refactor: apply traefik-wide security-headers on websecure entrypoint, minor comment and description changes

This commit is contained in:
forust committed 2026-01-26 08:54:10 +01:00
1 parent d58ae2a5e7
commit 146f63a39b
16 files changed
+25 -101

No files matched your search

+4 -5
View File
@@ -17,10 +17,11 @@ services:
# EntryPoints
- "--entryPoints.web.address=:80"
# - "--entryPoints.web.http.middlewares=error-pages@docker"
- "--entryPoints.web.http.redirections.entryPoint.to=websecure"
- "--entryPoints.web.http.redirections.entryPoint.scheme=https"
- "--entryPoints.web.http.redirections.entryPoint.permanent=true"
- "--entryPoints.websecure.address=:443"
- "--entryPoints.websecure.http.middlewares=error-pages@docker"
- "--entryPoints.websecure.http.middlewares=error-pages@docker,security-headers@file"
- "--entryPoints.websecure.http.tls=true"
- "--entryPoints.ssh.address=:2221"
@@ -53,20 +54,18 @@ services:
# Local Router
- "traefik.http.routers.traefik-dashboard-local.rule=Host(`traefik.workstation.internal`)"
- "traefik.http.routers.traefik-dashboard-local.entrypoints=websecure"
- "traefik.http.routers.traefik-dashboard-local.middlewares=security-headers@file"
- "traefik.http.routers.traefik-dashboard-local.service=api@internal"
- "traefik.http.routers.traefik-dashboard-local.tls=true"
# Dev Router
- "traefik.http.routers.traefik-dashboard-dev.rule=Host(`traefik.gigaforust.internal`)"
- "traefik.http.routers.traefik-dashboard-dev.entrypoints=websecure"
- "traefik.http.routers.traefik-dashboard-dev.middlewares=security-headers@file"
- "traefik.http.routers.traefik-dashboard-dev.service=api@internal"
- "traefik.http.routers.traefik-dashboard-dev.tls=true"
# Glance Metadata
- glance.name=Traefik
- glance.url=https://traefik.forust.xyz/
- glance.description=Traefik is a modern reverse proxy and load balancer
- glance.description=Traefik is a modern, beloved and hardcore reverse proxy and load balancer
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./dynamic:/etc/traefik/dynamic:ro