-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
81 lines (79 loc) · 2.64 KB
/
Copy pathdocker-compose.yml
File metadata and controls
81 lines (79 loc) · 2.64 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
services:
# Docker Socket Proxy - Restricts Docker API access
docker-socket-proxy:
image: tecnativa/docker-socket-proxy:latest
container_name: docker-socket-proxy
restart: unless-stopped
privileged: true
networks:
- socket_proxy_net
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
environment:
- CONTAINERS=1
- IMAGES=1
- NETWORKS=0
- VOLUMES=0
- POST=1
- BUILD=0
- COMMIT=0
- EXEC=0
- INFO=1
- PING=1
- VERSION=1
- EVENTS=1
- LOG_LEVEL=info
traefik:
image: "traefik:v3.7"
container_name: "traefik_reverse_proxy"
restart: unless-stopped
security_opt:
- no-new-privileges:true
command:
- "--api.dashboard=true"
- "--api.insecure=false"
- "--providers.docker=true"
- "--providers.docker.endpoint=tcp://docker-socket-proxy:2375"
- "--providers.docker.exposedbydefault=false"
- "--entrypoints.web.address=:80"
- "--entrypoints.web.http.redirections.entrypoint.to=websecure"
- "--entrypoints.web.http.redirections.entrypoint.scheme=https"
- "--entrypoints.websecure.address=:443"
- "--certificatesresolvers.cloudflare.acme.dnschallenge=true"
- "--certificatesresolvers.cloudflare.acme.dnschallenge.provider=${TRAEFIK_CERT_RESOLVER}"
- "--certificatesresolvers.cloudflare.acme.email=${ACME_EMAIL}"
- "--certificatesresolvers.cloudflare.acme.storage=/letsencrypt/acme.json"
- "--log.level=INFO"
- "--providers.file.directory=/dynamic"
networks:
- "traefik_net"
- "socket_proxy_net"
ports:
- "80:80"
- "443:443"
- "8080:8080"
environment:
- "CLOUDFLARE_DNS_API_TOKEN=${CLOUDFLARE_API_TOKEN}"
volumes:
- "./letsencrypt:/letsencrypt"
- "./dynamic:/dynamic"
depends_on:
- "docker-socket-proxy"
labels:
- "traefik.enable=true"
- "traefik.http.routers.traefik-dashboard.rule=Host(`traefik.${DOMAIN_NAME}`)"
- "traefik.http.routers.traefik-dashboard.entrypoints=websecure"
- "traefik.http.routers.traefik-dashboard.priority=10"
- "traefik.http.routers.traefik-dashboard.tls=true"
- "traefik.http.routers.traefik-dashboard.tls.certresolver=${TRAEFIK_CERT_RESOLVER}"
- "traefik.http.routers.traefik-dashboard.service=api@internal"
- "traefik.http.middlewares.traefik-auth.basicauth.users=admin:${TRAEFIK_ADMIN_AUTH}"
- "traefik.http.routers.traefik-dashboard.middlewares=traefik-auth"
networks:
traefik_net:
name: traefik_net
driver: bridge
socket_proxy_net:
name: socket_proxy_net
driver: bridge
internal: true