Compare commits

...

9 Commits

Author SHA1 Message Date
forust 4fe3d660f1 Merge pull request 'Added DoT support on dns.forust.xyz' (#2) from fix/dns into main
Reviewed-on: #2
2025-12-31 03:44:08 +01:00
forust 9675eac2bf feat: add DoT support on dns.forust.xyz
- Made adguard available on adguard. and dns. subdomain
- DoT and DoH implementation complete
2025-12-31 03:41:38 +01:00
forust dc7fe64fbc fix: clean up traefik configuration and add redirect middleware 2025-12-30 22:44:52 +01:00
forust 502810a12e fix: update traefik router rules for DNS and adjust letsencrypt volume path 2025-12-30 17:20:13 +01:00
forust c047cc291d LE for DoH 2025-12-30 16:54:23 +01:00
forust f2b951673c fix: add traefik route for dns o https 2025-12-30 15:47:39 +01:00
forust 6b7c0df586 Merge pull request 'refactor: update network refs form "traefik-proxy" to "proxy"' (#1) from refactor/traefik-network into main
Reviewed-on: #1
2025-12-30 14:26:09 +01:00
forust fb2f420520 refactor: update network refs form "traefik-proxy" to "proxy"
- To allow testing dev vers of other services
2025-12-30 14:14:24 +01:00
forust 60c7d4ff17 feat: add mailer support and credentials for gitea 2025-12-28 23:35:31 +01:00
19 changed files with 106 additions and 91 deletions
+4
View File
@@ -41,6 +41,9 @@ homepages/forust_files/assets/images/team/*
# Traefik files
traefik/letsencrypt/acme.json
traefik/logs/*
# SSL Certificates
adguardhome/certs/*
traefik/certs/*
# Monitoring
@@ -83,3 +86,4 @@ replacements.txt
# Temp files
edu_master/temp/
temp/*
+15 -9
View File
@@ -3,48 +3,54 @@ services:
image: adguard/adguardhome:latest
container_name: adguardhome
restart: unless-stopped
environment:
- TZ=${TZ}
ports:
- "53:53/tcp"
- "53:53/udp"
- "853:853/tcp" # DNS over TLS
# - "67:67/udp" # DHCP
# - "68:68/tcp" # DHCP
- "3000:3000/tcp"
volumes:
- ./data/work:/opt/adguardhome/work
- ./data/conf:/opt/adguardhome/conf
- ./certs:/certs:ro
networks:
- traefik-proxy
- proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
# Prod Router
- "traefik.http.routers.adguard.rule=Host(`adguard.forust.xyz`)"
- "traefik.http.routers.adguard.rule=Host(`dns.forust.xyz`) || Host(`adguard.forust.xyz`)"
- "traefik.http.routers.adguard.entrypoints=websecure"
- "traefik.http.routers.adguard.middlewares=security-headers@file"
- "traefik.http.routers.adguard.service=adguard"
- "traefik.http.routers.adguard.tls=true"
- "traefik.http.services.adguard.loadbalancer.server.port=3000"
# Local Router
- "traefik.http.routers.adguard-local.rule=Host(`adguard.workstation.internal`) || Host(`adguard.internal`)"
- "traefik.http.routers.adguard-local.rule=Host(`dns.workstation.internal`) || Host(`adguard.internal`) || Host(`adguard.workstation.internal`)"
- "traefik.http.routers.adguard-local.entrypoints=websecure"
- "traefik.http.routers.adguard-local.middlewares=security-headers@file"
- "traefik.http.routers.adguard-local.service=adguard"
- "traefik.http.routers.adguard-local.tls=true"
# Dev Router
- "traefik.http.routers.adguard-dev.rule=Host(`adguard.gigaforust.internal`)"
- "traefik.http.routers.adguard-dev.rule=Host(`dns.gigaforust.internal`) || Host(`adguard.gigaforust.internal`)"
- "traefik.http.routers.adguard-dev.entrypoints=websecure"
- "traefik.http.routers.adguard-dev.middlewares=security-headers@file"
- "traefik.http.routers.adguard-dev.service=adguard"
- "traefik.http.routers.adguard-dev.tls=true"
# DoH
- "traefik.http.routers.dns.rule=(Host(`dns.forust.xyz`) && PathPrefix(`/dns-query`))"
- "traefik.http.routers.dns.entrypoints=websecure"
- "traefik.http.routers.dns.service=adguard"
- "traefik.http.routers.dns.tls.certresolver=letsencrypt"
- glance.name=adguard
- glance.url=https://adguard.forust.xyz/
- glance.description=AdGuard Home is a network-wide software for blocking ads.
networks:
traefik-proxy:
proxy:
external: true
+3 -3
View File
@@ -40,7 +40,7 @@ services:
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Services
# - "traefik.http.services.authentik-server.loadbalancer.server.port=9443"
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
@@ -69,7 +69,7 @@ services:
- ./media:/media
- ./custom-templates:/templates
networks:
- traefik-proxy
- proxy
- authentik
depends_on:
postgresql:
@@ -102,5 +102,5 @@ volumes:
driver: local
networks:
authentik:
traefik-proxy:
proxy:
external: true
+3 -3
View File
@@ -16,10 +16,10 @@ services:
timeout: 10s
retries: 3
networks:
- traefik-proxy
- proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
@@ -50,5 +50,5 @@ services:
- glance.description=Dockmon is a lightweight Docker container monitoring and management tool with a user-friendly web interface.
networks:
traefik-proxy:
proxy:
external: true
+2 -2
View File
@@ -29,11 +29,11 @@ services:
- traefik.http.routers.downtify-dev.service=downtify
- traefik.http.routers.downtify-dev.tls=true
networks:
- traefik-proxy
- proxy
volumes:
- ./Downtify_downloads:/downloads
networks:
traefik-proxy:
proxy:
external: true
+3
View File
@@ -2,3 +2,6 @@ GITEA_POSTGRES_USER=
GITEA_POSTGRES_PASSWORD=
GITEA_POSTGRES_DB=gitea
BASIC-RUNNER_TOKEN=
GITEA_SMTP_PASS=
MAILER_ADDR=
SERVICE_EMAIL=email.used.by.services@domain.tld
+12 -3
View File
@@ -15,17 +15,26 @@ services:
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
- GITEA__server__SSH_PORT=2221
# Mailer
- GITEA__mailer__ENABLED=true
- GITEA__mailer__FROM=${SERVICE_EMAIL}
- GITEA__mailer__SMTP_ADDR=${MAILER_ADDR}:465
- GITEA__mailer__USER=${SERVICE_EMAIL}
- GITEA__mailer__PASSWD=${GITEA_SMTP_PASS}
- GITEA__mailer__PROTOCOL=SMTP
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
- GITEA__service__ENABLE_NOTIFY_MAIL=true
restart: always
networks:
- gitea-db
- traefik-proxy
- proxy
volumes:
- ./gitea-data:/data
- /etc/timezone:/etc/timezone:ro
- /etc/localtime:/etc/localtime:ro
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.gitea.rule=Host(`gitea.forust.xyz`)"
@@ -90,5 +99,5 @@ services:
networks:
gitea-db:
external: false
traefik-proxy:
proxy:
external: true
+3 -3
View File
@@ -11,7 +11,7 @@ services:
env_file: .env
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
@@ -31,10 +31,10 @@ services:
- "traefik.http.routers.glance-dev.middlewares=security-chain@file"
- "traefik.http.routers.glance-dev.tls=true"
networks:
- traefik-proxy
- proxy
dns:
- 1.1.1.1
- 8.8.8.8
networks:
traefik-proxy:
proxy:
external: true
+5 -5
View File
@@ -9,10 +9,10 @@ services:
volumes:
- ./forust_files:/usr/share/nginx/html
networks:
- traefik-proxy
- proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Services
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
@@ -48,10 +48,10 @@ services:
volumes:
- ./xdfnx_files:/usr/share/nginx/html
networks:
- traefik-proxy
- proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Services
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
@@ -79,5 +79,5 @@ services:
networks:
traefik-proxy:
proxy:
external: true
+3 -3
View File
@@ -14,7 +14,7 @@ services:
- ./MeTube_downloads:/downloads
labels:
- traefik.enable=true
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
@@ -39,7 +39,7 @@ services:
- "traefik.http.routers.metube-dev.tls=true"
networks:
- traefik-proxy
- proxy
networks:
traefik-proxy:
proxy:
external: true
+3 -3
View File
@@ -23,11 +23,11 @@ services:
- 1.1.1.1
- 8.8.8.8
networks:
- traefik-proxy
- proxy
- n8n
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.n8n.rule=Host(`n8n.forust.xyz`)"
@@ -58,5 +58,5 @@ services:
networks:
n8n:
external: false
traefik-proxy:
proxy:
external: true
+4 -4
View File
@@ -9,7 +9,7 @@ services:
- /var/run/docker.sock:/var/run/docker.sock:ro
networks:
- nextcloud-aio
- traefik-proxy # Optional: Connects the mastercontainer to the traefik-proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
- proxy # Optional: Connects the mastercontainer to the proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
# ports:
# - 8081:80 # may be removed if under reverse-proxy
# - 8443:8443
@@ -17,7 +17,7 @@ services:
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# AIO Services configuration
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
@@ -55,7 +55,7 @@ services:
AIO_DISABLE_BACKUP_SECTION: false
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
APACHE_IP_BINDING: 0.0.0.0 # Configure when going with reverse-proxy https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
APACHE_ADDITIONAL_NETWORK: traefik-proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
APACHE_ADDITIONAL_NETWORK: proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Backup retention See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy
COLLABORA_SECCOMP_DISABLED: false # Setting this to true allows to disable Collabora's Seccomp feature. See https://github.com/nextcloud/all-in-one#how-to-disable-collaboras-seccomp-feature
FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # adjust fulltextsearch java options. https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options
@@ -75,7 +75,7 @@ services:
# WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. For macos it needs to be '/var/run/docker.sock'
networks:
traefik-proxy:
proxy:
external: true
nextcloud-aio:
driver: bridge
+3 -3
View File
@@ -50,7 +50,7 @@ x-secret-key: &penpot-secret-key
networks:
penpot:
traefik-proxy:
proxy:
external: true
volumes:
@@ -98,11 +98,11 @@ services:
networks:
- penpot
- traefik-proxy
- proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.penpot.rule=Host(`penpot.forust.xyz`)"
+3 -3
View File
@@ -10,10 +10,10 @@ services:
- 9443:9443
# - 8000:8000 # Remove if you do not intend to use Edge Agents
networks:
- traefik-proxy
- proxy
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.portainer.rule=Host(`portainer.forust.xyz`)"
@@ -50,5 +50,5 @@ volumes:
networks:
default:
name: portainer_network
traefik-proxy:
proxy:
external: true
+3 -3
View File
@@ -11,7 +11,7 @@ services:
PORT: "8080"
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.termix.rule=Host(`termix.forust.xyz`)"
@@ -35,10 +35,10 @@ services:
- "traefik.http.routers.termix-dev.service=termix"
- "traefik.http.routers.termix-dev.tls=true"
networks:
- traefik-proxy
- proxy
networks:
traefik-proxy:
proxy:
external: true
volumes:
+10 -12
View File
@@ -11,7 +11,7 @@ services:
# Providers
- "--providers.docker=true"
- "--providers.docker.exposedbydefault=false"
- "--providers.docker.network=traefik-proxy"
- "--providers.docker.network=proxy"
- "--providers.file.directory=/etc/traefik/dynamic"
- "--providers.file.watch=true"
@@ -19,16 +19,14 @@ services:
- "--entryPoints.web.address=:80"
- "--entryPoints.websecure.address=:443"
- "--entryPoints.websecure.http.tls=true"
- "--entryPoints.web.http.redirections.entryPoint.to=websecure"
- "--entryPoints.web.http.redirections.entryPoint.scheme=https"
- "--entryPoints.ssh.address=:2221"
# Let's Encrypt STAGING. CURRENTLY USING CF ORIGIN CA INSTEAD
# - "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
# - "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
# Let's Encrypt
- "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
- "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
- "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
# # STAGING
# - "--certificatesresolvers.letsencrypt.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
# Cloudflare
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
@@ -41,7 +39,7 @@ services:
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router (Dash)
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
@@ -77,14 +75,14 @@ services:
- ./dynamic:/etc/traefik/dynamic:ro
- ./certs:/certs:ro
- ./logs:/var/log/traefik
# - ./traefik/letsencrypt:/letsencrypt
- ./letsencrypt:/letsencrypt
networks:
- traefik-proxy
- proxy
environment:
- TZ=Europe/Bratislava
networks:
traefik-proxy:
proxy:
external: true
-28
View File
@@ -1,33 +1,5 @@
http:
middlewares:
# HTTPS Redirect
redirect-https:
redirectScheme:
scheme: https
permanent: true
# Metube Basic Auth
metube-auth:
basicAuth:
users:
- "vv:$2y$05$JdT8AGUO9bd.E/PiCmKaoOJS1RFlXkrrmZ5mJ4f8/a1bEW39L3FbS"
realm: "MeTube Access"
# Basic Auth Traefik Dashboard
auth:
basicAuth:
users:
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
realm: "Traefik Dashboard"
# Basic Auth Dockmon
dockmon-auth:
basicAuth:
users:
- "admin:$2y$05$.CKDD82sNUxcpaRrLbHuK.dopqt1fgurc2yfTKAT5OFzT7RvPrJHK"
realm: "Dockmon Access"
# Cloudflare IP Whitelist
cloudflare-ipwhitelist:
ipWhiteList:
+23
View File
@@ -0,0 +1,23 @@
http:
middlewares:
redirect-https:
redirectScheme:
scheme: https
permanent: true
routers:
acme-challenge-exempt:
rule: "PathPrefix(`/.well-known/acme-challenge`)"
entryPoints:
- web
service: noop@internal
priority: 100
http-catchall:
rule: "HostRegexp(`{host:.+}`)"
entryPoints:
- web
middlewares:
- redirect-https
service: noop@internal
priority: 1
+3 -3
View File
@@ -10,7 +10,7 @@ services:
- "3001:3001"
labels:
- "traefik.enable=true"
- "traefik.docker.network=traefik-proxy"
- "traefik.docker.network=proxy"
# Prod Router
- "traefik.http.routers.uptime-kuma.rule=Host(`uptime.forust.xyz`)"
@@ -28,7 +28,7 @@ services:
- "traefik.http.routers.uptime-kuma-dev.entrypoints=websecure"
- "traefik.http.routers.uptime-kuma-dev.tls=true"
networks:
- traefik-proxy
- proxy
networks:
traefik-proxy:
proxy:
external: true