Compare commits
30 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 60c7d4ff17 | |||
| d20ec696a3 | |||
| c030b4cffa | |||
| e0f7ab6561 | |||
| f0682319a7 | |||
| dbd3f36f76 | |||
| 4471da827c | |||
| 163ea867ce | |||
| dc75dbaf7c | |||
| 17cae71952 | |||
| f4c695f95e | |||
| 6bdb16ad21 | |||
| 6eb62f41cc | |||
| 586f0e3f7d | |||
| 0e46193f53 | |||
| aed28ed15c | |||
| f3b73bae11 | |||
| be049cfa0d | |||
| 4f9e7ea990 | |||
| c31369f2b7 | |||
| 3bfcd6edf4 | |||
| 504cbc81a0 | |||
| aa7239ee83 | |||
| 6d9427cf2a | |||
| 70d60ed40a | |||
| aca6824309 | |||
| 6843befac3 | |||
| 0dfb09590d | |||
| 625eb9561b | |||
| b367b64879 |
+5
-1
@@ -12,6 +12,7 @@ sync.ffs_lock
|
|||||||
# Volumes and data directories
|
# Volumes and data directories
|
||||||
gitea/gitea-db/
|
gitea/gitea-db/
|
||||||
gitea/gitea-data/*
|
gitea/gitea-data/*
|
||||||
|
gitea/*runner/*
|
||||||
n8n/n8n-data/*
|
n8n/n8n-data/*
|
||||||
n8n/n8n-node-data/*
|
n8n/n8n-node-data/*
|
||||||
adguardhome/data/*
|
adguardhome/data/*
|
||||||
@@ -21,6 +22,8 @@ metube/MeTube_downloads
|
|||||||
uptime-kuma/data/
|
uptime-kuma/data/
|
||||||
termix/termix-data/*
|
termix/termix-data/*
|
||||||
cfddns/config.json
|
cfddns/config.json
|
||||||
|
checkmk/checkmk/*
|
||||||
|
downtify/Downtify_downloads
|
||||||
|
|
||||||
# Steaming services files
|
# Steaming services files
|
||||||
streaming/jellyfin/*
|
streaming/jellyfin/*
|
||||||
@@ -32,7 +35,8 @@ streaming/qbittorrent/*
|
|||||||
streaming/prowlarr/*
|
streaming/prowlarr/*
|
||||||
|
|
||||||
# Homepage
|
# Homepage
|
||||||
homepage/files/assets/images/team/*
|
homepages/forust_files/assets/images/team/*
|
||||||
|
|
||||||
|
|
||||||
# Traefik files
|
# Traefik files
|
||||||
traefik/letsencrypt/acme.json
|
traefik/letsencrypt/acme.json
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
# ===================================
|
||||||
|
# Authentification app (authentik)
|
||||||
|
|
||||||
|
# PostgresQL conf
|
||||||
|
PG_PASS=change_this_cuz_its_ur_db_pass
|
||||||
|
PG_USER=authentik # it's okay
|
||||||
|
|
||||||
|
# Image Settings
|
||||||
|
AUTHENTIK_IMAGE=ghcr.io/goauthentik/server
|
||||||
|
AUTHENTIK_TAG=2025.10.2
|
||||||
|
|
||||||
|
# Networking
|
||||||
|
PORT_HTTP=9000
|
||||||
|
PORT_HTTPS=9443 # btw likely already used by portainer
|
||||||
|
|
||||||
|
AUTHENTIK_SECRET_KEY=super_secret_super_scary_authenik_key
|
||||||
|
|
||||||
|
AUTHENTIK_BOOTSTRAP_PASSWORD=pls_change_this
|
||||||
|
|
||||||
|
AUTHENTIK_ERROR_REPORTING__ENABLED=true # Or false to turn off
|
||||||
@@ -0,0 +1,106 @@
|
|||||||
|
services:
|
||||||
|
postgresql:
|
||||||
|
image: docker.io/library/postgres:15-alpine
|
||||||
|
restart: unless-stopped
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
|
environment:
|
||||||
|
POSTGRES_DB: ${PG_DB:-authentik}
|
||||||
|
POSTGRES_PASSWORD: ${PG_PASS:?database password required}
|
||||||
|
POSTGRES_USER: ${PG_USER:-authentik}
|
||||||
|
healthcheck:
|
||||||
|
interval: 30s
|
||||||
|
retries: 5
|
||||||
|
start_period: 20s
|
||||||
|
test:
|
||||||
|
- CMD-SHELL
|
||||||
|
- pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}
|
||||||
|
timeout: 5s
|
||||||
|
volumes:
|
||||||
|
- database:/var/lib/postgresql/data
|
||||||
|
networks:
|
||||||
|
- authentik
|
||||||
|
|
||||||
|
server:
|
||||||
|
image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.10.2}
|
||||||
|
command: server
|
||||||
|
container_name: authentik-server
|
||||||
|
restart: unless-stopped
|
||||||
|
ports:
|
||||||
|
- ${PORT_HTTP:-9000}:9000
|
||||||
|
- ${PORT_HTTPS:-9443}:9443
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
|
environment:
|
||||||
|
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
||||||
|
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
||||||
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||||
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||||
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||||
|
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=traefik-proxy"
|
||||||
|
# Services
|
||||||
|
# - "traefik.http.services.authentik-server.loadbalancer.server.port=9443"
|
||||||
|
- "traefik.http.services.authentik-server.loadbalancer.server.port=9000"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.authentik-server.rule=Host(`auth.forust.xyz`)"
|
||||||
|
- "traefik.http.routers.authentik-server.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server.service=authentik-server"
|
||||||
|
- "traefik.http.routers.authentik-server.tls=true"
|
||||||
|
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.authentik-server-local.rule=Host(`auth.workstation.internal`) || Host(`auth-dashboard.internal`)"
|
||||||
|
- "traefik.http.routers.authentik-server-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server-local.service=authentik-server"
|
||||||
|
- "traefik.http.routers.authentik-server-local.tls=true"
|
||||||
|
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.authentik-server-dev.rule=Host(`auth.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.service=authentik-server"
|
||||||
|
- "traefik.http.routers.authentik-server-dev.tls=true"
|
||||||
|
volumes:
|
||||||
|
- ./media:/media
|
||||||
|
- ./custom-templates:/templates
|
||||||
|
networks:
|
||||||
|
- traefik-proxy
|
||||||
|
- authentik
|
||||||
|
depends_on:
|
||||||
|
postgresql:
|
||||||
|
condition: service_healthy
|
||||||
|
worker:
|
||||||
|
image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.10.2}
|
||||||
|
restart: unless-stopped
|
||||||
|
user: root
|
||||||
|
command: worker
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
|
environment:
|
||||||
|
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
||||||
|
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
||||||
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
||||||
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
||||||
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
||||||
|
volumes:
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
- ./media:/media
|
||||||
|
- ./certs:/certs
|
||||||
|
- ./custom-templates:/templates
|
||||||
|
networks:
|
||||||
|
- authentik
|
||||||
|
depends_on:
|
||||||
|
postgresql:
|
||||||
|
condition: service_healthy
|
||||||
|
volumes:
|
||||||
|
database:
|
||||||
|
driver: local
|
||||||
|
networks:
|
||||||
|
authentik:
|
||||||
|
traefik-proxy:
|
||||||
|
external: true
|
||||||
@@ -24,7 +24,7 @@ services:
|
|||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
- "traefik.http.routers.dockmon.rule=Host(`dockmon.forust.xyz`)"
|
||||||
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
- "traefik.http.routers.dockmon.entrypoints=websecure"
|
||||||
- "traefik.http.routers.dockmon.middlewares=security-headers@file,dockmon-auth@file"
|
- "traefik.http.routers.dockmon.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.dockmon.service=dockmon"
|
- "traefik.http.routers.dockmon.service=dockmon"
|
||||||
- "traefik.http.routers.dockmon.tls=true"
|
- "traefik.http.routers.dockmon.tls=true"
|
||||||
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
- "traefik.http.services.dockmon.loadbalancer.server.port=443"
|
||||||
@@ -41,7 +41,7 @@ services:
|
|||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
- "traefik.http.routers.dockmon-dev.rule=Host(`dockmon.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
- "traefik.http.routers.dockmon-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.dockmon-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.dockmon-dev.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.dockmon-dev.service=dockmon"
|
- "traefik.http.routers.dockmon-dev.service=dockmon"
|
||||||
- "traefik.http.routers.dockmon-dev.tls=true"
|
- "traefik.http.routers.dockmon-dev.tls=true"
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
services:
|
||||||
|
downtify:
|
||||||
|
container_name: downtify
|
||||||
|
image: ghcr.io/henriquesebastiao/downtify:latest
|
||||||
|
# ports:
|
||||||
|
# - '7077:8000'
|
||||||
|
labels:
|
||||||
|
- traefik.enable=true
|
||||||
|
- traefik.http.services.downtify.loadbalancer.server.port=8000
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- traefik.http.routers.downtify.rule=Host(`downtify.forust.xyz`)
|
||||||
|
- traefik.http.routers.downtify.entrypoints=websecure
|
||||||
|
- traefik.http.routers.downtify.middlewares=security-chain@file
|
||||||
|
- traefik.http.routers.downtify.service=downtify
|
||||||
|
- traefik.http.routers.downtify.tls=true
|
||||||
|
|
||||||
|
# Local Router
|
||||||
|
- traefik.http.routers.downtify-local.rule=Host(`downtify.workstation.internal`) || Host(`downtify.internal`)
|
||||||
|
- traefik.http.routers.downtify-local.entrypoints=websecure
|
||||||
|
- traefik.http.routers.downtify-local.middlewares=security-headers@file
|
||||||
|
- traefik.http.routers.downtify-local.service=downtify
|
||||||
|
- traefik.http.routers.downtify-local.tls=true
|
||||||
|
|
||||||
|
# Dev Router
|
||||||
|
- traefik.http.routers.downtify-dev.rule=Host(`downtify.gigaforust.internal`)
|
||||||
|
- traefik.http.routers.downtify-dev.entrypoints=websecure
|
||||||
|
- traefik.http.routers.downtify-dev.middlewares=security-chain@file
|
||||||
|
- traefik.http.routers.downtify-dev.service=downtify
|
||||||
|
- traefik.http.routers.downtify-dev.tls=true
|
||||||
|
networks:
|
||||||
|
- traefik-proxy
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
- ./Downtify_downloads:/downloads
|
||||||
|
|
||||||
|
networks:
|
||||||
|
traefik-proxy:
|
||||||
|
external: true
|
||||||
@@ -1,3 +1,7 @@
|
|||||||
GITEA_POSTGRES_USER=
|
GITEA_POSTGRES_USER=
|
||||||
GITEA_POSTGRES_PASSWORD=
|
GITEA_POSTGRES_PASSWORD=
|
||||||
GITEA_POSTGRES_DB=gitea
|
GITEA_POSTGRES_DB=gitea
|
||||||
|
BASIC-RUNNER_TOKEN=
|
||||||
|
GITEA_SMTP_PASS=
|
||||||
|
MAILER_ADDR=
|
||||||
|
SERVICE_EMAIL=email.used.by.services@domain.tld
|
||||||
@@ -13,7 +13,17 @@ services:
|
|||||||
- GITEA__database__NAME=gitea
|
- GITEA__database__NAME=gitea
|
||||||
#Server
|
#Server
|
||||||
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
- GITEA__server__ROOT_URL=https://gitea.forust.xyz
|
||||||
|
- GITEA__server__SSH_DOMAIN=gitssh.forust.xyz
|
||||||
- GITEA__server__SSH_PORT=2221
|
- GITEA__server__SSH_PORT=2221
|
||||||
|
# Mailer
|
||||||
|
- GITEA__mailer__ENABLED=true
|
||||||
|
- GITEA__mailer__FROM=${SERVICE_EMAIL}
|
||||||
|
- GITEA__mailer__SMTP_ADDR=${MAILER_ADDR}:465
|
||||||
|
- GITEA__mailer__USER=${SERVICE_EMAIL}
|
||||||
|
- GITEA__mailer__PASSWD=${GITEA_SMTP_PASS}
|
||||||
|
- GITEA__mailer__PROTOCOL=SMTP
|
||||||
|
- GITEA__service__REGISTER_EMAIL_CONFIRM=true
|
||||||
|
- GITEA__service__ENABLE_NOTIFY_MAIL=true
|
||||||
restart: always
|
restart: always
|
||||||
networks:
|
networks:
|
||||||
- gitea-db
|
- gitea-db
|
||||||
@@ -47,11 +57,33 @@ services:
|
|||||||
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.gitea-dev.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.gitea-dev.service=gitea"
|
- "traefik.http.routers.gitea-dev.service=gitea"
|
||||||
- "traefik.http.routers.gitea-dev.tls=true"
|
- "traefik.http.routers.gitea-dev.tls=true"
|
||||||
|
- "traefik.tcp.routers.gitea.entrypoints=ssh"
|
||||||
|
- "traefik.tcp.routers.gitea.rule=HostSNI(`*`)"
|
||||||
|
- "traefik.tcp.services.gitea.loadbalancer.server.port=22"
|
||||||
ports:
|
ports:
|
||||||
- "2221:22"
|
- "2221:22"
|
||||||
depends_on:
|
depends_on:
|
||||||
- db
|
- db
|
||||||
|
|
||||||
|
runner:
|
||||||
|
image: gitea/act_runner:0.2.11
|
||||||
|
container_name: gitea-runner
|
||||||
|
restart: always
|
||||||
|
depends_on:
|
||||||
|
- server
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
|
networks:
|
||||||
|
- gitea-db
|
||||||
|
environment:
|
||||||
|
- GITEA_INSTANCE_URL=http://server:3000
|
||||||
|
- GITEA_RUNNER_REGISTRATION_TOKEN=${BASIC-RUNNER_TOKEN}
|
||||||
|
- GITEA_RUNNER_NAME=basic-runner
|
||||||
|
- GITEA_RUNNER_LABELS=docker:docker://node:20-bookworm,ubuntu-latest:docker://node:20-bookworm
|
||||||
|
volumes:
|
||||||
|
- ./gitea-runner:/data
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
|
||||||
db:
|
db:
|
||||||
image: docker.io/library/postgres:14
|
image: docker.io/library/postgres:14
|
||||||
restart: always
|
restart: always
|
||||||
|
|||||||
+2
-2
@@ -16,7 +16,7 @@ services:
|
|||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
- "traefik.http.routers.glance.rule=Host(`glance.forust.xyz`)"
|
||||||
- "traefik.http.routers.glance.entrypoints=websecure"
|
- "traefik.http.routers.glance.entrypoints=websecure"
|
||||||
- "traefik.http.routers.glance.middlewares=security-headers@file"
|
- "traefik.http.routers.glance.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.glance.tls=true"
|
- "traefik.http.routers.glance.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
@@ -28,7 +28,7 @@ services:
|
|||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
- "traefik.http.routers.glance-dev.rule=Host(`glance.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
- "traefik.http.routers.glance-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.glance-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.glance-dev.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.glance-dev.tls=true"
|
- "traefik.http.routers.glance-dev.tls=true"
|
||||||
networks:
|
networks:
|
||||||
- traefik-proxy
|
- traefik-proxy
|
||||||
|
|||||||
@@ -1,39 +0,0 @@
|
|||||||
services:
|
|
||||||
forust-homepage:
|
|
||||||
build: .
|
|
||||||
ports:
|
|
||||||
- "8085:80"
|
|
||||||
restart: unless-stopped
|
|
||||||
volumes:
|
|
||||||
- ./files:/usr/share/nginx/html
|
|
||||||
networks:
|
|
||||||
- traefik-proxy
|
|
||||||
labels:
|
|
||||||
- "traefik.enable=true"
|
|
||||||
- "traefik.docker.network=traefik-proxy"
|
|
||||||
|
|
||||||
# Prod Router
|
|
||||||
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
|
||||||
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.forust-homepage.middlewares=security-headers@file"
|
|
||||||
- "traefik.http.routers.forust-homepage.service=forust-homepage"
|
|
||||||
- "traefik.http.routers.forust-homepage.tls=true"
|
|
||||||
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
|
||||||
|
|
||||||
# Local Router
|
|
||||||
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`) || Host(`landing.internal`)"
|
|
||||||
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file"
|
|
||||||
- "traefik.http.routers.forust-homepage-local.service=forust-homepage"
|
|
||||||
- "traefik.http.routers.forust-homepage-local.tls=true"
|
|
||||||
|
|
||||||
# Dev Router
|
|
||||||
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
|
||||||
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
|
||||||
- "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file"
|
|
||||||
- "traefik.http.routers.forust-homepage-dev.service=forust-homepage"
|
|
||||||
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
|
||||||
|
|
||||||
networks:
|
|
||||||
traefik-proxy:
|
|
||||||
external: true
|
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
# everyone use that
|
||||||
|
FROM nginx:alpine
|
||||||
|
|
||||||
|
RUN rm -rf /usr/share/nginx/html/*
|
||||||
|
|
||||||
|
COPY ./forust_files /usr/share/nginx/html
|
||||||
|
|
||||||
|
EXPOSE 80
|
||||||
|
# Start
|
||||||
|
CMD ["nginx", "-g", "daemon off;"]
|
||||||
@@ -3,7 +3,7 @@ FROM nginx:alpine
|
|||||||
|
|
||||||
RUN rm -rf /usr/share/nginx/html/*
|
RUN rm -rf /usr/share/nginx/html/*
|
||||||
|
|
||||||
COPY ./files /usr/share/nginx/html
|
COPY ./xdfnx_files /usr/share/nginx/html
|
||||||
|
|
||||||
EXPOSE 80
|
EXPOSE 80
|
||||||
# Start
|
# Start
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
services:
|
||||||
|
forust:
|
||||||
|
build:
|
||||||
|
context: .
|
||||||
|
dockerfile: Dockerfile.forust
|
||||||
|
ports:
|
||||||
|
- "8085:80"
|
||||||
|
restart: unless-stopped
|
||||||
|
volumes:
|
||||||
|
- ./forust_files:/usr/share/nginx/html
|
||||||
|
networks:
|
||||||
|
- traefik-proxy
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=traefik-proxy"
|
||||||
|
|
||||||
|
# Services
|
||||||
|
- "traefik.http.services.forust-homepage.loadbalancer.server.port=80"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.forust-homepage.rule=Host(`forust.xyz`)"
|
||||||
|
- "traefik.http.routers.forust-homepage.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.forust-homepage.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.forust-homepage.service=forust-homepage"
|
||||||
|
- "traefik.http.routers.forust-homepage.tls=true"
|
||||||
|
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.forust-homepage-local.rule=Host(`landing.workstation.internal`) || Host(`landing.internal`)"
|
||||||
|
- "traefik.http.routers.forust-homepage-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.forust-homepage-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.forust-homepage-local.service=forust-homepage"
|
||||||
|
- "traefik.http.routers.forust-homepage-local.tls=true"
|
||||||
|
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.forust-homepage-dev.rule=Host(`landing.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.forust-homepage-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.forust-homepage-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.forust-homepage-dev.service=forust-homepage"
|
||||||
|
- "traefik.http.routers.forust-homepage-dev.tls=true"
|
||||||
|
|
||||||
|
xdfnx:
|
||||||
|
build:
|
||||||
|
context: .
|
||||||
|
dockerfile: Dockerfile.xdfnx
|
||||||
|
ports:
|
||||||
|
- "8086:80"
|
||||||
|
restart: unless-stopped
|
||||||
|
volumes:
|
||||||
|
- ./xdfnx_files:/usr/share/nginx/html
|
||||||
|
networks:
|
||||||
|
- traefik-proxy
|
||||||
|
labels:
|
||||||
|
- "traefik.enable=true"
|
||||||
|
- "traefik.docker.network=traefik-proxy"
|
||||||
|
|
||||||
|
# Services
|
||||||
|
- "traefik.http.services.xdfnx-homepage.loadbalancer.server.port=80"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
|
- "traefik.http.routers.xdfnx.rule=Host(`xdfnx.cfd`)"
|
||||||
|
- "traefik.http.routers.xdfnx.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.xdfnx.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.xdfnx.service=xdfnx-homepage"
|
||||||
|
- "traefik.http.routers.xdfnx.tls=true"
|
||||||
|
|
||||||
|
# Local Router
|
||||||
|
- "traefik.http.routers.xdfnx-local.rule=Host(`xdfnx.workstation.internal`) || Host(`xdfnx.internal`)"
|
||||||
|
- "traefik.http.routers.xdfnx-local.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.xdfnx-local.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.xdfnx-local.service=xdfnx-homepage"
|
||||||
|
- "traefik.http.routers.xdfnx-local.tls=true"
|
||||||
|
|
||||||
|
# Dev Router
|
||||||
|
- "traefik.http.routers.xdfnx-dev.rule=Host(`xdfnx.gigaforust.internal`)"
|
||||||
|
- "traefik.http.routers.xdfnx-dev.entrypoints=websecure"
|
||||||
|
- "traefik.http.routers.xdfnx-dev.middlewares=security-headers@file"
|
||||||
|
- "traefik.http.routers.xdfnx-dev.service=xdfnx-homepage"
|
||||||
|
- "traefik.http.routers.xdfnx-dev.tls=true"
|
||||||
|
|
||||||
|
|
||||||
|
networks:
|
||||||
|
traefik-proxy:
|
||||||
|
external: true
|
||||||
Binary file not shown.
|
After Width: | Height: | Size: 42 KiB |
File diff suppressed because it is too large
Load Diff
+3
-3
@@ -19,7 +19,7 @@ services:
|
|||||||
# Prod Router
|
# Prod Router
|
||||||
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
|
- "traefik.http.routers.metube.rule=Host(`metube.forust.xyz`)"
|
||||||
- "traefik.http.routers.metube.entrypoints=websecure"
|
- "traefik.http.routers.metube.entrypoints=websecure"
|
||||||
- "traefik.http.routers.metube.middlewares=security-headers@file,metube-auth@file"
|
- "traefik.http.routers.metube.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.metube.service=metube"
|
- "traefik.http.routers.metube.service=metube"
|
||||||
- "traefik.http.routers.metube.tls=true"
|
- "traefik.http.routers.metube.tls=true"
|
||||||
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
- "traefik.http.services.metube.loadbalancer.server.port=8081"
|
||||||
@@ -27,14 +27,14 @@ services:
|
|||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`) || Host(`metube.internal`)"
|
- "traefik.http.routers.metube-local.rule=Host(`metube.workstation.internal`) || Host(`metube.internal`)"
|
||||||
- "traefik.http.routers.metube-local.entrypoints=websecure"
|
- "traefik.http.routers.metube-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.metube-local.middlewares=security-headers@file,metube-auth@file"
|
- "traefik.http.routers.metube-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.metube-local.service=metube"
|
- "traefik.http.routers.metube-local.service=metube"
|
||||||
- "traefik.http.routers.metube-local.tls=true"
|
- "traefik.http.routers.metube-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
|
- "traefik.http.routers.metube-dev.rule=Host(`metube.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.metube-dev.entrypoints=websecure"
|
- "traefik.http.routers.metube-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.metube-dev.middlewares=security-headers@file,metube-auth@file"
|
- "traefik.http.routers.metube-dev.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.metube-dev.service=metube"
|
- "traefik.http.routers.metube-dev.service=metube"
|
||||||
- "traefik.http.routers.metube-dev.tls=true"
|
- "traefik.http.routers.metube-dev.tls=true"
|
||||||
|
|
||||||
|
|||||||
+30
-30
@@ -1,35 +1,35 @@
|
|||||||
services:
|
services:
|
||||||
nextcloud-aio-mastercontainer:
|
nextcloud-aio-mastercontainer:
|
||||||
image: ghcr.io/nextcloud-releases/all-in-one:latest # This is the container image used. You can switch to ghcr.io/nextcloud-releases/all-in-one:beta if you want to help testing new releases. See https://github.com/nextcloud/all-in-one#how-to-switch-the-channel
|
image: ghcr.io/nextcloud-releases/all-in-one:beta
|
||||||
init: true # This setting makes sure that signals from main process inside the container are correctly forwarded to children. See https://docs.docker.com/reference/compose-file/services/#init
|
init: true # This setting makes sure that signals from main process inside the container are correctly forwarded to children. See https://docs.docker.com/reference/compose-file/services/#init
|
||||||
restart: unless-stopped # This makes sure that the container starts always together with the host OS. See https://docs.docker.com/reference/compose-file/services/#restart
|
restart: unless-stopped
|
||||||
container_name: nextcloud-aio-mastercontainer # This line is not allowed to be changed as otherwise AIO will not work correctly
|
container_name: nextcloud-aio-mastercontainer # Do not change
|
||||||
volumes:
|
volumes:
|
||||||
- nextcloud_aio_mastercontainer:/mnt/docker-aio-config # This line is not allowed to be changed as otherwise the built-in backup solution will not work
|
- nextcloud_aio_mastercontainer:/mnt/docker-aio-config # Do not change (backup)
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro # May be changed on macOS, Windows or docker rootless. See the applicable documentation. If adjusting, don't forget to also set 'WATCHTOWER_DOCKER_SOCKET_PATH'!
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
# network_mode: bridge # This adds the container to the same network as docker run would do. Comment this line and uncomment the line below and the networks section at the end of the file if you want to define a custom MTU size for the docker network
|
|
||||||
networks:
|
networks:
|
||||||
- nextcloud-aio
|
- nextcloud-aio
|
||||||
- traefik-proxy # Optional: Connects the mastercontainer to the traefik-proxy network in order to make the built-in reverse proxy detection work.
|
- traefik-proxy # Optional: Connects the mastercontainer to the traefik-proxy network in order to make the built-in reverse proxy detection work. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||||
# ports:
|
# ports:
|
||||||
# - 8081:80 # Can be removed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
# - 8081:80 # may be removed if under reverse-proxy
|
||||||
# - 8888:8080 # This is the AIO interface, served via https and self-signed certificate. See https://github.com/nextcloud/all-in-one#explanation-of-used-ports
|
# - 8443:8443
|
||||||
# - 8443:8443 # Can be removed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
# - 8888:8080 # AIO
|
||||||
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=traefik-proxy"
|
- "traefik.docker.network=traefik-proxy"
|
||||||
|
|
||||||
# Prod Router - DISABLED per user request
|
# AIO Services configuration
|
||||||
|
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
|
||||||
|
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
|
||||||
|
- "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file"
|
||||||
|
|
||||||
|
# Prod Router
|
||||||
# - "traefik.http.routers.nextcloud-aio.rule=Host(`nextcloud-aio.forust.xyz`)"
|
# - "traefik.http.routers.nextcloud-aio.rule=Host(`nextcloud-aio.forust.xyz`)"
|
||||||
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
|
# - "traefik.http.routers.nextcloud-aio.entrypoints=websecure"
|
||||||
# - "traefik.http.routers.nextcloud-aio.middlewares=security-headers"
|
# - "traefik.http.routers.nextcloud-aio.middlewares=security-headers"
|
||||||
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
|
# - "traefik.http.routers.nextcloud-aio.service=nextcloud-aio"
|
||||||
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
# - "traefik.http.routers.nextcloud-aio.tls=true"
|
||||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.port=8080"
|
|
||||||
- "traefik.http.services.nextcloud-aio.loadbalancer.server.scheme=https"
|
|
||||||
- "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file"
|
|
||||||
|
|
||||||
# - "traefik.http.services.nextcloud-aio.loadbalancer.serverstransport=insecureTransport@file"
|
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`nextcloud-aio.workstation.internal`) || Host(`nextcloud-aio.internal`)"
|
- "traefik.http.routers.nextcloud-aio-local.rule=Host(`nextcloud-aio.workstation.internal`) || Host(`nextcloud-aio.internal`)"
|
||||||
@@ -45,34 +45,34 @@ services:
|
|||||||
- "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio"
|
- "traefik.http.routers.nextcloud-aio-dev.service=nextcloud-aio"
|
||||||
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
|
- "traefik.http.routers.nextcloud-aio-dev.tls=true"
|
||||||
|
|
||||||
|
# Glanceapp/glance config
|
||||||
- glance.name=Nextcloud
|
- glance.name=Nextcloud
|
||||||
# - glance.icon=si:nextcloud
|
# - glance.icon=si:nextcloud
|
||||||
- glance.url=https://nextcloud.forust.xyz/
|
- glance.url=https://nextcloud.forust.xyz/
|
||||||
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
|
- glance.description=Nextcloud is a suite of client-server software for creating and using file hosting services.
|
||||||
|
|
||||||
environment:
|
environment:
|
||||||
# Is needed when using any of the options below
|
AIO_DISABLE_BACKUP_SECTION: false
|
||||||
AIO_DISABLE_BACKUP_SECTION: false # Setting this to true allows to hide the backup section in the AIO interface. See https://github.com/nextcloud/all-in-one#how-to-disable-the-backup-section
|
|
||||||
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
APACHE_PORT: 11000 # Is needed when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else). See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||||
APACHE_IP_BINDING: 0.0.0.0 # Should be set when running behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else) that is running on the same host. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
APACHE_IP_BINDING: 0.0.0.0 # Configure when going with reverse-proxy https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||||
APACHE_ADDITIONAL_NETWORK: traefik-proxy # (Optional) Connect the apache container to an additional docker network. Needed when behind a web server or reverse proxy (like Apache, Nginx, Caddy, Cloudflare Tunnel and else) running in a different docker network on same server. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
APACHE_ADDITIONAL_NETWORK: traefik-proxy # (Optional) Connect the apache container to an additional docker network. When going with reverse-proxy. See https://github.com/nextcloud/all-in-one/blob/main/reverse-proxy.md
|
||||||
BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Allows to adjust borgs retention policy. See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy
|
BORG_RETENTION_POLICY: --keep-within=7d --keep-weekly=4 --keep-monthly=6 # Backup retention See https://github.com/nextcloud/all-in-one#how-to-adjust-borgs-retention-policy
|
||||||
COLLABORA_SECCOMP_DISABLED: false # Setting this to true allows to disable Collabora's Seccomp feature. See https://github.com/nextcloud/all-in-one#how-to-disable-collaboras-seccomp-feature
|
COLLABORA_SECCOMP_DISABLED: false # Setting this to true allows to disable Collabora's Seccomp feature. See https://github.com/nextcloud/all-in-one#how-to-disable-collaboras-seccomp-feature
|
||||||
FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # Allows to adjust the fulltextsearch java options. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options
|
FULLTEXTSEARCH_JAVA_OPTIONS: "-Xms1024M -Xmx1024M" # adjust fulltextsearch java options. https://github.com/nextcloud/all-in-one#how-to-adjust-the-fulltextsearch-java-options
|
||||||
NEXTCLOUD_DATADIR: /media/forust/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
|
NEXTCLOUD_DATADIR: /media/forust/nextcloud/ncdata # Allows to set the host directory for Nextcloud's datadir. ⚠️⚠️⚠️ Warning: do not set or adjust this value after the initial Nextcloud installation is done! See https://github.com/nextcloud/all-in-one#how-to-change-the-default-location-of-nextclouds-datadir
|
||||||
NEXTCLOUD_MOUNT: /media/forust/nextcloud # Allows the Nextcloud container to access the chosen directory on the host. See https://github.com/nextcloud/all-in-one#how-to-allow-the-nextcloud-container-to-access-directories-on-the-host
|
NEXTCLOUD_MOUNT: /mnt/ # Allows the Nextcloud container to access the chosen directory on the host. See https://github.com/nextcloud/all-in-one#how-to-allow-the-nextcloud-container-to-access-directories-on-the-host
|
||||||
NEXTCLOUD_UPLOAD_LIMIT: 16G # Can be adjusted if you need more. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-upload-limit-for-nextcloud
|
NEXTCLOUD_UPLOAD_LIMIT: 16G # https://github.com/nextcloud/all-in-one#how-to-adjust-the-upload-limit-for-nextcloud
|
||||||
NEXTCLOUD_MAX_TIME: 3600 # Can be adjusted if you need more. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-max-execution-time-for-nextcloud
|
NEXTCLOUD_MAX_TIME: 7200 # Max uploading time See https://github.com/nextcloud/all-in-one#how-to-adjust-the-max-execution-time-for-nextcloud
|
||||||
NEXTCLOUD_MEMORY_LIMIT: 512M # Can be adjusted if you need more. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-php-memory-limit-for-nextcloud
|
NEXTCLOUD_MEMORY_LIMIT: 512M # Can be adjusted if you need more. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-php-memory-limit-for-nextcloud
|
||||||
# NEXTCLOUD_TRUSTED_CACERTS_DIR: /path/to/my/cacerts # CA certificates in this directory will be trusted by the OS of the nextcloud container (Useful e.g. for LDAPS) See https://github.com/nextcloud/all-in-one#how-to-trust-user-defined-certification-authorities-ca
|
# NEXTCLOUD_TRUSTED_CACERTS_DIR: /path/to/my/cacerts # CA certificates will be trusted by the OS of the nextcloud container See https://github.com/nextcloud/all-in-one#how-to-trust-user-defined-certification-authorities-ca
|
||||||
NEXTCLOUD_STARTUP_APPS: deck twofactor_totp tasks calendar contacts notes # Allows to modify the Nextcloud apps that are installed on starting AIO the first time. See https://github.com/nextcloud/all-in-one#how-to-change-the-nextcloud-apps-that-are-installed-on-the-first-startup
|
NEXTCLOUD_STARTUP_APPS: deck twofactor_totp tasks calendar contacts notes # Allows to modify the Nextcloud apps that are installed on starting AIO the first time. See https://github.com/nextcloud/all-in-one#how-to-change-the-nextcloud-apps-that-are-installed-on-the-first-startup
|
||||||
NEXTCLOUD_ADDITIONAL_APKS: imagemagick # This allows to add additional packages to the Nextcloud container permanently. Default is imagemagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-os-packages-permanently-to-the-nextcloud-container
|
NEXTCLOUD_ADDITIONAL_APKS: imagemagick # This allows to add additional packages to the Nextcloud container permanently. Default is imagemagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-os-packages-permanently-to-the-nextcloud-container
|
||||||
NEXTCLOUD_ADDITIONAL_PHP_EXTENSIONS: imagick # This allows to add additional php extensions to the Nextcloud container permanently. Default is imagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-php-extensions-permanently-to-the-nextcloud-container
|
NEXTCLOUD_ADDITIONAL_PHP_EXTENSIONS: imagick # dditional php extensions to the Nextcloud container permanently. Default is imagick but can be overwritten by modifying this value. See https://github.com/nextcloud/all-in-one#how-to-add-php-extensions-permanently-to-the-nextcloud-container
|
||||||
NEXTCLOUD_ENABLE_DRI_DEVICE: true # This allows to enable the /dev/dri device for containers that profit from it. ⚠️⚠️⚠️ Warning: this only works if the '/dev/dri' device is present on the host! If it should not exist on your host, don't set this to true as otherwise the Nextcloud container will fail to start! See https://github.com/nextcloud/all-in-one#how-to-enable-hardware-acceleration-for-nextcloud
|
NEXTCLOUD_ENABLE_DRI_DEVICE: true # This allows to enable the /dev/dri device for containers that profit from it. ⚠️⚠️⚠️ Warning: this only works if the '/dev/dri' device is present on the host! If it should not exist on your host, don't set this to true as otherwise the Nextcloud container will fail to start! See https://github.com/nextcloud/all-in-one#how-to-enable-hardware-acceleration-for-nextcloud
|
||||||
# NEXTCLOUD_KEEP_DISABLED_APPS: false # Setting this to true will keep Nextcloud apps that are disabled in the AIO interface and not uninstall them if they should be installed. See https://github.com/nextcloud/all-in-one#how-to-keep-disabled-apps
|
# NEXTCLOUD_KEEP_DISABLED_APPS: false # Setting this to true will keep Nextcloud apps that are disabled in the AIO interface and not uninstall them if they should be installed. See https://github.com/nextcloud/all-in-one#how-to-keep-disabled-apps
|
||||||
SKIP_DOMAIN_VALIDATION: false # This should only be set to true if things are correctly configured. See https://github.com/nextcloud/all-in-one?tab=readme-ov-file#how-to-skip-the-domain-validation
|
SKIP_DOMAIN_VALIDATION: true # This should only be set to true if things are correctly configured. See https://github.com/nextcloud/all-in-one?tab=readme-ov-file#how-to-skip-the-domain-validation
|
||||||
# TALK_PORT: 3478 # This a-llows to adjust the port that the talk container is using which is exposed on the host. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-talk-port
|
# TALK_PORT: 3478 # This a-llows to adjust the port that the talk container is using which is exposed on the host. See https://github.com/nextcloud/all-in-one#how-to-adjust-the-talk-port
|
||||||
# WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. Otherwise mastercontainer updates will fail. For macos it needs to be '/var/run/docker.sock'
|
# WATCHTOWER_DOCKER_SOCKET_PATH: /var/run/docker.sock # Needs to be specified if the docker socket on the host is not located in the default '/var/run/docker.sock'. For macos it needs to be '/var/run/docker.sock'
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
traefik-proxy:
|
traefik-proxy:
|
||||||
@@ -83,4 +83,4 @@ networks:
|
|||||||
volumes:
|
volumes:
|
||||||
# If you want to store the data on a different drive, see https://github.com/nextcloud/all-in-one#how-to-store-the-filesinstallation-on-a-separate-drive
|
# If you want to store the data on a different drive, see https://github.com/nextcloud/all-in-one#how-to-store-the-filesinstallation-on-a-separate-drive
|
||||||
nextcloud_aio_mastercontainer:
|
nextcloud_aio_mastercontainer:
|
||||||
name: nextcloud_aio_mastercontainer # This line is not allowed to be changed as otherwise the built-in backup solution will not work
|
name: nextcloud_aio_mastercontainer # Do not change
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# ===================================
|
||||||
|
# Traefik envs
|
||||||
|
EMAIL=bobrovod@national.shitposting.agency
|
||||||
+13
-14
@@ -33,35 +33,34 @@ services:
|
|||||||
# Cloudflare
|
# Cloudflare
|
||||||
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||||
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
||||||
|
# # Logging
|
||||||
# Logging
|
# - "--log.level=INFO"
|
||||||
- "--log.level=INFO"
|
# - "--log.filePath=/var/log/traefik/traefik.log"
|
||||||
- "--log.filePath=/var/log/traefik/traefik.log"
|
# - "--accesslog=true"
|
||||||
- "--accesslog=true"
|
# - "--accesslog.filepath=/var/log/traefik/access.log"
|
||||||
- "--accesslog.filepath=/var/log/traefik/access.log"
|
|
||||||
|
|
||||||
labels:
|
labels:
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=traefik-proxy"
|
- "traefik.docker.network=traefik-proxy"
|
||||||
|
|
||||||
# Prod Router (Dashboard) - DISABLED per user request
|
# Prod Router (Dash)
|
||||||
# - "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
|
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
|
||||||
# - "traefik.http.routers.traefik-dashboard.entrypoints=websecure"
|
- "traefik.http.routers.traefik-dashboard.entrypoints=websecure"
|
||||||
# - "traefik.http.routers.traefik-dashboard.middlewares=auth,security-headers"
|
- "traefik.http.routers.traefik-dashboard.middlewares=security-chain@file"
|
||||||
# - "traefik.http.routers.traefik-dashboard.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard.service=api@internal"
|
||||||
# - "traefik.http.routers.traefik-dashboard.tls=true"
|
- "traefik.http.routers.traefik-dashboard.tls=true"
|
||||||
|
|
||||||
# Local Router
|
# Local Router
|
||||||
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)"
|
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.middlewares=auth@file,security-headers@file"
|
- "traefik.http.routers.traefik-dashboard-local.middlewares=security-headers@file"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
||||||
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
||||||
|
|
||||||
# Dev Router
|
# Dev Router
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.middlewares=security-headers@file"
|
- "traefik.http.routers.traefik-dashboard-dev.middlewares=security-chain@file"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
||||||
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
||||||
|
|
||||||
|
|||||||
@@ -1,328 +0,0 @@
|
|||||||
http:
|
|
||||||
routers:
|
|
||||||
# Traefik Dashboard (ADMIN, local only)
|
|
||||||
traefik-dashboard:
|
|
||||||
rule: "Host(`traefik.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: api@internal
|
|
||||||
middlewares:
|
|
||||||
# - auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud AIO Interface (ADMIN, local is better)
|
|
||||||
nextcloud-aio:
|
|
||||||
rule: "Host(`nextcloud-aio.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud-aio
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Termix (public (account required))
|
|
||||||
termix:
|
|
||||||
rule: "Host(`termix.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: termix
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# MeTube
|
|
||||||
metube:
|
|
||||||
rule: "Host(`metube.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: metube
|
|
||||||
middlewares:
|
|
||||||
- metube-auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Portainer (public (account required))
|
|
||||||
portainer:
|
|
||||||
rule: "Host(`portainer.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: portainer
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Uptime Kuma
|
|
||||||
uptime-kuma:
|
|
||||||
rule: "Host(`uptime.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: uptime-kuma
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# AdGuard Home (public (account required))
|
|
||||||
adguard:
|
|
||||||
rule: "Host(`adguard.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: adguard
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
|
|
||||||
# Nextcloud Main (public (account required))
|
|
||||||
nextcloud:
|
|
||||||
rule: "Host(`nextcloud.forust.xyz`)"
|
|
||||||
entrypoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud
|
|
||||||
middlewares:
|
|
||||||
- nextcloud-chain
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Dockmon (public (account required))
|
|
||||||
dockmon:
|
|
||||||
rule: "Host(`dockmon.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: dockmon
|
|
||||||
middlewares:
|
|
||||||
# - dockmon-auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Gitea (public (account required))
|
|
||||||
gitea:
|
|
||||||
rule: "Host(`gitea.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
- ssh
|
|
||||||
service: gitea
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# # Glance (local only)
|
|
||||||
# glance:
|
|
||||||
# rule: "Host(`glance.workstation`)"
|
|
||||||
# entryPoints:
|
|
||||||
# - websecure
|
|
||||||
# service: glance
|
|
||||||
# middlewares:
|
|
||||||
# - security-headers
|
|
||||||
# tls: {}
|
|
||||||
|
|
||||||
# Watercrawl (local only)
|
|
||||||
watercrawl:
|
|
||||||
rule: "Host(`watercrawl.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: watercrawl
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# N8N (local only)
|
|
||||||
n8n:
|
|
||||||
rule: "Host(`n8n.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: n8n
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
|
|
||||||
services:
|
|
||||||
# Portainer
|
|
||||||
portainer:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "https://portainer:9443"
|
|
||||||
serversTransport: insecureTransport
|
|
||||||
|
|
||||||
# AdGuard Home
|
|
||||||
adguard:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://adguardhome:3000"
|
|
||||||
|
|
||||||
# Nextcloud AIO Interface
|
|
||||||
nextcloud-aio:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "https://nextcloud-aio-mastercontainer:8080"
|
|
||||||
serversTransport: insecureTransport
|
|
||||||
|
|
||||||
# Nextcloud Main
|
|
||||||
nextcloud:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://nextcloud-aio-apache:11000"
|
|
||||||
|
|
||||||
# Uptime Kuma
|
|
||||||
uptime-kuma:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://uptime-kuma:3001"
|
|
||||||
|
|
||||||
# Termix
|
|
||||||
termix:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://termix:8080"
|
|
||||||
|
|
||||||
# Dockmon
|
|
||||||
dockmon:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "https://dockmon:443"
|
|
||||||
serversTransport: insecureTransport
|
|
||||||
|
|
||||||
# # Glance
|
|
||||||
# glance:
|
|
||||||
# loadBalancer:
|
|
||||||
# servers:
|
|
||||||
# - url: "http://glance:8080"
|
|
||||||
|
|
||||||
# Watercrawl
|
|
||||||
watercrawl:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://nginx:80"
|
|
||||||
|
|
||||||
# N8N
|
|
||||||
n8n:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://n8n:5678"
|
|
||||||
|
|
||||||
# Gitea
|
|
||||||
gitea:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://gitea:3000"
|
|
||||||
# MeTube
|
|
||||||
metube:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://metube:8081"
|
|
||||||
|
|
||||||
serversTransports:
|
|
||||||
insecureTransport:
|
|
||||||
insecureSkipVerify: true
|
|
||||||
|
|
||||||
middlewares:
|
|
||||||
# HTTPS Redirect
|
|
||||||
redirect-https:
|
|
||||||
redirectScheme:
|
|
||||||
scheme: https
|
|
||||||
permanent: true
|
|
||||||
|
|
||||||
# Metube Basic Auth
|
|
||||||
metube-auth:
|
|
||||||
basicAuth:
|
|
||||||
users:
|
|
||||||
- "admin:$2y$05$3Q6gyLFW3NFNp4C6elnyfupntqB6VNB/tcIAeo8NEzvaqPxOjN0iC"
|
|
||||||
# - "jeepik:$2y$05$tIKrmhd7SYOe6yImRRAfpen7hpVdF8PnSbgBTCDZ.GI0Djx.Le2bq"
|
|
||||||
realm: "MeTube Access"
|
|
||||||
|
|
||||||
# Basic Auth Traefik Dashboard
|
|
||||||
auth:
|
|
||||||
basicAuth:
|
|
||||||
users:
|
|
||||||
- "admin:$$apr1$$57E60OUM$$JoYwmLr/uZKaTy6U4IQd9."
|
|
||||||
# - "jeepik:$2y$05$Q8QqJwSjpycVYONyk4id/.rDFApW9oL8tycRMlGttNySsDv71Rnsu"
|
|
||||||
# - "vv:"
|
|
||||||
realm: "Traefik Dashboard"
|
|
||||||
|
|
||||||
# Basic Auth Dockmon
|
|
||||||
dockmon-auth:
|
|
||||||
basicAuth:
|
|
||||||
users:
|
|
||||||
- "admin:$$apr1$$.bCpmIHl$$dxPEKdw5aZLAwo8wUz52b1"
|
|
||||||
realm: "Dockmon Access"
|
|
||||||
|
|
||||||
# Cloudflare IP Whitelist
|
|
||||||
cloudflare-ipwhitelist:
|
|
||||||
ipWhiteList:
|
|
||||||
sourceRange:
|
|
||||||
- "173.245.48.0/20"
|
|
||||||
- "103.21.244.0/22"
|
|
||||||
- "103.22.200.0/22"
|
|
||||||
- "103.31.4.0/22"
|
|
||||||
- "141.101.64.0/18"
|
|
||||||
- "108.162.192.0/18"
|
|
||||||
- "190.93.240.0/20"
|
|
||||||
- "188.114.96.0/20"
|
|
||||||
- "197.234.240.0/22"
|
|
||||||
- "198.41.128.0/17"
|
|
||||||
- "162.158.0.0/15"
|
|
||||||
- "104.16.0.0/13"
|
|
||||||
- "104.24.0.0/14"
|
|
||||||
- "172.64.0.0/13"
|
|
||||||
- "131.0.72.0/22"
|
|
||||||
|
|
||||||
# Security Headers
|
|
||||||
security-headers:
|
|
||||||
headers:
|
|
||||||
browserXssFilter: true
|
|
||||||
contentTypeNosniff: true
|
|
||||||
forceSTSHeader: true
|
|
||||||
stsIncludeSubdomains: true
|
|
||||||
stsPreload: true
|
|
||||||
stsSeconds: 31536000
|
|
||||||
customFrameOptionsValue: "SAMEORIGIN"
|
|
||||||
customResponseHeaders:
|
|
||||||
X-Content-Type-Options: "nosniff"
|
|
||||||
Referrer-Policy: "strict-origin-when-cross-origin"
|
|
||||||
|
|
||||||
# Nextcloud specific headers
|
|
||||||
nextcloud-secure-headers:
|
|
||||||
headers:
|
|
||||||
hostsProxyHeaders:
|
|
||||||
- "X-Forwarded-Host"
|
|
||||||
- "X-Forwarded-Proto"
|
|
||||||
referrerPolicy: "same-origin"
|
|
||||||
customFrameOptionsValue: "SAMEORIGIN"
|
|
||||||
|
|
||||||
# Rate limiting
|
|
||||||
rate-limit:
|
|
||||||
rateLimit:
|
|
||||||
average: 100
|
|
||||||
burst: 50
|
|
||||||
period: 1m
|
|
||||||
|
|
||||||
# Nextcloud chain
|
|
||||||
nextcloud-chain:
|
|
||||||
chain:
|
|
||||||
middlewares:
|
|
||||||
- nextcloud-secure-headers
|
|
||||||
- security-headers
|
|
||||||
|
|
||||||
# TLS Configuration
|
|
||||||
tls:
|
|
||||||
certificates:
|
|
||||||
# Cloudflare Origin CA *.forust.xyz
|
|
||||||
- certFile: /certs/cloudflare.pem
|
|
||||||
keyFile: /certs/cloudflare.key
|
|
||||||
# Local certificate
|
|
||||||
- certFile: /certs/workstation+1.pem
|
|
||||||
keyFile: /certs/workstation+1-key.pem
|
|
||||||
|
|
||||||
stores:
|
|
||||||
default:
|
|
||||||
defaultCertificate:
|
|
||||||
# Fallback local certificate
|
|
||||||
certFile: /certs/workstation+1.pem
|
|
||||||
keyFile: /certs/workstation+1-key.pem
|
|
||||||
|
|
||||||
options:
|
|
||||||
default:
|
|
||||||
minVersion: VersionTLS12
|
|
||||||
sniStrict: true
|
|
||||||
cipherSuites:
|
|
||||||
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
|
|
||||||
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
|
|
||||||
- TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305
|
|
||||||
@@ -2,20 +2,3 @@ http:
|
|||||||
serversTransports:
|
serversTransports:
|
||||||
insecureTransport:
|
insecureTransport:
|
||||||
insecureSkipVerify: true
|
insecureSkipVerify: true
|
||||||
|
|
||||||
routers:
|
|
||||||
# Nextcloud Main (public (account required))
|
|
||||||
nextcloud:
|
|
||||||
rule: "Host(`nextcloud.forust.xyz`)"
|
|
||||||
entrypoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud
|
|
||||||
middlewares:
|
|
||||||
- nextcloud-chain
|
|
||||||
tls: {}
|
|
||||||
services:
|
|
||||||
# Nextcloud Main
|
|
||||||
nextcloud:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://nextcloud-aio-apache:11000"
|
|
||||||
@@ -10,7 +10,7 @@ http:
|
|||||||
metube-auth:
|
metube-auth:
|
||||||
basicAuth:
|
basicAuth:
|
||||||
users:
|
users:
|
||||||
- "vv:$2y$05$JdT8AGUO9bd.E/PiCmKaoOJS1RFlXkrrmZ5mJ4f8/a1bEW39L3FbS"
|
- "vv:$2y$05$JdT8AGUO9bd.E/PiCmKaoOJS1RFlXkrrmZ5mJ4f8/a1bEW39L3FbS"
|
||||||
|
|
||||||
realm: "MeTube Access"
|
realm: "MeTube Access"
|
||||||
|
|
||||||
@@ -48,6 +48,29 @@ http:
|
|||||||
- "172.64.0.0/13"
|
- "172.64.0.0/13"
|
||||||
- "131.0.72.0/22"
|
- "131.0.72.0/22"
|
||||||
|
|
||||||
|
# Authentik + secure headers
|
||||||
|
security-chain:
|
||||||
|
chain:
|
||||||
|
middlewares:
|
||||||
|
- authentik@file
|
||||||
|
- security-headers@file
|
||||||
|
authentik:
|
||||||
|
forwardAuth:
|
||||||
|
address: "http://authentik-server:9000/outpost.goauthentik.io/auth/traefik"
|
||||||
|
trustForwardHeader: true
|
||||||
|
authResponseHeaders:
|
||||||
|
- X-authentik-username
|
||||||
|
- X-authentik-groups
|
||||||
|
- X-authentik-email
|
||||||
|
- X-authentik-name
|
||||||
|
- X-authentik-uid
|
||||||
|
- X-authentik-jwt
|
||||||
|
- X-authentik-meta-jwks
|
||||||
|
- X-authentik-meta-outpost
|
||||||
|
- X-authentik-meta-provider
|
||||||
|
- X-authentik-meta-app
|
||||||
|
- X-authentik-meta-version
|
||||||
|
|
||||||
# Security Headers
|
# Security Headers
|
||||||
security-headers:
|
security-headers:
|
||||||
headers:
|
headers:
|
||||||
@@ -82,5 +105,5 @@ http:
|
|||||||
nextcloud-chain:
|
nextcloud-chain:
|
||||||
chain:
|
chain:
|
||||||
middlewares:
|
middlewares:
|
||||||
- nextcloud-secure-headers
|
- nextcloud-secure-headers@file
|
||||||
- security-headers
|
- security-headers@file
|
||||||
|
|||||||
@@ -0,0 +1,40 @@
|
|||||||
|
http:
|
||||||
|
routers:
|
||||||
|
# Nextcloud prod
|
||||||
|
nextcloud:
|
||||||
|
rule: "Host(`nextcloud.forust.xyz`)"
|
||||||
|
entrypoints:
|
||||||
|
- websecure
|
||||||
|
service: nextcloud
|
||||||
|
middlewares:
|
||||||
|
- nextcloud-chain
|
||||||
|
tls: {}
|
||||||
|
|
||||||
|
# Nextcloud dev
|
||||||
|
nextcloud-local:
|
||||||
|
rule: "Host(`nextcloud.workstation.internal`)"
|
||||||
|
entrypoints:
|
||||||
|
- websecure
|
||||||
|
- web
|
||||||
|
service: nextcloud
|
||||||
|
middlewares:
|
||||||
|
- nextcloud-chain
|
||||||
|
tls: {}
|
||||||
|
|
||||||
|
# Nextcloud dev
|
||||||
|
nextcloud-dev:
|
||||||
|
rule: "Host(`nextcloud.gigaforust.internal`)"
|
||||||
|
entrypoints:
|
||||||
|
- websecure
|
||||||
|
- web
|
||||||
|
service: nextcloud
|
||||||
|
middlewares:
|
||||||
|
- nextcloud-chain
|
||||||
|
tls: {}
|
||||||
|
|
||||||
|
services:
|
||||||
|
# Nextcloud Main
|
||||||
|
nextcloud:
|
||||||
|
loadBalancer:
|
||||||
|
servers:
|
||||||
|
- url: "http://nextcloud-aio-apache:11000"
|
||||||
@@ -1,153 +0,0 @@
|
|||||||
http:
|
|
||||||
routers:
|
|
||||||
# Traefik Dashboard (dev access. local only)
|
|
||||||
traefik-dashboard-dev:
|
|
||||||
rule: "Host(`traefik.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: api@internal
|
|
||||||
middlewares:
|
|
||||||
# - auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud AIO Interface (dev access. local only)
|
|
||||||
nextcloud-aio-dev:
|
|
||||||
rule: "Host(`nextcloud-aio.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud-aio
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Termix (dev access, (account required))
|
|
||||||
termix-dev:
|
|
||||||
rule: "Host(`termix.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: termix
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# MeTube (dev access, (auth required))
|
|
||||||
metube-dev:
|
|
||||||
rule: "Host(`metube.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: metube
|
|
||||||
middlewares:
|
|
||||||
- metube-auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Portainer (dev acess, (account required))
|
|
||||||
portainer-dev:
|
|
||||||
rule: "Host(`portainer.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: portainer
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Uptime Kuma (dev access, (account required))
|
|
||||||
uptime-kuma-dev:
|
|
||||||
rule: "Host(`uptime.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: uptime-kuma
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# AdGuard Home (dev access, (account required))
|
|
||||||
adguard-dev:
|
|
||||||
rule: "Host(`adguard.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: adguard
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud Main (public (account required))
|
|
||||||
nextcloud-dev:
|
|
||||||
rule: "Host(`nextcloud.gigaforust`)"
|
|
||||||
entrypoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud
|
|
||||||
middlewares:
|
|
||||||
- nextcloud-chain
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Dockmon (dev access (account required))
|
|
||||||
dockmon-dev:
|
|
||||||
rule: "Host(`dockmon.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: dockmon
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Gitea (dev access (account required))
|
|
||||||
gitea-dev:
|
|
||||||
rule: "Host(`gitea.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
- ssh
|
|
||||||
service: gitea
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Glance (dev access, local only)
|
|
||||||
glance-dev:
|
|
||||||
rule: "Host(`glance.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: glance
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Watercrawl (dev access, local only)
|
|
||||||
watercrawl-dev:
|
|
||||||
rule: "Host(`watercrawl.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: watercrawl
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# N8N (local only)
|
|
||||||
n8n-dev:
|
|
||||||
rule: "Host(`n8n.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: n8n
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Landing Page (public)
|
|
||||||
forust-homepage-dev:
|
|
||||||
rule: "Host(`landing.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: forust-homepage
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Penpot
|
|
||||||
penpot-dev:
|
|
||||||
rule: "Host(`penpot.gigaforust`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
- web
|
|
||||||
service: penpot
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
@@ -1,152 +0,0 @@
|
|||||||
http:
|
|
||||||
routers:
|
|
||||||
# Traefik Dashboard (local access, ADMIN, local only)
|
|
||||||
traefik-dashboard-local:
|
|
||||||
rule: "Host(`traefik.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: api@internal
|
|
||||||
middlewares:
|
|
||||||
# - auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud AIO Interface (local access. ADMIN, local only)
|
|
||||||
nextcloud-aio-local:
|
|
||||||
rule: "Host(`nextcloud-aio.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud-aio
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Termix (local access, (account required))
|
|
||||||
termix-local:
|
|
||||||
rule: "Host(`termix.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: termix
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# MeTube (local access, (auth required))
|
|
||||||
metube-local:
|
|
||||||
rule: "Host(`metube.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: metube
|
|
||||||
middlewares:
|
|
||||||
- metube-auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Portainer (dev acess, (account required))
|
|
||||||
portainer-local:
|
|
||||||
rule: "Host(`portainer.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: portainer
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Uptime Kuma (local access, (account required))
|
|
||||||
uptime-kuma-local:
|
|
||||||
rule: "Host(`uptime.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: uptime-kuma
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# AdGuard Home (local access, (account required))
|
|
||||||
adguard-local:
|
|
||||||
rule: "Host(`adguard.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: adguard
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud Main (public (account required))
|
|
||||||
nextcloud-local:
|
|
||||||
rule: "Host(`nextcloud.workstation`)"
|
|
||||||
entrypoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud
|
|
||||||
middlewares:
|
|
||||||
- nextcloud-chain
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud Main (public (account required))
|
|
||||||
penpot-local:
|
|
||||||
rule: "Host(`penpot.workstation`)"
|
|
||||||
entrypoints:
|
|
||||||
- websecure
|
|
||||||
service: penpot
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Dockmon (local access (account required))
|
|
||||||
dockmon-local:
|
|
||||||
rule: "Host(`dockmon.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: dockmon
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Gitea (local access (account required))
|
|
||||||
gitea-local:
|
|
||||||
rule: "Host(`gitea.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
- ssh
|
|
||||||
service: gitea
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Glance (local access)
|
|
||||||
glance-local:
|
|
||||||
rule: "Host(`glance.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: glance
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Watercrawl (local access)
|
|
||||||
watercrawl-local:
|
|
||||||
rule: "Host(`watercrawl.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: watercrawl
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# N8N (local only)
|
|
||||||
n8n-local:
|
|
||||||
rule: "Host(`n8n.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: n8n
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Landing Page (local access)
|
|
||||||
forust-homepage-local:
|
|
||||||
rule: "Host(`landing.workstation`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: forust-homepage
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
@@ -1,152 +0,0 @@
|
|||||||
http:
|
|
||||||
routers:
|
|
||||||
# Traefik Dashboard (ADMIN, without subdomeain)
|
|
||||||
traefik-dashboard:
|
|
||||||
rule: "Host(`traefik.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: api@internal
|
|
||||||
middlewares:
|
|
||||||
- auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud AIO Interface (ADMIN, without subdomeain)
|
|
||||||
nextcloud-aio:
|
|
||||||
rule: "Host(`nextcloud-aio.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud-aio
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud AIO Interface (ADMIN, without subdomeain)
|
|
||||||
penpot:
|
|
||||||
rule: "Host(`penpot.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: penpot
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Termix (public (account required))
|
|
||||||
termix:
|
|
||||||
rule: "Host(`termix.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: termix
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# MeTube (public (auth required))
|
|
||||||
metube:
|
|
||||||
rule: "Host(`metube.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: metube
|
|
||||||
middlewares:
|
|
||||||
- metube-auth
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Portainer (public (account required))
|
|
||||||
portainer:
|
|
||||||
rule: "Host(`portainer.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: portainer
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Uptime Kuma (public (account required))
|
|
||||||
uptime-kuma:
|
|
||||||
rule: "Host(`uptime.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: uptime-kuma
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# AdGuard Home (public (account required))
|
|
||||||
adguard:
|
|
||||||
rule: "Host(`adguard.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: adguard
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Nextcloud Main (public (account required))
|
|
||||||
nextcloud:
|
|
||||||
rule: "Host(`nextcloud.forust.xyz`)"
|
|
||||||
entrypoints:
|
|
||||||
- websecure
|
|
||||||
service: nextcloud
|
|
||||||
middlewares:
|
|
||||||
- nextcloud-chain
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Dockmon (public (account required))
|
|
||||||
dockmon:
|
|
||||||
rule: "Host(`dockmon.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: dockmon
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Gitea (public (account required))
|
|
||||||
gitea:
|
|
||||||
rule: "Host(`gitea.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
- ssh
|
|
||||||
service: gitea
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Glance (public, without subdomain)
|
|
||||||
glance:
|
|
||||||
rule: "Host(`glance.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: glance
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Watercrawl (public, without subdomain)
|
|
||||||
watercrawl:
|
|
||||||
rule: "Host(`watercrawl.fourst.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: watercrawl
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# N8N (public, without subdomain)
|
|
||||||
n8n:
|
|
||||||
rule: "Host(`n8n.forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: n8n
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
|
|
||||||
# Landing Page (public)
|
|
||||||
forust-homepage:
|
|
||||||
rule: "Host(`forust.xyz`)"
|
|
||||||
entryPoints:
|
|
||||||
- websecure
|
|
||||||
service: forust-homepage
|
|
||||||
middlewares:
|
|
||||||
- security-headers
|
|
||||||
tls: {}
|
|
||||||
@@ -1,86 +0,0 @@
|
|||||||
http:
|
|
||||||
services:
|
|
||||||
# Portainer
|
|
||||||
portainer:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "https://portainer:9443"
|
|
||||||
serversTransport: insecureTransport
|
|
||||||
|
|
||||||
# AdGuard Home
|
|
||||||
adguard:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://adguardhome:3000"
|
|
||||||
|
|
||||||
# Nextcloud AIO Interface
|
|
||||||
nextcloud-aio:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "https://nextcloud-aio-mastercontainer:8080"
|
|
||||||
serversTransport: insecureTransport
|
|
||||||
|
|
||||||
# Penpot
|
|
||||||
penpot:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://penpot-frontend:8080"
|
|
||||||
|
|
||||||
# Nextcloud Main
|
|
||||||
nextcloud:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://nextcloud-aio-apache:11000"
|
|
||||||
|
|
||||||
# Uptime Kuma
|
|
||||||
uptime-kuma:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://uptime-kuma:3001"
|
|
||||||
|
|
||||||
# Termix
|
|
||||||
termix:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://termix:8080"
|
|
||||||
|
|
||||||
# Dockmon
|
|
||||||
dockmon:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "https://dockmon:443"
|
|
||||||
serversTransport: insecureTransport
|
|
||||||
|
|
||||||
# Glance
|
|
||||||
glance:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://glance:8080"
|
|
||||||
|
|
||||||
# Watercrawl
|
|
||||||
watercrawl:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://nginx:80"
|
|
||||||
|
|
||||||
# N8N
|
|
||||||
n8n:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://n8n:5678"
|
|
||||||
|
|
||||||
# Gitea
|
|
||||||
gitea:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://gitea:3000"
|
|
||||||
# MeTube
|
|
||||||
metube:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://metube:8081"
|
|
||||||
# Landing Page
|
|
||||||
forust-homepage:
|
|
||||||
loadBalancer:
|
|
||||||
servers:
|
|
||||||
- url: "http://forust-homepage:80"
|
|
||||||
@@ -4,7 +4,8 @@ tls:
|
|||||||
# Cloudflare Origin CA *.forust.xyz
|
# Cloudflare Origin CA *.forust.xyz
|
||||||
- certFile: /certs/cloudflare.pem
|
- certFile: /certs/cloudflare.pem
|
||||||
keyFile: /certs/cloudflare.key
|
keyFile: /certs/cloudflare.key
|
||||||
|
- certFile: /certs/xdfnx.pem
|
||||||
|
keyFile: /certs/xdfnx.key
|
||||||
stores:
|
stores:
|
||||||
default:
|
default:
|
||||||
defaultCertificate:
|
defaultCertificate:
|
||||||
|
|||||||
@@ -1,9 +1,8 @@
|
|||||||
services:
|
services:
|
||||||
userbot_forust:
|
forust:
|
||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
container_name: userbot_forust
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
env_file:
|
env_file:
|
||||||
- .env
|
- .env
|
||||||
@@ -16,11 +15,10 @@ services:
|
|||||||
- 8.8.8.8
|
- 8.8.8.8
|
||||||
- 1.1.1.1
|
- 1.1.1.1
|
||||||
|
|
||||||
userbot_anna:
|
anna:
|
||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
container_name: userbot_anna
|
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
env_file:
|
env_file:
|
||||||
- .env
|
- .env
|
||||||
@@ -32,26 +30,3 @@ services:
|
|||||||
dns:
|
dns:
|
||||||
- 8.8.8.8
|
- 8.8.8.8
|
||||||
- 1.1.1.1
|
- 1.1.1.1
|
||||||
develop:
|
|
||||||
watch:
|
|
||||||
- action: sync
|
|
||||||
path: modules
|
|
||||||
target: /app/modules
|
|
||||||
- action: sync
|
|
||||||
path: utils
|
|
||||||
target: /app/utils
|
|
||||||
- action: sync
|
|
||||||
path: main.py
|
|
||||||
target: /app/main.py
|
|
||||||
- action: rebuild
|
|
||||||
path: .env
|
|
||||||
- action: rebuild
|
|
||||||
path: .env.anna
|
|
||||||
|
|
||||||
|
|
||||||
volumes:
|
|
||||||
downloads:
|
|
||||||
|
|
||||||
networks:
|
|
||||||
userbot_network:
|
|
||||||
driver: bridge
|
|
||||||
Reference in New Issue
Block a user