correction a encore valider
Compose CI / lint-ci-scripts (push) Successful in 7s
Compose CI / compose-verify (push) Failing after 39s

This commit is contained in:
hcornet committed 2026-09-18 12:33:30 +02:00
1 parent 814a099b12
commit 4492e7fb60
2 files changed
+51 -30

No files matched your search

+10 -2
View File
@@ -80,7 +80,11 @@ entryPoints:
address: ":8200"
forwardedHeaders:
trustedIPs:
- 0.0.0.0/0
- 10.0.100.0/29
http:
middlewares:
- lan-only@file
tls: {}
# elasticsearch:
# address: ":9200"
metrics:
@@ -97,6 +101,7 @@ providers:
docker:
endpoint: "unix:///var/run/docker.sock"
exposedByDefault: false
network: traefik_front_network
watch: true
file:
directory: /etc/traefik/dynamic
@@ -132,11 +137,14 @@ api:
insecure: false
dashboard: true
ping:
entryPoint: metrics
log:
level: INFO
filepath: "/var/log/traefik/traefik.log"
format: json
# default: "common"
accesslog:
# level: INFO
+41 -28
View File
@@ -13,19 +13,22 @@ networks:
- subnet: 10.0.110.0/24
socket_proxy_network:
driver: bridge
attachable: true
name: socket_proxy_network
internal: true
ipam:
config:
- subnet: 10.0.120.0/29
- subnet: 10.0.120.0/24
cloudflare_network:
driver: bridge
name: cloudflare_network
ipam:
config:
- subnet: 10.0.100.0/29
monitoring_network:
external: true
name: monitoring_network
### Volumes
#volumes:
# traefik-logs:
### services
services:
@@ -36,18 +39,18 @@ services:
image: traefik:latest
restart: always
ports:
# - "22:22"
- "80:80"
- "443:443"
- "8181:8181"
- "9090:9090"
- "9091:9091/udp"
# - "3841:3841"
# - "25:25" # SMTP (explicit TLS => STARTTLS, Authentication is DISABLED => use port 465/587 instead)
# - "143:143" # IMAP4 (explicit TLS => STARTTLS)
# - "465:465" # ESMTP (implicit TLS)
# - "587:587" # ESMTP (explicit TLS => STARTTLS)
# - "993:993" # IMAP4 (implicit TLS)
# - "22:22" # SSH
- "80:80" # HTTP
- "443:443" # HTTPS
- "8181:8181" #
- "9090:9090" #
- "9091:9091/udp" #
# - "3841:3841" #
# - "25:25" # SMTP (explicit TLS => STARTTLS, Authentication is DISABLED => use port 465/587 instead)
# - "143:143" # IMAP4 (explicit TLS => STARTTLS)
# - "465:465" # ESMTP (implicit TLS)
# - "587:587" # ESMTP (explicit TLS => STARTTLS)
# - "993:993" # IMAP4 (implicit TLS)
volumes:
- "/var/run/docker.sock:/var/run/docker.sock:ro"
- "/etc/localtime:/etc/localtime:ro"
@@ -61,7 +64,6 @@ services:
- "./crowdsec/lapi-key:/etc/traefik/lapi-key:ro"
environment:
- CF_DNS_API_TOKEN=${CF_DNS_API_TOKEN}
# - CLOUDFLARE_DNS_API_TOKEN_FILE=/run/secrets/cf_token
- CLOUDFLARE_HTTP_TIMEOUT=${HTTP_TIMEOUT}
- CLOUDFLARE_POLLING_INTERVAL=${POLLING_INTERVAL}
- CLOUDFLARE_PROPAGATION_TIMEOUT=${PROPAGATION_TIMEOUT}
@@ -70,6 +72,13 @@ services:
- back_network
- front_network
- cloudflare_network
- monitoring_network
healthcheck:
test: ["CMD", "traefik", "healthcheck", "--ping"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
labels:
- "com.centurylinklabs.watchtower.enable=true"
- "fathom.vault.CF_DNS_API_TOKEN=secret/cloudflare"
@@ -103,8 +112,6 @@ services:
- TUNNEL_TOKEN=${CF_TUNNEL_TOKEN}
networks:
- cloudflare_network
labels:
- "com.centurylinklabs.watchtower.enable=true"
security_opt:
- no-new-privileges
cap_drop:
@@ -122,6 +129,8 @@ services:
reservations:
cpus: '0.25'
memory: 256M
labels:
- "com.centurylinklabs.watchtower.enable=true"
### Crowdsec:
crowdsec:
@@ -129,20 +138,24 @@ services:
hostname: crowdsec-app
image: crowdsecurity/crowdsec:latest
restart: unless-stopped
# ports:
# - "8090:8080"
environment:
COLLECTIONS: "crowdsecurity/linux crowdsecurity/traefik"
GID: "1000"
# depends_on:
# - "reverse-proxy"
volumes:
- "./crowdsec/acquis.yaml:/etc/crowdsec/acquis.yaml"
- "./logs:/var/log/traefik/:ro"
- "./crowdsec-db:/var/lib/crowdsec/data/"
- "./crowdsec-config:/etc/crowdsec/"
environment:
COLLECTIONS: "crowdsecurity/linux crowdsecurity/traefik"
GID: "1000"
PROMETHEUS: "true"
networks:
- back_network
- monitoring_network
healthcheck:
test: ["CMD", "cscli", "lapi", "status"]
interval: 30s
timeout: 10s
retries: 3
start_period: 60s
### socket-proxy:
socket-proxy:
@@ -150,14 +163,14 @@ services:
hostname: socket-proxy
image: ghcr.io/tecnativa/docker-socket-proxy:latest
restart: always
security_opt:
- no-new-privileges:true
environment:
- CONTAINERS=1
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
networks:
- socket_proxy_network
security_opt:
- no-new-privileges:true
labels:
- "com.centurylinklabs.watchtower.enable=true"
- "fathom.exempt.socket-docker=proxy de socket filtrant, c'est sa raison d'etre"