=${ENABLE_BACKUPS:-true}"
|
||||||
|
|
||||||
socket-proxy:
|
socket-proxy:
|
||||||
image: lscr.io/linuxserver/socket-proxy:3.2.10-r0-ls65
|
image: lscr.io/linuxserver/socket-proxy:3.4.2
|
||||||
deploy:
|
deploy:
|
||||||
endpoint_mode: dnsrr
|
endpoint_mode: dnsrr
|
||||||
environment:
|
environment:
|
||||||
@@ -84,6 +94,7 @@ services:
|
|||||||
- TASKS=1 # Needs access
|
- TASKS=1 # Needs access
|
||||||
- VERSION=1 # Needs access
|
- VERSION=1 # Needs access
|
||||||
- VOLUMES=0
|
- VOLUMES=0
|
||||||
|
- LOG_LEVEL=warning
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
networks:
|
networks:
|
||||||
@@ -111,3 +122,4 @@ configs:
|
|||||||
volumes:
|
volumes:
|
||||||
letsencrypt:
|
letsencrypt:
|
||||||
file-providers:
|
file-providers:
|
||||||
|
traefik-logs:
|
||||||
|
|||||||
@@ -0,0 +1,5 @@
|
|||||||
|
filenames:
|
||||||
|
- /var/log/traefik/*
|
||||||
|
labels:
|
||||||
|
type: traefik
|
||||||
|
|
||||||
+23
-1
@@ -22,6 +22,16 @@ http:
|
|||||||
basicAuth:
|
basicAuth:
|
||||||
usersFile: "/run/secrets/usersfile"
|
usersFile: "/run/secrets/usersfile"
|
||||||
{{ end }}
|
{{ end }}
|
||||||
|
{{ if eq (env "CROWDSEC_ENABLED") "1" }}
|
||||||
|
crowdsec:
|
||||||
|
plugin:
|
||||||
|
bouncer:
|
||||||
|
enabled: {{ if eq (env "CROWDSEC_BOUNCER_ENABLED") "1" }}true{{ else }}false{{ end }}
|
||||||
|
logLevel: DEBUG
|
||||||
|
crowdsecMode: live
|
||||||
|
crowdsecLapiKey: "{{ if eq (env "CROWDSEC_BOUNCER_ENABLED") "1" }}{{ secret "crowdsec_lapi_key" }}{{ else }}please_set_CROWDSEC_BOUNCER_ENABLED_to_1{{ end }}"
|
||||||
|
crowdsecLapiHost: crowdsec:8080
|
||||||
|
{{ end }}
|
||||||
security:
|
security:
|
||||||
headers:
|
headers:
|
||||||
frameDeny: true
|
frameDeny: true
|
||||||
@@ -30,6 +40,18 @@ http:
|
|||||||
stsIncludeSubdomains: true
|
stsIncludeSubdomains: true
|
||||||
stsPreload: true
|
stsPreload: true
|
||||||
stsSeconds: "31536000"
|
stsSeconds: "31536000"
|
||||||
|
{{ if eq (env "METRICS_ENABLED") "1" }}
|
||||||
|
routers:
|
||||||
|
traefik-metrics:
|
||||||
|
rule: "Host(`{{ env "METRICS_FQDN" }}`)"
|
||||||
|
entrypoints:
|
||||||
|
- web-secure
|
||||||
|
tls:
|
||||||
|
certResolver: {{ env "LETS_ENCRYPT_ENV" }}
|
||||||
|
middlewares:
|
||||||
|
- basicauth@file
|
||||||
|
service: prometheus@internal
|
||||||
|
{{ end }}
|
||||||
|
|
||||||
tls:
|
tls:
|
||||||
options:
|
options:
|
||||||
@@ -49,4 +71,4 @@ tls:
|
|||||||
certificates:
|
certificates:
|
||||||
- certFile: /run/secrets/ssl_cert
|
- certFile: /run/secrets/ssl_cert
|
||||||
keyFile: /run/secrets/ssl_key
|
keyFile: /run/secrets/ssl_key
|
||||||
{{ end }}
|
{{ end }}
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
Short summary of the latest changes:
|
||||||
|
|
||||||
|
* Traefik has been upgraded with a patch release, no issues expected.
|
||||||
|
* "CurveP256" has been included to the TLS options.
|
||||||
|
* The default TIMEOUT value has been removed from the label directly.
|
||||||
|
* Anubis support is here, try out `compose.anubis.yml` and see the README.md for more.
|
||||||
|
* Onion services with Tor are not supported! See the README.md for more.
|
||||||
|
* There are now officially 3 recipe maintainers for Traefik!
|
||||||
|
|
||||||
|
All changes: https://git.coopcloud.tech/coop-cloud/traefik/compare/3.9.0+v3.6.5...master
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
Short summary of the latest changes:
|
||||||
|
|
||||||
|
* Exposed ports have been switched to host-mode port publishing by default
|
||||||
|
This adds support for IPv6 ingress, which means that after deploying this
|
||||||
|
change, DNS AAAA records can be made to point to the relevant IPv6
|
||||||
|
address and Traefik will handle public IPv6 ingress traffic (including ACME
|
||||||
|
HTTP-01 challenges)
|
||||||
|
|
||||||
|
/!\ This is a breaking change. It is still possible to revert ports 80 and
|
||||||
|
443 to ingress-mode (the previous default) but keep in mind that there
|
||||||
|
is no longer an easy way to publish additional ports in ingress mode.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
/!\ BREAKING CHANGE: Change metrics endpoint to use https instead of http 8082
|
||||||
|
to prevent sending BASIC_AUTH in plaintext
|
||||||
|
|
||||||
|
The metrics endpoint changed from http on port 8082 to the web-secure
|
||||||
|
endpoint to prevent sending BASIC_AUTH credentials plaintext. If metrics is
|
||||||
|
enabled you need to configure a FQDN for it by setting METRICS_FQDN in your
|
||||||
|
.env. You should also update the scrape config files in prometheus for
|
||||||
|
Traefik metrics from port 8082 to the new FQDN.
|
||||||
|
|
||||||
|
All changes: https://git.coopcloud.tech/coop-cloud/traefik/compare/5.0.0+v3.6.10...4.0.0+v3.6.10
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
Patched CVES: CVE-2026-32595 and CVE-2026-32305
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
!Breaking: Starting with v3.6.16, the Docker provider requires Docker API version v1.40 or above (Docker Engine v19.03). Users running older (end of life) versions of Docker Engine should update their Docker Engine or use the DOCKER_API_VERSION environment variable to override the API version used by Traefik.
|
||||||
|
|
||||||
|
letsencrypt: Avoid HTTP-01 challenge if `LETS_ENCRYPT_DNS_CHALLENGE_ENABLED` is set, in order to rely on DNS-01 challenges for servers not exposed to the internet.
|
||||||
|
|
||||||
|
matrix-federation: Entrypoint was changed to :8448 to match published port
|
||||||
|
|
||||||
|
fix: ensure large uploads work. You can now set the following env vars:
|
||||||
|
- READ_TIMEOUT
|
||||||
|
- WRITE_TIMEOUT
|
||||||
|
|
||||||
|
cloudflare: Add Cloudflare as DNS provider
|
||||||
|
|
||||||
|
For more information take a look at the migration guide: https://doc.traefik.io/traefik/v3.7/migrate/v3/#v377
|
||||||
+65
-46
@@ -5,20 +5,25 @@ core:
|
|||||||
log:
|
log:
|
||||||
level: {{ env "LOG_LEVEL" }}
|
level: {{ env "LOG_LEVEL" }}
|
||||||
maxAge: {{ env "LOG_MAX_AGE" }}
|
maxAge: {{ env "LOG_MAX_AGE" }}
|
||||||
|
{{- if eq (env "CROWDSEC_ENABLED") "1" }}
|
||||||
|
filePath: "/var/log/traefik/traefik.log"
|
||||||
|
accessLog:
|
||||||
|
filePath: "/var/log/traefik/access.log"
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
providers:
|
providers:
|
||||||
swarm:
|
swarm:
|
||||||
endpoint: "tcp://socket-proxy:2375"
|
endpoint: "tcp://socket-proxy:2375"
|
||||||
exposedByDefault: false
|
exposedByDefault: false
|
||||||
network: proxy
|
network: proxy
|
||||||
{{ if eq (env "FILE_PROVIDER_DIRECTORY_ENABLED") "1" }}
|
{{- if eq (env "FILE_PROVIDER_DIRECTORY_ENABLED") "1" }}
|
||||||
file:
|
file:
|
||||||
directory: /etc/traefik/file-providers
|
directory: /etc/traefik/file-providers
|
||||||
watch: true
|
watch: true
|
||||||
{{ else }}
|
{{- else }}
|
||||||
file:
|
file:
|
||||||
filename: /etc/traefik/file-provider.yml
|
filename: /etc/traefik/file-provider.yml
|
||||||
{{ end }}
|
{{- end }}
|
||||||
|
|
||||||
api:
|
api:
|
||||||
dashboard: {{ env "DASHBOARD_ENABLED" }}
|
dashboard: {{ env "DASHBOARD_ENABLED" }}
|
||||||
@@ -33,6 +38,10 @@ entrypoints:
|
|||||||
to: web-secure
|
to: web-secure
|
||||||
web-secure:
|
web-secure:
|
||||||
address: ":443"
|
address: ":443"
|
||||||
|
transport:
|
||||||
|
respondingTimeouts:
|
||||||
|
readTimeout: {{ env "READ_TIMEOUT" }}
|
||||||
|
writeTimeout: {{ env "WRITE_TIMEOUT" }}
|
||||||
http:
|
http:
|
||||||
encodedCharacters:
|
encodedCharacters:
|
||||||
allowEncodedSlash: true
|
allowEncodedSlash: true
|
||||||
@@ -42,86 +51,84 @@ entrypoints:
|
|||||||
allowEncodedPercent: true
|
allowEncodedPercent: true
|
||||||
allowEncodedQuestionMark: true
|
allowEncodedQuestionMark: true
|
||||||
allowEncodedHash: true
|
allowEncodedHash: true
|
||||||
{{ if eq (env "GITEA_SSH_ENABLED") "1" }}
|
{{- if eq (env "GITEA_SSH_ENABLED") "1" }}
|
||||||
gitea-ssh:
|
gitea-ssh:
|
||||||
address: ":2222"
|
address: ":2222"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "P2PANDA_ENABLED") "1" }}
|
{{- if eq (env "P2PANDA_ENABLED") "1" }}
|
||||||
p2panda-udp-v4:
|
p2panda-udp-v4:
|
||||||
address: ":2022/udp"
|
address: ":2022/udp"
|
||||||
p2panda-udp-v6:
|
p2panda-udp-v6:
|
||||||
address: ":2023/udp"
|
address: ":2023/udp"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "GARAGE_RPC_ENABLED") "1" }}
|
{{- if eq (env "GARAGE_RPC_ENABLED") "1" }}
|
||||||
garage-rpc:
|
garage-rpc:
|
||||||
address: ":3901"
|
address: ":3901"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "FOODSOFT_SMTP_ENABLED") "1" }}
|
{{- if eq (env "FOODSOFT_SMTP_ENABLED") "1" }}
|
||||||
foodsoft-smtp:
|
foodsoft-smtp:
|
||||||
address: ":2525"
|
address: ":2525"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "SMTP_ENABLED") "1" }}
|
{{- if eq (env "SMTP_ENABLED") "1" }}
|
||||||
smtp-submission:
|
smtp-submission:
|
||||||
address: ":587"
|
address: ":587"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "PEERTUBE_RTMP_ENABLED") "1" }}
|
{{- if eq (env "PEERTUBE_RTMP_ENABLED") "1" }}
|
||||||
peertube-rtmp:
|
peertube-rtmp:
|
||||||
address: ":1935"
|
address: ":1935"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "WEB_ALT_ENABLED") "1" }}
|
{{- if eq (env "WEB_ALT_ENABLED") "1" }}
|
||||||
web-alt:
|
web-alt:
|
||||||
address: ":8000"
|
address: ":8000"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "SSB_MUXRPC_ENABLED") "1" }}
|
{{- if eq (env "SSB_MUXRPC_ENABLED") "1" }}
|
||||||
ssb-muxrpc:
|
ssb-muxrpc:
|
||||||
address: ":8008"
|
address: ":8008"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "MSSQL_ENABLED") "1" }}
|
{{- if eq (env "MSSQL_ENABLED") "1" }}
|
||||||
mssql:
|
mssql:
|
||||||
address: ":1433"
|
address: ":1433"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "MUMBLE_ENABLED") "1" }}
|
{{- if eq (env "MUMBLE_ENABLED") "1" }}
|
||||||
mumble:
|
mumble:
|
||||||
address: ":64738"
|
address: ":64738"
|
||||||
mumble-udp:
|
mumble-udp:
|
||||||
address: ":64738/udp"
|
address: ":64738/udp"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "COMPY_ENABLED") "1" }}
|
{{- if eq (env "COMPY_ENABLED") "1" }}
|
||||||
compy:
|
compy:
|
||||||
address: ":9999"
|
address: ":9999"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "IRC_ENABLED") "1" }}
|
{{- if eq (env "IRC_ENABLED") "1" }}
|
||||||
irc:
|
irc:
|
||||||
address: ":6697"
|
address: ":6697"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "METRICS_ENABLED") "1" }}
|
{{- if eq (env "MATRIX_FEDERATION_ENABLED") "1" }}
|
||||||
metrics:
|
|
||||||
address: ":8082"
|
|
||||||
http:
|
|
||||||
middlewares:
|
|
||||||
- basicauth@file
|
|
||||||
{{ end }}
|
|
||||||
{{ if eq (env "MATRIX_FEDERATION_ENABLED") "1" }}
|
|
||||||
matrix-federation:
|
matrix-federation:
|
||||||
address: ":9001"
|
address: ":8448"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
{{ if eq (env "NEXTCLOUD_TALK_HPB_ENABLED") "1" }}
|
{{- if eq (env "NEXTCLOUD_TALK_HPB_ENABLED") "1" }}
|
||||||
nextcloud-talk-hpb:
|
nextcloud-talk-hpb:
|
||||||
address: ":3478"
|
address: ":3478"
|
||||||
nextcloud-talk-hpb-udp:
|
nextcloud-talk-hpb-udp:
|
||||||
address: ":3478/udp"
|
address: ":3478/udp"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
|
{{- if eq (env "ONION_ENABLED") "1" }}
|
||||||
|
onion:
|
||||||
|
address: ":9052"
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
ping:
|
ping:
|
||||||
entryPoint: web
|
entryPoint: web
|
||||||
|
|
||||||
{{ if eq (env "METRICS_ENABLED") "1" }}
|
{{- if eq (env "METRICS_ENABLED") "1" }}
|
||||||
metrics:
|
metrics:
|
||||||
prometheus:
|
prometheus:
|
||||||
entryPoint: metrics
|
entryPoint: web-secure
|
||||||
|
manualRouting: true
|
||||||
addRoutersLabels: true
|
addRoutersLabels: true
|
||||||
addServicesLabels: true
|
addServicesLabels: true
|
||||||
{{ end }}
|
{{- end }}
|
||||||
|
|
||||||
certificatesResolvers:
|
certificatesResolvers:
|
||||||
staging:
|
staging:
|
||||||
@@ -129,25 +136,37 @@ certificatesResolvers:
|
|||||||
email: {{ env "LETS_ENCRYPT_EMAIL" }}
|
email: {{ env "LETS_ENCRYPT_EMAIL" }}
|
||||||
storage: /etc/letsencrypt/staging-acme.json
|
storage: /etc/letsencrypt/staging-acme.json
|
||||||
caServer: "https://acme-staging-v02.api.letsencrypt.org/directory"
|
caServer: "https://acme-staging-v02.api.letsencrypt.org/directory"
|
||||||
|
{{- if ne (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
||||||
httpChallenge:
|
httpChallenge:
|
||||||
entryPoint: web
|
entryPoint: web
|
||||||
{{ if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
{{- end }}
|
||||||
|
{{- if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
||||||
dnsChallenge:
|
dnsChallenge:
|
||||||
provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }}
|
provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }}
|
||||||
resolvers:
|
resolvers:
|
||||||
- "1.1.1.1:53"
|
- "1.1.1.1:53"
|
||||||
- "8.8.8.8:53"
|
- "8.8.8.8:53"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
production:
|
production:
|
||||||
acme:
|
acme:
|
||||||
email: {{ env "LETS_ENCRYPT_EMAIL" }}
|
email: {{ env "LETS_ENCRYPT_EMAIL" }}
|
||||||
storage: /etc/letsencrypt/production-acme.json
|
storage: /etc/letsencrypt/production-acme.json
|
||||||
|
{{- if ne (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
||||||
httpChallenge:
|
httpChallenge:
|
||||||
entryPoint: web
|
entryPoint: web
|
||||||
{{ if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
{{- end }}
|
||||||
|
{{- if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }}
|
||||||
dnsChallenge:
|
dnsChallenge:
|
||||||
provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }}
|
provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }}
|
||||||
resolvers:
|
resolvers:
|
||||||
- "1.1.1.1:53"
|
- "1.1.1.1:53"
|
||||||
- "9.9.9.9:53"
|
- "9.9.9.9:53"
|
||||||
{{ end }}
|
{{- end }}
|
||||||
|
|
||||||
|
{{ if eq (env "CROWDSEC_ENABLED") "1" }}
|
||||||
|
experimental:
|
||||||
|
plugins:
|
||||||
|
bouncer:
|
||||||
|
moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
|
||||||
|
version: v1.6.0
|
||||||
|
{{- end }}
|
||||||
|
|||||||
Reference in New Issue
Block a user