Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ## EXTERNAL ROUTING - Only use if you want to proxy something manually ##
- routers:
- # Plex routing - Remove if not used
- plex:
- entryPoints:
- - https
- rule: 'Host(`plex.eksen.duckdns.org`)'
- service: plex
- # middlewares:
- # - "auth"
- ## SERVICES ##
- services:
- # Plex service - Remove if not used
- plex:
- loadBalancer:
- servers:
- - url: http://192.168.0.178:32400/
- ## MIDDLEWARES ##
- middlewares:
- # Only Allow Local networks
- local-ipallowlist:
- ipAllowList:
- sourceRange:
- - 172.20.0.0/32 # localhost
- - 192.168.0.0/24 # LAN Subnet
- # used for crowdsec-bouncer
- crowdsec-bouncer:
- forwardauth:
- address: http://crowdsec-traefik-bouncer:8080/api/v1/forwardAuth
- trustForwardHeader: true
- # Authentik
- auth:
- forwardauth:
- address: http://authentik-server:9000/outpost.goauthentik.io/auth/traefik
- trustForwardHeader: true
- authResponseHeaders:
- - X-authentik-username
- - X-authentik-groups
- - X-authentik-email
- - X-authentik-name
- - X-authentik-uid
- - X-authentik-jwt
- - X-authentik-meta-jwks
- - X-authentik-meta-outpost
- - X-authentik-meta-provider
- - X-authentik-meta-app
- - X-authentik-meta-version
- # Security headers
- securityHeaders:
- headers:
- customResponseHeaders:
- X-Robots-Tag: "none,noarchive,nosnippet,notranslate,noimageindex"
- X-Forwarded-Proto: "https"
- server: ""
- customRequestHeaders:
- X-Forwarded-Proto: "https"
- sslProxyHeaders:
- X-Forwarded-Proto: "https"
- referrerPolicy: "same-origin"
- hostsProxyHeaders:
- - "X-Forwarded-Host"
- contentTypeNosniff: true
- browserXssFilter: true
- forceSTSHeader: true
- stsIncludeSubdomains: true
- stsSeconds: 63072000
- stsPreload: true
- # Only use secure ciphers - https://ssl-config.mozilla.org/#server=traefik&version=2.6.0&config=intermediate&guideline=5.6
- tls:
- options:
- default:
- minVersion: VersionTLS12
- cipherSuites:
- - TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
- - TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- - TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- - TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- - TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
- - TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement