correction

This commit is contained in:
hcornet committed 2026-09-19 22:36:47 +02:00
1 parent 851f5f8d03
commit dd4503218a
10 files changed
+36 -26

No files matched your search

+11 -1
View File
@@ -9,7 +9,7 @@ STATIC_IP=
# DOMAIN
########################
DOMAIN='tips-of-mine.fr'
ROOT_DOMAIN='tips-of-mine.com'
########################
# NOTIFICATIONS
@@ -86,3 +86,13 @@ PORTAINER_ENVIRONMENT=1
########################
WATCHTOWER_API_KEY='insecure_watchtower_api_key'
########################
# CLOUDFLARE
########################
CF_DNS_API_TOKEN=
HTTP_TIMEOUT=
POLLING_INTERVAL=
PROPAGATION_TIMEOUT=
TTL=
+6 -6
View File
@@ -94,16 +94,16 @@ services:
- "homepage.group=Security"
- "homepage.name=Authentik"
- "homepage.icon=authelia.png"
- "homepage.href=https://authentik.tips-of-mine.com/"
- "homepage.href=https://authentik.${ROOT_DOMAIN}/"
- "homepage.description=Authentication"
# Traefik
- "traefik.enable=true"
- "traefik.docker.network=traefik_front_network"
- "traefik.docker.network=front_network"
# HTTP
- "traefik.http.routers.authentik-http.rule=Host(`authentik.tips-of-mine.com`)"
- "traefik.http.routers.authentik-http.rule=Host(`authentik.${ROOT_DOMAIN}`)"
- "traefik.http.routers.authentik-http.entrypoints=http"
# HTTPS
- "traefik.http.routers.authentik-https.rule=Host(`authentik.tips-of-mine.com`)"
- "traefik.http.routers.authentik-https.rule=Host(`authentik.${ROOT_DOMAIN}`)"
- "traefik.http.routers.authentik-https.entrypoints=https"
- "traefik.http.routers.authentik-https.service=authentik-service"
- "traefik.http.routers.authentik-https.tls=true"
@@ -118,7 +118,7 @@ services:
# - "traefik.http.middlewares.authentik-middlewares.headers.browserXSSFilter=true"
# - "traefik.http.middlewares.authentik-middlewares.headers.contentTypeNosniff=true"
- "traefik.http.middlewares.authentik-middlewares.headers.forceSTSHeader=true"
# - "traefik.http.middlewares.authentik-middlewares.headers.SSLHost=tips-of-mine.com"
# - "traefik.http.middlewares.authentik-middlewares.headers.SSLHost=${ROOT_DOMAIN}"
- "traefik.http.middlewares.authentik-middlewares.headers.STSIncludeSubdomains=true"
- "traefik.http.middlewares.authentik-middlewares.headers.STSPreload=true"
# Service
@@ -162,7 +162,7 @@ services:
redis:
condition: service_healthy
restart: true
msmtpd:
msmtpd-app:
condition: service_healthy
restart: true
labels:
+1 -1
View File
@@ -7,7 +7,7 @@ services:
volumes:
- "./data:/data"
environment:
- TZ=${TZ}
- TZ=${TIMEZONE}
- LOG_LEVEL=info
- LOG_JSON=false
- DIUN_WATCH_WORKERS=20
+1 -1
View File
@@ -75,7 +75,7 @@ networks:
attachable: true
ipam:
config:
- subnet: 10.0.170 .0/24
- subnet: 10.0.170.0/24
watchtower_network:
name: watchtower_network
driver: bridge
+3 -3
View File
@@ -10,7 +10,7 @@ services:
environment:
- PUID=1000
- PGID=1000
- TZ=${TZ}
- TZ=${TIMEZONE}
- HOMEPAGE_ALLOWED_HOSTS=${DOMAIN},${STATIC_IP}:3000
volumes:
- ./config:/app/config
@@ -26,8 +26,8 @@ services:
labels:
- "com.centurylinklabs.watchtower.enable=true"
- "traefik.enable=true"
- "traefik.http.routers.homepage.rule=Host(`${DOMAIN}`)"
- "traefik.http.routers.homepage.entrypoints=websecure"
- "traefik.http.routers.homepage.rule=Host(`${ROOT_DOMAIN}`)"
- "traefik.http.routers.homepage.entrypoints=https"
- "traefik.http.routers.homepage.tls.certresolver=letsencrypt"
- "traefik.http.routers.homepage.middlewares=chain-secure-ip@file"
- "traefik.http.services.homepage.loadbalancer.server.port=3000"
+2 -2
View File
@@ -7,13 +7,13 @@ services:
ports:
- 9100:9000
environment:
- TZ=${TZ}
- TZ=${TIMEZONE}
volumes:
- portainer_data:/data
networks:
- homepage_network
- socket_proxy_network
- traefik_network
- front_network
- watchtower_network
depends_on:
- socket-proxy
+2 -2
View File
@@ -40,8 +40,8 @@ services:
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
networks:
- socket_proxy_network:
ipv4_address: 10.0.120.254 # Static IP
socket_proxy_network:
ipv4_address: 10.0.130.254 # Static IP
read_only: true
tmpfs:
- /run
@@ -5,28 +5,29 @@ http:
cloudflarewarp:
disableDefault: false
trustip:
- "172.18.0.1/32"
- "10.0.100.0/29"
my-crowdsec-bouncer-traefik-plugin:
plugin:
crowdsec-bouncer-traefik-plugin:
enabled: "true"
enabled: true
crowdsecMode: stream
crowdsecLapiScheme: http
crowdsecLapiHost: crowdsec-app:8080
crowdsecLapiKeyFile: /etc/traefik/lapi-key
forwardedHeadersTrustedIPs:
- 172.18.0.0/16
- 10.0.100.0/29
forwardedHeadersCustomName: CF-Connecting-IP
clientTrustedIPs:
- 10.0.4.0/24
- 10.0.5.0/24
- 82.66.77.254/32
# CrowdsecLapiKey: 4yn3ayFS4V6fvlXFEvVHj2qRUE57Wuww5pT48BD2
# CrowdsecLapiKey:
# Enabled: "true"
my-fail2ban:
plugin:
fail2ban:
allowlist:
ip: ::1,127.0.0.1,10.0.4.0/24
ip: ::1,127.0.0.1,10.0.4.0/24,10.0.5.0/24
denylist:
ip: 192.168.0.0/24
rules:
@@ -63,7 +64,7 @@ http:
hsts-headers:
headers:
frameDeny: true
sslRedirect: true
# sslRedirect: true
browserXssFilter: true
contentTypeNosniff: true
stsIncludeSubdomains: true
@@ -72,7 +73,7 @@ http:
forceStsHeader: true
referrerPolicy: same-origin
customResponseHeaders:
permissions-Policy: vibrate=(self), geolocation=(self), midi=(self), notifications=(self), push=(self), microphone=(), $
Permissions-Policy: vibrate=(self), geolocation=(self), midi=(self), notifications=(self), push=(self), microphone=(), camera=(), magnetometer=(), gyroscope=(), speaker=(self), payment=(), usb=(), accelerometer=(), fullscreen=(self)
X-Permitted-Cross-Domain-Policies: none
expect-ct: max-age=604800, report-uri="https://oak.ct.letsencrypt.org/2021"
##########################################
@@ -162,4 +163,4 @@ http:
# chain:
# middlewares:
# - default-whitelist
# - default-headers
# - default-headers
-1
View File
@@ -188,4 +188,3 @@ experimental:
cloudflarewarp:
moduleName: "github.com/BetterCorp/cloudflarewarp"
version: "v1.3.3"
root@SLDOKP03:/opt/traefik#
+1 -1
View File
@@ -38,7 +38,7 @@ services:
- CLOUDFLARE_TTL=${TTL}
networks:
- back_network:
ipv4_address: 10.0.111.254 # Static IP
ipv4_address: 10.0.120.254 # Static IP
- front_network:
ipv4_address: 10.0.110.254 # Static IP
- cloudflare_network