This repository has been archived on 2020-09-29. You can view files and clone it, but cannot push or open issues or pull requests.
traefik.autonomic.zone/docker-compose.production.yml

85 lines
2.2 KiB
YAML
Raw Normal View History

---
version: "3.8"
2020-04-30 09:50:59 +00:00
services:
traefik:
ports:
2020-04-30 12:24:29 +00:00
- "80:80"
- "443:443"
2020-04-30 12:24:29 +00:00
- "8080:8080"
2020-04-30 09:50:59 +00:00
volumes:
- "/var/run/docker.sock:/var/run/docker.sock"
- "letsencrypt:/etc/letsencrypt"
configs:
- source: traefik-yml-prod-v3
target: /etc/traefik/traefik.yml
- source: file-provider-prod-v1
target: /etc/traefik/file-provider.yml
networks:
- proxy
deploy:
mode: replicated
2020-05-01 15:24:28 +00:00
replicas: 1
2020-04-30 13:23:08 +00:00
update_config:
failure_action: rollback
placement:
constraints:
- node.role == manager
labels:
- "traefik.enable=true"
2020-04-30 13:28:17 +00:00
- "traefik.http.services.traefik.loadbalancer.server.port=web"
- "traefik.http.routers.traefik.rule=Host(`traefik.swarm.autonomic.zone`)"
- "traefik.http.routers.traefik.entrypoints=web-secure"
- "traefik.http.routers.traefik.tls.certresolver=staging"
- "traefik.http.routers.traefik.service=api@internal"
- "traefik.http.routers.traefik.middlewares=keycloak@file"
traefik-forward-auth:
image: thomseddon/traefik-forward-auth:2
configs:
- source: forward-ini-prod-v1
target: /etc/forward.ini
networks:
- proxy
environment:
- CONFIG=/etc/forward.ini
secrets:
- oidc-client-id-v1
- oidc-client-secret-v1
- oidc-issuer-url-v1
- secret-nonce-v1
deploy:
labels:
- "traefik.enable=true"
- "traefik.http.services.tfa.loadBalancer.server.port=4181"
- "traefik.http.routers.tfa.rule=Host(`auth.swarm.autonomic.zone`)"
- "traefik.http.routers.tfa.entrypoints=web-secure"
- "traefik.http.routers.tfa.tls.certresolver=staging"
- "traefik.http.routers.tfa.middlewares=keycloak@file"
networks:
proxy:
external: true
configs:
traefik-yml-prod-v3:
2020-04-30 13:26:01 +00:00
file: configs/prod/traefik.yml
file-provider-prod-v1:
file: configs/prod/file-provider.yml
forward-ini-prod-v1:
file: configs/prod/forward.ini.tmpl
template_driver: golang
secrets:
secret-nonce-v1:
external: true
oidc-issuer-url-v1:
external: true
oidc-client-id-v1:
external: true
oidc-client-secret-v1:
external: true
2020-04-30 09:50:59 +00:00
volumes:
letsencrypt: