expose Traefik dashboard on traefik.pivoine.art, vpn-only gated
Previous attempt tried a separate internal-only :8080 entrypoint for pulsenode to reach the API directly - that turned out to 404 no matter what (--api.dashboard=true alone didn't register a working router there, and adding --api=true plus an explicit entrypoint still didn't produce a matching router; verified against a local traefik:v3 container before giving up on that path rather than keep guessing against the live one). Cleaner approach: expose it through the same web/web-secure entrypoints everything else already uses, via a new file-provider router (traefik/dynamic/dashboard.yaml) matching Traefik's own documented self-referencing pattern - Host(`traefik.pivoine.art`) && (PathPrefix(`/api`) || PathPrefix(`/dashboard`)) routed to the built-in api@internal service, gated by vpn-only same as pulsenode's own router. vpn-only's sourceRange now also includes falcon_network's own subnet (172.18.0.0/16) alongside the tailnet ranges - a container on our own internal docker network is as trusted as a tailnet peer, and without this pulsenode's own request to the API (a container-to-container call, not a VPN-sourced one) would get the same 403 a random internet visitor would. pulsenode's traefik widget now points at https://traefik.pivoine.art/api instead of the internal :8080 attempt.
This commit is contained in:
@@ -0,0 +1,32 @@
|
||||
# Exposes Traefik's own API/dashboard (api@internal is a built-in service,
|
||||
# not something defined below) on traefik.pivoine.art, gated by vpn-only.
|
||||
# Path prefixes match Traefik's own documented self-referencing pattern:
|
||||
# /api serves the JSON pulsenode's traefik widget reads, /dashboard serves
|
||||
# the browsable UI.
|
||||
http:
|
||||
middlewares:
|
||||
traefik-redirect-web-secure:
|
||||
redirectScheme:
|
||||
scheme: https
|
||||
|
||||
routers:
|
||||
traefik-dashboard-web:
|
||||
rule: "Host(`traefik.pivoine.art`) && (PathPrefix(`/api`) || PathPrefix(`/dashboard`))"
|
||||
entrypoints:
|
||||
- web
|
||||
middlewares:
|
||||
- vpn-only@file
|
||||
- traefik-redirect-web-secure
|
||||
service: api@internal
|
||||
|
||||
traefik-dashboard-web-secure:
|
||||
rule: "Host(`traefik.pivoine.art`) && (PathPrefix(`/api`) || PathPrefix(`/dashboard`))"
|
||||
entrypoints:
|
||||
- web-secure
|
||||
tls:
|
||||
certResolver: resolver
|
||||
middlewares:
|
||||
- vpn-only@file
|
||||
- security-headers@file
|
||||
- no-index@file
|
||||
service: api@internal
|
||||
Reference in New Issue
Block a user