167 lines
5.9 KiB
YAML
167 lines
5.9 KiB
YAML
services:
|
|
traefik:
|
|
image: traefik:latest
|
|
container_name: traefik
|
|
restart: unless-stopped
|
|
command:
|
|
# API
|
|
- "--api.insecure=true"
|
|
- "--api.dashboard=true"
|
|
|
|
# Providers
|
|
- "--providers.docker=true"
|
|
- "--providers.docker.exposedbydefault=false"
|
|
- "--providers.docker.network=traefik-proxy"
|
|
- "--providers.file.directory=/etc/traefik/dynamic"
|
|
- "--providers.file.watch=true"
|
|
|
|
# EntryPoints
|
|
- "--entryPoints.web.address=:80"
|
|
- "--entryPoints.websecure.address=:443"
|
|
- "--entryPoints.websecure.http.tls=true"
|
|
- "--entryPoints.web.http.redirections.entryPoint.to=websecure"
|
|
- "--entryPoints.web.http.redirections.entryPoint.scheme=https"
|
|
- "--entryPoints.ssh.address=:2221"
|
|
|
|
# Let's Encrypt STAGING. CURRENTLY USING CF ORIGIN CA INSTEAD
|
|
# - "--certificatesresolvers.letsencrypt.acme.email=${EMAIL}"
|
|
# - "--certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json"
|
|
# - "--certificatesresolvers.letsencrypt.acme.caserver=https://acme-staging-v02.api.letsencrypt.org/directory"
|
|
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
|
|
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=web"
|
|
|
|
# Cloudflare
|
|
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
|
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
|
|
|
# Logging
|
|
- "--log.level=INFO"
|
|
- "--log.filePath=/var/log/traefik/traefik.log"
|
|
- "--accesslog=true"
|
|
- "--accesslog.filepath=/var/log/traefik/access.log"
|
|
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.docker.network=traefik-proxy"
|
|
|
|
# Prod Router (Dashboard) - DISABLED per user request
|
|
# - "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.forust.xyz`)"
|
|
# - "traefik.http.routers.traefik-dashboard.entrypoints=websecure"
|
|
# - "traefik.http.routers.traefik-dashboard.middlewares=auth,security-headers"
|
|
# - "traefik.http.routers.traefik-dashboard.service=api@internal"
|
|
# - "traefik.http.routers.traefik-dashboard.tls=true"
|
|
|
|
# Local Router
|
|
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`) || Host(`traefik.internal`)"
|
|
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
|
|
- "traefik.http.routers.traefik-dashboard-local.middlewares=auth@file,security-headers@file"
|
|
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
|
|
- "traefik.http.routers.traefik-dashboard-local.tls=true"
|
|
|
|
# Dev Router
|
|
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
|
|
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
|
|
- "traefik.http.routers.traefik-dashboard-dev.middlewares=security-headers@file"
|
|
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
|
|
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
|
|
|
|
- glance.name=Traefik
|
|
- glance.url=https://traefik.forust.xyz/
|
|
- glance.description=Traefik is a modern reverse proxy and load balancer
|
|
|
|
ports:
|
|
- "80:80"
|
|
- "443:443"
|
|
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
- ./dynamic:/etc/traefik/dynamic:ro
|
|
- ./certs:/certs:ro
|
|
- ./logs:/var/log/traefik
|
|
# - ./traefik/letsencrypt:/letsencrypt
|
|
|
|
networks:
|
|
- traefik-proxy
|
|
|
|
environment:
|
|
- TZ=Europe/Bratislava
|
|
|
|
postgresql:
|
|
image: docker.io/library/postgres:15
|
|
restart: unless-stopped
|
|
container_name: authentik-postgresql
|
|
env_file:
|
|
- .env
|
|
environment:
|
|
POSTGRES_DB: ${PG_DB:-authentik}
|
|
POSTGRES_PASSWORD: ${PG_PASS:?database password required}
|
|
POSTGRES_USER: ${PG_USER:-authentik}
|
|
volumes:
|
|
- auth-database:/var/lib/postgresql/data
|
|
healthcheck:
|
|
interval: 30s
|
|
retries: 5
|
|
start_period: 20s
|
|
test:
|
|
- CMD-SHELL
|
|
- pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}
|
|
timeout: 5s
|
|
|
|
server:
|
|
image: ghcr.io/goauthentik/server:${AUTHENTIK_TAG:-2025.10.2}
|
|
restart: unless-stopped
|
|
container_name: authentik-server
|
|
command: server
|
|
ports:
|
|
- ${PORT_HTTP:-9000}:9000
|
|
- ${PORT_HTTPS:-9443}:9443
|
|
env_file:
|
|
- .env
|
|
environment:
|
|
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
|
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
|
volumes:
|
|
- ./auth-media:/media
|
|
- ./auth-custom-templates:/templates
|
|
networks:
|
|
- traefik-proxy
|
|
depends_on:
|
|
postgresql:
|
|
condition: service_healthy
|
|
|
|
worker:
|
|
image: ghcr.io/goauthentik/server:${AUTHENTIK_TAG:-2025.10.2}
|
|
restart: unless-stopped
|
|
container_name: authentik-worker
|
|
command: worker
|
|
user: root
|
|
env_file:
|
|
- .env
|
|
environment:
|
|
AUTHENTIK_POSTGRESQL__HOST: postgresql
|
|
AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
|
|
AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
|
|
AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
|
|
AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
- ./auth-media:/media
|
|
- ./certs:/certs
|
|
- ./auth-custom-templates:/templates
|
|
depends_on:
|
|
postgresql:
|
|
condition: service_healthy
|
|
networks:
|
|
- traefik-proxy
|
|
|
|
volumes:
|
|
auth-database:
|
|
driver: local
|
|
|
|
networks:
|
|
traefik-proxy:
|
|
external: true
|