From 7610c9f4dbbd9737c322bae2113b46531490c18f Mon Sep 17 00:00:00 2001 From: f Date: Tue, 28 Jul 2026 17:01:17 -0300 Subject: [PATCH] feat: trusted ips when traefik is behind a reverse proxy, we need to tell it which networks to trust with x-real-ip headers --- .env.sample | 6 ++++++ abra.sh | 2 +- traefik.yml.tmpl | 4 ++++ 3 files changed, 11 insertions(+), 1 deletion(-) diff --git a/.env.sample b/.env.sample index 81015a7..d3e4633 100644 --- a/.env.sample +++ b/.env.sample @@ -235,3 +235,9 @@ WRITE_TIMEOUT=0s ## Access logs #COMPOSE_FILE="$COMPOSE_FILE:compose.access-log.yml" + +# YAML array of subnets from which Traefik's trusts the x-real-ip +# header. +# +# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-forwardedHeaders-trustedIPs +#TRUSTED_IPS="['10.13.12.1']" # 10.13.12.1 is an example diff --git a/abra.sh b/abra.sh index 8abc11d..a6e2b10 100644 --- a/abra.sh +++ b/abra.sh @@ -1,4 +1,4 @@ -export TRAEFIK_YML_VERSION=v33 +export TRAEFIK_YML_VERSION=v34 export FILE_PROVIDER_YML_VERSION=v12 export ENTRYPOINT_VERSION=v5 export ANUBIS_YML_VERSION=v1 diff --git a/traefik.yml.tmpl b/traefik.yml.tmpl index 3c4a175..44767a5 100644 --- a/traefik.yml.tmpl +++ b/traefik.yml.tmpl @@ -48,6 +48,10 @@ entrypoints: to: web-secure web-secure: address: ":443" +{{ if ne (env "TRUSTED_IPS") "" }} + forwardedHeaders: + trustedIPs: {{ env "TRUSTED_IPS" }} +{{ end }} transport: respondingTimeouts: readTimeout: {{ env "READ_TIMEOUT" }}