feat(traefik): route *.falcon.pivoine.art to apps on falcon over Tailscale
Falcon (home machine) stays off the public internet; the VPS Traefik terminates TLS/ACME as usual and forwards to falcon's tailnet IP.
This commit is contained in:
@@ -0,0 +1,38 @@
|
|||||||
|
# Routes for apps running on the local machine "falcon", reached over the
|
||||||
|
# Tailscale/Headscale mesh (falcon's tailnet IP: 100.64.0.1). DNS for
|
||||||
|
# *.falcon.pivoine.art points here (the VPS), which terminates TLS and
|
||||||
|
# forwards over the tunnel — falcon itself is never exposed directly.
|
||||||
|
#
|
||||||
|
# To add another app: duplicate the <name>-web / <name>-web-secure routers
|
||||||
|
# and the service block below, swap the hostname and backend port.
|
||||||
|
|
||||||
|
http:
|
||||||
|
middlewares:
|
||||||
|
triggershell-redirect-web-secure:
|
||||||
|
redirectScheme:
|
||||||
|
scheme: https
|
||||||
|
|
||||||
|
routers:
|
||||||
|
triggershell-web:
|
||||||
|
rule: "Host(`triggershell.falcon.pivoine.art`)"
|
||||||
|
entrypoints:
|
||||||
|
- web
|
||||||
|
middlewares:
|
||||||
|
- triggershell-redirect-web-secure
|
||||||
|
service: triggershell
|
||||||
|
|
||||||
|
triggershell-web-secure:
|
||||||
|
rule: "Host(`triggershell.falcon.pivoine.art`)"
|
||||||
|
entrypoints:
|
||||||
|
- web-secure
|
||||||
|
tls:
|
||||||
|
certResolver: resolver
|
||||||
|
middlewares:
|
||||||
|
- security-headers@file
|
||||||
|
service: triggershell
|
||||||
|
|
||||||
|
services:
|
||||||
|
triggershell:
|
||||||
|
loadBalancer:
|
||||||
|
servers:
|
||||||
|
- url: "http://100.64.0.1:4173"
|
||||||
Reference in New Issue
Block a user