ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
ci / deploy-userbot-panel (push) Skipped
All prod IngressRoutes switch tls.certResolver to tls.secretName backed by per-router Certificates (HTTP-01, letsencrypt-prod). adguard-prod reuses the shared adguard-certs secret (also feeds DoT :853); sync CronJob removed as redundant. Traefik certificatesResolvers removed: its internal acme-http@internal router hijacks HTTP-01 for every host while enabled, blocking external solvers. Dormant files (kener, downtify) converted for consistency but not applied; n8n untouched per live-only rule.
82 lines
1.9 KiB
YAML
82 lines
1.9 KiB
YAML
apiVersion: traefik.io/v1alpha1
|
|
kind: IngressRoute
|
|
metadata:
|
|
name: xui-local
|
|
namespace: xui
|
|
spec:
|
|
entryPoints:
|
|
- websecure
|
|
routes:
|
|
- match: Host(`xui.workstation.internal`) || Host(`xui.gigaforust.internal`)
|
|
kind: Rule
|
|
services:
|
|
- name: xui-service
|
|
port: 30379
|
|
---
|
|
# Public panel access (optional).
|
|
# Realistic, but intentionally disabled: the panel has its own login,
|
|
# security-chain adds Authentik in front of it.
|
|
# To enable: uncomment and add Public Hostname `xui.forust.xyz`
|
|
# in the Cloudflare tunnel (same as other *.forust.xyz hosts).
|
|
# ---
|
|
# apiVersion: traefik.io/v1alpha1
|
|
# kind: IngressRoute
|
|
# metadata:
|
|
# name: xui-prod
|
|
# namespace: xui
|
|
# spec:
|
|
# entryPoints:
|
|
# - websecure
|
|
# routes:
|
|
# - match: Host(`xui.forust.xyz`)
|
|
# kind: Rule
|
|
# middlewares:
|
|
# - name: security-chain@file
|
|
# services:
|
|
# - name: xui-service
|
|
# port: 30379
|
|
# tls:
|
|
# certResolver: letsencrypt
|
|
---
|
|
apiVersion: traefik.io/v1alpha1
|
|
kind: IngressRoute
|
|
metadata:
|
|
name: xray-prod
|
|
namespace: xui
|
|
spec:
|
|
entryPoints:
|
|
- websecure
|
|
routes:
|
|
- match: Host(`xray.forust.xyz`) && PathPrefix(`/pzzfpz6oi281f0u8`)
|
|
kind: Rule
|
|
services:
|
|
- name: xui-service
|
|
port: 2096
|
|
- match: Host(`xray.forust.xyz`)
|
|
kind: Rule
|
|
services:
|
|
- name: xui-service
|
|
port: 10000
|
|
tls:
|
|
secretName: xray-prod-tls
|
|
---
|
|
apiVersion: traefik.io/v1alpha1
|
|
kind: IngressRoute
|
|
metadata:
|
|
name: xray-local
|
|
namespace: xui
|
|
spec:
|
|
entryPoints:
|
|
- websecure
|
|
routes:
|
|
- match: (Host(`xray.workstation.internal`) || Host(`xray.gigaforust.internal`)) && PathPrefix(`/pzzfpz6oi281f0u8`)
|
|
kind: Rule
|
|
services:
|
|
- name: xui-service
|
|
port: 2096
|
|
- match: Host(`xray.workstation.internal`) || Host(`xray.gigaforust.internal`)
|
|
kind: Rule
|
|
services:
|
|
- name: xui-service
|
|
port: 10000
|