From 45ce789f585f137c5e6d691ccf1e606e116f12e4 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Mon, 19 Jan 2026 23:33:50 +0100 Subject: [PATCH] chore: compose cleanup: - Remove TZ envs - +- unified compose structure - Minify where possible - Remove .internal routers - Remove service specifications where possible Affected services: - adguardhome - authentik - cfddns - checkmk - dockmon - downtify - gitea - glance - headscale - homepages - metube - nextcloud - penpot - portainer - termix - traefik - uptime-kuma TODO: Move data from directory to volumes --- adguardhome/compose.yaml | 22 ++++++++-------------- authentik/compose.yaml | 11 +++-------- cfddns/compose.yaml | 2 +- checkmk/compose.yaml | 24 ++++++++---------------- dockmon/compose.yaml | 21 +++++++-------------- downtify/compose.yaml | 12 +++--------- gitea/compose.yaml | 26 ++++++++++---------------- glance/compose.yaml | 8 ++------ headscale/compose.yaml | 13 ++++--------- homepages/compose.yaml | 26 +++++--------------------- metube/compose.yaml | 14 ++++---------- nextcloud/compose.yaml | 12 ++---------- penpot/compose.yaml | 11 ++--------- portainer/compose.yaml | 19 +++++-------------- termix/compose.yaml | 14 +++----------- traefik/compose.yaml | 22 +++++++--------------- uptime-kuma/compose.yaml | 10 ++++------ 17 files changed, 78 insertions(+), 189 deletions(-) diff --git a/adguardhome/compose.yaml b/adguardhome/compose.yaml index 503a82d..03ab0c6 100644 --- a/adguardhome/compose.yaml +++ b/adguardhome/compose.yaml @@ -14,43 +14,37 @@ services: - ./data/work:/opt/adguardhome/work - ./data/conf:/opt/adguardhome/conf - ./certs:/certs:ro - networks: - - proxy labels: - "traefik.enable=true" - "traefik.docker.network=proxy" - "traefik.http.services.adguard.loadbalancer.server.port=3000" - + # Prod Router - "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)" - "traefik.http.routers.adguard.entrypoints=websecure" - "traefik.http.routers.adguard.middlewares=security-headers@file" - - "traefik.http.routers.adguard.service=adguard" - "traefik.http.routers.adguard.tls=true" - # Local Router - - "traefik.http.routers.adguard-local.rule=Host(`dns.workstation.internal`) || Host(`adguard.internal`) || Host(`adguard.workstation.internal`)" + - "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)" - "traefik.http.routers.adguard-local.entrypoints=websecure" - "traefik.http.routers.adguard-local.middlewares=security-headers@file" - - "traefik.http.routers.adguard-local.service=adguard" - "traefik.http.routers.adguard-local.tls=true" - # Dev Router - - "traefik.http.routers.adguard-dev.rule=Host(`dns.gigaforust.internal`) || Host(`adguard.gigaforust.internal`)" + - "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) Host(`dns.gigaforust.internal`)" - "traefik.http.routers.adguard-dev.entrypoints=websecure" - "traefik.http.routers.adguard-dev.middlewares=security-headers@file" - - "traefik.http.routers.adguard-dev.service=adguard" - "traefik.http.routers.adguard-dev.tls=true" - - # DoH + # DoH Router - "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))" - "traefik.http.routers.dns.entrypoints=websecure" - - "traefik.http.routers.dns.service=adguard" - "traefik.http.routers.dns.tls.certresolver=letsencrypt" - + + # Glance Metadata - glance.name=adguard - glance.url=https://adguard.forust.xyz/ - glance.description=AdGuard Home is a network-wide software for blocking ads. + networks: + - proxy networks: proxy: external: true diff --git a/authentik/compose.yaml b/authentik/compose.yaml index 4acee8e..ca933cd 100644 --- a/authentik/compose.yaml +++ b/authentik/compose.yaml @@ -37,12 +37,12 @@ services: AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS} AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik} AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required} - + volumes: + - ./media:/media + - ./custom-templates:/templates labels: - "traefik.enable=true" - "traefik.docker.network=proxy" - # Services - # - "traefik.http.services.authentik-server.loadbalancer.server.port=9443" - "traefik.http.services.authentik-server.loadbalancer.server.port=9000" # Prod Router @@ -51,23 +51,18 @@ services: - "traefik.http.routers.authentik-server.middlewares=security-headers@file" - "traefik.http.routers.authentik-server.service=authentik-server" - "traefik.http.routers.authentik-server.tls=true" - # Local Router - "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`) || Host(`auth-dashboard.internal`)" - "traefik.http.routers.authentik-server-local.entrypoints=websecure" - "traefik.http.routers.authentik-server-local.middlewares=security-headers@file" - "traefik.http.routers.authentik-server-local.service=authentik-server" - "traefik.http.routers.authentik-server-local.tls=true" - # Dev Router - "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)" - "traefik.http.routers.authentik-server-dev.entrypoints=websecure" - "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file" - "traefik.http.routers.authentik-server-dev.service=authentik-server" - "traefik.http.routers.authentik-server-dev.tls=true" - volumes: - - ./media:/media - - ./custom-templates:/templates networks: - proxy - authentik diff --git a/cfddns/compose.yaml b/cfddns/compose.yaml index 8c3a0f3..d5d4426 100644 --- a/cfddns/compose.yaml +++ b/cfddns/compose.yaml @@ -2,6 +2,7 @@ services: cloudflare-ddns: image: timothyjmiller/cloudflare-ddns:latest container_name: cloudflare-ddns + restart: unless-stopped security_opt: - no-new-privileges:true network_mode: 'host' @@ -10,4 +11,3 @@ services: - PGID=1000 volumes: - ./config.json:/config.json - restart: unless-stopped diff --git a/checkmk/compose.yaml b/checkmk/compose.yaml index 5cc9cc0..e44f4e8 100644 --- a/checkmk/compose.yaml +++ b/checkmk/compose.yaml @@ -2,18 +2,17 @@ services: checkmk: image: "checkmk/check-mk-raw:2.4.0-latest" container_name: "checkmk" - environment: - - CMK_PASSWORD=${CMK_PASSWORD:-password} - - CMK_SITE_ID=cmk - + restart: unless-stopped + # ports: + # - 5000:5000 + # - 6776:8000 volumes: - sites:/omd/sites tmpfs: - /opt/omd/sites/cmk/tmp:uid=1000,gid=1000 - ports: - - 5000:5000 - - 6776:8000 - restart: unless-stopped + environment: + - CMK_PASSWORD=${CMK_PASSWORD:-password} + - CMK_SITE_ID=cmk labels: - "traefik.enable=true" - "traefik.docker.network=proxy" @@ -22,27 +21,20 @@ services: # Prod Router - "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)" - "traefik.http.routers.checkmk.entrypoints=websecure" - - "traefik.http.routers.checkmk.service=checkmk" - "traefik.http.routers.checkmk.middlewares=security-headers@file" - "traefik.http.routers.checkmk.tls=true" - # Local Router - - "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`) || Host(`cmk.internal`)" + - "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)" - "traefik.http.routers.checkmk-local.entrypoints=websecure" - - "traefik.http.routers.checkmk-local.service=checkmk" - "traefik.http.routers.checkmk-local.middlewares=security-headers@file" - "traefik.http.routers.checkmk-local.tls=true" - # Dev Router - "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)" - "traefik.http.routers.checkmk-dev.middlewares=security-headers@file" - - "traefik.http.routers.checkmk-dev.service=checkmk" - "traefik.http.routers.checkmk-dev.entrypoints=websecure" - "traefik.http.routers.checkmk-dev.tls=true" - networks: - proxy - networks: proxy: external: true diff --git a/dockmon/compose.yaml b/dockmon/compose.yaml index b7f11de..a0e7e36 100644 --- a/dockmon/compose.yaml +++ b/dockmon/compose.yaml @@ -3,10 +3,8 @@ services: image: darthnorse/dockmon:latest container_name: dockmon restart: unless-stopped - ports: - - 8000:443 - environment: - - TZ=Europe/Bratislava + # ports: + # - 8000:443 volumes: - ./data:/app/data - /var/run/docker.sock:/var/run/docker.sock @@ -15,11 +13,10 @@ services: interval: 30s timeout: 10s retries: 3 - networks: - - proxy labels: - "traefik.enable=true" - "traefik.docker.network=proxy" + - "traefik.http.services.dockmon.loadbalancer.server.port=443" # Prod Router - "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)" @@ -27,27 +24,23 @@ services: - "traefik.http.routers.dockmon.middlewares=security-chain@file" - "traefik.http.routers.dockmon.service=dockmon" - "traefik.http.routers.dockmon.tls=true" - - "traefik.http.services.dockmon.loadbalancer.server.port=443" - - "traefik.http.services.dockmon.loadbalancer.server.scheme=https" - - "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file" - # Local Router - - "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`) || Host(`dockmon.internal`)" + - "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)" - "traefik.http.routers.dockmon-local.entrypoints=websecure" - "traefik.http.routers.dockmon-local.middlewares=security-headers@file" - - "traefik.http.routers.dockmon-local.service=dockmon" - "traefik.http.routers.dockmon-local.tls=true" - # Dev Router - "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)" - "traefik.http.routers.dockmon-dev.entrypoints=websecure" - "traefik.http.routers.dockmon-dev.middlewares=security-chain@file" - - "traefik.http.routers.dockmon-dev.service=dockmon" - "traefik.http.routers.dockmon-dev.tls=true" + # Glance Metadata - glance.name=dockmon - glance.url=https://dockmon.forust.xyz/ - glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface. + networks: + - proxy networks: proxy: diff --git a/downtify/compose.yaml b/downtify/compose.yaml index f507091..b20b9ab 100644 --- a/downtify/compose.yaml +++ b/downtify/compose.yaml @@ -4,36 +4,30 @@ services: image: ghcr.io/henriquesebastiao/downtify:latest # ports: # - '7077:8000' + volumes: + - ./Downtify_downloads:/downloads labels: - traefik.enable=true + - traefik.docker.network=proxy - traefik.http.services.downtify.loadbalancer.server.port=8000 # Prod Router - traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`) - traefik.http.routers.downtify.entrypoints=websecure - traefik.http.routers.downtify.middlewares=security-chain@file - - traefik.http.routers.downtify.service=downtify - traefik.http.routers.downtify.tls=true - # Local Router - traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`) || Host(`downtify.internal`) - traefik.http.routers.downtify-local.entrypoints=websecure - traefik.http.routers.downtify-local.middlewares=security-headers@file - - traefik.http.routers.downtify-local.service=downtify - traefik.http.routers.downtify-local.tls=true - # Dev Router - traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`) - traefik.http.routers.downtify-dev.entrypoints=websecure - traefik.http.routers.downtify-dev.middlewares=security-chain@file - - traefik.http.routers.downtify-dev.service=downtify - traefik.http.routers.downtify-dev.tls=true networks: - proxy - - volumes: - - ./Downtify_downloads:/downloads - networks: proxy: external: true diff --git a/gitea/compose.yaml b/gitea/compose.yaml index 16ca04f..fefac70 100644 --- a/gitea/compose.yaml +++ b/gitea/compose.yaml @@ -2,6 +2,7 @@ services: server: image: docker.gitea.com/gitea:1.25.1 container_name: gitea + restart: always environment: - USER_UID=1000 - USER_GID=1000 @@ -24,10 +25,6 @@ services: - GITEA__mailer__PROTOCOL=SMTP - GITEA__service__REGISTER_EMAIL_CONFIRM=true - GITEA__service__ENABLE_NOTIFY_MAIL=true - restart: always - networks: - - gitea-db - - proxy volumes: - ./gitea-data:/data - /etc/timezone:/etc/timezone:ro @@ -35,36 +32,34 @@ services: labels: - "traefik.enable=true" - "traefik.docker.network=proxy" + - "traefik.http.services.gitea.loadbalancer.server.port=3000" # Prod Router - "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)" - "traefik.http.routers.gitea.entrypoints=websecure" - "traefik.http.routers.gitea.middlewares=security-headers@file" - - "traefik.http.routers.gitea.service=gitea" - "traefik.http.routers.gitea.tls=true" - - "traefik.http.services.gitea.loadbalancer.server.port=3000" - # Local Router - - "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`) || Host(`gitea.internal`)" + - "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`)" - "traefik.http.routers.gitea-local.entrypoints=websecure" - "traefik.http.routers.gitea-local.middlewares=security-headers@file" - - "traefik.http.routers.gitea-local.service=gitea" - "traefik.http.routers.gitea-local.tls=true" - # Dev Router - "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)" - "traefik.http.routers.gitea-dev.entrypoints=websecure" - "traefik.http.routers.gitea-dev.middlewares=security-headers@file" - - "traefik.http.routers.gitea-dev.service=gitea" - "traefik.http.routers.gitea-dev.tls=true" + # SSH Router + - "traefik.tcp.services.gitea.loadbalancer.server.port=22" - "traefik.tcp.routers.gitea.entrypoints=ssh" - "traefik.tcp.routers.gitea.rule=HostSNI(`*`)" - - "traefik.tcp.services.gitea.loadbalancer.server.port=22" ports: - "2221:22" + networks: + - gitea-db + - proxy depends_on: - db - db: image: docker.io/library/postgres:14 restart: always @@ -72,11 +67,10 @@ services: - POSTGRES_USER=gitea - POSTGRES_PASSWORD=gitea - POSTGRES_DB=gitea - networks: - - gitea-db volumes: - ./gitea-db/:/var/lib/postgresql/data - + networks: + - gitea-db networks: gitea-db: external: false diff --git a/glance/compose.yaml b/glance/compose.yaml index 2ebc851..dc1ec97 100644 --- a/glance/compose.yaml +++ b/glance/compose.yaml @@ -12,19 +12,18 @@ services: labels: - "traefik.enable=true" - "traefik.docker.network=proxy" + # FIXME: traefik.services.glance.loadbalancer.server.port ?? # Prod Router - "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)" - "traefik.http.routers.glance.entrypoints=websecure" - "traefik.http.routers.glance.middlewares=security-headers@file" - "traefik.http.routers.glance.tls=true" - # Local Router - - "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`) || Host(`glance.internal`)" + - "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`)" - "traefik.http.routers.glance-local.entrypoints=websecure" - "traefik.http.routers.glance-local.middlewares=security-headers@file" - "traefik.http.routers.glance-local.tls=true" - # Dev Router - "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)" - "traefik.http.routers.glance-dev.entrypoints=websecure" @@ -32,9 +31,6 @@ services: - "traefik.http.routers.glance-dev.tls=true" networks: - proxy - dns: - - 1.1.1.1 - - 8.8.8.8 networks: proxy: external: true \ No newline at end of file diff --git a/headscale/compose.yaml b/headscale/compose.yaml index e4c299e..de0bc37 100644 --- a/headscale/compose.yaml +++ b/headscale/compose.yaml @@ -47,14 +47,9 @@ services: - "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure" - "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics" - "traefik.http.routers.headscale-metrics-dev.tls=true" - dns: - - 1.1.1.1 - - 1.0.0.1 web: image: goodieshq/headscale-admin:latest restart: unless-stopped - networks: - - proxy labels: - "traefik.enable=true" - "treafik.docker.network=proxy" @@ -64,21 +59,21 @@ services: - "traefik.http.routers.headscale-ui.rule=Host(`hs.forust.xyz`) && PathPrefix(`/admin`)" - "traefik.http.routers.headscale-ui.entrypoints=websecure" - "traefik.http.routers.headscale-ui.middlewares=security-chain@file" - - "traefik.http.routers.headscale-ui.service=headscale-ui" - "traefik.http.routers.headscale-ui.tls=true" # Local Router - "traefik.http.routers.headscale-ui-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/admin`)" - "traefik.http.routers.headscale-ui-local.entrypoints=websecure" - "traefik.http.routers.headscale-ui-local.middlewares=security-chain@file" - - "traefik.http.routers.headscale-ui-local.service=headscale-ui" - "traefik.http.routers.headscale-ui-local.tls=true" # Dev Router - "traefik.http.routers.headscale-ui-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/admin`)" - "traefik.http.routers.headscale-ui-dev.entrypoints=websecure" - "traefik.http.routers.headscale-ui-dev.middlewares=security-chain@file" - - "traefik.http.routers.headscale-ui-dev.service=headscale-ui" - "traefik.http.routers.headscale-ui-dev.tls=true" - + networks: + - proxy +volumes: + headscale-data: networks: proxy: external: true diff --git a/homepages/compose.yaml b/homepages/compose.yaml index 17c3fac..9187c0d 100644 --- a/homepages/compose.yaml +++ b/homepages/compose.yaml @@ -13,70 +13,54 @@ services: labels: - "traefik.enable=true" - "traefik.docker.network=proxy" - - # Services - "traefik.http.services.forust-homepage.loadbalancer.server.port=80" # Prod Router - "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)" - "traefik.http.routers.forust-homepage.entrypoints=websecure" - "traefik.http.routers.forust-homepage.middlewares=security-headers@file" - - "traefik.http.routers.forust-homepage.service=forust-homepage" - "traefik.http.routers.forust-homepage.tls=true" - # Local Router - - "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`) || Host(`landing.internal`)" + - "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`)" - "traefik.http.routers.forust-homepage-local.entrypoints=websecure" - "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file" - - "traefik.http.routers.forust-homepage-local.service=forust-homepage" - "traefik.http.routers.forust-homepage-local.tls=true" - # Dev Router - "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)" - "traefik.http.routers.forust-homepage-dev.entrypoints=websecure" - "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file" - - "traefik.http.routers.forust-homepage-dev.service=forust-homepage" - "traefik.http.routers.forust-homepage-dev.tls=true" - xdfnx: build: context: . dockerfile: Dockerfile.xdfnx + restart: unless-stopped # ports: # - "8086:80" - restart: unless-stopped volumes: - ./xdfnx_files:/usr/share/nginx/html - networks: - - proxy labels: - "traefik.enable=true" - "traefik.docker.network=proxy" - - # Services - "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80" # Prod Router - "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)" - "traefik.http.routers.xdfnx.entrypoints=websecure" - "traefik.http.routers.xdfnx.middlewares=security-headers@file" - - "traefik.http.routers.xdfnx.service=xdfnx-homepage" - "traefik.http.routers.xdfnx.tls=true" - # Local Router - - "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`) || Host(`xdfnx.internal`)" + - "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`)" - "traefik.http.routers.xdfnx-local.entrypoints=websecure" - "traefik.http.routers.xdfnx-local.middlewares=security-headers@file" - - "traefik.http.routers.xdfnx-local.service=xdfnx-homepage" - "traefik.http.routers.xdfnx-local.tls=true" - # Dev Router - "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)" - "traefik.http.routers.xdfnx-dev.entrypoints=websecure" - "traefik.http.routers.xdfnx-dev.middlewares=security-headers@file" - - "traefik.http.routers.xdfnx-dev.service=xdfnx-homepage" - "traefik.http.routers.xdfnx-dev.tls=true" - + networks: + - proxy networks: proxy: external: true diff --git a/metube/compose.yaml b/metube/compose.yaml index 47490eb..a4714e3 100644 --- a/metube/compose.yaml +++ b/metube/compose.yaml @@ -1,7 +1,7 @@ services: metube: image: ghcr.io/alexta69/metube - # container_name: metube + container_name: metube restart: unless-stopped # ports: # - "8081:8081" @@ -13,31 +13,25 @@ services: volumes: - ./MeTube_downloads:/downloads labels: - - traefik.enable=true + - "traefik.enable=true" - "traefik.docker.network=proxy" + - "traefik.http.services.metube.loadbalancer.server.port=8081" # Prod Router - "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)" - "traefik.http.routers.metube.entrypoints=websecure" - "traefik.http.routers.metube.middlewares=security-chain@file" - - "traefik.http.routers.metube.service=metube" - "traefik.http.routers.metube.tls=true" - - "traefik.http.services.metube.loadbalancer.server.port=8081" - # Local Router - - "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`) || Host(`metube.internal`)" + - "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`))" - "traefik.http.routers.metube-local.entrypoints=websecure" - "traefik.http.routers.metube-local.middlewares=security-headers@file" - - "traefik.http.routers.metube-local.service=metube" - "traefik.http.routers.metube-local.tls=true" - # Dev Router - "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)" - "traefik.http.routers.metube-dev.entrypoints=websecure" - "traefik.http.routers.metube-dev.middlewares=security-chain@file" - - "traefik.http.routers.metube-dev.service=metube" - "traefik.http.routers.metube-dev.tls=true" - networks: - proxy networks: diff --git a/nextcloud/compose.yaml b/nextcloud/compose.yaml index fa087c4..0fb2fa3 100644 --- a/nextcloud/compose.yaml +++ b/nextcloud/compose.yaml @@ -18,10 +18,8 @@ services: labels: - "traefik.enable=true" - "traefik.docker.network=proxy" - # AIO Services configuration - "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080" - - "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https" - "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file" # Prod Router @@ -30,27 +28,21 @@ services: # - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file" # - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio" # - "traefik.http.routers.nextcloud-aio.tls=true" - # Local Router - - "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`) || Host(`nextcloud-aio.internal`)" + - "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`)" - "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure" - "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file" - - "traefik.http.routers.nextcloud-aio-local.service=nextcloud-aio" - "traefik.http.routers.nextcloud-aio-local.tls=true" - # Dev Router - "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)" - "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure" - "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file" - - "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio" - "traefik.http.routers.nextcloud-aio-dev.tls=true" - # Glanceapp/glance config + # Glance Metadata - glance.name=Nextcloud - # - glance.icon=si:nextcloud - glance.url=https://nextcloud.forust.xyz/ - glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services. - environment: AIO_DISABLE_BACKUP_SECTION: false APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md diff --git a/penpot/compose.yaml b/penpot/compose.yaml index 3f1c5d8..9f50231 100644 --- a/penpot/compose.yaml +++ b/penpot/compose.yaml @@ -103,32 +103,25 @@ services: labels: - "traefik.enable=true" - "traefik.docker.network=proxy" + - "traefik.http.services.penpot.loadbalancer.server.port=8080" # Prod Router - "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)" - "traefik.http.routers.penpot.entrypoints=websecure" - "traefik.http.routers.penpot.middlewares=security-headers@file" - - "traefik.http.routers.penpot.service=penpot" - "traefik.http.routers.penpot.tls=true" - - "traefik.http.services.penpot.loadbalancer.server.port=8080" - # Local Router - - "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`) || Host(`penpot.internal`)" + - "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`)" - "traefik.http.routers.penpot-local.entrypoints=websecure" - "traefik.http.routers.penpot-local.middlewares=security-headers@file" - - "traefik.http.routers.penpot-local.service=penpot" - "traefik.http.routers.penpot-local.tls=true" - # Dev Router - "traefik.http.routers.penpot-dev.rule=Host(`penpot.gigaforust.internal`)" - "traefik.http.routers.penpot-dev.entrypoints=websecure" - "traefik.http.routers.penpot-dev.middlewares=security-headers@file" - - "traefik.http.routers.penpot-dev.service=penpot" - "traefik.http.routers.penpot-dev.tls=true" - environment: <<: [ *penpot-flags, *penpot-http-body-size ] - penpot-backend: image: "penpotapp/backend:${PENPOT_VERSION:-latest}" restart: always diff --git a/portainer/compose.yaml b/portainer/compose.yaml index c56e465..2ad0aec 100644 --- a/portainer/compose.yaml +++ b/portainer/compose.yaml @@ -1,7 +1,7 @@ services: portainer: - container_name: portainer image: portainer/portainer-ce:latest + container_name: portainer restart: always volumes: - /var/run/docker.sock:/var/run/docker.sock @@ -9,46 +9,37 @@ services: ports: - 9443:9443 # - 8000:8000 # Remove if you do not intend to use Edge Agents - networks: - - proxy labels: - "traefik.enable=true" - "traefik.docker.network=proxy" + - "traefik.http.services.portainer.loadbalancer.server.port=9443" # Prod Router - "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)" - "traefik.http.routers.portainer.entrypoints=websecure" - "traefik.http.routers.portainer.middlewares=security-headers@file" - - "traefik.http.routers.portainer.service=portainer" - "traefik.http.routers.portainer.tls=true" - - "traefik.http.services.portainer.loadbalancer.server.port=9443" - - "traefik.http.services.portainer.loadbalancer.server.scheme=https" - - "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file" - # Local Router - "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`) || Host(`portainer.internal`)" - "traefik.http.routers.portainer-local.entrypoints=websecure" - "traefik.http.routers.portainer-local.middlewares=security-headers@file" - - "traefik.http.routers.portainer-local.service=portainer" - "traefik.http.routers.portainer-local.tls=true" - # Dev Router - "traefik.http.routers.portainer-dev.rule=Host(`portainer.gigaforust.internal`)" - "traefik.http.routers.portainer-dev.entrypoints=websecure" - "traefik.http.routers.portainer-dev.middlewares=security-headers@file" - - "traefik.http.routers.portainer-dev.service=portainer" - "traefik.http.routers.portainer-dev.tls=true" + # Glance Metadata - glance.name=Portainer - glance.url=https://portainer.forust.xyz/ - glance.description=Portainer is a lightweight management UI which allows you to easily manage your Docker environments. - + networks: + - proxy volumes: portainer_data: name: portainer_data networks: - default: - name: portainer_network proxy: external: true diff --git a/termix/compose.yaml b/termix/compose.yaml index 92cdf52..9e9ded4 100644 --- a/termix/compose.yaml +++ b/termix/compose.yaml @@ -12,35 +12,27 @@ services: labels: - "traefik.enable=true" - "traefik.docker.network=proxy" + - "traefik.http.services.termix.loadbalancer.server.port=8080" # Prod Router - "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)" - "traefik.http.routers.termix.entrypoints=websecure" - "traefik.http.routers.termix.middlewares=security-headers@file" - - "traefik.http.routers.termix.service=termix" - "traefik.http.routers.termix.tls=true" - - "traefik.http.services.termix.loadbalancer.server.port=8080" - # Local Router - - "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`) || Host(`termix.internal`)" + - "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`)" - "traefik.http.routers.termix-local.entrypoints=websecure" - "traefik.http.routers.termix-local.middlewares=security-headers@file" - - "traefik.http.routers.termix-local.service=termix" - "traefik.http.routers.termix-local.tls=true" - # Dev Router - "traefik.http.routers.termix-dev.rule=Host(`termix.gigaforust.internal`)" - "traefik.http.routers.termix-dev.entrypoints=websecure" - "traefik.http.routers.termix-dev.middlewares=security-headers@file" - - "traefik.http.routers.termix-dev.service=termix" - "traefik.http.routers.termix-dev.tls=true" networks: - proxy - networks: proxy: external: true - volumes: - termix-data: - driver: local + termix-data: \ No newline at end of file diff --git a/traefik/compose.yaml b/traefik/compose.yaml index 492f401..5cf8e38 100644 --- a/traefik/compose.yaml +++ b/traefik/compose.yaml @@ -34,12 +34,12 @@ services: # Cloudflare - "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22" - "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22" + # # Logging # - "--log.level=INFO" # - "--log.filePath=/var/log/traefik/traefik.log" # - "--accesslog=true" # - "--accesslog.filepath=/var/log/traefik/access.log" - labels: - "traefik.enable=true" - "traefik.docker.network=proxy" @@ -50,14 +50,12 @@ services: - "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file" - "traefik.http.routers.traefik-dashboard.service=api@internal" - "traefik.http.routers.traefik-dashboard.tls=true" - # Local Router - - "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)" + - "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`)" - "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure" - "traefik.http.routers.traefik-dashboard-local.middlewares=security-headers@file" - "traefik.http.routers.traefik-dashboard-local.service=api@internal" - "traefik.http.routers.traefik-dashboard-local.tls=true" - # Dev Router - "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)" - "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure" @@ -65,27 +63,21 @@ services: - "traefik.http.routers.traefik-dashboard-dev.service=api@internal" - "traefik.http.routers.traefik-dashboard-dev.tls=true" + # Glance Metadata - glance.name=Traefik - glance.url=https://traefik.forust.xyz/ - glance.description=Traefik is a modern reverse proxy and load balancer - - ports: - - "80:80" - - "443:443" - volumes: - /var/run/docker.sock:/var/run/docker.sock:ro - ./dynamic:/etc/traefik/dynamic:ro - ./certs:/certs:ro - ./logs:/var/log/traefik - ./letsencrypt:/letsencrypt - + ports: + - "80:80" + - "443:443" networks: - proxy - - environment: - - TZ=Europe/Bratislava - networks: proxy: - external: true + external: true \ No newline at end of file diff --git a/uptime-kuma/compose.yaml b/uptime-kuma/compose.yaml index a918a8e..a0078fc 100644 --- a/uptime-kuma/compose.yaml +++ b/uptime-kuma/compose.yaml @@ -1,8 +1,8 @@ services: uptime-kuma: image: louislam/uptime-kuma:2 - restart: unless-stopped container_name: uptime-kuma + restart: unless-stopped volumes: - ./data:/app/data # ports: @@ -11,18 +11,16 @@ services: labels: - "traefik.enable=true" - "traefik.docker.network=proxy" + - "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001" # Prod Router - "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)" - "traefik.http.routers.uptime-kuma.entrypoints=websecure" - "traefik.http.routers.uptime-kuma.tls=true" - - "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001" - # Local Router - - "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`) || Host(`uptime.internal`)" + - "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`)" - "traefik.http.routers.uptime-kuma-local.entrypoints=websecure" - "traefik.http.routers.uptime-kuma-local.tls=true" - # Dev Router - "traefik.http.routers.uptime-kuma-dev.rule=Host(`uptime.gigaforust.internal`)" - "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure" @@ -31,4 +29,4 @@ services: - proxy networks: proxy: - external: true + external: true \ No newline at end of file