Previous attempt tried a separate internal-only :8080 entrypoint for pulsenode to reach the API directly - that turned out to 404 no matter what (--api.dashboard=true alone didn't register a working router there, and adding --api=true plus an explicit entrypoint still didn't produce a matching router; verified against a local traefik:v3 container before giving up on that path rather than keep guessing against the live one). Cleaner approach: expose it through the same web/web-secure entrypoints everything else already uses, via a new file-provider router (traefik/dynamic/dashboard.yaml) matching Traefik's own documented self-referencing pattern - Host(`traefik.pivoine.art`) && (PathPrefix(`/api`) || PathPrefix(`/dashboard`)) routed to the built-in api@internal service, gated by vpn-only same as pulsenode's own router. vpn-only's sourceRange now also includes falcon_network's own subnet (172.18.0.0/16) alongside the tailnet ranges - a container on our own internal docker network is as trusted as a tailnet peer, and without this pulsenode's own request to the API (a container-to-container call, not a VPN-sourced one) would get the same 403 a random internet visitor would. pulsenode's traefik widget now points at https://traefik.pivoine.art/api instead of the internal :8080 attempt.
72 lines
1.5 KiB
YAML
72 lines
1.5 KiB
YAML
settings:
|
|
title: PulseNode
|
|
|
|
theme:
|
|
mode: dark
|
|
|
|
groups:
|
|
- name: Services
|
|
widgets:
|
|
- type: system
|
|
interval: 5s
|
|
|
|
- type: traefik
|
|
name: Traefik
|
|
apiUrl: https://traefik.pivoine.art/api
|
|
interval: 15s
|
|
|
|
- type: docker
|
|
name: Coolify
|
|
containerName: coolify
|
|
icon: coolify
|
|
href: https://${TRAEFIK_HOST_COOLIFY}
|
|
interval: 10s
|
|
|
|
- type: docker
|
|
name: Gitea
|
|
containerName: gitea
|
|
icon: gitea
|
|
href: https://${TRAEFIK_HOST_GITEA}
|
|
interval: 10s
|
|
|
|
- type: docker
|
|
name: Code Server
|
|
containerName: code
|
|
href: https://${TRAEFIK_HOST_CODE}
|
|
interval: 10s
|
|
|
|
- type: docker
|
|
name: Immich
|
|
containerName: immich
|
|
icon: immich
|
|
href: https://${TRAEFIK_HOST_IMMICH}
|
|
interval: 10s
|
|
|
|
- type: docker
|
|
name: n8n
|
|
containerName: n8n
|
|
icon: n8n
|
|
href: https://${TRAEFIK_HOST_N8N}
|
|
interval: 10s
|
|
|
|
- type: docker
|
|
name: Passbolt
|
|
containerName: passbolt
|
|
icon: passbolt
|
|
href: https://${TRAEFIK_HOST_PASSBOLT}
|
|
interval: 10s
|
|
|
|
- type: docker
|
|
name: Umami
|
|
containerName: umami
|
|
icon: umami
|
|
href: https://${TRAEFIK_HOST_UMAMI}
|
|
interval: 10s
|
|
|
|
- type: docker
|
|
name: Headscale
|
|
containerName: headscale
|
|
icon: headscale
|
|
href: https://${TRAEFIK_HOST_HEADSCALE}
|
|
interval: 10s
|