1e8d045815
- felhom-tunnel network 172.16.253.0/29 (ip-range .4/30): cloudflared alone at .2, traefik at .3; traefik's websecure trusts forwarded headers from 172.16.253.2/32 only, and every request passes felhom-forwarded@file, which removes the client-writable host/path/address headers (X-Forwarded-Host/-Uri/-Method/-Prefix, Forwarded, True-Client-Ip, …) and fixes X-Forwarded-Port to 443 (measured: Cloudflare passes a client's X-Forwarded-Host/-Port). - EnsureBaseStack reconciles a RUNNING traefik/cloudflared whose rendered files changed (recreate), refuses a rewrite that would drop a certificate resolver, and moves cloudflared only once traefik is on the tunnel network. - clientIP: believed only when the TCP peer is traefik; the rightmost X-Forwarded-For entry (the hop traefik saw); the tunnel hop → CF-Connecting-IP (the edge refuses a client-sent one, measured 403). rateKey: IPv6 per /64. Dashboard login, claim, share and escrow counters key on it; the setup gate logs it. - Dashboard login messages: keys, informal voice, both languages. Red-proofs: RP-A1 (leftmost hop), RP-A2 (shared tunnel key), RP-A3 (no reconcile) — felhom.eu audits/visitors-2026-10-01/A. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
42 lines
912 B
Cheetah
42 lines
912 B
Cheetah
# Traefik Reverse Proxy — managed by felhom-controller (base-infra bring-up).
|
|
services:
|
|
traefik:
|
|
image: {{.Image}}
|
|
container_name: traefik
|
|
restart: unless-stopped
|
|
dns:
|
|
- 1.1.1.1
|
|
- 8.8.8.8
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
ports:
|
|
- "80:80"
|
|
- "443:443"
|
|
{{- if .CFAPIToken}}
|
|
env_file:
|
|
- .env
|
|
{{- end}}
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
|
- ./traefik.yml:/etc/traefik/traefik.yml:ro
|
|
- ./dynamic:/etc/traefik/dynamic:ro
|
|
- ./acme.json:/etc/traefik/acme.json
|
|
- ./certs:/etc/traefik/certs:ro
|
|
{{- if .Tunnel}}
|
|
networks:
|
|
traefik-public: {}
|
|
{{.TunnelNetwork}}:
|
|
ipv4_address: {{.TunnelTraefikAddr}}
|
|
{{- else}}
|
|
networks:
|
|
- traefik-public
|
|
{{- end}}
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|
|
{{- if .Tunnel}}
|
|
{{.TunnelNetwork}}:
|
|
external: true
|
|
{{- end}}
|