Compare commits

..
Author SHA1 Message Date
fauno 99936080ae doc: trusted ips context 2026-08-25 18:08:28 -03:00
fauno 7610c9f4db feat: trusted ips
when traefik is behind a reverse proxy, we need to tell it which
networks to trust with x-real-ip headers
2026-08-25 16:46:35 -03:00
6 changed files with 16 additions and 28 deletions
+10 -6
View File
@@ -139,14 +139,10 @@ WRITE_TIMEOUT=0s
#####################################################################
## Enable prometheus metrics collection
## Metrics are served unauthenticated on :8082, reachable only from
## other services on the proxy network (e.g. monitoring-ng's Alloy,
## which auto-discovers it via the prometheus.io/scrape label)
## used used by the coop-cloud monitoring stack
## BASIC_AUTH should also be enabled
#COMPOSE_FILE="$COMPOSE_FILE:compose.metrics.yml"
#METRICS_ENABLED=1
## Setting METRICS_FQDN also adds a public metrics endpoint (behind
## basic auth). BASIC_AUTH should be enabled for this.
#METRICS_FQDN=metrics.traefik.example.com
#####################################################################
@@ -239,3 +235,11 @@ WRITE_TIMEOUT=0s
## Access logs
#COMPOSE_FILE="$COMPOSE_FILE:compose.access-log.yml"
## Behind a reverse proxy
#
# YAML array of subnets from which Traefik's trusts the x-real-ip
# header when behind a reverse proxy.
#
# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-forwardedHeaders-trustedIPs
#TRUSTED_IPS="['10.13.12.1']" # 10.13.12.1 is an example
+2 -2
View File
@@ -1,4 +1,4 @@
export TRAEFIK_YML_VERSION=v35
export FILE_PROVIDER_YML_VERSION=v13
export TRAEFIK_YML_VERSION=v34
export FILE_PROVIDER_YML_VERSION=v12
export ENTRYPOINT_VERSION=v5
export ANUBIS_YML_VERSION=v1
-6
View File
@@ -3,9 +3,3 @@ services:
app:
environment:
- METRICS_ENABLED
deploy:
labels:
# lets monitoring-ng's Alloy auto-discover and scrape metrics-internal
# via the proxy network.
- "prometheus.io/scrape=true"
- "prometheus.io/port=8082"
-9
View File
@@ -32,7 +32,6 @@ http:
stsSeconds: "31536000"
{{ if eq (env "METRICS_ENABLED") "1" }}
routers:
{{ if ne (env "METRICS_FQDN") "" }}
traefik-metrics:
rule: "Host(`{{ env "METRICS_FQDN" }}`)"
entrypoints:
@@ -42,14 +41,6 @@ http:
middlewares:
- basicauth@file
service: prometheus@internal
{{ end }}
# reachable from other services on the proxy network only (this port
# isn't published to the host), without auth
traefik-metrics-internal:
rule: "PathPrefix(`/`)"
entrypoints:
- metrics-internal
service: prometheus@internal
{{ end }}
tls:
-1
View File
@@ -1 +0,0 @@
1. compose.metrics.yml now adds prometheus.io/scrape labels so services like monitoring-ng can automatically discover and scrape Traefik's metrics.
+4 -4
View File
@@ -48,6 +48,10 @@ entrypoints:
to: web-secure
web-secure:
address: ":443"
{{ if ne (env "TRUSTED_IPS") "" }}
forwardedHeaders:
trustedIPs: {{ env "TRUSTED_IPS" }}
{{ end }}
transport:
respondingTimeouts:
readTimeout: {{ env "READ_TIMEOUT" }}
@@ -127,10 +131,6 @@ entrypoints:
onion:
address: ":9052"
{{- end }}
{{- if eq (env "METRICS_ENABLED") "1" }}
metrics-internal:
address: ":8082"
{{- end }}
ping:
entryPoint: web