Finalise this app setup

This commit is contained in:
Luke Murphy 2020-10-27 09:30:47 +01:00
parent ee1e186146
commit 3947537018
No known key found for this signature in database
GPG Key ID: 5E2EF5A63E3718CC
4 changed files with 53 additions and 54 deletions

View File

@ -1,5 +1,3 @@
# traefik-forward-auth
> https://github.com/thomseddon/traefik-forward-auth
**Work In Progress.**
[![Build Status](https://drone.autonomic.zone/api/badges/coop-cloud/traefik-forward-auth/status.svg)](https://drone.autonomic.zone/coop-cloud/traefik-forward-auth)

46
compose.yml Normal file
View File

@ -0,0 +1,46 @@
---
version: "3.8"
services:
app:
image: "thomseddon/traefik-forward-auth:2"
configs:
- source: forward_ini
target: /etc/forward.ini
networks:
- proxy
environment:
- CONFIG=/etc/forward.ini
- OIDC_CLIENT_ID
- OIDC_ISSUER_URL
- COOKIE_DOMAIN
- AUTH_HOST
secrets:
- oidc_client_secret
- secret_nonce
deploy:
labels:
- "traefik.enable=true"
- "traefik.http.services.tfa.loadBalancer.server.port=4181"
- "traefik.http.routers.tfa.rule=Host(`${DOMAIN}`)"
- "traefik.http.routers.tfa.entrypoints=web-secure"
- "traefik.http.routers.tfa.tls.certresolver=production"
- "traefik.http.routers.tfa.middlewares=keycloak@file"
networks:
proxy:
external: true
configs:
forward_ini:
name: ${STACK_NAME}_forward_ini_${FORWARD_INI_VERSION}
file: forward.ini.tmpl
template_driver: golang
secrets:
secret_nonce:
name: ${STACK_NAME}_secret_nonce_${SERCRET_NONCE_VERSION}
external: true
oidc_client_secret:
name: ${STACK_NAME}_oidc_client_secret_${OIDC_CLIENT_SECRET_VERSION}
external: true

View File

@ -1,45 +0,0 @@
---
version: "3.8"
services:
traefik-forward-auth:
image: thomseddon/traefik-forward-auth:2
configs:
- source: forward-ini-prod-v1
target: /etc/forward.ini
networks:
- proxy
environment:
- CONFIG=/etc/forward.ini
secrets:
- oidc-client-id-v1
- oidc-client-secret-v1
- oidc-issuer-url-v1
- secret-nonce-v1
deploy:
labels:
- "traefik.enable=true"
- "traefik.http.services.tfa.loadBalancer.server.port=4181"
- "traefik.http.routers.tfa.rule=Host(`auth.swarm.autonomic.zone`)"
- "traefik.http.routers.tfa.entrypoints=web-secure"
- "traefik.http.routers.tfa.tls.certresolver=staging"
- "traefik.http.routers.tfa.middlewares=keycloak@file"
networks:
proxy:
external: true
configs:
forward-ini-prod-v1:
file: forward.ini.tmpl
template_driver: golang
secrets:
secret-nonce-v1:
external: true
oidc-issuer-url-v1:
external: true
oidc-client-id-v1:
external: true
oidc-client-secret-v1:
external: true

View File

@ -1,9 +1,9 @@
secret = {{ secret "secret-nonce-v1" }}
secret = {{ secret "secret_nonce" }}
log-level = info
cookie-domain = swarm.autonomic.zone
auth-host = auth.swarm.autonomic.zone
cookie-domain = {{ env "COOKIE_DOMAIN" }}
auth-host = {{ env "AUTH_HOST" }}
default-provider = oidc
providers.oidc.issuer-url = {{ secret "oidc-issuer-url-v1" }}
providers.oidc.client-id = {{ secret "oidc-client-id-v1" }}
providers.oidc.client-secret = {{ secret "oidc-client-secret-v1" }}
providers.oidc.issuer-url = {{ env "OIDC_ISSUER_URL" }}
providers.oidc.client-id = {{ env "OIDC_CLIENT_ID" }}
providers.oidc.client-secret = {{ secret "oidc_client_secret" }}