correction
This commit is contained in:
1 parent
851f5f8d03
commit
dd4503218a
10 files changed
+36
-26
No files matched your search
+11
-1
@@ -9,7 +9,7 @@ STATIC_IP=
|
||||
# DOMAIN
|
||||
########################
|
||||
|
||||
DOMAIN='tips-of-mine.fr'
|
||||
ROOT_DOMAIN='tips-of-mine.com'
|
||||
|
||||
########################
|
||||
# NOTIFICATIONS
|
||||
@@ -86,3 +86,13 @@ PORTAINER_ENVIRONMENT=1
|
||||
########################
|
||||
|
||||
WATCHTOWER_API_KEY='insecure_watchtower_api_key'
|
||||
|
||||
########################
|
||||
# CLOUDFLARE
|
||||
########################
|
||||
|
||||
CF_DNS_API_TOKEN=
|
||||
HTTP_TIMEOUT=
|
||||
POLLING_INTERVAL=
|
||||
PROPAGATION_TIMEOUT=
|
||||
TTL=
|
||||
@@ -94,16 +94,16 @@ services:
|
||||
- "homepage.group=Security"
|
||||
- "homepage.name=Authentik"
|
||||
- "homepage.icon=authelia.png"
|
||||
- "homepage.href=https://authentik.tips-of-mine.com/"
|
||||
- "homepage.href=https://authentik.${ROOT_DOMAIN}/"
|
||||
- "homepage.description=Authentication"
|
||||
# Traefik
|
||||
- "traefik.enable=true"
|
||||
- "traefik.docker.network=traefik_front_network"
|
||||
- "traefik.docker.network=front_network"
|
||||
# HTTP
|
||||
- "traefik.http.routers.authentik-http.rule=Host(`authentik.tips-of-mine.com`)"
|
||||
- "traefik.http.routers.authentik-http.rule=Host(`authentik.${ROOT_DOMAIN}`)"
|
||||
- "traefik.http.routers.authentik-http.entrypoints=http"
|
||||
# HTTPS
|
||||
- "traefik.http.routers.authentik-https.rule=Host(`authentik.tips-of-mine.com`)"
|
||||
- "traefik.http.routers.authentik-https.rule=Host(`authentik.${ROOT_DOMAIN}`)"
|
||||
- "traefik.http.routers.authentik-https.entrypoints=https"
|
||||
- "traefik.http.routers.authentik-https.service=authentik-service"
|
||||
- "traefik.http.routers.authentik-https.tls=true"
|
||||
@@ -118,7 +118,7 @@ services:
|
||||
# - "traefik.http.middlewares.authentik-middlewares.headers.browserXSSFilter=true"
|
||||
# - "traefik.http.middlewares.authentik-middlewares.headers.contentTypeNosniff=true"
|
||||
- "traefik.http.middlewares.authentik-middlewares.headers.forceSTSHeader=true"
|
||||
# - "traefik.http.middlewares.authentik-middlewares.headers.SSLHost=tips-of-mine.com"
|
||||
# - "traefik.http.middlewares.authentik-middlewares.headers.SSLHost=${ROOT_DOMAIN}"
|
||||
- "traefik.http.middlewares.authentik-middlewares.headers.STSIncludeSubdomains=true"
|
||||
- "traefik.http.middlewares.authentik-middlewares.headers.STSPreload=true"
|
||||
# Service
|
||||
@@ -162,7 +162,7 @@ services:
|
||||
redis:
|
||||
condition: service_healthy
|
||||
restart: true
|
||||
msmtpd:
|
||||
msmtpd-app:
|
||||
condition: service_healthy
|
||||
restart: true
|
||||
labels:
|
||||
|
||||
@@ -7,7 +7,7 @@ services:
|
||||
volumes:
|
||||
- "./data:/data"
|
||||
environment:
|
||||
- TZ=${TZ}
|
||||
- TZ=${TIMEZONE}
|
||||
- LOG_LEVEL=info
|
||||
- LOG_JSON=false
|
||||
- DIUN_WATCH_WORKERS=20
|
||||
|
||||
+1
-1
@@ -75,7 +75,7 @@ networks:
|
||||
attachable: true
|
||||
ipam:
|
||||
config:
|
||||
- subnet: 10.0.170 .0/24
|
||||
- subnet: 10.0.170.0/24
|
||||
watchtower_network:
|
||||
name: watchtower_network
|
||||
driver: bridge
|
||||
|
||||
@@ -10,7 +10,7 @@ services:
|
||||
environment:
|
||||
- PUID=1000
|
||||
- PGID=1000
|
||||
- TZ=${TZ}
|
||||
- TZ=${TIMEZONE}
|
||||
- HOMEPAGE_ALLOWED_HOSTS=${DOMAIN},${STATIC_IP}:3000
|
||||
volumes:
|
||||
- ./config:/app/config
|
||||
@@ -26,8 +26,8 @@ services:
|
||||
labels:
|
||||
- "com.centurylinklabs.watchtower.enable=true"
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.homepage.rule=Host(`${DOMAIN}`)"
|
||||
- "traefik.http.routers.homepage.entrypoints=websecure"
|
||||
- "traefik.http.routers.homepage.rule=Host(`${ROOT_DOMAIN}`)"
|
||||
- "traefik.http.routers.homepage.entrypoints=https"
|
||||
- "traefik.http.routers.homepage.tls.certresolver=letsencrypt"
|
||||
- "traefik.http.routers.homepage.middlewares=chain-secure-ip@file"
|
||||
- "traefik.http.services.homepage.loadbalancer.server.port=3000"
|
||||
|
||||
@@ -7,13 +7,13 @@ services:
|
||||
ports:
|
||||
- 9100:9000
|
||||
environment:
|
||||
- TZ=${TZ}
|
||||
- TZ=${TIMEZONE}
|
||||
volumes:
|
||||
- portainer_data:/data
|
||||
networks:
|
||||
- homepage_network
|
||||
- socket_proxy_network
|
||||
- traefik_network
|
||||
- front_network
|
||||
- watchtower_network
|
||||
depends_on:
|
||||
- socket-proxy
|
||||
|
||||
@@ -40,8 +40,8 @@ services:
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||
networks:
|
||||
- socket_proxy_network:
|
||||
ipv4_address: 10.0.120.254 # Static IP
|
||||
socket_proxy_network:
|
||||
ipv4_address: 10.0.130.254 # Static IP
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /run
|
||||
|
||||
@@ -5,28 +5,29 @@ http:
|
||||
cloudflarewarp:
|
||||
disableDefault: false
|
||||
trustip:
|
||||
- "172.18.0.1/32"
|
||||
- "10.0.100.0/29"
|
||||
my-crowdsec-bouncer-traefik-plugin:
|
||||
plugin:
|
||||
crowdsec-bouncer-traefik-plugin:
|
||||
enabled: "true"
|
||||
enabled: true
|
||||
crowdsecMode: stream
|
||||
crowdsecLapiScheme: http
|
||||
crowdsecLapiHost: crowdsec-app:8080
|
||||
crowdsecLapiKeyFile: /etc/traefik/lapi-key
|
||||
forwardedHeadersTrustedIPs:
|
||||
- 172.18.0.0/16
|
||||
- 10.0.100.0/29
|
||||
forwardedHeadersCustomName: CF-Connecting-IP
|
||||
clientTrustedIPs:
|
||||
- 10.0.4.0/24
|
||||
- 10.0.5.0/24
|
||||
- 82.66.77.254/32
|
||||
# CrowdsecLapiKey: 4yn3ayFS4V6fvlXFEvVHj2qRUE57Wuww5pT48BD2
|
||||
# CrowdsecLapiKey:
|
||||
# Enabled: "true"
|
||||
my-fail2ban:
|
||||
plugin:
|
||||
fail2ban:
|
||||
allowlist:
|
||||
ip: ::1,127.0.0.1,10.0.4.0/24
|
||||
ip: ::1,127.0.0.1,10.0.4.0/24,10.0.5.0/24
|
||||
denylist:
|
||||
ip: 192.168.0.0/24
|
||||
rules:
|
||||
@@ -63,7 +64,7 @@ http:
|
||||
hsts-headers:
|
||||
headers:
|
||||
frameDeny: true
|
||||
sslRedirect: true
|
||||
# sslRedirect: true
|
||||
browserXssFilter: true
|
||||
contentTypeNosniff: true
|
||||
stsIncludeSubdomains: true
|
||||
@@ -72,7 +73,7 @@ http:
|
||||
forceStsHeader: true
|
||||
referrerPolicy: same-origin
|
||||
customResponseHeaders:
|
||||
permissions-Policy: vibrate=(self), geolocation=(self), midi=(self), notifications=(self), push=(self), microphone=(), $
|
||||
Permissions-Policy: vibrate=(self), geolocation=(self), midi=(self), notifications=(self), push=(self), microphone=(), camera=(), magnetometer=(), gyroscope=(), speaker=(self), payment=(), usb=(), accelerometer=(), fullscreen=(self)
|
||||
X-Permitted-Cross-Domain-Policies: none
|
||||
expect-ct: max-age=604800, report-uri="https://oak.ct.letsencrypt.org/2021"
|
||||
##########################################
|
||||
@@ -162,4 +163,4 @@ http:
|
||||
# chain:
|
||||
# middlewares:
|
||||
# - default-whitelist
|
||||
# - default-headers
|
||||
# - default-headers
|
||||
@@ -188,4 +188,3 @@ experimental:
|
||||
cloudflarewarp:
|
||||
moduleName: "github.com/BetterCorp/cloudflarewarp"
|
||||
version: "v1.3.3"
|
||||
root@SLDOKP03:/opt/traefik#
|
||||
@@ -38,7 +38,7 @@ services:
|
||||
- CLOUDFLARE_TTL=${TTL}
|
||||
networks:
|
||||
- back_network:
|
||||
ipv4_address: 10.0.111.254 # Static IP
|
||||
ipv4_address: 10.0.120.254 # Static IP
|
||||
- front_network:
|
||||
ipv4_address: 10.0.110.254 # Static IP
|
||||
- cloudflare_network
|
||||
|
||||
Reference in new issue
Block a user