From 74193326fb250923ccc0e2e80366eaa82f2017b9 Mon Sep 17 00:00:00 2001 From: decentral1se Date: Wed, 25 Mar 2026 00:11:53 +0100 Subject: [PATCH 01/13] chore: add moritz as maintainer --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 77b187b..a2bf262 100644 --- a/README.md +++ b/README.md @@ -5,7 +5,7 @@ > https://docs.traefik.io -* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@decentral1se](https://git.coopcloud.tech/decentral1se), [@javielico](https://git.coopcloud.tech/javielico) +* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@decentral1se](https://git.coopcloud.tech/decentral1se), [@javielico](https://git.coopcloud.tech/javielico), [@moritz](https://git.coopcloud.tech/moritz) * **Status**: `stable` * **Category**: Utilities * **Features**: ? From 440a7f5228d83de3aa16e0f9688fbdfef1eba00a Mon Sep 17 00:00:00 2001 From: fauno Date: Sat, 18 Apr 2026 06:13:54 +0000 Subject: [PATCH 02/13] fix: garage ports on host mode (#99) * [x] I have deployed and tested my changes * [ ] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash) * [ ] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes) * [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes) Co-authored-by: f Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/99 Reviewed-by: p4u1 Reviewed-by: decentral1se Co-authored-by: fauno Co-committed-by: fauno --- compose.garage.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/compose.garage.yml b/compose.garage.yml index 9de1cc2..009c042 100644 --- a/compose.garage.yml +++ b/compose.garage.yml @@ -4,4 +4,7 @@ services: environment: - GARAGE_RPC_ENABLED ports: - - "3901:3901" + - target: 3901 + published: 3901 + protocol: tcp + mode: host From 7c6dd3f5a54fe925b930de0b47e84f824e37aa2b Mon Sep 17 00:00:00 2001 From: decentral1se Date: Sat, 2 May 2026 09:36:11 +0200 Subject: [PATCH 03/13] chore: patch bump for traefik/proxy tags --- compose.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/compose.yml b/compose.yml index f6a0891..8562d7f 100644 --- a/compose.yml +++ b/compose.yml @@ -3,7 +3,7 @@ version: "3.8" services: app: - image: "traefik:v3.6.11" + image: "traefik:v3.6.15" # Note(decentral1se): *please do not* add any additional ports here. # Doing so could break new installs with port conflicts. Please use # the usual `compose.$app.yml` approach for any additional ports @@ -60,7 +60,7 @@ services: - "backupbot.backup=${ENABLE_BACKUPS:-true}" socket-proxy: - image: lscr.io/linuxserver/socket-proxy:3.2.14 + image: lscr.io/linuxserver/socket-proxy:3.2.17 deploy: endpoint_mode: dnsrr environment: From 005f0235c094720b68628a8c06e788ce75d935f9 Mon Sep 17 00:00:00 2001 From: decentral1se Date: Sat, 2 May 2026 09:37:11 +0200 Subject: [PATCH 04/13] chore: publish 5.1.1+v3.6.15 release --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 8562d7f..68afb10 100644 --- a/compose.yml +++ b/compose.yml @@ -55,7 +55,7 @@ services: - "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}" - "traefik.http.routers.${STACK_NAME}.service=api@internal" - "traefik.http.routers.${STACK_NAME}.middlewares=security@file" - - "coop-cloud.${STACK_NAME}.version=5.1.0+v3.6.11" + - "coop-cloud.${STACK_NAME}.version=5.1.1+v3.6.15" - "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}" - "backupbot.backup=${ENABLE_BACKUPS:-true}" From 7fc2cac6ff87dc31a573b7aaa79c48097f0fea81 Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Sat, 16 May 2026 23:36:24 +0000 Subject: [PATCH 05/13] chore(deps): update lscr.io/linuxserver/socket-proxy docker tag to v3.2.19 (#101) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This PR contains the following updates: | Package | Update | Change | |---|---|---| | [lscr.io/linuxserver/socket-proxy](https://github.com/linuxserver/docker-socket-proxy/packages) ([source](https://github.com/linuxserver/docker-socket-proxy)) | patch | `3.2.17` -> `3.2.19` | > :exclamation: **Important** > > Release Notes retrieval for this PR were skipped because no github.com credentials were available. > If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes). --- ### Configuration πŸ“… **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. β™» **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. πŸ”• **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/101 Reviewed-by: decentral1se Reviewed-by: p4u1 Co-authored-by: Renovate Bot Co-committed-by: Renovate Bot --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index 68afb10..c06de25 100644 --- a/compose.yml +++ b/compose.yml @@ -60,7 +60,7 @@ services: - "backupbot.backup=${ENABLE_BACKUPS:-true}" socket-proxy: - image: lscr.io/linuxserver/socket-proxy:3.2.17 + image: lscr.io/linuxserver/socket-proxy:3.2.19 deploy: endpoint_mode: dnsrr environment: From 25cf7862ed66a62128b4c1a99d261fa56d485495 Mon Sep 17 00:00:00 2001 From: Zigzagill Date: Sat, 16 May 2026 23:37:49 +0000 Subject: [PATCH 06/13] Add Cloudflare as DNS provider (#103) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * [x] I have deployed and tested my changes LetsEncrypt challenges passed * [x] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash) No relevant versions to update * [x] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes) Only new env vars were added * [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes) Unsure if this is necessary but I'm happy to add notes if we want them πŸ˜„ Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/103 Reviewed-by: p4u1 Reviewed-by: decentral1se Co-authored-by: Zigzagill Co-committed-by: Zigzagill --- .env.sample | 9 +++++++++ README.md | 4 ++-- compose.cloudflare.yml | 18 ++++++++++++++++++ 3 files changed, 29 insertions(+), 2 deletions(-) create mode 100644 compose.cloudflare.yml diff --git a/.env.sample b/.env.sample index 0ac5747..cb14413 100644 --- a/.env.sample +++ b/.env.sample @@ -86,6 +86,15 @@ COMPOSE_FILE="compose.yml" #SECRET_PORKBUN_API_KEY_VERSION=v1 #SECRET_PORKBUN_SECRET_API_KEY_VERSION=v1 +## Cloudflare, htps://cloudflare.com +## To insert your secrets: +## abra app secret insert {myapp.example.coop} cf_email v1 "" +## abra app secret insert {myapp.example.coop} cf_api_key v1 "" +## cf_api_key is an account API key from Cloudflare that has DNS read + edit permission +#COMPOSE_FILE="$COMPOSE_FILE:compose.cloudflare.yml" +#SECRET_CLOUDFLARE_EMAIL_VERSION=v1 # generate=false +#SECRET_CLOUDFLARE_API_KEY_VERSION=v1 # generate=false + ##################################################################### # Manual wildcard certificate insertion # ##################################################################### diff --git a/README.md b/README.md index a2bf262..e0e84bb 100644 --- a/README.md +++ b/README.md @@ -42,8 +42,8 @@ subdomains, like need to give Traefik access to your DNS provider so that it can carry out Letsencrypt DNS challenges. -1. Use Gandi, OVH, DO, Azure, or PorkBun for DNS 🀑 (support for other providers - can be easily added, see +1. Use Gandi, OVH, DO, Azure, PorkBun, or Cloudflare for DNS 🀑 (support for + other providers can be easily added, see [the `lego` docs](https://go-acme.github.io/lego/dns/#dns-providers). 2. Run `abra app config YOURAPPDOMAIN` 3. Uncomment e.g. `ENABLE_GANDI` and the related `SECRET_.._VERSION` line, e.g. diff --git a/compose.cloudflare.yml b/compose.cloudflare.yml new file mode 100644 index 0000000..1feb55b --- /dev/null +++ b/compose.cloudflare.yml @@ -0,0 +1,18 @@ +version: "3.8" + +services: + app: + environment: + - CLOUDFLARE_EMAIL_FILE=/run/secrets/cf_email + - CLOUDFLARE_API_KEY_FILE=/run/secrets/cf_api_key + secrets: + - cf_email + - cf_api_key + +secrets: + cf_email: + name: ${STACK_NAME}_cf_email_${SECRET_CLOUDFLARE_EMAIL_VERSION} + external: true + cf_api_key: + name: ${STACK_NAME}_cf_api_key_${SECRET_CLOUDFLARE_API_KEY_VERSION} + external: true From 6e67d0c8c0e41138940c3db8b4fd7bffcf274631 Mon Sep 17 00:00:00 2001 From: carla Date: Wed, 10 Jun 2026 09:30:57 +0000 Subject: [PATCH 07/13] update maintenance and readme (#108) * [ ] I have deployed and tested my changes * [ ] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash) * [ ] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes) * [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes) Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/108 Reviewed-by: p4u1 Reviewed-by: decentral1se Co-authored-by: carla Co-committed-by: carla --- MAINTENANCE.md | 7 +++---- README.md | 6 +++--- 2 files changed, 6 insertions(+), 7 deletions(-) diff --git a/MAINTENANCE.md b/MAINTENANCE.md index c82e528..e6990c3 100644 --- a/MAINTENANCE.md +++ b/MAINTENANCE.md @@ -7,10 +7,9 @@ certain quality and consistency, that others can rely on. A recipe maintainer has the following responsibilities: -- Respond to pull requests / issues within a week -- Make image security updates within a day -- Make image patch / minor updates within a week -- Make image major updates within a month +- Respond to pull requests / issues within two weeks +- Make image security updates within a week +- Make image major updates every three months In order to fullfill these responsibilities a recipe maintainer: diff --git a/README.md b/README.md index e0e84bb..2a71d90 100644 --- a/README.md +++ b/README.md @@ -5,7 +5,7 @@ > https://docs.traefik.io -* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@decentral1se](https://git.coopcloud.tech/decentral1se), [@javielico](https://git.coopcloud.tech/javielico), [@moritz](https://git.coopcloud.tech/moritz) +* **Maintainer**: [@p4u1](https://git.coopcloud.tech/p4u1), [@decentral1se](https://git.coopcloud.tech/decentral1se), [@javielico](https://git.coopcloud.tech/javielico), Local-IT: [@moritz](https://git.coopcloud.tech/moritz), [@msimon](https://git.coopcloud.tech/simon), [@carla](https://git.coopcloud.tech/carla) * **Status**: `stable` * **Category**: Utilities * **Features**: ? @@ -42,8 +42,8 @@ subdomains, like need to give Traefik access to your DNS provider so that it can carry out Letsencrypt DNS challenges. -1. Use Gandi, OVH, DO, Azure, PorkBun, or Cloudflare for DNS 🀑 (support for - other providers can be easily added, see +1. Use Gandi, OVH, DO, Azure, or PorkBun for DNS 🀑 (support for other providers + can be easily added, see [the `lego` docs](https://go-acme.github.io/lego/dns/#dns-providers). 2. Run `abra app config YOURAPPDOMAIN` 3. Uncomment e.g. `ENABLE_GANDI` and the related `SECRET_.._VERSION` line, e.g. From 97a68f28ac14b5866551d2c22e458cf827c76d85 Mon Sep 17 00:00:00 2001 From: f Date: Sun, 14 Jun 2026 09:08:30 +0000 Subject: [PATCH 08/13] feat: anubis log levels (#110) * [x] I have deployed and tested my changes * [ ] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash) * [x] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes) * [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes) Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/110 Reviewed-by: decentral1se Co-authored-by: f Co-committed-by: f --- .env.sample | 1 + compose.anubis.yml | 1 + 2 files changed, 2 insertions(+) diff --git a/.env.sample b/.env.sample index cb14413..2efc342 100644 --- a/.env.sample +++ b/.env.sample @@ -212,6 +212,7 @@ COMPOSE_FILE="compose.yml" #ANUBIS_OG_EXPIRY_TIME=1h #ANUBIS_OG_CACHE_CONSIDER_HOST=true #ANUBIS_SERVE_ROBOTS_TXT=true +#ANUBIS_SLOG_LEVEL=INFO ## Enable onion service support #ONION_ENABLED=1 diff --git a/compose.anubis.yml b/compose.anubis.yml index 526db81..adb4411 100644 --- a/compose.anubis.yml +++ b/compose.anubis.yml @@ -17,6 +17,7 @@ services: OG_EXPIRY_TIME: "${ANUBIS_OG_EXPIRY_TIME}" OG_CACHE_CONSIDER_HOST: "${ANUBIS_OG_CACHE_CONSIDER_HOST}" SERVE_ROBOTS_TXT: "${ANUBIS_SERVE_ROBOTS_TXT}" + SLOG_LEVEL: "${ANUBIS_SLOG_LEVEL:-INFO}" networks: - proxy deploy: From b39bb5adaf77ddb8ff9d5a4ec1e636fe1f1a4a27 Mon Sep 17 00:00:00 2001 From: Luis Barrueco Date: Fri, 19 Jun 2026 12:56:52 +0000 Subject: [PATCH 09/13] feat: disable httpChallenge when DNS challenge is configured (#112) As documented in the README's "Configuring wildcard SSL using DNS" section, the necessary pieces for DNS-01 ACME challenges to work are already baked into Traefik's recipe, though they were originally considered for provisioning wildcard certificates. Furthermore, in environments where the server is not exposed to the internet, the default HTTP-01 challenge mechanism doesn't work, so, taking advantage of this alternative method makes complete sense. This change causes ACME validations to be done always using DNS when LETS_ENCRYPT_DNS_CHALLENGE_ENABLED is active. Without it, for standard certificate requests Traefik uses the HTTP-01 challenge method, which doesn't work in servers behind a firewall. We should amend the related section in the [operators handbook](https://docs.coopcloud.tech/operators/handbook/#running-an-offline-coop-cloud-server) to make a not about the possibility of using DNS challenges in those scenarios as well. * [x] I have deployed and tested my changes I tested this with both a server "exposed" to the internet and one behind a firewall. The first one continued to use the HTTP-01 challenge because no DNS-related settings were added to it, and the second one was successfully able to provision certificates (even though it's only reachable within the LAN). * [x] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash) * [x] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes) Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/112 Co-authored-by: Luis Barrueco Co-committed-by: Luis Barrueco --- README.md | 13 +++++++------ abra.sh | 2 +- release/next | 1 + traefik.yml.tmpl | 4 ++++ 4 files changed, 13 insertions(+), 7 deletions(-) create mode 100644 release/next diff --git a/README.md b/README.md index 2a71d90..b845d48 100644 --- a/README.md +++ b/README.md @@ -32,15 +32,16 @@ 3. Insert the secret: `abra app secret insert usersfile v1 -f usersfile 4. Redploy your app: `abra app deploy -f ` -## Configuring wildcard SSL using DNS +## Configuring SSL using DNS -Automatic certificate generation will Just Workβ„’ for most recipes which use a fixed -number of subdomains. For some recipes which need to work across arbitrary +Automatic certificate generation will Just Workβ„’ for most recipes which use a +fixed number of subdomains. If your server can't be reached from the Internet, +or if you're deploying a recipe that needs to work across arbitrary subdomains, like [`federatedwiki`](https://git.coopcloud.tech/coop-cloud/federatedwiki/) and -[`go-ssb-room`](https://git.coopcloud.tech/coop-cloud/federatedwiki/), you'll -need to give Traefik access to your DNS provider so that it can carry out -Letsencrypt DNS challenges. +[`go-ssb-room`](https://git.coopcloud.tech/coop-cloud/federatedwiki/) (requiring +the use of wildcard certificates,) you can give Traefik access to your DNS provider +so that it can carry out Letsencrypt DNS challenges. 1. Use Gandi, OVH, DO, Azure, or PorkBun for DNS 🀑 (support for other providers can be easily added, see diff --git a/abra.sh b/abra.sh index ac93525..9a1fab8 100644 --- a/abra.sh +++ b/abra.sh @@ -1,3 +1,3 @@ -export TRAEFIK_YML_VERSION=v30 +export TRAEFIK_YML_VERSION=v31 export FILE_PROVIDER_YML_VERSION=v12 export ENTRYPOINT_VERSION=v5 diff --git a/release/next b/release/next new file mode 100644 index 0000000..08d5a07 --- /dev/null +++ b/release/next @@ -0,0 +1 @@ +letsencrypt: Avoid HTTP-01 challenge if `LETS_ENCRYPT_DNS_CHALLENGE_ENABLED` is set, in order to rely on DNS-01 challenges for servers not exposed to the internet. diff --git a/traefik.yml.tmpl b/traefik.yml.tmpl index d51f7f8..0ad4a07 100644 --- a/traefik.yml.tmpl +++ b/traefik.yml.tmpl @@ -127,8 +127,10 @@ certificatesResolvers: email: {{ env "LETS_ENCRYPT_EMAIL" }} storage: /etc/letsencrypt/staging-acme.json caServer: "https://acme-staging-v02.api.letsencrypt.org/directory" + {{- if ne (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }} httpChallenge: entryPoint: web + {{- end }} {{- if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }} dnsChallenge: provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }} @@ -140,8 +142,10 @@ certificatesResolvers: acme: email: {{ env "LETS_ENCRYPT_EMAIL" }} storage: /etc/letsencrypt/production-acme.json + {{- if ne (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }} httpChallenge: entryPoint: web + {{- end }} {{- if eq (env "LETS_ENCRYPT_DNS_CHALLENGE_ENABLED") "1" }} dnsChallenge: provider: {{ (env "LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER") }} From b2b311fef4fa01bbbfeb42cd946250ab4a05f18f Mon Sep 17 00:00:00 2001 From: Zigzagill Date: Sun, 21 Jun 2026 12:48:19 +0000 Subject: [PATCH 10/13] Fix Cloudlfare DNS (#104) Apologies for submitting changes and then immediately undoing some of them. I made a mistake previously by assuming that letsdebug.net tests were sufficient to confirm that this setup was working. But, it turns out that my site was still failing to get valid SSL certs. After digging into the Lego docs I realized I needed to be using different environment variables, which I added here. Once I deployed these changes to a fresh VPS on a different domain with a more straightforward configuration, I confirmed that HTTPS connections to the Traefik dashboard worked just fine. Please let me know if there's anything else I can do to verify these fixes so I can be extra-super-sure that it's good to go. I'm still new to a lot of this and clearly have lots to learn. As a treat, I also added `generate=false` flags to the DNS secrets for other providers, as discussed in my previous PR. Cheers! * [x] I have deployed and tested my changes Deployed on a fresh VPS, confirmed that HTTPS connections work after deploying these changes * [x] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash) No version update needed * [x] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes) This does remove the two environment variables that I introduced in my prior PR. Since those haven't been picked up in a release, I'm hoping this is an acceptable regression. Those two variables are both perfectly valid, they just require an account-wide API token which is unnecessarily risky in my opinion. But if we want to keep them in, I'm happy to put things back as they were :) * [x] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes) Not necessary Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/104 Reviewed-by: decentral1se Reviewed-by: p4u1 Co-authored-by: Zigzagill Co-committed-by: Zigzagill --- .env.sample | 30 ++++++++++++++++-------------- compose.cloudflare.yml | 18 +++++++++--------- 2 files changed, 25 insertions(+), 23 deletions(-) diff --git a/.env.sample b/.env.sample index 2efc342..bc877f0 100644 --- a/.env.sample +++ b/.env.sample @@ -38,7 +38,7 @@ COMPOSE_FILE="compose.yml" ## Enable dns challenge (for wildcard domains) ## https://go-acme.github.io/lego/dns/#dns-providers #LETS_ENCRYPT_DNS_CHALLENGE_ENABLED=1 -## *Currently* one of ovh, gandi, gandiv5, digitalocean, azure, porkbun. +## *Currently* one of ovh, gandi, gandiv5, digitalocean, azure, porkbun, and cloudflare. ## Uncomment the corresponding provider below to insert your secret token/key. #LETS_ENCRYPT_DNS_CHALLENGE_PROVIDER=ovh @@ -47,25 +47,25 @@ COMPOSE_FILE="compose.yml" #OVH_ENABLED=1 #OVH_APPLICATION_KEY= #OVH_ENDPOINT= -#SECRET_OVH_APP_SECRET_VERSION=v1 -#SECRET_OVH_CONSUMER_KEY=v1 +#SECRET_OVH_APP_SECRET_VERSION=v1 # generate=false +#SECRET_OVH_CONSUMER_KEY=v1 # generate=false ## Gandi, https://gandi.net ## note(3wc): only "V5" (new) API is supported, so far #COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-api-key.yml" #GANDI_API_KEY_ENABLED=1 -#SECRET_GANDIV5_API_KEY_VERSION=v1 +#SECRET_GANDIV5_API_KEY_VERSION=v1 # generate=false ## Gandi, https://gandi.net ## note: uses GandiV5 Personal Access Token #COMPOSE_FILE="$COMPOSE_FILE:compose.gandi-personal-access-token.yml" #GANDI_PERSONAL_ACCESS_TOKEN_ENABLED=1 -#SECRET_GANDIV5_PERSONAL_ACCESS_TOKEN_VERSION=v1 +#SECRET_GANDIV5_PERSONAL_ACCESS_TOKEN_VERSION=v1 # generate=false ## DigitalOcean, https://digitalocean.com #COMPOSE_FILE="$COMPOSE_FILE:compose.digitalocean.yml" #DIGITALOCEAN_ENABLED=1 -#SECRET_DIGITALOCEAN_AUTH_TOKEN_VERSION=v1 +#SECRET_DIGITALOCEAN_AUTH_TOKEN_VERSION=v1 # generate=false ## Azure, https://azure.com ## To insert your Azure client secret: @@ -76,24 +76,26 @@ COMPOSE_FILE="compose.yml" #AZURE_CLIENT_ID= #AZURE_SUBSCRIPTION_ID= #AZURE_RESOURCE_GROUP= -#SECRET_AZURE_SECRET_VERSION=v1 +#SECRET_AZURE_SECRET_VERSION=v1 # generate=false ## Porkbun, https://porkbun.com ## To insert your secrets: ## abra app secret insert 1312.net pb_api_key v1 pk1_413 ## abra app secret insert 1312.net pb_s_api_key v1 sk1_612 #COMPOSE_FILE="$COMPOSE_FILE:compose.porkbun.yml" -#SECRET_PORKBUN_API_KEY_VERSION=v1 -#SECRET_PORKBUN_SECRET_API_KEY_VERSION=v1 +#SECRET_PORKBUN_API_KEY_VERSION=v1 # generate=false +#SECRET_PORKBUN_SECRET_API_KEY_VERSION=v1 # generate=false ## Cloudflare, htps://cloudflare.com ## To insert your secrets: -## abra app secret insert {myapp.example.coop} cf_email v1 "" -## abra app secret insert {myapp.example.coop} cf_api_key v1 "" -## cf_api_key is an account API key from Cloudflare that has DNS read + edit permission +## abra app secret insert {myapp.example.coop} cf_dns_token v1 "" +## abra app secret insert {myapp.example.coop} cf_zone_token v1 "" +## These can be the same token or different tokens +## cf_dns_token needs DNS edit access, cf_zone_token needs zone edit access +## See LEGO docs for more info: https://go-acme.github.io/lego/dns/cloudflare/index.html #COMPOSE_FILE="$COMPOSE_FILE:compose.cloudflare.yml" -#SECRET_CLOUDFLARE_EMAIL_VERSION=v1 # generate=false -#SECRET_CLOUDFLARE_API_KEY_VERSION=v1 # generate=false +#SECRET_CLOUDFLARE_DNS_API_TOKEN_VERSION=v1 # generate=false +#SECRET_CLOUDFLARE_ZONE_API_TOKEN_VERSION=v1 # generate=false ##################################################################### # Manual wildcard certificate insertion # diff --git a/compose.cloudflare.yml b/compose.cloudflare.yml index 1feb55b..89c87d4 100644 --- a/compose.cloudflare.yml +++ b/compose.cloudflare.yml @@ -3,16 +3,16 @@ version: "3.8" services: app: environment: - - CLOUDFLARE_EMAIL_FILE=/run/secrets/cf_email - - CLOUDFLARE_API_KEY_FILE=/run/secrets/cf_api_key + - CLOUDFLARE_DNS_API_TOKEN_FILE=/run/secrets/cf_dns_token + - CLOUDFLARE_ZONE_API_TOKEN_FILE=/run/secrets/cf_zone_token secrets: - - cf_email - - cf_api_key - + - cf_dns_token + - cf_zone_token + secrets: - cf_email: - name: ${STACK_NAME}_cf_email_${SECRET_CLOUDFLARE_EMAIL_VERSION} + cf_dns_token: + name: ${STACK_NAME}_cf_dns_token_${SECRET_CLOUDFLARE_DNS_API_TOKEN_VERSION} external: true - cf_api_key: - name: ${STACK_NAME}_cf_api_key_${SECRET_CLOUDFLARE_API_KEY_VERSION} + cf_zone_token: + name: ${STACK_NAME}_cf_zone_token_${SECRET_CLOUDFLARE_ZONE_API_TOKEN_VERSION} external: true From 92b7093e45a97ae6d2ce7aa607823cc420698ebc Mon Sep 17 00:00:00 2001 From: f Date: Mon, 22 Jun 2026 12:55:18 +0000 Subject: [PATCH 11/13] fix: decrease socket proxy log verbosity (#106) The default seems to be `info` and fills logs with what seem to be requests to docker daemon (which makes me wonder what needs network access to the docker daemon?). Please let me know if it should be made configurable. * [x] I have deployed and tested my changes * [ ] I have [updated relevant versions in `abra.sh`](https://docs.coopcloud.tech/maintainers/upgrade/#updating-versions-in-the-abrash) * [ ] I have made my environment variable changes [backwards compatible](https://docs.coopcloud.tech/maintainers/upgrade/#backwards-compatible-environment-variable-changes) * [ ] I have added a [release note entry](https://docs.coopcloud.tech/maintainers/upgrade/#creating-new-release-notes) Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/106 Reviewed-by: p4u1 Co-authored-by: f Co-committed-by: f --- compose.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/compose.yml b/compose.yml index c06de25..c84e301 100644 --- a/compose.yml +++ b/compose.yml @@ -91,6 +91,7 @@ services: - TASKS=1 # Needs access - VERSION=1 # Needs access - VOLUMES=0 + - LOG_LEVEL=warning volumes: - /var/run/docker.sock:/var/run/docker.sock:ro networks: From 928bc2104a99a1d31331bd01f8233d2ac117296f Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Mon, 22 Jun 2026 12:56:20 +0000 Subject: [PATCH 12/13] chore(deps): update lscr.io/linuxserver/socket-proxy docker tag to v3.4.0 (#111) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This PR contains the following updates: | Package | Update | Change | |---|---|---| | [lscr.io/linuxserver/socket-proxy](https://github.com/linuxserver/docker-socket-proxy/packages) ([source](https://github.com/linuxserver/docker-socket-proxy)) | minor | `3.2.19` -> `3.4.0` | > :exclamation: **Important** > > Release Notes retrieval for this PR were skipped because no github.com credentials were available. > If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes). --- ### Configuration πŸ“… **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. β™» **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. πŸ”• **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/111 Co-authored-by: Renovate Bot Co-committed-by: Renovate Bot --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index c84e301..cd0230b 100644 --- a/compose.yml +++ b/compose.yml @@ -60,7 +60,7 @@ services: - "backupbot.backup=${ENABLE_BACKUPS:-true}" socket-proxy: - image: lscr.io/linuxserver/socket-proxy:3.2.19 + image: lscr.io/linuxserver/socket-proxy:3.4.0 deploy: endpoint_mode: dnsrr environment: From 693fa79449517e7cdbf75da3efac622935d6c021 Mon Sep 17 00:00:00 2001 From: Renovate Bot Date: Mon, 22 Jun 2026 13:00:36 +0000 Subject: [PATCH 13/13] chore(deps): update traefik docker tag to v3.7.5 (#102) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This PR contains the following updates: | Package | Update | Change | |---|---|---| | [traefik](https://github.com/containous/traefik) | minor | `v3.6.15` -> `v3.7.5` | > :exclamation: **Important** > > Release Notes retrieval for this PR were skipped because no github.com credentials were available. > If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes). --- ### Configuration πŸ“… **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. β™» **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. πŸ”• **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). Reviewed-on: https://git.coopcloud.tech/coop-cloud/traefik/pulls/102 Co-authored-by: Renovate Bot Co-committed-by: Renovate Bot --- compose.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yml b/compose.yml index cd0230b..e4c44fa 100644 --- a/compose.yml +++ b/compose.yml @@ -3,7 +3,7 @@ version: "3.8" services: app: - image: "traefik:v3.6.15" + image: "traefik:v3.7.5" # Note(decentral1se): *please do not* add any additional ports here. # Doing so could break new installs with port conflicts. Please use # the usual `compose.$app.yml` approach for any additional ports