Improve traefik config

This commit is contained in:
Jade Ellis
2024-10-20 18:29:00 +01:00
parent 8f6420e2d0
commit 426b4fae83
16 changed files with 95 additions and 113 deletions
-70
View File
@@ -1,70 +0,0 @@
[log]
level = "INFO"
# [ping]
[providers.docker]
exposedbydefault = false
[providers.file]
directory="/etc/traefik/additional/"
watch=true
[entrypoints.http]
address = ":80"
[entrypoints.https]
address = ":443"
[entrypoints.https.http3]
[entrypoints.matrix]
address = ":8448"
[entrypoints.matrix.http3]
[entryPoints.http.proxyProtocol]
insecure = false
trustedIPs = [ ]
[entryPoints.http.forwardedHeaders]
insecure = false
trustedIPs = [ ]
[entryPoints.https.proxyProtocol]
insecure = false
trustedIPs = [ ]
[entryPoints.https.forwardedHeaders]
insecure = false
trustedIPs = [ ]
[entryPoints.matrix.proxyProtocol]
insecure = false
trustedIPs = [ ]
[entryPoints.matrix.forwardedHeaders]
insecure = false
trustedIPs = [ ]
[entrypoints.http.http.redirections.entryPoint]
to="https"
scheme = "https"
[http.middlewares]
[http.middlewares.traefik-compress.compress]
[http.routers.http]
middlewares = "traefik-compress"
[http.routers.https]
middlewares = "traefik-compress"
[http.routers.traefik]
middlewares = "traefik-compress"
# [entryPoints.traefik]
# address = ":9000"
[certificatesresolvers.letsencrypt.acme]
email = 'jade@ellis.link'
storage = "/certificates/acme.json"
# - "--certificatesresolvers.letsencrypt.acme.httpchallenge=true"
# - "--certificatesresolvers.letsencrypt.acme.httpChallenge.entryPoint=http"
# tlschallenge = true
[certificatesresolvers.letsencrypt.acme.dnschallenge]
provider = "cloudflare"
+82
View File
@@ -0,0 +1,82 @@
global:
checkNewVersion: false
log:
level: INFO
providers:
docker:
exposedbydefault: false
file:
directory: /etc/traefik/additional/
watch: true
entrypoints:
http:
address: :80
http3: {}
http:
redirections:
entryPoint:
to: https
scheme: https
# proxyProtocol:
# insecure: false
# trustedIPs: []
# forwardedHeaders:
# insecure: false
# trustedIPs: []
https:
address: :443
http3: {}
# proxyProtocol:
# insecure: false
# trustedIPs: []
# forwardedHeaders:
# insecure: false
# trustedIPs: []
http:
tls:
certResolver: letsencrypt
matrix:
address: :8448
http3: {}
# proxyProtocol:
# insecure: false
# trustedIPs: []
# forwardedHeaders:
# insecure: false
# trustedIPs: []
smtp:
address: :25
proxyProtocol:
trustedIPs: # Trust IPs from inside the "web" network
- 10.89.0.0/24
- fd76:6f6d:f45e:ea1a::/64
smtps:
address: :465
proxyProtocol:
trustedIPs:
- 10.89.0.0/24
- fd76:6f6d:f45e:ea1a::/64
imaps:
address: :993
proxyProtocol:
trustedIPs:
- 10.89.0.0/24
- fd76:6f6d:f45e:ea1a::/64
http:
middlewares:
traefik-compress:
compress: {}
routers:
http:
middlewares: traefik-compress
https:
middlewares: traefik-compress
traefik:
middlewares: traefik-compress
certificatesresolvers:
letsencrypt:
acme:
email: jade@ellis.link
storage: /certificates/acme.json
dnschallenge:
provider: cloudflare