Compare commits
8 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
5b3ef39102
|
|||
|
bf72007b14
|
|||
|
0bad0a817e
|
|||
| 525fed3b92 | |||
|
fe5e5c5e35
|
|||
|
72aa022048
|
|||
|
f18d4d9be4
|
|||
|
45ce789f58
|
@@ -22,9 +22,6 @@ downtify/Downtify_downloads
|
|||||||
headscale/config/*
|
headscale/config/*
|
||||||
headscale/data/*
|
headscale/data/*
|
||||||
|
|
||||||
# Steaming services files
|
|
||||||
streaming/config/*
|
|
||||||
|
|
||||||
# Steaming services files
|
# Steaming services files
|
||||||
streaming/jellyfin/*
|
streaming/jellyfin/*
|
||||||
streaming/jellyseerr/*
|
streaming/jellyseerr/*
|
||||||
|
|||||||
@@ -14,43 +14,37 @@ services:
|
|||||||
- ./data/work:/opt/adguardhome/work
|
- ./data/work:/opt/adguardhome/work
|
||||||
- ./data/conf:/opt/adguardhome/conf
|
- ./data/conf:/opt/adguardhome/conf
|
||||||
- ./certs:/certs:ro
|
- ./certs:/certs:ro
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
|
||||||
- "traefik.http.routers.adguard.entrypoints=websecure"
|
- "traefik.http.routers.adguard.entrypoints=websecure"
|
||||||
- "traefik.http.routers.adguard.middlewares=security-headers@file"
|
- "traefik.http.routers.adguard.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.adguard.service=adguard"
|
|
||||||
- "traefik.http.routers.adguard.tls=true"
|
- "traefik.http.routers.adguard.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.adguard-local.rule=Host(`dns.workstation.internal`) || Host(`adguard.internal`) || Host(`adguard.workstation.internal`)"
|
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`dns.workstation.internal`)"
|
||||||
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
- "traefik.http.routers.adguard-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.adguard-local.middlewares=security-headers@file"
|
- "traefik.http.routers.adguard-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.adguard-local.service=adguard"
|
|
||||||
- "traefik.http.routers.adguard-local.tls=true"
|
- "traefik.http.routers.adguard-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.adguard-dev.rule=Host(`dns.gigaforust.internal`) || Host(`adguard.gigaforust.internal`)"
|
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`) Host(`dns.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.adguard-dev.service=adguard"
|
|
||||||
- "traefik.http.routers.adguard-dev.tls=true"
|
- "traefik.http.routers.adguard-dev.tls=true"
|
||||||
|
# DoH Router
|
||||||
# DoH
|
|
||||||
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
|
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
|
||||||
- "traefik.http.routers.dns.entrypoints=websecure"
|
- "traefik.http.routers.dns.entrypoints=websecure"
|
||||||
- "traefik.http.routers.dns.service=adguard"
|
|
||||||
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
|
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
|
||||||
|
|
||||||
|
# Glance Metadata
|
||||||
- glance.name=adguard
|
- glance.name=adguard
|
||||||
- glance.url=https://adguard.forust.xyz/
|
- glance.url=https://adguard.forust.xyz/
|
||||||
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
- glance.description=AdGuard Home is a network-wide software for blocking ads.
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -37,12 +37,12 @@ services:
|
|||||||
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||||
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||||
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||||
|
volumes:
|
||||||
|
- ./media:/media
|
||||||
|
- ./custom-templates:/templates
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
# Services
|
|
||||||
# - "traefik.http.services.authentik-server.loadbalancer.server.port=9443"
|
|
||||||
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
@@ -51,23 +51,18 @@ services:
|
|||||||
- "traefik.http.routers.authentik-server.middlewares=security-headers@file"
|
- "traefik.http.routers.authentik-server.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.authentik-server.service=authentik-server"
|
- "traefik.http.routers.authentik-server.service=authentik-server"
|
||||||
- "traefik.http.routers.authentik-server.tls=true"
|
- "traefik.http.routers.authentik-server.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`) || Host(`auth-dashboard.internal`)"
|
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`) || Host(`auth-dashboard.internal`)"
|
||||||
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.authentik-server-local.middlewares=security-headers@file"
|
- "traefik.http.routers.authentik-server-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.authentik-server-local.service=authentik-server"
|
- "traefik.http.routers.authentik-server-local.service=authentik-server"
|
||||||
- "traefik.http.routers.authentik-server-local.tls=true"
|
- "traefik.http.routers.authentik-server-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.authentik-server-dev.service=authentik-server"
|
- "traefik.http.routers.authentik-server-dev.service=authentik-server"
|
||||||
- "traefik.http.routers.authentik-server-dev.tls=true"
|
- "traefik.http.routers.authentik-server-dev.tls=true"
|
||||||
volumes:
|
|
||||||
- ./media:/media
|
|
||||||
- ./custom-templates:/templates
|
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
- authentik
|
- authentik
|
||||||
|
|||||||
+1
-1
@@ -2,6 +2,7 @@ services:
|
|||||||
cloudflare-ddns:
|
cloudflare-ddns:
|
||||||
image: timothyjmiller/cloudflare-ddns:latest
|
image: timothyjmiller/cloudflare-ddns:latest
|
||||||
container_name: cloudflare-ddns
|
container_name: cloudflare-ddns
|
||||||
|
restart: unless-stopped
|
||||||
security_opt:
|
security_opt:
|
||||||
- no-new-privileges:true
|
- no-new-privileges:true
|
||||||
network_mode: 'host'
|
network_mode: 'host'
|
||||||
@@ -10,4 +11,3 @@ services:
|
|||||||
- PGID=1000
|
- PGID=1000
|
||||||
volumes:
|
volumes:
|
||||||
- ./config.json:/config.json
|
- ./config.json:/config.json
|
||||||
restart: unless-stopped
|
|
||||||
|
|||||||
+8
-16
@@ -2,18 +2,17 @@ services:
|
|||||||
checkmk:
|
checkmk:
|
||||||
image: "checkmk/check-mk-raw:2.4.0-latest"
|
image: "checkmk/check-mk-raw:2.4.0-latest"
|
||||||
container_name: "checkmk"
|
container_name: "checkmk"
|
||||||
environment:
|
restart: unless-stopped
|
||||||
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
# ports:
|
||||||
- CMK_SITE_ID=cmk
|
# - 5000:5000
|
||||||
|
# - 6776:8000
|
||||||
volumes:
|
volumes:
|
||||||
- sites:/omd/sites
|
- sites:/omd/sites
|
||||||
tmpfs:
|
tmpfs:
|
||||||
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
- /opt/omd/sites/cmk/tmp:uid=1000,gid=1000
|
||||||
ports:
|
environment:
|
||||||
- 5000:5000
|
- CMK_PASSWORD=${CMK_PASSWORD:-password}
|
||||||
- 6776:8000
|
- CMK_SITE_ID=cmk
|
||||||
restart: unless-stopped
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
@@ -22,27 +21,20 @@ services:
|
|||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
- "traefik.http.routers.checkmk.rule=Host(`cmk.forust.xyz`)"
|
||||||
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
- "traefik.http.routers.checkmk.entrypoints=websecure"
|
||||||
- "traefik.http.routers.checkmk.service=checkmk"
|
|
||||||
- "traefik.http.routers.checkmk.middlewares=security-headers@file"
|
- "traefik.http.routers.checkmk.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.checkmk.tls=true"
|
- "traefik.http.routers.checkmk.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`) || Host(`cmk.internal`)"
|
- "traefik.http.routers.checkmk-local.rule=Host(`cmk.workstation.internal`)"
|
||||||
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
- "traefik.http.routers.checkmk-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.checkmk-local.service=checkmk"
|
|
||||||
- "traefik.http.routers.checkmk-local.middlewares=security-headers@file"
|
- "traefik.http.routers.checkmk-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.checkmk-local.tls=true"
|
- "traefik.http.routers.checkmk-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
- "traefik.http.routers.checkmk-dev.rule=Host(`cmk.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.checkmk-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.checkmk-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.checkmk-dev.service=checkmk"
|
|
||||||
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
- "traefik.http.routers.checkmk-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.checkmk-dev.tls=true"
|
- "traefik.http.routers.checkmk-dev.tls=true"
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
+12
-16
@@ -3,23 +3,22 @@ services:
|
|||||||
image: darthnorse/dockmon:latest
|
image: darthnorse/dockmon:latest
|
||||||
container_name: dockmon
|
container_name: dockmon
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
ports:
|
# ports:
|
||||||
- 8000:443
|
# - 8000:443
|
||||||
environment:
|
|
||||||
- TZ=Europe/Bratislava
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./data:/app/data
|
- data:/app/data
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
test: [ "CMD", "curl", "-k", "-f", "https://localhost:443/health" ]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 3
|
retries: 3
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
||||||
|
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||||
@@ -27,28 +26,25 @@ services:
|
|||||||
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
|
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.dockmon.service=dockmon"
|
- "traefik.http.routers.dockmon.service=dockmon"
|
||||||
- "traefik.http.routers.dockmon.tls=true"
|
- "traefik.http.routers.dockmon.tls=true"
|
||||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
|
||||||
- "traefik.http.services.dockmon.loadbalancer.server.scheme=https"
|
|
||||||
- "traefik.http.services.dockmon.loadbalancer.serverstransport=insecureTransport@file"
|
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`) || Host(`dockmon.internal`)"
|
- "traefik.http.routers.dockmon-local.rule=Host(`dockmon.workstation.internal`)"
|
||||||
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
- "traefik.http.routers.dockmon-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.dockmon-local.middlewares=security-headers@file"
|
- "traefik.http.routers.dockmon-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.dockmon-local.service=dockmon"
|
|
||||||
- "traefik.http.routers.dockmon-local.tls=true"
|
- "traefik.http.routers.dockmon-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.dockmon-dev.middlewares=security-chain@file"
|
- "traefik.http.routers.dockmon-dev.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.dockmon-dev.service=dockmon"
|
|
||||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||||
|
|
||||||
|
# Glance Metadata
|
||||||
- glance.name=dockmon
|
- glance.name=dockmon
|
||||||
- glance.url=https://dockmon.forust.xyz/
|
- glance.url=https://dockmon.forust.xyz/
|
||||||
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
|
volumes:
|
||||||
|
data:
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -4,36 +4,30 @@ services:
|
|||||||
image: ghcr.io/henriquesebastiao/downtify:latest
|
image: ghcr.io/henriquesebastiao/downtify:latest
|
||||||
# ports:
|
# ports:
|
||||||
# - '7077:8000'
|
# - '7077:8000'
|
||||||
|
volumes:
|
||||||
|
- ./Downtify_downloads:/downloads
|
||||||
labels:
|
labels:
|
||||||
- traefik.enable=true
|
- traefik.enable=true
|
||||||
|
- traefik.docker.network=proxy
|
||||||
- traefik.http.services.downtify.loadbalancer.server.port=8000
|
- traefik.http.services.downtify.loadbalancer.server.port=8000
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)
|
- traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)
|
||||||
- traefik.http.routers.downtify.entrypoints=websecure
|
- traefik.http.routers.downtify.entrypoints=websecure
|
||||||
- traefik.http.routers.downtify.middlewares=security-chain@file
|
- traefik.http.routers.downtify.middlewares=security-chain@file
|
||||||
- traefik.http.routers.downtify.service=downtify
|
|
||||||
- traefik.http.routers.downtify.tls=true
|
- traefik.http.routers.downtify.tls=true
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`) || Host(`downtify.internal`)
|
- traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`) || Host(`downtify.internal`)
|
||||||
- traefik.http.routers.downtify-local.entrypoints=websecure
|
- traefik.http.routers.downtify-local.entrypoints=websecure
|
||||||
- traefik.http.routers.downtify-local.middlewares=security-headers@file
|
- traefik.http.routers.downtify-local.middlewares=security-headers@file
|
||||||
- traefik.http.routers.downtify-local.service=downtify
|
|
||||||
- traefik.http.routers.downtify-local.tls=true
|
- traefik.http.routers.downtify-local.tls=true
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)
|
- traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)
|
||||||
- traefik.http.routers.downtify-dev.entrypoints=websecure
|
- traefik.http.routers.downtify-dev.entrypoints=websecure
|
||||||
- traefik.http.routers.downtify-dev.middlewares=security-chain@file
|
- traefik.http.routers.downtify-dev.middlewares=security-chain@file
|
||||||
- traefik.http.routers.downtify-dev.service=downtify
|
|
||||||
- traefik.http.routers.downtify-dev.tls=true
|
- traefik.http.routers.downtify-dev.tls=true
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
|
||||||
volumes:
|
|
||||||
- ./Downtify_downloads:/downloads
|
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
+10
-16
@@ -2,6 +2,7 @@ services:
|
|||||||
server:
|
server:
|
||||||
image: docker.gitea.com/gitea:1.25.1
|
image: docker.gitea.com/gitea:1.25.1
|
||||||
container_name: gitea
|
container_name: gitea
|
||||||
|
restart: always
|
||||||
environment:
|
environment:
|
||||||
- USER_UID=1000
|
- USER_UID=1000
|
||||||
- USER_GID=1000
|
- USER_GID=1000
|
||||||
@@ -24,10 +25,6 @@ services:
|
|||||||
- GITEA__mailer__PROTOCOL=SMTP
|
- GITEA__mailer__PROTOCOL=SMTP
|
||||||
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
||||||
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
||||||
restart: always
|
|
||||||
networks:
|
|
||||||
- gitea-db
|
|
||||||
- proxy
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./gitea-data:/data
|
- ./gitea-data:/data
|
||||||
- /etc/timezone:/etc/timezone:ro
|
- /etc/timezone:/etc/timezone:ro
|
||||||
@@ -35,36 +32,34 @@ services:
|
|||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
|
||||||
- "traefik.http.routers.gitea.entrypoints=websecure"
|
- "traefik.http.routers.gitea.entrypoints=websecure"
|
||||||
- "traefik.http.routers.gitea.middlewares=security-headers@file"
|
- "traefik.http.routers.gitea.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.gitea.service=gitea"
|
|
||||||
- "traefik.http.routers.gitea.tls=true"
|
- "traefik.http.routers.gitea.tls=true"
|
||||||
- "traefik.http.services.gitea.loadbalancer.server.port=3000"
|
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`) || Host(`gitea.internal`)"
|
- "traefik.http.routers.gitea-local.rule=Host(`gitea.workstation.internal`)"
|
||||||
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
- "traefik.http.routers.gitea-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.gitea-local.middlewares=security-headers@file"
|
- "traefik.http.routers.gitea-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.gitea-local.service=gitea"
|
|
||||||
- "traefik.http.routers.gitea-local.tls=true"
|
- "traefik.http.routers.gitea-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
- "traefik.http.routers.gitea-dev.rule=Host(`gitea.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
- "traefik.http.routers.gitea-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.gitea-dev.service=gitea"
|
|
||||||
- "traefik.http.routers.gitea-dev.tls=true"
|
- "traefik.http.routers.gitea-dev.tls=true"
|
||||||
|
# SSH Router
|
||||||
|
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
||||||
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
||||||
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
||||||
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
|
||||||
ports:
|
ports:
|
||||||
- "2221:22"
|
- "2221:22"
|
||||||
|
networks:
|
||||||
|
- gitea-db
|
||||||
|
- proxy
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: docker.io/library/postgres:14
|
image: docker.io/library/postgres:14
|
||||||
restart: always
|
restart: always
|
||||||
@@ -72,11 +67,10 @@ services:
|
|||||||
- POSTGRES_USER=gitea
|
- POSTGRES_USER=gitea
|
||||||
- POSTGRES_PASSWORD=gitea
|
- POSTGRES_PASSWORD=gitea
|
||||||
- POSTGRES_DB=gitea
|
- POSTGRES_DB=gitea
|
||||||
networks:
|
|
||||||
- gitea-db
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./gitea-db/:/var/lib/postgresql/data
|
- ./gitea-db/:/var/lib/postgresql/data
|
||||||
|
networks:
|
||||||
|
- gitea-db
|
||||||
networks:
|
networks:
|
||||||
gitea-db:
|
gitea-db:
|
||||||
external: false
|
external: false
|
||||||
|
|||||||
+2
-6
@@ -12,19 +12,18 @@ services:
|
|||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
# FIXME: traefik.services.glance.loadbalancer.server.port ??
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
||||||
- "traefik.http.routers.glance.entrypoints=websecure"
|
- "traefik.http.routers.glance.entrypoints=websecure"
|
||||||
- "traefik.http.routers.glance.middlewares=security-headers@file"
|
- "traefik.http.routers.glance.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.glance.tls=true"
|
- "traefik.http.routers.glance.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`) || Host(`glance.internal`)"
|
- "traefik.http.routers.glance-local.rule=Host(`glance.workstation.internal`)"
|
||||||
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
- "traefik.http.routers.glance-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.glance-local.middlewares=security-headers@file"
|
- "traefik.http.routers.glance-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.glance-local.tls=true"
|
- "traefik.http.routers.glance-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
||||||
@@ -32,9 +31,6 @@ services:
|
|||||||
- "traefik.http.routers.glance-dev.tls=true"
|
- "traefik.http.routers.glance-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
dns:
|
|
||||||
- 1.1.1.1
|
|
||||||
- 8.8.8.8
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
+25
-32
@@ -1,14 +1,16 @@
|
|||||||
services:
|
services:
|
||||||
server:
|
headscale:
|
||||||
image: headscale/headscale:latest
|
image: headscale/headscale:latest
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
container_name: headscale-server
|
||||||
command: serve
|
command: serve
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
volumes:
|
volumes:
|
||||||
- ./config:/etc/headscale
|
- ./config/headscale.yaml:/etc/headscale/config.yaml
|
||||||
- ./data:/var/lib/headscale
|
- data:/var/lib/headscale
|
||||||
labels:
|
labels:
|
||||||
|
- "me.tale.headplane.target: headscale"
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
- "traefik.http.services.headscale.loadbalancer.server.port=8080"
|
- "traefik.http.services.headscale.loadbalancer.server.port=8080"
|
||||||
@@ -47,38 +49,29 @@ services:
|
|||||||
- "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure"
|
- "traefik.http.routers.headscale-metrics-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics"
|
- "traefik.http.routers.headscale-metrics-dev.service=headscale-metrics"
|
||||||
- "traefik.http.routers.headscale-metrics-dev.tls=true"
|
- "traefik.http.routers.headscale-metrics-dev.tls=true"
|
||||||
dns:
|
headplane:
|
||||||
- 1.1.1.1
|
image: ghcr.io/tale/headplane:latest
|
||||||
- 1.0.0.1
|
container_name: headplane
|
||||||
web:
|
|
||||||
image: goodieshq/headscale-admin:latest
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
ports:
|
||||||
|
- '3000:3000'
|
||||||
|
volumes:
|
||||||
|
- ./config/headplane.yaml:/etc/headplane/config.yaml
|
||||||
|
- ./config/headscale.yaml:/etc/headscale/config.yaml
|
||||||
|
- headplane-data:/var/lib/headplane
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
labels:
|
healthcheck:
|
||||||
- "traefik.enable=true"
|
test: [ "CMD", "/bin/hp_healthcheck" ]
|
||||||
- "treafik.docker.network=proxy"
|
interval: 30s
|
||||||
- "traefik.http.services.headscale-ui.loadbalancer.server.port=80"
|
timeout: 5s
|
||||||
|
start_period: 5s
|
||||||
# Prod Router
|
retries: 3
|
||||||
- "traefik.http.routers.headscale-ui.rule=Host(`hs.forust.xyz`) && PathPrefix(`/admin`)"
|
volumes:
|
||||||
- "traefik.http.routers.headscale-ui.entrypoints=websecure"
|
data:
|
||||||
- "traefik.http.routers.headscale-ui.middlewares=security-chain@file"
|
headplane-data:
|
||||||
- "traefik.http.routers.headscale-ui.service=headscale-ui"
|
name: headplane_data
|
||||||
- "traefik.http.routers.headscale-ui.tls=true"
|
|
||||||
# Local Router
|
|
||||||
- "traefik.http.routers.headscale-ui-local.rule=Host(`hs.workstation.internal`) && PathPrefix(`/admin`)"
|
|
||||||
- "traefik.http.routers.headscale-ui-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.headscale-ui-local.middlewares=security-chain@file"
|
|
||||||
- "traefik.http.routers.headscale-ui-local.service=headscale-ui"
|
|
||||||
- "traefik.http.routers.headscale-ui-local.tls=true"
|
|
||||||
# Dev Router
|
|
||||||
- "traefik.http.routers.headscale-ui-dev.rule=Host(`hs.gigaforust.internal`) && PathPrefix(`/admin`)"
|
|
||||||
- "traefik.http.routers.headscale-ui-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.headscale-ui-dev.middlewares=security-chain@file"
|
|
||||||
- "traefik.http.routers.headscale-ui-dev.service=headscale-ui"
|
|
||||||
- "traefik.http.routers.headscale-ui-dev.tls=true"
|
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -0,0 +1,221 @@
|
|||||||
|
# Configuration for the Headplane server and web application
|
||||||
|
server:
|
||||||
|
# These are the default values, change them as needed
|
||||||
|
host: "0.0.0.0"
|
||||||
|
port: 3000
|
||||||
|
# Should not include the dashboard prefix (/admin) portion.
|
||||||
|
# # Prod server_url
|
||||||
|
# base_url: https://hs.forust.xyz
|
||||||
|
# # Local base_url
|
||||||
|
# base_url: https://hs.workstation.internal
|
||||||
|
# # Dev base_url
|
||||||
|
# base_url: https://hs.gigaforust.internal
|
||||||
|
|
||||||
|
# You may provide `cookie_secret_path` instead to read a value from disk.
|
||||||
|
# See https://headplane.net/configuration/#sensitive-values
|
||||||
|
cookie_secret: "<change_me_to_something_secure!>"
|
||||||
|
|
||||||
|
# Whether cookies should be marked as Secure
|
||||||
|
# * Should be false if running without HTTPs
|
||||||
|
# * Should be true if running behind a reverse proxy with HTTPs
|
||||||
|
cookie_secure: true
|
||||||
|
# The maximum age of the session cookie in seconds
|
||||||
|
cookie_max_age: 86400 # 1 day in seconds
|
||||||
|
|
||||||
|
# This is not required, but if you want to restrict the cookie
|
||||||
|
# to a specific domain, set it here. Otherwise leave it commented out.
|
||||||
|
# This may not work as expected if not using a reverse proxy.
|
||||||
|
# cookie_domain: ""
|
||||||
|
|
||||||
|
# The path to persist Headplane specific data. All data going forward
|
||||||
|
# is stored in this directory, including the internal database and
|
||||||
|
# any cache related files.
|
||||||
|
data_path: "/var/lib/headplane"
|
||||||
|
|
||||||
|
# The info secret is optional and allows access to certain debug endpoints
|
||||||
|
# that may expose sensitive information about your Headplane instance.
|
||||||
|
#
|
||||||
|
# As of now, this protects the /api/info endpoint which exposes details about
|
||||||
|
# the Headplane and Headscale versions in use. In the future, more endpoints
|
||||||
|
# may be protected by this secret.
|
||||||
|
#
|
||||||
|
# If not set, these endpoints will be disabled.
|
||||||
|
# info_secret: "<change_me_to_something_secure!>"
|
||||||
|
|
||||||
|
# Headscale specific settings to allow Headplane to talk
|
||||||
|
# to Headscale and access deep integration features
|
||||||
|
headscale:
|
||||||
|
# The URL to your Headscale instance
|
||||||
|
# (All API requests are routed through this URL)
|
||||||
|
# (THIS IS NOT the gRPC endpoint, but the HTTP endpoint)
|
||||||
|
#
|
||||||
|
# IMPORTANT: If you are using TLS this MUST be set to `https://`
|
||||||
|
url: "http://headscale-server:8080"
|
||||||
|
|
||||||
|
# If you use the TLS configuration in Headscale, and you are not using
|
||||||
|
# Let's Encrypt for your certificate, pass in the path to the certificate.
|
||||||
|
# (This has no effect if `url` does not start with `https://`)
|
||||||
|
# tls_cert_path: "/var/lib/headplane/tls.crt"
|
||||||
|
|
||||||
|
# Optional, public URL if its different from the `headscale.url`
|
||||||
|
# This affects certain parts of the web UI which shows Headscale's URL
|
||||||
|
public_url: "https://headscale.example.com"
|
||||||
|
|
||||||
|
# Path to the Headscale configuration file
|
||||||
|
# This is optional, but HIGHLY recommended for the best experience
|
||||||
|
# If this is read only, Headplane will show your configuration settings
|
||||||
|
# in the Web UI, but they cannot be changed.
|
||||||
|
config_path: "/etc/headscale/config.yaml"
|
||||||
|
|
||||||
|
# Whether the Headscale configuration should be strictly validated
|
||||||
|
# when reading from `config_path`. If true, Headplane will not interact
|
||||||
|
# with Headscale if there are any issues with the configuration file.
|
||||||
|
#
|
||||||
|
# This is recommended to be true for production deployments to, however it
|
||||||
|
# may not work if you are using a version of Headscale that has configuration
|
||||||
|
# options unknown to Headplane.
|
||||||
|
config_strict: true
|
||||||
|
|
||||||
|
# If you are using `dns.extra_records_path` in your Headscale
|
||||||
|
# configuration, you need to set this to the path for Headplane
|
||||||
|
# to be able to read the DNS records.
|
||||||
|
#
|
||||||
|
# Pass it in if using Docker and ensure that the file is both
|
||||||
|
# readable and writable to the Headplane process.
|
||||||
|
# When using this, Headplane will no longer need to automatically
|
||||||
|
# restart Headscale for DNS record changes.
|
||||||
|
# dns_records_path: "/var/lib/headscale/extra_records.json"
|
||||||
|
|
||||||
|
# Integration configurations for Headplane to interact with Headscale
|
||||||
|
integration:
|
||||||
|
# The Headplane agent allows retrieving information about nodes
|
||||||
|
# This allows the UI to display version, OS, and connectivity data
|
||||||
|
# You will see the Headplane agent in your Tailnet as a node when
|
||||||
|
# it connects.
|
||||||
|
agent:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
# To connect to your Tailnet, you need to generate a pre-auth key
|
||||||
|
# This can be done via the web UI or through the `headscale` CLI.
|
||||||
|
pre_authkey: "<your-preauth-key>"
|
||||||
|
|
||||||
|
# Optionally change the name of the agent in the Tailnet.
|
||||||
|
# host_name: "headplane-agent"
|
||||||
|
|
||||||
|
# Configure different caching settings. By default, the agent will store
|
||||||
|
# caches in the path below for a maximum of 1 minute. If you want data
|
||||||
|
# to update faster, reduce the TTL, but this will increase the frequency
|
||||||
|
# of requests to Headscale.
|
||||||
|
# cache_ttl: 60
|
||||||
|
# cache_path: /var/lib/headplane/agent_cache.json
|
||||||
|
|
||||||
|
# The work_dir represents where the agent will store its data to be able
|
||||||
|
# to automatically reauthenticate with your Tailnet. It needs to be
|
||||||
|
# writable by the user running the Headplane process.
|
||||||
|
#
|
||||||
|
# If using Docker, it is best to leave this as the default.
|
||||||
|
# work_dir: "/var/lib/headplane/agent"
|
||||||
|
|
||||||
|
# Only one of these should be enabled at a time or you will get errors
|
||||||
|
# This does not include the agent integration (above), which can be enabled
|
||||||
|
# at the same time as any of these and is recommended for the best experience.
|
||||||
|
docker:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
# By default we check for the presence of a container label (see the docs)
|
||||||
|
# to determine the container to signal when changes are made to DNS settings.
|
||||||
|
container_label: "me.tale.headplane.target=headscale"
|
||||||
|
|
||||||
|
# HOWEVER, you can fallback to a container name if you desire, but this is
|
||||||
|
# not recommended as its brittle and doesn't work with orchestrators that
|
||||||
|
# automatically assign container names.
|
||||||
|
#
|
||||||
|
# If `container_name` is set, it will override any label checks.
|
||||||
|
# container_name: "headscale-server"
|
||||||
|
|
||||||
|
# The path to the Docker socket (do not change this if you are unsure)
|
||||||
|
# Docker socket paths must start with unix:// or tcp:// and at the moment
|
||||||
|
# https connections are not supported.
|
||||||
|
socket: "unix:///var/run/docker.sock"
|
||||||
|
|
||||||
|
# Please refer to docs/integration/Kubernetes.md for more information
|
||||||
|
# on how to configure the Kubernetes integration. There are requirements in
|
||||||
|
# order to allow Headscale to be controlled by Headplane in a cluster.
|
||||||
|
kubernetes:
|
||||||
|
enabled: false
|
||||||
|
# Validates the manifest for the Pod to ensure all of the criteria
|
||||||
|
# are set correctly. Turn this off if you are having issues with
|
||||||
|
# shareProcessNamespace not being validated correctly.
|
||||||
|
validate_manifest: true
|
||||||
|
# This should be the name of the Pod running Headscale and Headplane.
|
||||||
|
# If this isn't static you should be using the Kubernetes Downward API
|
||||||
|
# to set this value (refer to docs/Integrated-Mode.md for more info).
|
||||||
|
pod_name: "headscale"
|
||||||
|
|
||||||
|
# Proc is the "Native" integration that only works when Headscale and
|
||||||
|
# Headplane are running outside of a container. There is no configuration,
|
||||||
|
# but you need to ensure that the Headplane process can terminate the
|
||||||
|
# Headscale process.
|
||||||
|
#
|
||||||
|
# (If they are both running under systemd as sudo, this will work).
|
||||||
|
proc:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
# OIDC Configuration for simpler authentication
|
||||||
|
# (This is optional, but recommended for the best experience)
|
||||||
|
# oidc:
|
||||||
|
# The OIDC issuer URL
|
||||||
|
# issuer: "https://accounts.google.com"
|
||||||
|
|
||||||
|
# If you are using OIDC, you need to generate an API key
|
||||||
|
# that can be used to authenticate other sessions when signing in.
|
||||||
|
#
|
||||||
|
# This can be done with `headscale apikeys create --expiration 999d`
|
||||||
|
# headscale_api_key: "<your-headscale-api-key>"
|
||||||
|
|
||||||
|
# If your OIDC provider does not support discovery (does not have the URL at
|
||||||
|
# `/.well-known/openid-configuration`), you need to manually set endpoints.
|
||||||
|
# This also works to override endpoints if you so desire or if your OIDC
|
||||||
|
# discovery is missing certain endpoints (ie GitHub).
|
||||||
|
# For some typical providers, see https://headplane.net/features/sso.
|
||||||
|
# authorization_endpoint: ""
|
||||||
|
# token_endpoint: ""
|
||||||
|
# userinfo_endpoint: ""
|
||||||
|
|
||||||
|
# The authentication method to use when communicating with the token endpoint.
|
||||||
|
# This is fully optional and Headplane will attempt to auto-detect the best
|
||||||
|
# method and fall back to `client_secret_basic` if unsure.
|
||||||
|
# token_endpoint_auth_method: "client_secret_post"
|
||||||
|
|
||||||
|
# The client ID for the OIDC client
|
||||||
|
# For the best experience please ensure this is *identical* to the client_id
|
||||||
|
# you are using for Headscale. because
|
||||||
|
# client_id: "your-client-id"
|
||||||
|
|
||||||
|
# The client secret for the OIDC client
|
||||||
|
# You may also provide `client_secret_path` instead to read a value from disk.
|
||||||
|
# See https://headplane.net/configuration/#sensitive-values
|
||||||
|
# client_secret: "<your-client-secret>"
|
||||||
|
|
||||||
|
# Whether to use PKCE when authenticating users. This is recommended as it
|
||||||
|
# adds an extra layer of security to the authentication process. Enabling this
|
||||||
|
# means your OIDC provider must support PKCE and it must be enabled on the
|
||||||
|
# client.
|
||||||
|
# use_pkce: true
|
||||||
|
|
||||||
|
# If you want to disable traditional login via Headscale API keys
|
||||||
|
# disable_api_key_login: false
|
||||||
|
|
||||||
|
# By default profile pictures are pulled from the OIDC provider when
|
||||||
|
# we go to fetch the userinfo endpoint. Optionally, this can be set to
|
||||||
|
# "oidc" or "gravatar" as of 0.6.1.
|
||||||
|
# profile_picture_source: "gravatar"
|
||||||
|
|
||||||
|
# The scopes to request when authenticating users. The default is below.
|
||||||
|
# scope: "openid email profile"
|
||||||
|
|
||||||
|
# Extra query parameters can be passed to the authorization endpoint
|
||||||
|
# by setting them here. This is useful for providers that require any kind
|
||||||
|
# of custom hinting.
|
||||||
|
# extra_params:
|
||||||
|
# prompt: "select_account" # Example: force account selection on Google
|
||||||
+5
-21
@@ -13,70 +13,54 @@ services:
|
|||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Services
|
|
||||||
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
||||||
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
||||||
- "traefik.http.routers.forust-homepage.middlewares=security-headers@file"
|
- "traefik.http.routers.forust-homepage.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.forust-homepage.service=forust-homepage"
|
|
||||||
- "traefik.http.routers.forust-homepage.tls=true"
|
- "traefik.http.routers.forust-homepage.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`) || Host(`landing.internal`)"
|
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`)"
|
||||||
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file"
|
- "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.forust-homepage-local.service=forust-homepage"
|
|
||||||
- "traefik.http.routers.forust-homepage-local.tls=true"
|
- "traefik.http.routers.forust-homepage-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.forust-homepage-dev.service=forust-homepage"
|
|
||||||
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
||||||
|
|
||||||
xdfnx:
|
xdfnx:
|
||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: Dockerfile.xdfnx
|
dockerfile: Dockerfile.xdfnx
|
||||||
|
restart: unless-stopped
|
||||||
# ports:
|
# ports:
|
||||||
# - "8086:80"
|
# - "8086:80"
|
||||||
restart: unless-stopped
|
|
||||||
volumes:
|
volumes:
|
||||||
- ./xdfnx_files:/usr/share/nginx/html
|
- ./xdfnx_files:/usr/share/nginx/html
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# Services
|
|
||||||
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
|
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)"
|
- "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)"
|
||||||
- "traefik.http.routers.xdfnx.entrypoints=websecure"
|
- "traefik.http.routers.xdfnx.entrypoints=websecure"
|
||||||
- "traefik.http.routers.xdfnx.middlewares=security-headers@file"
|
- "traefik.http.routers.xdfnx.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.xdfnx.service=xdfnx-homepage"
|
|
||||||
- "traefik.http.routers.xdfnx.tls=true"
|
- "traefik.http.routers.xdfnx.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`) || Host(`xdfnx.internal`)"
|
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`)"
|
||||||
- "traefik.http.routers.xdfnx-local.entrypoints=websecure"
|
- "traefik.http.routers.xdfnx-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.xdfnx-local.middlewares=security-headers@file"
|
- "traefik.http.routers.xdfnx-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.xdfnx-local.service=xdfnx-homepage"
|
|
||||||
- "traefik.http.routers.xdfnx-local.tls=true"
|
- "traefik.http.routers.xdfnx-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)"
|
- "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.xdfnx-dev.entrypoints=websecure"
|
- "traefik.http.routers.xdfnx-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.xdfnx-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.xdfnx-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.xdfnx-dev.service=xdfnx-homepage"
|
|
||||||
- "traefik.http.routers.xdfnx-dev.tls=true"
|
- "traefik.http.routers.xdfnx-dev.tls=true"
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
+4
-10
@@ -1,7 +1,7 @@
|
|||||||
services:
|
services:
|
||||||
metube:
|
metube:
|
||||||
image: ghcr.io/alexta69/metube
|
image: ghcr.io/alexta69/metube
|
||||||
# container_name: metube
|
container_name: metube
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
# ports:
|
# ports:
|
||||||
# - "8081:8081"
|
# - "8081:8081"
|
||||||
@@ -13,31 +13,25 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
- ./MeTube_downloads:/downloads
|
- ./MeTube_downloads:/downloads
|
||||||
labels:
|
labels:
|
||||||
- traefik.enable=true
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
|
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
|
||||||
- "traefik.http.routers.metube.entrypoints=websecure"
|
- "traefik.http.routers.metube.entrypoints=websecure"
|
||||||
- "traefik.http.routers.metube.middlewares=security-chain@file"
|
- "traefik.http.routers.metube.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.metube.service=metube"
|
|
||||||
- "traefik.http.routers.metube.tls=true"
|
- "traefik.http.routers.metube.tls=true"
|
||||||
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`) || Host(`metube.internal`)"
|
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`))"
|
||||||
- "traefik.http.routers.metube-local.entrypoints=websecure"
|
- "traefik.http.routers.metube-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.metube-local.middlewares=security-headers@file"
|
- "traefik.http.routers.metube-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.metube-local.service=metube"
|
|
||||||
- "traefik.http.routers.metube-local.tls=true"
|
- "traefik.http.routers.metube-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
|
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.metube-dev.entrypoints=websecure"
|
- "traefik.http.routers.metube-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.metube-dev.middlewares=security-chain@file"
|
- "traefik.http.routers.metube-dev.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.metube-dev.service=metube"
|
|
||||||
- "traefik.http.routers.metube-dev.tls=true"
|
- "traefik.http.routers.metube-dev.tls=true"
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
networks:
|
networks:
|
||||||
|
|||||||
@@ -18,7 +18,6 @@ services:
|
|||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
|
||||||
# AIO Services configuration
|
# AIO Services configuration
|
||||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
|
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
|
||||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
|
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
|
||||||
@@ -30,27 +29,21 @@ services:
|
|||||||
# - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file"
|
# - "traefik.http.routers.nextcloud-aio.middlewares=security-chain@file"
|
||||||
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
|
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
|
||||||
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`) || Host(`nextcloud-aio.internal`)"
|
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`naio.workstation.internal`)"
|
||||||
- "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure"
|
- "traefik.http.routers.nextcloud-aio-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file"
|
- "traefik.http.routers.nextcloud-aio-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.nextcloud-aio-local.service=nextcloud-aio"
|
|
||||||
- "traefik.http.routers.nextcloud-aio-local.tls=true"
|
- "traefik.http.routers.nextcloud-aio-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)"
|
- "traefik.http.routers.nextcloud-aio-dev.rule=Host(`naio.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure"
|
- "traefik.http.routers.nextcloud-aio-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.nextcloud-aio-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio"
|
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
|
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
|
||||||
|
|
||||||
# Glanceapp/glance config
|
# Glance Metadata
|
||||||
- glance.name=Nextcloud
|
- glance.name=Nextcloud
|
||||||
# - glance.icon=si:nextcloud
|
|
||||||
- glance.url=https://nextcloud.forust.xyz/
|
- glance.url=https://nextcloud.forust.xyz/
|
||||||
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
|
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
|
||||||
|
|
||||||
environment:
|
environment:
|
||||||
AIO_DISABLE_BACKUP_SECTION: false
|
AIO_DISABLE_BACKUP_SECTION: false
|
||||||
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||||
|
|||||||
+2
-9
@@ -103,32 +103,25 @@ services:
|
|||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
|
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
|
||||||
- "traefik.http.routers.penpot.entrypoints=websecure"
|
- "traefik.http.routers.penpot.entrypoints=websecure"
|
||||||
- "traefik.http.routers.penpot.middlewares=security-headers@file"
|
- "traefik.http.routers.penpot.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.penpot.service=penpot"
|
|
||||||
- "traefik.http.routers.penpot.tls=true"
|
- "traefik.http.routers.penpot.tls=true"
|
||||||
- "traefik.http.services.penpot.loadbalancer.server.port=8080"
|
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`) || Host(`penpot.internal`)"
|
- "traefik.http.routers.penpot-local.rule=Host(`penpot.workstation.internal`)"
|
||||||
- "traefik.http.routers.penpot-local.entrypoints=websecure"
|
- "traefik.http.routers.penpot-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.penpot-local.middlewares=security-headers@file"
|
- "traefik.http.routers.penpot-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.penpot-local.service=penpot"
|
|
||||||
- "traefik.http.routers.penpot-local.tls=true"
|
- "traefik.http.routers.penpot-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.penpot-dev.rule=Host(`penpot.gigaforust.internal`)"
|
- "traefik.http.routers.penpot-dev.rule=Host(`penpot.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.penpot-dev.entrypoints=websecure"
|
- "traefik.http.routers.penpot-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.penpot-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.penpot-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.penpot-dev.service=penpot"
|
|
||||||
- "traefik.http.routers.penpot-dev.tls=true"
|
- "traefik.http.routers.penpot-dev.tls=true"
|
||||||
|
|
||||||
environment:
|
environment:
|
||||||
<<: [ *penpot-flags, *penpot-http-body-size ]
|
<<: [ *penpot-flags, *penpot-http-body-size ]
|
||||||
|
|
||||||
penpot-backend:
|
penpot-backend:
|
||||||
image: "penpotapp/backend:${PENPOT_VERSION:-latest}"
|
image: "penpotapp/backend:${PENPOT_VERSION:-latest}"
|
||||||
restart: always
|
restart: always
|
||||||
|
|||||||
+10
-19
@@ -1,54 +1,45 @@
|
|||||||
services:
|
services:
|
||||||
portainer:
|
portainer:
|
||||||
container_name: portainer
|
|
||||||
image: portainer/portainer-ce:latest
|
image: portainer/portainer-ce:latest
|
||||||
|
container_name: portainer
|
||||||
restart: always
|
restart: always
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
- ./portainer_data:/data
|
- data:/data
|
||||||
ports:
|
ports:
|
||||||
- 9443:9443
|
- 9443:9443
|
||||||
# - 8000:8000 # Remove if you do not intend to use Edge Agents
|
# - 8000:8000 # Remove if you do not intend to use Edge Agents
|
||||||
networks:
|
|
||||||
- proxy
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.http.services.portainer.loadbalancer.server.port=9443"
|
||||||
|
- "traefik.http.services.portainer.loadbalancer.server.scheme=https"
|
||||||
|
- "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
|
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
|
||||||
- "traefik.http.routers.portainer.entrypoints=websecure"
|
- "traefik.http.routers.portainer.entrypoints=websecure"
|
||||||
- "traefik.http.routers.portainer.middlewares=security-headers@file"
|
- "traefik.http.routers.portainer.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.portainer.service=portainer"
|
|
||||||
- "traefik.http.routers.portainer.tls=true"
|
- "traefik.http.routers.portainer.tls=true"
|
||||||
- "traefik.http.services.portainer.loadbalancer.server.port=9443"
|
|
||||||
- "traefik.http.services.portainer.loadbalancer.server.scheme=https"
|
|
||||||
- "traefik.http.services.portainer.loadbalancer.serverstransport=insecureTransport@file"
|
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`) || Host(`portainer.internal`)"
|
- "traefik.http.routers.portainer-local.rule=Host(`portainer.workstation.internal`)"
|
||||||
- "traefik.http.routers.portainer-local.entrypoints=websecure"
|
- "traefik.http.routers.portainer-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.portainer-local.middlewares=security-headers@file"
|
- "traefik.http.routers.portainer-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.portainer-local.service=portainer"
|
|
||||||
- "traefik.http.routers.portainer-local.tls=true"
|
- "traefik.http.routers.portainer-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.portainer-dev.rule=Host(`portainer.gigaforust.internal`)"
|
- "traefik.http.routers.portainer-dev.rule=Host(`portainer.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.portainer-dev.entrypoints=websecure"
|
- "traefik.http.routers.portainer-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.portainer-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.portainer-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.portainer-dev.service=portainer"
|
|
||||||
- "traefik.http.routers.portainer-dev.tls=true"
|
- "traefik.http.routers.portainer-dev.tls=true"
|
||||||
|
|
||||||
|
# Glance Metadata
|
||||||
- glance.name=Portainer
|
- glance.name=Portainer
|
||||||
- glance.url=https://portainer.forust.xyz/
|
- glance.url=https://portainer.forust.xyz/
|
||||||
- glance.description=Portainer is a lightweight management UI which allows you to easily manage your Docker environments.
|
- glance.description=Portainer is a lightweight management UI which allows you to easily manage your Docker environments.
|
||||||
|
networks:
|
||||||
|
- proxy
|
||||||
volumes:
|
volumes:
|
||||||
portainer_data:
|
data:
|
||||||
name: portainer_data
|
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
default:
|
|
||||||
name: portainer_network
|
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
TZ=Europe/Moscow
|
|
||||||
+13
-61
@@ -1,74 +1,26 @@
|
|||||||
services:
|
# sudo mount /dev/sdc5 /mnt/mediaserver
|
||||||
jellyfin:
|
|
||||||
image: lscr.io/linuxserver/jellyfin:latest
|
|
||||||
container_name: jellyfin
|
# volumes:
|
||||||
restart: unless-stopped
|
# - /mnt/mediaserver:/<somepath>
|
||||||
ports:
|
|
||||||
- "8096:8096/tcp"
|
|
||||||
- "7359:7359/udp"
|
|
||||||
volumes:
|
|
||||||
# HACK: Binding while bootstrapping, testing
|
|
||||||
# - jellyfin-cfg:/config
|
|
||||||
- ./config/jellyfin:/config
|
|
||||||
- /mnt/mediaserver/media/movies:/media/movies
|
|
||||||
- /mnt/mediaserver/media/movies:/media/movies
|
|
||||||
devices:
|
|
||||||
- /dev/dri:/dev/dri
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
- "traefik.http.services.jellyfin.loadbalancer.server.port=8096"
|
- "traefik.http.services.lampa.loadbalancer.server.port=<container port>"
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.jellyfin.rule=Host(`media.forust.xyz`)"
|
- "traefik.http.routers.lampa.rule=Host(`media.forust.xyz`)"
|
||||||
- "traefik.http.routers.jellyfin.entrypoints=websecure"
|
- "traefik.http.routers.lampa.entrypoints=websecure"
|
||||||
- "traefik.http.routers.jellyfin.tls=true"
|
- "traefik.http.routers.lampa.tls=true"
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.jellyfin-local.rule=Host(`media.workstation.internal`) || Host(`ms.internal`)"
|
- "traefik.http.routers.lampa-local.rule=Host(`media.workstation.internal`)"
|
||||||
- "traefik.http.routers.jellyfin-local.entrypoints=websecure"
|
- "traefik.http.routers.lampa-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.jellyfin-local.tls=true"
|
- "traefik.http.routers.lampa-local.tls=true"
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.jellyfin-dev.rule=Host(`media.gigaforust.internal`)"
|
- "traefik.http.routers.lampa-dev.rule=Host(`media.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.jellyfin-dev.entrypoints=websecure"
|
- "traefik.http.routers.jellyfin-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.jellyfin-dev.tls=true"
|
- "traefik.http.routers.jellyfin-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
- streaming
|
|
||||||
qbittorrent:
|
|
||||||
image: lscr.io/linuxserver/qbittorrent:latest
|
|
||||||
container_name: qbittorrent
|
|
||||||
restart: unless-stopped
|
|
||||||
environment:
|
|
||||||
- WEBUI_PORT=8080
|
|
||||||
volumes:
|
|
||||||
# HACK: Binding while bootstrapping, testing
|
|
||||||
# - qbittorrent-cfg:/config
|
|
||||||
- ./config/qbittorrent:/config
|
|
||||||
- /mnt/mediaserver/downloads:/downloads
|
|
||||||
ports:
|
|
||||||
- 8080:8080
|
|
||||||
- 6881:6881
|
|
||||||
- 6881:6881/udp
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
radarr:
|
|
||||||
image: lscr.io/linuxserver/radarr:latest
|
|
||||||
container_name: radarr
|
|
||||||
restart: unless-stopped
|
|
||||||
ports:
|
|
||||||
- 7878:7878
|
|
||||||
volumes:
|
|
||||||
# HACK: Binding while bootstrapping, testing
|
|
||||||
# - radarr-cfg:/config
|
|
||||||
- ./config/radarr:/config
|
|
||||||
- /mnt/mediaserver/downloads:/downloads
|
|
||||||
- /mnt/mediaserver/movies:/movies
|
|
||||||
networks:
|
|
||||||
- streaming
|
|
||||||
volumes:
|
|
||||||
jellyfin-cfg:
|
|
||||||
qbittorrent-cfg:
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
streaming:
|
|
||||||
name: streaming
|
|
||||||
+4
-12
@@ -6,41 +6,33 @@ services:
|
|||||||
# ports:
|
# ports:
|
||||||
# - "3331:8080"
|
# - "3331:8080"
|
||||||
volumes:
|
volumes:
|
||||||
- ./termix-data:/app/data
|
- data:/app/data
|
||||||
environment:
|
environment:
|
||||||
PORT: "8080"
|
PORT: "8080"
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.http.services.termix.loadbalancer.server.port=8080"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
|
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
|
||||||
- "traefik.http.routers.termix.entrypoints=websecure"
|
- "traefik.http.routers.termix.entrypoints=websecure"
|
||||||
- "traefik.http.routers.termix.middlewares=security-headers@file"
|
- "traefik.http.routers.termix.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.termix.service=termix"
|
|
||||||
- "traefik.http.routers.termix.tls=true"
|
- "traefik.http.routers.termix.tls=true"
|
||||||
- "traefik.http.services.termix.loadbalancer.server.port=8080"
|
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`) || Host(`termix.internal`)"
|
- "traefik.http.routers.termix-local.rule=Host(`termix.workstation.internal`)"
|
||||||
- "traefik.http.routers.termix-local.entrypoints=websecure"
|
- "traefik.http.routers.termix-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.termix-local.middlewares=security-headers@file"
|
- "traefik.http.routers.termix-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.termix-local.service=termix"
|
|
||||||
- "traefik.http.routers.termix-local.tls=true"
|
- "traefik.http.routers.termix-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.termix-dev.rule=Host(`termix.gigaforust.internal`)"
|
- "traefik.http.routers.termix-dev.rule=Host(`termix.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.termix-dev.entrypoints=websecure"
|
- "traefik.http.routers.termix-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.termix-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.termix-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.termix-dev.service=termix"
|
|
||||||
- "traefik.http.routers.termix-dev.tls=true"
|
- "traefik.http.routers.termix-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
termix-data:
|
data:
|
||||||
driver: local
|
|
||||||
+7
-15
@@ -34,12 +34,12 @@ services:
|
|||||||
# Cloudflare
|
# Cloudflare
|
||||||
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||||
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||||
|
|
||||||
# # Logging
|
# # Logging
|
||||||
# - "--log.level=INFO"
|
# - "--log.level=INFO"
|
||||||
# - "--log.filePath=/var/log/traefik/traefik.log"
|
# - "--log.filePath=/var/log/traefik/traefik.log"
|
||||||
# - "--accesslog=true"
|
# - "--accesslog=true"
|
||||||
# - "--accesslog.filepath=/var/log/traefik/access.log"
|
# - "--accesslog.filepath=/var/log/traefik/access.log"
|
||||||
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
@@ -50,14 +50,12 @@ services:
|
|||||||
- "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file"
|
- "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.traefik-dashboard.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard.service=api@internal"
|
||||||
- "traefik.http.routers.traefik-dashboard.tls=true"
|
- "traefik.http.routers.traefik-dashboard.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)"
|
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`)"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.middlewares=security-headers@file"
|
- "traefik.http.routers.traefik-dashboard-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
||||||
@@ -65,27 +63,21 @@ services:
|
|||||||
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
||||||
|
|
||||||
|
# Glance Metadata
|
||||||
- glance.name=Traefik
|
- glance.name=Traefik
|
||||||
- glance.url=https://traefik.forust.xyz/
|
- glance.url=https://traefik.forust.xyz/
|
||||||
- glance.description=Traefik is a modern reverse proxy and load balancer
|
- glance.description=Traefik is a modern reverse proxy and load balancer
|
||||||
|
|
||||||
ports:
|
|
||||||
- "80:80"
|
|
||||||
- "443:443"
|
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
- ./dynamic:/etc/traefik/dynamic:ro
|
- ./dynamic:/etc/traefik/dynamic:ro
|
||||||
- ./certs:/certs:ro
|
- ./certs:/certs:ro
|
||||||
- ./logs:/var/log/traefik
|
- ./logs:/var/log/traefik
|
||||||
- ./letsencrypt:/letsencrypt
|
- ./letsencrypt:/letsencrypt
|
||||||
|
ports:
|
||||||
|
- "80:80"
|
||||||
|
- "443:443"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
|
||||||
environment:
|
|
||||||
- TZ=Europe/Bratislava
|
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
@@ -1,34 +1,33 @@
|
|||||||
services:
|
services:
|
||||||
uptime-kuma:
|
uptime-kuma:
|
||||||
image: louislam/uptime-kuma:2
|
image: louislam/uptime-kuma:2
|
||||||
restart: unless-stopped
|
|
||||||
container_name: uptime-kuma
|
container_name: uptime-kuma
|
||||||
|
restart: unless-stopped
|
||||||
volumes:
|
volumes:
|
||||||
- ./data:/app/data
|
- data:/app/data
|
||||||
# ports:
|
# ports:
|
||||||
# <Host Port>:<Container Port>
|
# - "3001:3001"
|
||||||
# - "3001:3001"
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=proxy"
|
- "traefik.docker.network=proxy"
|
||||||
|
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
||||||
|
|
||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
|
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
|
||||||
- "traefik.http.routers.uptime-kuma.entrypoints=websecure"
|
- "traefik.http.routers.uptime-kuma.entrypoints=websecure"
|
||||||
- "traefik.http.routers.uptime-kuma.tls=true"
|
- "traefik.http.routers.uptime-kuma.tls=true"
|
||||||
- "traefik.http.services.uptime-kuma.loadbalancer.server.port=3001"
|
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`) || Host(`uptime.internal`)"
|
- "traefik.http.routers.uptime-kuma-local.rule=Host(`uptime.workstation.internal`)"
|
||||||
- "traefik.http.routers.uptime-kuma-local.entrypoints=websecure"
|
- "traefik.http.routers.uptime-kuma-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.uptime-kuma-local.tls=true"
|
- "traefik.http.routers.uptime-kuma-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.uptime-kuma-dev.rule=Host(`uptime.gigaforust.internal`)"
|
- "traefik.http.routers.uptime-kuma-dev.rule=Host(`uptime.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
|
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.uptime-kuma-dev.tls=true"
|
- "traefik.http.routers.uptime-kuma-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- proxy
|
- proxy
|
||||||
|
volumes:
|
||||||
|
data:
|
||||||
networks:
|
networks:
|
||||||
proxy:
|
proxy:
|
||||||
external: true
|
external: true
|
||||||
Reference in New Issue
Block a user